47 questions · regulations first, then working with Aeroz · every date verified 30 August 2026.
Compliance deadlines move, and most published guidance does not move with them. Everything below is checked against the regulation or the issuing authority, and dated. Where a rule has been postponed we say so, and where something is not yet law we say that too — including when it would be easier for us if it were.
Grouped by framework. Each answer states the instrument and the operative date, so you can check us.
A structured set of product data — identity, composition, durability, repair and end-of-life information — held against a unique product identifier and reachable from a data carrier on the product itself. ESPR sets the framework; a delegated act per product group sets the fields that are actually binding for that group.
ESPR is in force, but no ESPR delegated act has been adopted for any product group as of August 2026 — so no ESPR passport is binding on any product yet. The exception is batteries, which are governed by the separate Battery Regulation and carry a hard date of 18 February 2027. Anyone telling you the DPP is mandatory for textiles or furniture today is ahead of the law.
It phases in by product group between 2027 and 2030, each on its own delegated act. Textiles were the first preparatory study completed and the textiles delegated act is targeted for 2027, with compliance expected around 2029. Nothing binds until the act for your group is adopted, which is exactly why the dates keep moving.
Six priority groups: textiles and apparel, furniture, mattresses and tyres as final products, plus iron and steel and aluminium as intermediate products. Footwear was left out pending its own study. Sixteen energy-related product groups carry over from the previous Ecodesign framework.
The European Commission opened the Digital Product Passport Registry on 20 July 2026, together with a testing environment. It is where passports get registered and where access and user verification are governed. It is in a testing phase — obligations attach as each product category comes into scope, and the first is large batteries on 18 February 2027.
No. ESPR requires a data carrier that links to the passport; it does not mandate one technology. EN 18220:2026, the European standard for DPP data carriers, permits optical 2D codes such as QR and Data Matrix as well as RFID and NFC. The choice is yours, and it should follow your counterfeit and durability risk, not a rulebook.
For the passport requirement itself, generally yes — a QR code is an accepted carrier. What a printed code cannot do is prove the item is genuine, because print can be photographed and reprinted. Identification and authentication are two different jobs, and only one of them is solved by ink.
The economic operator placing the product on the EU market. For an EU manufacturer that is the manufacturer; for goods made outside the EU it lands on the importer or the authorised representative. Retailers have to make the passport accessible, but they do not author it.
From 18 February 2027, for EV batteries, LMT batteries (e-bikes, scooters and similar) and industrial batteries above 2 kWh placed on the EU market. This is the first legally binding product passport in the EU, and it is the reason battery makers are further ahead than any other sector.
No. A BMS holds state data inside the pack; the passport is an externally reachable record tied to a unique identifier, carrying composition, carbon footprint, due diligence and end-of-life data for parties outside your company. The BMS is a source that feeds the passport, not a substitute for it.
Article 77(7) treats it as a new product: the repurposed battery needs its own passport, linked back to the passport of the battery it came from. That linkage is the hard part — it means your identifier scheme has to record lineage rather than simply reissuing a number.
Yes. The stabilization period ended 27 November 2024, and FDA's phased exemptions have now expired for every trading-partner category except small dispensers — manufacturers in May 2025, wholesale distributors in August 2025, larger dispensers in November 2025. Enhanced drug distribution security is live.
27 November 2027, for small dispensers — pharmacies with 25 or fewer full-time-equivalent licensed pharmacists and technicians. FDA extended that date in August 2026. It is the only clock left.
No. DSCSA requires unit-level, electronic, interoperable tracing, carried today on a GS1 DataMatrix. Nothing in §582 mandates a chip. What DSCSA does require is verification — and verifying a printed identifier tells you the number is valid, not that the package in your hand is the one it was printed for.
No. Serialization platforms — TraceLink, Antares Vision, MediLedger and the rest — do the job they were bought for. Authentication is a layer above them, consuming and emitting EPCIS 2.0, not a replacement for them.
20 July 2028. FDA extended the original date by 30 months in August 2025, and Congress made the extension binding in November 2025. The rule itself did not change — only the clock.
No. The rule requires key data elements captured at critical tracking events and produced to FDA within 24 hours in a sortable electronic format. It is technology-neutral. The practical problem is not the format — it is that lot-level records make you recall a month of output when a swab comes back positive on one line.
From 30 December 2026 for large and medium operators and traders, and 30 June 2027 for micro and small enterprises — dates set by the postponement in Regulation (EU) 2025/2650. Micro and small operators already covered by the old EU Timber Regulation come in on 30 December 2026 with everyone else. It is not in application today, despite a great deal of published material that still says it is.
A due-diligence statement filed in the EU information system for each consignment, backed by geolocation of every plot of land the commodity was produced on — polygons for plots above four hectares. The land must have been deforestation-free after 31 December 2020. Region-level or cooperative-level origin is not sufficient.
No. Mass-balance certification proves a volume was bought into a certified pool; EUDR asks which plot this consignment came from. Certification is useful evidence inside a due-diligence system, but it does not discharge the obligation on its own.
The Carbon Border Adjustment Mechanism, Reg. (EU) 2023/956. The definitive regime has been running since 1 January 2026, covering iron and steel, aluminium, cement, fertilisers, electricity and hydrogen. Importers report embedded emissions and surrender certificates against them.
14 December 2027. Reg. (EU) 2024/3015 entered into force on 13 December 2024 with a three-year runway. It bans placing products made with forced labour on the EU market and exporting them from it, and it applies to any product regardless of sector or company size.
An industry initiative, not a law: retail point-of-sale systems ready to scan 2D codes — QR or Data Matrix carrying GS1 Digital Link — by the end of 2027. It matters because it is what makes a single code on a pack work for both the till and the consumer.
FDA's final rule, issued March 2026, moves every US drug product to a uniform 12-digit National Drug Code in a 6-4-2 format, carried in a GS1 2D data carrier. It takes effect in 2033, which sounds distant until you consider that every drug label in the US has to be re-issued.
Yes, and it is the efficient design. The frameworks differ in what they ask for, but they share a foundation: a unique identifier per unit, a resolvable data carrier, and a tamper-evident record of what happened to that unit. Build that once and configure it per regulation, rather than running a separate stack for each.
Six European standards were published in 2026: EN 18219 (unique identifiers), EN 18220 (data carriers), EN 18221 (storage, archiving and persistence), EN 18222 (APIs), EN 18216 (data exchange protocols) and EN 18223 (system interoperability). Two more — access rights and data authentication — are still in draft.
A way of expressing a product identifier as a web address, so one code resolves to different destinations depending on who scans it — a consumer gets the passport, a distributor gets the custody record, a regulator gets the audit trail. It is what lets a single carrier serve the till and the shopper.
The GS1 standard for supply-chain event data — what happened, to which object, when, where, and why. It matters because compliance questions are almost always event questions, and an append-only event log answers them without reconstructing the chain from invoices after the fact.
QR is cheap, prints on anything, and identifies well. NFC costs more per unit and authenticates, because the chip answers a challenge rather than displaying a value. Use QR where the risk is a missing record and NFC where the risk is a convincing fake. Most real programmes use both, on the same identity.
Yes — trivially. A QR code or Data Matrix is a picture of a number, and a photograph of it scans identically to the original. That is not a flaw in the code; identification is what it was designed for. Authentication needs an identity that cannot be reproduced by copying what is visible.
No. Current iPhone and Android handsets read NFC natively and open the returned web address in the default browser. Requiring an app install is one of the most common reasons consumer-facing passport programmes go unused.
What we do, what we do not do, and what we are prepared to claim.
The verification layer for regulated supply chains. It adds unit-level authentication and an audit-defensible custody record on top of the serialization stack you already run, pairing a dual-frequency NFC + UHF chip with the GS1 2D barcode so an individual unit can be proven genuine and traced through an append-only EPCIS 2.0 log.
No. Aeroz sits on top of those platforms using GS1 Digital Link and EPCIS 2.0, adding the unit-level authentication and immutable custody record they do not provide. Your existing serialization investment stays exactly where it is.
No. It is EPCIS-native and GS1-based, so it interoperates with what you run rather than displacing it. That is a deliberate choice: rip-and-replace projects are where compliance programmes go to die.
Not yet, and we will not until our engineering team signs it off. We have bought and read all six published standards and mapped our identifier, carrier, storage, API and interoperability behaviour against them — that work is underway and has already changed our code. Conformance is a claim you earn, not one you assert in marketing.
For consumer and counter-staff verification, no — the phone in their pocket reads the tag. Warehouse and yard-scale UHF reading uses standard RFID infrastructure, which is where fixed readers earn their keep. The rule of thumb: one-at-a-time verification needs no hardware, bulk reading does.
It depends on the product, and it is tested rather than assumed — under-surface placement for furniture, a sewn label for soft goods, a stamped component tag for industrial parts, on-pack for pharmaceuticals. Placement and read-rate per product type are measured during the audit, because a tag nobody can find is a tag nobody taps.
Four to eight weeks for a first line or SKU, on your existing stack. The long pole is almost never the technology — it is agreeing what data has to be in the record and who owns each field.
The 2D barcode still identifies the unit, and the custody record still exists — you lose authentication for that item, not traceability. Read-rate is an engineering target we test and report per deployment rather than a number we quote in advance.
That is the point of bonding identity to the product rather than to packaging. Second and third owners get the same one-tap answer, and service, repair or repurposing events append to the unit's record instead of overwriting it.
You do. The custody record is your record; portability is a term we expect to be held to, and the underlying standards exist precisely so that a passport is not hostage to the vendor who issued it.
With a fixed-fee compliance audit — from $5,000, with a written gap analysis returned in 14 days. You can book it online or email info@aeroz.io. Larger multi-regulation scopes are quoted after a short scoping call.
A written gap analysis against the regulation and your current stack, a data-carrier and read-rate assessment on your actual products, a traceback simulation on a sampled unit with the time baselined, a scoped remediation plan with cost and timeline, and a pilot scope for one SKU or line.
No. It is a standalone engagement with a written deliverable and no commitment to proceed. Some clients use it purely to size their exposure, and that is a legitimate outcome.
A pilot with Kia at a vehicle yard, work with Global Ordinance, and audit engagements run to FDA and DSCSA discipline. We do not publish customer counts or performance statistics we cannot evidence, and we would rather show you a tagged sample you can tap yourself than a number you have to take on trust.
The US (DSCSA §582, FSMA 204, FDA NDC-12), the EU (ESPR, Battery Regulation, EUDR, CBAM, Forced Labour Regulation, FMD), the UK, and the UAE and wider GCC including Tatmeen. A market we have not mapped is a mapping exercise on the same layer, not a different product.
Yes. Every checklist is a free PDF. You give us an email, we send it, and you can unsubscribe from the occasional compliance update at any time.
A fixed-fee Aeroz audit maps your actual products against the regulations that reach them and returns a written gap analysis in 14 days, with a scoped remediation plan and no commitment to proceed. From $5,000.