Glossary · DPP: data, identifiers and standards
UpdatedDPP security standards (EN 18239:2026 and EN 18246:2026)
Also known as: EN 18239, EN 18246, EN 18239:2026, EN 18246:2026, DPP access and integrity standards, prEN 18239, prEN 18246
The DPP security standards are two final European standards for the digital product passport, made available by CEN/CENELEC on September 16, 2026: EN 18239:2026 on access rights management, information system security and business confidentiality, and EN 18246:2026 on data authentication, reliability and integrity. As of September 27, 2026 their references were not cited in the Official Journal of the European Union, so they do not confer presumption of conformity with the ESPR requirements they address.
- EU
- DPP
- Data governance
In one sentence
EN 18239:2026 (access, security, confidentiality) and EN 18246:2026 (authentication, integrity) are final DPP standards, not yet cited in the OJEU.
Example
A company designing its passport access model applies EN 18239:2026, records the edition in its documentation and adds its own risk-based justification, because the standard is not yet cited and gives no presumption of conformity.
How it applies
- Status: Both are final European standards. Their references are not cited in the Official Journal — Implementing Decision (EU) 2026/1736 lists only EN 18216 and EN 18219–18223 — so they do not confer presumption of conformity. Re-check the citation status before stating it.
- Subjects: EN 18239:2026 addresses access rights, information system security and business confidentiality; EN 18246:2026 addresses authentication, reliability and integrity of passport data.
- Using them now: Teams can apply the standards before citation, but they still justify their access, security and trust mechanisms on their own responsibility. Record the edition applied, and re-check the implementation when the references are cited. Most of the organizational work lies there anyway.
- Security law: Passport systems and connected products may also fall under the Cyber Resilience Act; the DPP standards do not replace its requirements.
Compared with the USA, Canada and China
No other of the four has security standards for a product passport. Access and security for traceability data follow general cybersecurity rules and frameworks, such as the NIST frameworks in the USA or China's data security and cybersecurity laws.
Read more on AI TechDoc Press
The in-depth analysis behind this entry, in the AI TechDoc Press newsletter. Subscribe for free