Technical standards & interoperability
The standards our platform is built on

Built on the open standards of the DPP ecosystem
A Digital Product Passport only works if it is interoperable — with the EU registry, with GS1 identifiers and with your partners' systems. WIARA's platform is built on the open standards of the ecosystem, so you are not locked into one solution and your passports can be read everywhere.
See what it looks like in practice on the platform and what the Digital Product Passport →
Key capabilities
Technical standards & interoperability
We publish what we cannot do yet
The table below has three states: ✅ supported today, ◐ partly there — in preparation or not yet complete, and 🔜 on the roadmap. We publish all three — including the things we cannot do yet.
“Full compliance” is a sentence a buyer has no way to check. A table broken down by standard, with a date on it, can be checked in minutes. That is why we keep ours this way — and why it is worth asking the same of every provider you are looking at: a separate status per standard, and the date it holds good.
The criteria worth comparing them on are set out separately.
Standards & interoperability
Which standards and capabilities the platform supports today.
EU DPP Registry
◐ In preparation — The registry has been live since 20 July 2026 under Implementing Regulation (EU) 2026/1778. The platform produces passports in the registry’s format; the production connection is being built, and registration also requires a qualified electronic seal.
GS1 Digital Link
✅ Supported — A standard data carrier — a QR code that opens the passport and stays valid for the product's whole life.
GTIN
✅ Supported — Global Trade Item Number as part of the product's identification.
REST API
✅ Supported — Full programmatic access for integration with your ERP and PLM systems.
CIRPASS-2
✅ Aligned — Built to the CIRPASS-2 reference architecture and data models.
Role-based access + eIDAS
✅ Supported — Roles for the public, economic operators (recyclers, service centres, importers) and authorities via eIDAS.
EN 18216–18223
◐ Built to them — The platform implements the technical decisions the six standards lock in: GS1 identifiers, QR/NFC carriers, REST APIs, JSON-LD, long-term retention. They were cited in the Official Journal on 15 July 2026; a full conformity assessment has not been carried out, and the two security standards (EN 18239, EN 18246) are not yet published.
EPCIS 2.0
🔜 On the roadmap — Supply-chain event traceability — coming on the roadmap.
How to check each of these
Every row above is a claim. Here is what each one rests on and where you can verify it yourself — the standard it follows and the page that shows it working.
Unique product identifier (EN 18219) — every passport is identified by a UPI built on the GS1 GTIN and opened through GS1 Digital Link, with a resolver conforming to ISO/IEC 18975. See it working in a demo passport or on the API page.
Data carrier (EN 18220) — QR as the primary carrier, NFC and RFID as secondary. Every demo passport opens from its own QR code.
Machine-readable content (EN 18223) — every published passport carries JSON-LD and Schema.org, not a proprietary format. View the source of a demo passport, or read the API page.
Programmatic access (EN 18222) — over a hundred operations documented to OpenAPI 3.0.3; the dashboard is a client of the same interface you are given. Details on API and integrations.
Long-term availability (EN 18221) — published passports stay reachable for the product's lifecycle plus ten years, and the audit trail is kept for seven. Stated on pricing and security.
Legal status of these standards — the six were cited in the Official Journal on 15 July 2026 by Implementing Decision (EU) 2026/1736, which carries a presumption of conformity with ESPR Articles 10 and 11. The two security standards, EN 18239 and EN 18246, are not yet published — so no such presumption exists for access rights or data authentication, ours or anyone else's.
Information security — ISO/IEC 27001:2022, certificate BG2026030401, issued by INCERT, valid to 3 March 2029. Verify it independently in the IAF global database.
EU registry — live since 20 July 2026 under Implementing Regulation (EU) 2026/1778. Our production connection is in preparation, and registration additionally requires a qualified electronic seal for your legal entity.
Who is responsible for what. WIARA answers for the platform: availability, data integrity, the passport format to EN 18216–18223, the audit trail and export in open formats. The manufacturer answers for the accuracy of the declared data and the conformity of the product — under the ESPR and the CPR that responsibility does not pass to a software provider. More on security.
Technical standards
Frequently asked questions
GS1 Digital Link is a standard way for a single QR code to point to a product's passport. We use it so the data carrier is interoperable and valid for the product's whole life.
EPCIS 2.0 (supply-chain traceability events) is on our roadmap. The basic passport does not require EPCIS; for traceability-heavy sectors we plan it as an extension.
Through role-based access. Market surveillance authorities log in via eIDAS (the European digital identity) and see the data intended for them, separate from the public and professional views.
Yes, we offer a REST API for programmatic access, so passports connect directly to your ERP, PLM or production systems.


