How Conformity Assessment Works for Digital Product Passports

Executive Summary

Two questions are constantly conflated in Digital Product Passport programmes. The first is “does this product meet the requirements that apply to it?” The second is “is the required product information available in the required form?” The first question is answered through conformity assessment. The second is increasingly answered, in part, through a Digital Product Passport. They interact. They are not the same thing, and treating them as the same thing is one of the more consequential mistakes an enterprise can make.

Conformity assessment is the process of determining or demonstrating whether specified requirements have been fulfilled. It exists because the Union market operates on the principle that products placed on it satisfy the applicable requirements, and that the operator responsible can show it. A Digital Product Passport, by contrast, is a mechanism for making specified product information available in a structured, accessible form where the applicable framework requires it. A complete passport does not establish that a product conforms. A conforming product does not automatically have a compliant passport.

The relationship between them runs in one direction more strongly than the other. Requirements come first. Assessment establishes whether those requirements are fulfilled. That assessment produces or relies upon evidence, technical documentation and, where the applicable legislation requires it, a declaration. Only then does a subset of that information, where required by the applicable framework, become passport content. The passport is downstream. It is a publication surface over a compliance environment that must already exist.

This article introduces the DPP Conformity Assessment Relationship Model, a tieback educational model describing four layers, applicable requirements, conformity assessment, compliance evidence and documentation, and Digital Product Passport information, together with two relationships that run across them: a consistency relationship, requiring that published passport information does not contradict the authoritative compliance record, and a surveillance relationship, recording that authorities may examine both the passport and the underlying compliance environment without the passport ever substituting for the assessment.

It also corrects a second widespread error. Conformity assessment is not a synonym for third-party certification. Depending on the applicable legislation, the required procedure may be performed by the manufacturer through internal production control, or it may require testing, examination, quality-system assessment, product or unit verification, or the involvement of a notified body. There is no universal DPP conformity-assessment procedure, and this article does not invent one.

Key Takeaways
  • Conformity assessment determines or demonstrates whether specified requirements have been fulfilled. A Digital Product Passport makes specified product information available. They are distinct instruments that interact. - A passport is not a certificate, a declaration, technical documentation, a notified-body opinion or proof that every applicable product requirement has been satisfied. - The required conformity-assessment procedure depends on the applicable legislation. Some regimes permit manufacturer self-assessment. Others require third-party involvement for some or all requirements. - No notified body does not mean no conformity assessment, and notified-body involvement does not transfer statutory responsibility away from the operator the law identifies.
  • Harmonised standards are voluntary, but where the applicable legislation provides and the reference has been published, applying them can give rise to a presumption of conformity limited to the requirements those standards cover. - Passport information must remain consistent with the authoritative compliance record. Inconsistency is a compliance and surveillance problem even when the underlying product conforms.

This is the seventh article in the Regulations section, and the third and final article in the three-part sequence covering the back half of the regulatory journey. It follows How Digital Product Passports Will Be Enforced, which explains what authorities may do, and Who Is Legally Responsible for a Digital Product Passport?, which explains who they may look to. This article explains the compliance environment that sits behind both.

FrameworkTBF-040
The DPP Conformity Assessment Relationship Model

A four layer educational model describing how conformity assessment relates to a Digital Product Passport. Layer one, applicable requirements, holds the framework legislation, product specific measures, delegated and implementing measures, technical requirements and any standards or specifications used. Layer two, conformity assessment, holds the procedure prescribed or permitted by the applicable legislation, including internal production control, testing, examination, quality system assessment, product verification and unit verification, with a conditional branch for third party or notified body involvement that applies only where the applicable legislation requires it. Layer three, compliance evidence and documentation, holds technical documentation, test reports, calculations, risk assessment, supplier declarations, assessment outputs, certificates where applicable and the declaration of conformity where required. Layer four, Digital Product Passport information, holds the narrower subset of information the applicable framework requires to be available through the passport. Two relationships run across the layers: a consistency rail requiring that published passport information does not contradict the authoritative compliance record, and a market surveillance feedback path recording that authorities may examine both the passport and the underlying compliance environment without the passport replacing the assessment. An economic operator responsibility rail runs the full height of the stack, recording that arranging work through a laboratory, consultant or notified body performs the work without moving the statutory obligation. The model is built on the principles that conformity assessment determines or demonstrates whether specified requirements have been fulfilled while a passport makes specified information available, that conformity assessment is not a synonym for third party certification, that self assessment is real assessment, and that publishing correct information is not the same as maintaining conformity. It begins from the requirements produced by the ESPR framework TBF-005 and the product specific measures of the delegated act model TBF-006 without restating them, draws its boundary against the enterprise data controls of the data validation control model TBF-033, consumes but does not recreate the evidence lifecycle TBF-034, states that the enterprise assurance model TBF-035 has no statutory conformity status, supplies the compliance environment that the enforcement lifecycle TBF-038 later examines, and pairs with the legal responsibility model TBF-039 by describing what conformity related responsibilities must be performed or arranged by the operator that model identifies.

Educational scope

This article provides general educational information about EU product regulation concepts. It does not determine the conformity-assessment obligations applicable to any particular organisation, product or market, and it is not legal advice. Which procedure applies to a given product is a legal question that depends on the applicable legislation and the specific facts.

Table of Contents

Definition

Definition
Conformity assessment

The process of determining or demonstrating whether specified requirements relating to a product, process, service, system, person or body have been fulfilled. In EU product legislation, the specified requirements are those set by the applicable Union act and any product-specific measure adopted under it, and the procedure to be followed is the one that the applicable legislation prescribes or permits for the product concerned.

Three features of that definition matter more than the wording itself.

First, conformity assessment is always relative to specified requirements. There is no abstract state of being “assessed”. A product is assessed against particular requirements arising from particular legislation. Change the requirements and the assessment question changes with them.

Second, conformity assessment is a process, not a document. Certificates, reports and declarations are outputs of, or inputs into, the process. They are not the process itself, and possessing one of them does not mean the applicable procedure was followed.

Third, conformity assessment is prescribed. The operator does not generally get to choose a convenient method. Where the applicable legislation specifies which procedures may be used, the choice is confined to those procedures, and in some cases to one procedure only.

Terminology used in this article

This article uses “applicable legislation” to mean the specific Union act, and any product-specific measure adopted under it, that governs the product in question. It deliberately avoids stating that any particular procedure, document or body applies to Digital Product Passport products generally, because at framework level no such universal rule exists.

Conformity Assessment and Digital Product Passports

The clearest way to hold the two apart is to state what each one answers.

Conformity assessment answers: have the specified requirements been fulfilled, and can that be demonstrated?

A Digital Product Passport answers: is the required product information available, in the required structure, to the parties entitled to see it?

These are different questions with different failure modes. A product can fulfil every applicable substantive requirement and still fail an information obligation because its passport is incomplete, inaccessible or wrong. A product can have an immaculate passport and still fail a substantive requirement, in which case the passport merely documents a non-conforming product accurately.

A Digital Product Passport is therefore not automatically any of the following:

  • A conformity assessment. It is a publication of information, not a determination that requirements have been met.
  • A certificate. Certification is a third-party attestation issued in a defined process. A passport is not issued by an attestation body by virtue of being a passport.
  • An EU declaration of conformity. Where the applicable legislation requires a declaration, that is a specific legal instrument with a defined author and defined content.
  • Technical documentation. The technical file supports the assessment and is generally made available to authorities on request rather than published.
  • A notified-body opinion. Where a notified body is involved, its output is defined by the procedure it performed, not by what appears in the passport.
  • Proof that every product requirement has been satisfied. A passport typically carries a selected subset of information. Silence in a passport is not evidence of conformity, and presence in a passport is not proof of it.
Tip

A useful internal test: if the passport were deleted tomorrow, which applicable requirements would still have to be met, and which documents would still have to exist? Almost all of them. That is the size of the compliance environment sitting underneath the passport.

The interaction runs both ways, but asymmetrically. Conformity work produces information that may populate the passport. The passport produces visibility that may draw attention to the conformity work. What the passport never does is discharge the assessment obligation.

The DPP Conformity Assessment Relationship Model

The DPP Conformity Assessment Relationship Model is a tieback educational model. No EU instrument defines it. Its purpose is to give programme teams a stable way to reason about where conformity work sits relative to passport work, so that the two are neither merged nor separated into silos that drift apart.

The model describes four layers and two cross-cutting relationships.

Two properties of the model are worth stating explicitly.

The layers are directional but not sequential in time. Requirements precede assessment logically, and evidence precedes publication logically, but in a real programme all four layers are live at once across a portfolio. One product is being assessed while another is being republished after a supplier change.

The layers are not interchangeable. Work performed at Layer 4 cannot satisfy an obligation arising at Layer 2. This is the single most common structural error in DPP programmes, and it usually appears as a plan that treats “populating the passport” as the compliance deliverable.

Layer 1: Applicable Requirements

Conformity assessment begins with specified requirements. Until those are identified, there is nothing to assess against, and any assessment activity is guesswork with documentation attached.

Requirements relevant to a product may arise from several sources, depending on the product and the market:

  • Directly applicable Union legislation, such as a regulation that imposes obligations without national transposition.
  • Product-specific measures adopted under a framework act, which set the requirements that actually bite for a given product group.
  • Delegated acts, where the framework empowers the Commission to adopt them, as What Are Delegated Acts? explains in detail.
  • Implementing measures, where the applicable framework provides for them.
  • Technical requirements expressed in the applicable act, including performance, information and documentation requirements.
  • Standards or technical specifications, where the applicable framework gives them a role.

Under the ESPR framework, this layering is explicit: the framework regulation creates the machinery, and product-specific measures determine what a given product group must satisfy. That structure is covered in What is the Ecodesign for Sustainable Products Regulation (ESPR)?, and the question of which products are affected, and when, is covered in Which Products Will Require a Digital Product Passport? and When Will Digital Product Passports Become Mandatory?. This article does not restate them.

Best Practice

Maintain a requirements register per product and per market before designing any assessment activity. Record the instrument, the specific requirement, whether it is in force, the applicable date, and whether an assessment procedure is prescribed. A requirements register that lists laws rather than requirements is not yet usable.

The governing principle of this layer is uncomfortable but unavoidable:

You cannot design conformity assessment until you know which requirements apply.

Programmes that invert this order, by building data collection and passport publication first and mapping requirements later, tend to discover late that they have collected the wrong information to a standard of evidence nobody can defend.

Layer 2: Conformity Assessment

At this layer, the question is narrow and consistent regardless of product: has the specified requirement been fulfilled, and can that be demonstrated in the way the applicable legislation requires?

Conformity assessment in EU product legislation generally has three characteristics. It is tied to specified requirements. It follows a prescribed procedure. It produces or relies on a record capable of demonstrating the conclusion to someone who was not present when the work was done.

It is worth separating conformity assessment from five things that resemble it:

  • Data validation asks whether data satisfies defined rules. It is an enterprise control, covered by How to Validate Digital Product Passport Data.
  • Verification of an individual claim asks whether a specific statement is supported. It may form part of an assessment, but it is narrower than the assessment as a whole.
  • Enterprise assurance asks whether an organisation’s own capability is ready and controlled, as covered by How to Test and Assure a Digital Product Passport.
  • Market surveillance is performed by competent authorities on products already on the market.
  • Certification is one form of third-party attestation. It is a possible component of some procedures, not a synonym for the concept.
  • DPP publication makes information available. It is an information obligation, not an assessment method.

Each of these can interact with conformity assessment. None of them is conformity assessment.

How Conformity Assessment Procedures Differ

EU product legislation does not use a single procedure. Instead, the framework for the marketing of products, established by Decision No 768/2008/EC, sets out a menu of conformity-assessment modules which individual pieces of legislation then draw on, adapt and prescribe. The modules exist so that the intensity of assessment can be matched to the risk and nature of the requirement rather than applied uniformly.

Expressed conceptually, the recurring approaches include:

  • Internal production control. The manufacturer carries out the assessment itself, prepares technical documentation, and takes the measures needed to ensure that manufactured products conform to that documentation and to the applicable requirements. No third party is involved in the assessment as such.
  • Examination. A defined examination of the product design or of a representative specimen against the applicable requirements, which in some legislation is performed by a third party.
  • Testing. Determination of characteristics against a defined method, whether performed internally, by an external laboratory, or under third-party supervision, according to what the applicable legislation provides.
  • Quality assurance approaches. Assessment of the manufacturer’s quality system for production, final inspection or the full lifecycle, rather than of individual units.
  • Product verification. Checking conformity of products, in some cases by examination and testing of every product and in others on a statistical basis.
  • Unit verification. Assessment of a single product, typically used where products are made individually or in very small numbers.
  • Third-party assessment. Involvement of a body independent of the manufacturer, in the specific role that the applicable procedure defines.
Do not assume module portability

Module labels recur across EU product legislation, but the exact obligations attaching to a module are defined by the act that prescribes it. Two regimes can use similarly named procedures with materially different content. Always read the procedure as set out in the applicable act rather than relying on familiarity from another regime.

Which of these applies to a product is determined by the applicable legislation, not by preference, precedent or industry habit. In some cases the legislation offers a choice between listed procedures. In others it prescribes exactly one. In others still, the procedure varies by requirement, so that a single product may be subject to different assessment intensities for different characteristics.

For Digital Product Passport purposes, the practical consequence is that no single answer exists to “what conformity assessment do we need for our DPP?” The passport does not carry its own assessment procedure at framework level. The relevant procedures are those that apply to the product’s substantive and information requirements under the acts that govern it.

Self-Assessment vs Third-Party Assessment

This distinction deserves its own treatment because it is the source of two symmetrical errors.

Some EU product regimes permit the manufacturer to perform the required conformity assessment itself, without the involvement of any third party. Where the applicable legislation provides for internal production control, the manufacturer performs the assessment, compiles the technical documentation, applies the required marking where relevant, and draws up the declaration where required. The obligation is fully discharged without an external body being involved in the assessment.

Other regimes, or specific requirements within a regime, require third-party involvement. Where this is the case, the applicable legislation defines what the third party does, which is usually much narrower than “approving the product”.

From this follow two statements that need to be repeated inside programmes until they stick.

No notified body does not mean no conformity assessment. Self-assessment is assessment. It carries the same requirement to determine that the applicable requirements are fulfilled, the same requirement to hold technical documentation where applicable, and the same exposure during market surveillance. It is not a lighter obligation, only a differently supervised one. Organisations that read “self-assessment” as “no work required” typically discover the gap when an authority requests documentation.

Notified-body involvement does not mean the notified body owns the DPP. A notified body performs the task the procedure assigns to it. It does not thereby become responsible for the accuracy of passport content, for keeping information current, for publishing the passport, or for the product’s continuing conformity in production. Those responsibilities sit where the applicable legislation places them, as Who Is Legally Responsible for a Digital Product Passport? sets out.

Common Mistake

Treating the choice between self-assessment and third-party assessment as a commercial or risk preference. Where the applicable legislation prescribes the procedure, it is not a decision the operator gets to make. Where the legislation offers a choice, the choice is confined to the listed options and must be documented.

What Is a Notified Body?

A notified body is a conformity assessment body that has been designated by a Member State and notified to the Commission and the other Member States to carry out third-party conformity-assessment tasks under specific Union legislation. The framework for accreditation and for the notification of such bodies is set out in Regulation (EC) No 765/2008 and in Decision No 768/2008/EC, with the detailed tasks defined by the legislation under which the body is notified.

Four points matter for DPP programmes.

Notified bodies act within specific procedures under specific legislation. A body is not notified in general. It is notified for defined tasks under defined acts, and it may act only within that scope. A body competent for one regime is not automatically competent for another.

Involvement depends on the applicable legislation. Where the applicable act prescribes a procedure requiring third-party involvement, a notified body is engaged. Where it does not, none is required. Not every product, and not every requirement within a product, requires one.

A notified body is not a market-surveillance authority. These are structurally different roles. The following distinction is worth holding precisely:

RoleWhat it isWhen it actsWhat it does not do
Notifying authorityThe national authority responsible for designating and monitoring conformity assessment bodiesOn designation, monitoring and withdrawal of notificationDoes not assess individual products, and does not police the market
Notified bodyA conformity assessment body notified to perform defined third-party tasks under specific lawWhere the applicable procedure requires third-party involvementDoes not enforce, does not assume the operator’s statutory obligations, does not own the DPP
Market-surveillance authorityThe competent national authority supervising products on the marketAfter products are made available, and in response to risk or intelligenceDoes not perform the operator’s conformity assessment on its behalf

A notified body is not automatically responsible for the DPP. Its output, where it exists, may become part of the compliance evidence at Layer 3, and a reference to it may in some circumstances appear at Layer 4. That is a data relationship, not a transfer of accountability.

Layer 3: Compliance Evidence and Documentation

Layer 3 is where conformity conclusions become defensible. It holds the records that allow the operator to demonstrate, later and to someone else, that the applicable requirements were assessed and fulfilled.

Depending on the applicable legislation, this layer may include technical documentation, test reports, calculation records, risk assessments, records of the standards or specifications applied, assessment outputs from third parties where involved, certificates where the procedure produces them, manufacturing and inspection records, supplier declarations and material information, and the declaration of conformity where one is required.

The distinguishing feature of this layer is authority. These records are the authoritative basis for the compliance conclusion. Passport content, at Layer 4, is derived from this environment. When the two disagree, the compliance record does not become wrong because the passport says something else.

What Is Technical Documentation?

Technical documentation is the compiled body of information that demonstrates how a product meets the applicable requirements. Where the applicable legislation requires it, the manufacturer prepares and retains it, and makes it available to authorities on request for the period the legislation specifies.

Its purpose is reconstructive. It should allow a competent reader who was not involved in the product’s development to understand what the product is, which requirements applied, how conformity was determined, and on what basis. A technical file that only a member of the original team can interpret has failed at its purpose even if it is technically complete.

Depending on the applicable legislation, the contents may include:

  • A general description of the product sufficient to identify it.
  • Design and manufacturing information, including drawings, schemes and component descriptions where relevant.
  • Specifications and the applicable requirements they address.
  • Calculations, models and design assumptions.
  • Test reports and measurement results.
  • Risk assessment where the applicable legislation requires one.
  • A list of the standards or technical specifications applied, in full or in part.
  • Descriptions of solutions adopted where a standard was not applied.
  • Records of the conformity-assessment procedure carried out, and third-party outputs where relevant.
  • Supporting supplier information and evidence.
No universal checklist

The contents of technical documentation are defined by the applicable legislation and, where relevant, by the specific conformity-assessment procedure. The list above is illustrative. Building an internal template is sensible; presenting that template as a legal requirement is not.

The relationship with the passport must be stated bluntly:

Technical documentation is not a Digital Product Passport.

They differ in audience, in scope and in access model. Technical documentation is normally an internal compliance artefact made available to authorities on request. A passport makes specified information available to defined parties, often including actors far outside the compliance function. A passport may expose selected required information, or a reference to the existence of documentation, where the applicable framework requires it. It does not thereby replace the file, and it does not reduce the retention obligation attaching to it.

What Is an EU Declaration of Conformity?

Where the applicable Union legislation requires one, an EU declaration of conformity is the formal statement by which the responsible economic operator, typically the manufacturer, declares that the product concerned meets the applicable requirements of the legislation identified in the declaration. Its general form and function are set out in Decision No 768/2008/EC, with the specific content and requirement determined by the applicable act.

Four relationships define its position.

Relationship to conformity assessment. The declaration sits downstream of the assessment. It records a conclusion that the prescribed procedure has already produced. Drawing up a declaration does not create conformity, and a declaration drawn up without the underlying assessment is a statement without a basis.

Relationship to legal responsibility. By drawing up the declaration, the operator assumes responsibility for the compliance of the product with the requirements it identifies. This is why authorship matters and why the declaration cannot simply be delegated to a supplier or a service provider.

Relationship to technical documentation. The declaration is the summary conclusion. The technical documentation is the substantiation. Authorities typically encounter the declaration first and the documentation second.

Relationship to DPP information. Where the applicable framework requires it, a passport may include conformity-related information or a reference associated with the declaration. Including such a reference does not turn the passport into the declaration, and the declaration remains a distinct instrument with its own requirements.

Common Mistake

Publishing a scanned declaration in the passport and treating that as both the declaration obligation and the passport obligation discharged. They are separate obligations with separate requirements. Publication does not satisfy retention or availability duties that the applicable legislation defines differently.

Not every regime that involves passport-style information requires an identical declaration mechanism. The requirement, the content and the retention period all depend on the applicable act.

Evidence and Conformity

Conformity conclusions rest on evidence. Depending on the requirement and the procedure, that evidence may include test reports, certificates where the applicable procedure produces them, calculations, supplier declarations, material and composition information, measurement results, and inspection or production records.

The governed handling of that evidence, from requirement through acquisition, association, validation, verification, acceptance, controlled use and eventual retirement, is the subject of How to Manage Evidence for Digital Product Passports. This article does not restate that lifecycle. What it adds is the conformity boundary around it.

Evidence is not automatically proof of overall product conformity. A test report demonstrates a result under a defined method for a defined sample. A supplier declaration states what a supplier asserts. A calculation produces a value under stated assumptions. Each supports a specific requirement or a specific step within the applicable assessment. None of them, individually, establishes that the product as a whole fulfils every applicable requirement.

Three failure patterns follow from ignoring this.

Scope inflation. A report covering one characteristic is treated as covering the product. This usually surfaces when an authority asks which requirement a given document addresses and the answer is unclear.

Method drift. Evidence is produced under a method other than the one the applicable requirement or standard specifies, then used as though the methods were equivalent.

Currency loss. Evidence that was valid at assessment has since expired, been superseded, or been overtaken by a product or supplier change, while the conclusion that depended on it remains unchanged in the record and in the passport.

Best Practice

Record, for every piece of evidence, which specific requirement it supports and under which method or standard it was produced. Evidence stored without that association is difficult to defend and almost impossible to reassess efficiently when a requirement or a standard changes.

Standards and Conformity Assessment

Standards are frequently misdescribed in DPP programmes as a form of regulation. They are not.

A regulation sets legal requirements. It is adopted through a legislative process and is binding in the terms it sets.

A standard provides technical specifications, methods or definitions. It is developed by a standardisation body through a consensus process. It describes how something may be specified, measured, tested, expressed or exchanged.

The existence of a standard does not make it legally mandatory. A standard acquires legal significance only through the way the applicable framework uses it. Possible relationships include the applicable legislation referring to a standard, requiring a method set out in a standard, giving the use of a standard a defined legal effect such as a presumption of conformity, or saying nothing about standards at all, in which case applying one is an engineering or commercial decision rather than a compliance one.

Why this matters for passports

Data standards used to structure, identify or exchange passport information may be genuinely useful and may be referenced by the applicable framework, but the reason to apply them should be stated correctly. “It is required by the applicable act” and “it is good practice and improves interoperability” are different justifications with different consequences if challenged.

What Is a Harmonised Standard?

A harmonised standard is a European standard adopted by a European standardisation organisation on the basis of a request made by the Commission for the application of Union harmonisation legislation. The concept, the standardisation request process and the publication of references are governed by Regulation (EU) No 1025/2012 on European standardisation.

Four elements distinguish a harmonised standard from a European standard generally:

  • It responds to a standardisation request. The Commission requests it for the application of identified Union harmonisation legislation. A standard developed without such a request is not harmonised, however widely used it is.
  • It is developed by a European standardisation organisation in accordance with the applicable procedures.
  • Its reference may be published in the Official Journal of the European Union. Publication of the reference is the step that connects the standard to the legal effect the applicable legislation attaches to it.
  • Its effect is scoped. The effect concerns the requirements that the standard, or the relevant part of it, covers under the legislation for which it was requested.

Two negatives are as important as the definition.

Not every European standard is a harmonised standard. Many standards are developed without a standardisation request and carry no such status.

Not every requirement has a harmonised standard. Where a framework is new or a product-specific measure is recent, harmonised standards covering its requirements may not yet exist, may be under development, or may cover only part of the requirement set. Programmes should verify the current position for their own requirements rather than assuming coverage.

What Is Presumption of Conformity?

Presumption of conformity is one of the most frequently misunderstood concepts in EU product law, and the misunderstanding is almost always in the same direction: the presumption is read as a guarantee.

Where the applicable Union legislation so provides, products which are in conformity with harmonised standards, or parts thereof, the references of which have been published in the Official Journal of the European Union, are presumed to be in conformity with the requirements covered by those standards, or parts thereof, set out in that legislation.

Read carefully, that sentence contains five limitations.

It applies where the applicable legislation provides for it. The presumption is a mechanism that legislation grants. It is not an ambient property of standards.

It is limited to published references. The connection is made by publication of the reference in the Official Journal. A draft, withdrawn or unpublished standard does not produce the effect, and references can be published with restrictions or withdrawn.

It is limited to the requirements the standard covers. This is the limitation most often lost. Where a standard covers part of a requirement set, the presumption reaches only that part. Requirements outside the standard’s scope remain to be addressed on their own terms.

It is a presumption, not a determination. It shifts the starting position; it does not make the question unaskable. Market-surveillance authorities retain their powers, and the applicable legislation may provide procedures where a harmonised standard is considered not to fully satisfy the requirements it covers.

It does not remove the need for evidence. The operator still has to be able to show that the product actually conforms to the standard relied on. Claiming application of a standard is not the same as demonstrating conformity with it.

Alternative technical solutions

Applying a harmonised standard is generally voluntary. Where the applicable legislation permits it, an operator may demonstrate conformity by other means, but then carries the full burden of demonstrating that the applicable requirements are met, without the benefit of the presumption. The availability of that route depends entirely on the applicable act.

Example
How the scope limitation bites

A product-specific measure imposes requirements covering durability, repairability and information provision. A harmonised standard is available covering a defined durability test method, and its reference is published. Applying that standard correctly may support the durability requirement it covers. It says nothing about the repairability or information requirements, which must be addressed separately. A programme that records “harmonised standard applied” at product level, with no mapping to requirements, cannot tell which of the three requirements are actually supported.

Regulation vs Standard vs Harmonised Standard

ConceptWho creates or adopts itLegal characterRole in conformityRelationship to the DPP
EU RegulationEU legislator, published in the Official JournalBinding in its entirety and directly applicable in the Member StatesSets the requirements and determines which conformity-assessment procedures apply or may be chosenMay create the passport obligation itself and define what must be available through it
Delegated actCommission, under a delegation of power in a framework actBinding where adopted and in force, within the scope of the delegationSets the product-specific requirements that assessment must addressTypically determines the product-specific passport requirements, including information content
StandardA standardisation body, through a consensus processVoluntary in itself; no legal force merely by existingProvides methods, specifications or definitions that may be used in assessmentMay inform how passport information is structured, identified or exchanged, without being legally required
Harmonised standardA European standardisation organisation, on a Commission standardisation requestVoluntary to apply; capable of producing defined legal effects where the applicable legislation so provides and the reference is publishedWhere applicable, use may give rise to a presumption of conformity limited to the requirements coveredMay cover requirements whose outcomes appear in the passport, without making the passport itself a conformity output
GuidanceCommission services, authorities, sector bodiesNot binding law; explains how provisions are understood or appliedAssists interpretation of requirements and procedures; does not itself create or discharge themUseful for programme design; never a substitute for the applicable act
tieback educational frameworktieback, for teaching purposesNo legal status whatsoeverOrganises reasoning about how the pieces relate; performs no assessment and confers no compliance statusHelps teams structure passport and compliance work; creates no obligation and satisfies none

Layer 4: Digital Product Passport Information

Layer 4 is what the outside world sees. It is also the smallest of the four layers in most programmes, which is why it makes such a poor proxy for the other three.

Where the applicable framework requires it, passport information may include product identity and product identifiers, economic operator information, conformity-related information or references, sustainability information, technical characteristics, references indicating that documentation or evidence exists, and other product-specific information determined by the applicable measure.

The authoritative treatment of what a passport contains is What Information Does a Digital Product Passport Contain?, and the mechanics of how it is reached and rendered are covered in How Does a Digital Product Passport Work?. This article deliberately does not list mandatory fields, because the applicable product-specific measure determines them and inventing a universal field set would be misleading.

What matters here is the relationship. Passport information is derived, selected and published. It is derived from the compliance environment and enterprise systems, selected according to what the applicable framework requires to be available, and published to defined audiences with defined access. Each of those three operations is a place where the passport can diverge from the record behind it.

DPP Information vs Conformity Evidence

The clearest way to see the difference is with a single value.

Example
A published value and the environment behind it

A passport displays: Recycled content: 40%.

Behind that single number, the compliance environment may contain a supplier declaration stating the recycled content of an input material, material records identifying the input batches used, the calculation methodology that converts input data into a product-level figure, the assumptions and boundaries applied by that methodology, validation results showing the value passed the applicable controls, evidence of the supplier’s own substantiation, and records showing which production period the figure applies to.

The passport shows a number. The compliance environment holds the reason the number is defensible.

Three consequences follow.

The published value is not the evidence chain. It is the conclusion of one. Publishing it does not publish the substantiation, and does not need to, unless the applicable framework requires that information to be available.

Publishing a value is a claim. The moment it appears in the passport, it is a statement about the product capable of being checked. The controls described in How to Validate Digital Product Passport Data and How to Manage Evidence for Digital Product Passports exist so that publication is not the first moment anyone examines it.

The two can drift. The number in the passport is a copy of a conclusion. Copies age. This is the reason the next section exists.

Maintaining Consistency Between Compliance Records and the DPP

The practical control that connects Layer 3 and Layer 4 can be stated in one sentence:

Digital Product Passport information should not contradict the authoritative information supporting the applicable compliance conclusions.

This is not a legal test, and it is not a substitute for the requirements of the applicable act. It is an enterprise control that reduces the chance of a compliance, assurance or surveillance problem arising from divergence rather than from the product itself.

Typical inconsistencies, and why each one matters:

  • The passport product identifier differs from the identifier in the technical documentation. The link between the published information and the assessed product becomes unprovable, which can make an otherwise sound compliance position difficult to demonstrate.
  • Passport material composition differs from the composition in the assessed records. Either the passport is wrong, or the product changed and the assessment was not revisited. Both are problems, and they have different remedies.
  • The passport references an obsolete declaration. The reference points at a superseded conclusion, which can suggest the current product state was never declared.
  • The passport displays an expired certification as current. This is a presentational failure that can look, from the outside, like a misleading claim.
  • The passport carries a value inconsistent with its supporting evidence. For example, a recalculated figure was updated in one system and not the other.
Best Practice

Treat every conformity-relevant passport element as having a named authoritative source and a defined refresh trigger. The disciplines in What is Product Data Governance? and What is a System of Record? apply directly: an element with no authoritative source is an element that will eventually contradict something.

Consistency is a two-way control. When divergence is found, the correct first action is to determine which side is wrong. Silently updating the passport to match the record, or the record to match the passport, without establishing which reflects the product, converts a detectable inconsistency into an undetectable error.

Change Control and Reassessment

Conformity is established in relation to a product as assessed. Products change. So do requirements. Neither the assessment nor the passport is automatically valid forever.

Events that may require an organisation to consider whether reassessment is needed include:

  • A product design change.
  • A material or component change.
  • A supplier change, including a change of manufacturing site for an existing supplier.
  • A manufacturing process change.
  • A revision or withdrawal of a standard relied upon, including changes to published references.
  • An amendment to the applicable legislation, or a new product-specific measure.
  • Expiry, withdrawal or supersession of evidence relied upon.
  • A correction to product information that reveals the assessed data was wrong.
  • A significant modification of the product, where the applicable legislation attaches consequences to it.

For each such event, the organisation has to determine what it affects. The question set is stable even though the answers are not:

  1. Does the change affect the conformity conclusion for any applicable requirement?
  2. Does it invalidate or require new evidence?
  3. Does it require the technical documentation to be updated?
  4. Does it require a new or amended declaration, where one is required?
  5. Does it require third-party involvement to be repeated, where the applicable procedure requires it?
  6. Does it require the passport information to be updated, and by when?
No universal triggers

Whether a given change requires reassessment is determined by the applicable legislation, the procedure used, and the nature of the change. This article does not, and cannot, supply the answer for a specific case. What it can say is that an organisation without a defined process for asking the question will answer it inconsistently.

The operational machinery for detecting and routing these events is covered by How to Operate a Digital Product Passport Programme. The point here is narrower: the passport update and the conformity reassessment are different decisions, and doing one does not perform the other.

Conformity Assessment vs Data Validation

Data validation asks: does this data meet the defined rules? Rules may cover presence, format, range, referential integrity, unit consistency, provenance, evidence linkage and publication readiness. The full control model is set out in How to Validate Digital Product Passport Data.

Conformity assessment asks: have the specified product requirements been fulfilled?

The two are related and distinct, and the relationship is easiest to see through two asymmetries.

Valid data can describe a non-conforming product. A recycled content value of 12% can be perfectly formed, correctly sourced, evidence-backed and validated, and still fall below an applicable requirement. Validation controls the data. It does not control the product.

Invalid data can prevent an organisation from demonstrating conformity. If the value cannot be traced to a source, if the evidence is missing, or if the identifier does not resolve to the assessed product, the organisation may be unable to demonstrate a conclusion that is in fact correct.

Validation is therefore necessary but not sufficient. It is a precondition for defensible publication, not a substitute for assessment.

Conformity Assessment vs Verification

Verification, in ordinary compliance usage, means confirming that specified information, evidence or a claim is truthful, accurate or meets defined criteria. It is typically applied to a particular item: a document, a value, a claim, a record.

Conformity assessment is broader. It is directed at whether specified requirements under the applicable framework have been fulfilled, and it follows a prescribed procedure. Verification activity may form part of it, and in some legislation “verification” is itself the name of a prescribed procedure with a defined meaning.

Read the term in context

Because “verification” carries a general meaning in enterprise practice and a specific meaning inside particular conformity-assessment procedures, the term should always be read in the context of the applicable act. This article does not assert a single universal definition outside that context.

The practical distinction for a programme: verifying that a supplier’s declaration is genuine, and that the figure in it matches the figure published, is verification. Determining whether the product meets the applicable durability requirement is conformity assessment. A programme can do the first flawlessly and never have done the second.

Conformity Assessment vs Enterprise Assurance

tieback enterprise assurance, described in How to Test and Assure a Digital Product Passport, examines whether an organisation’s DPP capability is ready and controlled: whether data flows correctly from source to publication, whether evidence is present and current, whether access behaves as intended, whether change is controlled, and whether the operating response works.

That is an enterprise implementation model. It is not statutory conformity assessment, and it has no legal status of any kind.

The consequence is uncomfortable and should be stated in programme governance:

A capability can pass internal DPP assurance while a product still fails an applicable conformity requirement. Assurance can confirm that the system publishes the value correctly, from the right source, with evidence attached, and that the value is exactly the one the business intended. It cannot confirm that the value satisfies a legal requirement, because that determination belongs to the assessment process against the applicable requirement.

The reverse holds too. A product can be fully conforming while the passport capability is unready, in which case the exposure is an information obligation, not a product one.

Conformity Assessment vs Market Surveillance

Conformity assessment is performed by, or on behalf of, the operator that the applicable legislation makes responsible, as required to demonstrate fulfilment of requirements at the points the legislation identifies, typically around placing on the market and thereafter as circumstances require.

Market surveillance is performed by competent national authorities in relation to products on the market, under the framework established by Regulation (EU) 2019/1020 and the applicable sectoral legislation.

They are distinct controls with distinct actors, timings and purposes. The full mechanics of surveillance, findings, operator response, corrective and restrictive action and follow-up are set out in How Digital Product Passports Will Be Enforced, and are not restated here.

The connection between them is one directional dependency. Market-surveillance authorities may examine conformity documentation and passport information when assessing a product. What they examine at Layer 3 and Layer 4 is the output of work that should already have been done. Surveillance does not perform the assessment on the operator’s behalf, and the absence of surveillance activity is not evidence that an assessment obligation was met.

Conformity Assessment vs Certification

Certification is third-party attestation relating to products, processes, systems or persons. Within conformity-assessment concepts it is one possible form of attestation, used where the applicable procedure or a voluntary scheme provides for it.

Two errors follow from treating the terms as synonyms.

Assuming certification is always required. Many conformity assessments produce no certificate at all. Where the applicable legislation provides for internal production control, the outputs are technical documentation and, where required, a declaration.

Assuming a certificate settles the question. A certificate attests to what its scope says it attests to, under the scheme that issued it, at the time it was issued. A voluntary sustainability certificate is not a determination of conformity with a legal requirement unless the applicable legislation gives it that role.

The relationship is therefore one of containment:

Conformity assessment is broader than certification. Certification may appear inside it. It does not define it.

Who Is Responsible for Conformity Assessment?

The applicable legislation determines which economic operator must perform or arrange conformity assessment, prepare and retain technical documentation, draw up declarations where required, retain records for the specified period, and cooperate with authorities. The allocation of those responsibilities across manufacturers, importers, distributors, authorised representatives and other roles is the subject of Who Is Legally Responsible for a Digital Product Passport?, and is not restated here.

Two points specific to conformity assessment are worth adding.

Arranging is not delegating. An operator may engage a laboratory, a consultant, a testing house or, where required, a notified body. Engaging them performs the work. It does not move the statutory obligation to have the work performed correctly, to hold the resulting documentation, or to stand behind the conclusion.

Third-party involvement does not transfer statutory obligations. Where a notified body performs a prescribed task, the operator remains the party the applicable legislation identifies. The same is true of technology providers operating the passport, suppliers producing input data, and internal teams performing the analysis.

Conformity Information and Market Surveillance

Where the applicable legislation provides, market-surveillance authorities may need access to required product information, declarations, technical documentation, evidence, conformity-assessment outputs and passport information. Different instruments define different access rights, different recipients and different retention periods, and this article does not assert a single access regime.

The Digital Product Passport can genuinely improve accessibility here. Where the applicable framework requires specified information to be available through the passport, an authority may be able to reach identity, operator and required product information immediately, rather than through correspondence. That is a real operational benefit and part of the policy rationale for passports.

What it does not do is eliminate the environment behind it. The technical documentation still has to exist and be retained. The evidence still has to be traceable. The declaration, where required, still has to have been drawn up on a proper basis. A passport that resolves quickly to well-structured information sitting on top of an unmaintained compliance environment improves the speed at which a problem is discovered, not the position of the operator.

Practical Example

A manufacturer produces a household appliance subject to a product-specific measure that imposes, among other requirements, a defined durability requirement and a requirement to make specified information available through a Digital Product Passport. The example follows one requirement only, and is illustrative rather than a statement of what any particular measure requires.

Applicable requirement. The measure sets a minimum durability characteristic, expressed as a performance threshold under a defined method, and requires the resulting value to be available through the passport.

Assessment method. The applicable measure prescribes the conformity-assessment procedure. In this example it permits internal production control, so the manufacturer performs the assessment itself and no notified body is involved. That does not reduce what must be done; it determines who does it.

Test, calculation and evidence. The manufacturer tests representative samples under the specified method, records the measurement results, retains the test reports, and documents the sampling rationale and the production configuration to which the results apply. Component evidence from suppliers supports the configuration tested.

Conformity conclusion. On the basis of the results, the manufacturer concludes that the product meets the durability requirement, and records the reasoning and the requirement each piece of evidence supports.

Technical documentation. The description, design information, the method used, the test reports, the sampling rationale, the supplier evidence and the conclusion are compiled into the technical documentation and retained for the period the applicable legislation specifies.

Declaration where applicable. Where the applicable legislation requires a declaration, the manufacturer draws it up, identifying the product and the legislation with which conformity is declared.

Selected DPP information. The passport carries the product identity, the operator information and the durability value that the measure requires to be available. It does not carry the test reports, the sampling rationale or the technical file, unless the applicable measure requires them to be available.

Market availability. The product is placed on the market with the passport available as required.

Ongoing change control. The conformity conclusion, the documentation and the passport information are all subject to the change-control question set above.

The change

Twelve months later, the manufacturer changes the supplier of a component that contributes to the durability characteristic. The new component meets the internal specification and costs less.

The organisation must now determine whether the change affects:

  • The conformity conclusion. Was the tested configuration dependent on the previous component?
  • The evidence. Do the existing test reports still describe the product being manufactured?
  • The technical documentation. Does the description of components and configuration remain accurate?
  • The declaration. Does the declared product remain the product being placed on the market?
  • The passport information. Does any published value change as a result?

The correct answers depend on the applicable measure, the procedure used, and the technical significance of the change. This article does not prescribe them. What it does prescribe is that the questions are asked, by a named owner, before the changed product ships.

The failure mode

Now consider what happens when the organisation updates only the passport.

The procurement change goes through. Product data is refreshed, a component reference is updated in the product record, the passport is republished, and the data pipeline reports success. Every enterprise control passes: the data is valid, sourced, evidence-linked and consistent with the product record. Internal assurance is green.

Nobody asked whether the durability conclusion still holds.

Externally, nothing looks wrong. The passport is complete and current. If an authority later examines the product, the examination will not stop at the passport. It will reach the technical documentation, which describes a configuration that is no longer manufactured, and test reports that relate to a component the product no longer contains. At that point the organisation is defending a conformity conclusion for which its evidence no longer matches the product, with a passport that looks impeccable.

This is the argument of the entire article compressed into one scenario:

Publishing correct information is not the same as maintaining conformity. The passport can be right while the compliance position has quietly become indefensible.

Common Mistakes

Common Mistake

“A DPP is a conformity certificate.” It is neither a certificate nor an attestation. It is a mechanism for making specified product information available. Nothing in its existence demonstrates that requirements have been assessed or fulfilled.

Common Mistake

“If the DPP is complete, the product is conforming.” Completeness is an information property. A passport can be complete, accurate and current for a product that fails a substantive requirement it does not mention.

Common Mistake

“Every conformity assessment requires a notified body.” Third-party involvement is required only where the applicable legislation prescribes a procedure that includes it. Many regimes provide for manufacturer self-assessment through internal production control.

Common Mistake

“Self-assessment means there is no conformity assessment.” Self-assessment is assessment performed by the manufacturer. The requirements must still be fulfilled, the documentation must still exist, and the conclusion must still be defensible under surveillance.

Common Mistake

“A notified body becomes legally responsible for the product.” The body performs the task the applicable procedure assigns to it. Statutory responsibility remains with the operator the legislation identifies, and that includes responsibility for the passport where the obligation attaches to it.

Common Mistake

“A DPP replaces technical documentation.” The technical file supports the assessment and is made available to authorities as the applicable legislation requires. A passport may expose selected information or references, which is a different function with a different audience.

Common Mistake

“The EU Declaration of Conformity and the DPP are the same document.” The declaration is a formal statement of conformity with identified legislation, drawn up by a defined operator. The passport is an information mechanism. Referencing one from the other does not merge them.

Common Mistake

“Every standard is legally mandatory.” Standards are voluntary in themselves. Legal significance arises only where the applicable framework gives it to them.

Common Mistake

“Every European standard is a harmonised standard.” A harmonised standard is developed in response to a Commission standardisation request for the application of identified Union legislation. Most standards are not.

Common Mistake

“Using a harmonised standard proves the entire product is compliant.” Where the applicable legislation provides, the presumption is limited to the requirements the standard, or the relevant part of it, covers. Requirements outside that scope are unaffected.

Common Mistake

“Presumption of conformity prevents authorities from challenging compliance.” It is a presumption, not an immunity. Market-surveillance powers remain, and the applicable legislation may provide procedures where a standard is considered not to fully satisfy the requirements it covers.

Common Mistake

“Certification and conformity assessment mean the same thing.” Certification is one form of third-party attestation. Conformity assessment is the broader concept, and many assessments produce no certificate at all.

Common Mistake

“Passing enterprise DPP assurance proves product conformity.” Enterprise assurance evaluates the organisation’s own capability. It has no legal status and cannot determine whether an applicable product requirement is met.

Common Mistake

“Correct DPP data proves the underlying product conforms.” Correct data proves the published value matches its source. Whether the value satisfies a legal requirement, and whether the product meets requirements the passport does not display, are separate questions.

Common Mistake

“Updating the DPP automatically updates the conformity assessment.” Republishing information is a publication act. Whether a change requires reassessment, new evidence, updated documentation or a new declaration is a separate determination that publication does not perform.

Frequently Asked Questions

What is conformity assessment? It is the process of determining or demonstrating whether specified requirements have been fulfilled. In EU product legislation, the requirements come from the applicable act and any product-specific measure adopted under it, and the procedure is the one that legislation prescribes or permits.

Is a Digital Product Passport a conformity assessment? No. A passport makes specified product information available where the applicable framework requires it. Conformity assessment determines whether requirements are fulfilled. A passport may carry information produced by conformity work, but it does not perform or replace it.

Does every product need conformity assessment? It depends on whether Union harmonisation legislation applies to the product and what that legislation requires. Where it applies, it will normally specify the applicable procedure. There is no general answer independent of the applicable act.

Does every conformity assessment require a notified body? No. Third-party involvement is required only where the applicable legislation prescribes a procedure that includes it. Many regimes permit manufacturer self-assessment through internal production control.

Can a manufacturer perform its own conformity assessment? Where the applicable legislation provides for a procedure such as internal production control, yes. The manufacturer then performs the assessment, holds the technical documentation and draws up the declaration where required, carrying full responsibility for the conclusion.

What is technical documentation? The compiled information demonstrating how a product meets the applicable requirements, prepared and retained by the responsible operator where the applicable legislation requires it, and made available to authorities on request. Its required contents are defined by the applicable act.

Does a DPP replace technical documentation? No. A passport may expose selected required information or references. The underlying documentation obligation, including retention and availability to authorities, continues to exist on its own terms.

What is an EU Declaration of Conformity? Where the applicable legislation requires one, it is the formal statement by which the responsible operator declares that the product meets the applicable requirements of the legislation identified in it. It sits downstream of the conformity-assessment conclusion.

What is a harmonised standard? A European standard adopted by a European standardisation organisation on the basis of a Commission request for the application of Union harmonisation legislation, under Regulation (EU) No 1025/2012. References to such standards may be published in the Official Journal of the European Union.

Are harmonised standards mandatory? Applying them is generally voluntary. Their significance is that, where the applicable legislation so provides and the reference has been published, applying them can give rise to a presumption of conformity with the requirements they cover.

What is presumption of conformity? Where the applicable legislation provides, conformity with harmonised standards, or parts thereof, whose references have been published, gives rise to a presumption of conformity with the requirements covered by those standards. It is limited to the covered requirements, and it does not remove surveillance powers or the need to demonstrate that the standard was actually met.

Can a DPP contain conformity information? Yes, where the applicable framework requires or permits it. The passport may carry conformity-related information or references. Containing such information does not make the passport a conformity output.

Does correct DPP information prove a product is compliant? No. It establishes that the published information matches its source. Compliance depends on whether the applicable requirements are fulfilled, including requirements the passport does not display.

What happens when a product changes after conformity assessment? The organisation must determine whether the change affects the conformity conclusion, the evidence, the technical documentation, the declaration, any required third-party involvement, and the passport information. What the change requires depends on the applicable legislation and the nature of the change.

What is the difference between conformity assessment and market surveillance? Conformity assessment is performed by or for the responsible operator to demonstrate fulfilment of requirements. Market surveillance is performed by competent authorities in relation to products on the market. Authorities may examine the outputs of assessment, but they do not perform it for the operator.

What is the difference between conformity assessment and certification? Certification is one form of third-party attestation that may be used within conformity assessment where the applicable procedure or a voluntary scheme provides for it. Conformity assessment is the broader process, and it frequently produces no certificate.

Who is legally responsible for conformity assessment? The applicable legislation determines this, typically placing the obligation on the manufacturer, with related duties on importers, distributors and authorised representatives depending on the role and the act. Engaging a third party performs the work without moving the obligation.

Key Takeaways

Key Takeaways
  • Conformity assessment determines or demonstrates whether specified requirements have been fulfilled. A Digital Product Passport makes specified information available. Both may be required; neither substitutes for the other. - The DPP Conformity Assessment Relationship Model runs from applicable requirements, through conformity assessment, into compliance evidence and documentation, and only then into passport information, with a consistency rail and a surveillance feedback path across the lower layers. - The applicable legislation determines the procedure. Internal production control, testing, examination, quality-system assessment, product verification, unit verification and third-party assessment are options that legislation prescribes or permits, not a universal sequence. - Self-assessment is real assessment, and notified-body involvement neither reduces nor relocates the responsible operator’s statutory obligations. - Technical documentation and the declaration of conformity, where required, remain distinct instruments with their own content, retention and availability requirements. A passport does not absorb them. - Standards are voluntary in themselves. Harmonised standards can produce a presumption of conformity where the applicable legislation provides and the reference has been published, limited to the requirements covered. - Passport information must remain consistent with the authoritative compliance record, and change events require an explicit decision about reassessment rather than a republication.

References

About This Article

tieback Knowledge is a continuously maintained reference library covering Digital Product Passports, product traceability, product compliance and related regulations. Articles are reviewed regularly as legislation, standards and implementation guidance evolve.