The EU Digital Battery Passport: Who Is Affected, What Must Be Done, and When
A practical guide to product scope, organisational responsibilities, data obligations, and the February 2027 deadline
An evidence-based guide to the European Union’s digital battery passport, explaining which batteries and organisations are affected, what each participant must prepare, and when the principal obligations take effect.
energy
essay
regulation and compliance
🇬🇧
Author
Affiliation
Antonio Montano
4M4
Published
July 18, 2026
Modified
July 18, 2026
Abstract
The European Union’s digital battery passport is an electronic record for individual electric-vehicle batteries, light-means-of-transport batteries, and industrial batteries with a capacity greater than 2 kWh. For batteries placed on the Union market or put into service from 18 February 2027, the passport must provide prescribed product, sustainability, performance, durability, conformity, repair, and lifecycle information through differentiated access rights.
Although the central legal responsibility falls on the economic operator placing the finished battery on the market, compliance depends on a wider information chain. Material, cell, and module suppliers must provide reliable source evidence; battery and vehicle manufacturers must integrate and validate it; importers and private-label operators must determine whether they assume the responsible role; technical providers must support interoperable and durable records; and repair, repurposing, remanufacturing, waste-management, and recycling operators must update or succeed the record as the battery changes status.
This article argues that the battery passport should be treated as governed lifecycle data infrastructure rather than as a QR-code or labelling project. It distinguishes directly regulated batteries and organisations from supporting participants, explains the required information and access structure, reconstructs the implementation timetable as it stood on 18 July 2026, and translates the legal framework into a role-based preparation plan. It also identifies areas in which secondary legislation, technical operation, and industry practice were still developing.
Keywords
EU Digital Battery Passport, battery passport regulation, Regulation (EU) 2023/1542, digital product passport, Cyber Resilience Act, Regulation (EU) 2024/2847, battery compliance, electric vehicle batteries, EV battery passport, light means of transport batteries, LMT batteries, industrial batteries, battery lifecycle data, battery traceability, battery data governance, battery passport requirements, battery passport deadline, 18 February 2027, economic operators, battery manufacturers, battery importers, battery suppliers, battery management systems, battery state of health, battery state of charge, battery repurposing, battery remanufacturing, battery recycling, circular economy, battery due diligence, battery carbon footprint, recycled content, QR code compliance, DPP Registry, battery passport interoperability, battery passport cybersecurity, products with digital elements, CRA compliance, vulnerability management, cybersecurity risk assessment, software bill of materials, SBOM, battery data access rights, legitimate interest, battery passport service providers, EU battery regulation
An evidence-based guide to the European Union’s digital battery passport, explaining which batteries and organisations are affected, what each participant must prepare, and when the principal obligations take effect.
A compliance deadline that reorganises the battery value chain
The digital battery passport is sometimes described as a label that becomes visible when a user scans a QR code. That description identifies the interface but not the regulated system. The QR code links the physical battery to a unique identifier. Behind it must sit an electronic record containing model-level and individual-battery information that is accurate, complete, current, machine-readable, structured, searchable, interoperable, and available according to the requester’s access rights.1
The principal obligation begins on 18 February 2027. From that date, each electric-vehicle battery, each light-means-of-transport battery, and each industrial battery with a capacity greater than 2 kWh that is placed on the European Union market or put into service must have a battery passport. The European Commission describes these batteries as the first product group for which the broader EU digital-product-passport framework becomes mandatory.2
The economic operator placing the finished battery on the market must ensure that the passport information is accurate, complete, and up to date. The operator may authorise another party to perform work on its behalf, but the legal responsibility does not disappear merely because a supplier, software provider, consultant, or overseas manufacturer creates or hosts the data.3
The practical impact is therefore wider than the organisation formally accountable for the passport. Upstream suppliers hold information about materials, cells, modules, manufacturing sites, recycled content, and carbon-footprint inputs. Manufacturers hold product-design, performance, conformity, and traceability records. Battery-management and service systems generate information about use and condition. Repairers and second-life operators need controlled access to dismantling, condition, and predecessor information. Waste operators and recyclers require data that support safe treatment and material recovery.
The central implementation problem is not how to print a QR code. It is how to maintain a defensible chain of responsibility from upstream evidence to an individual battery, while preserving identity, provenance, access control, lifecycle updates, continuity, and regulatory accountability.
Which batteries and market actors are in scope
Scope has two independent dimensions. First, the battery must fall within one of the categories covered by Article 77. Second, a legally relevant event—placing the battery on the Union market or putting it into service—must occur on or after 18 February 2027.4
Three battery categories require passports
Battery category
Passport requirement from 18 February 2027
Principal boundary
Electric-vehicle battery
Required for each battery in the category
No separate capacity threshold
Light-means-of-transport battery
Required for each battery in the category
No separate capacity threshold
Industrial battery
Required where capacity is greater than 2 kWh
The 2 kWh threshold applies only to industrial batteries
Portable battery
No Article 77 passport solely because it is portable
Other labelling and QR-code requirements may still apply
Starting, lighting and ignition battery
No Article 77 passport solely because it is an SLI battery
Other regulatory information remains applicable
Industrial battery of 2 kWh or less
Outside the Article 77 passport threshold
Other provisions of the Batteries Regulation still apply
Table 1: Product scope of the EU battery-passport requirement.
A light-means-of-transport battery is a sealed traction battery weighing 25 kg or less, designed for a wheeled vehicle powered by an electric motor alone or by a combination of motor and human power, and not classified as an electric-vehicle battery. E-bike and e-scooter batteries are familiar examples.5
An electric-vehicle battery is defined by the vehicle for which it is designed. It includes traction batteries for hybrid or electric vehicles in categories M, N, and O, and qualifying category-L batteries weighing more than 25 kg. The weight condition helps separate some category-L batteries from the light-means-of-transport category; it is not a general minimum capacity or weight for electric-car batteries.
The industrial category is broader than ordinary commercial usage of the word industrial. It includes batteries designed for industrial use, batteries intended for industrial use after repurposing, and other batteries weighing more than 5 kg that do not fall into the electric-vehicle, light-means-of-transport, or starting-lighting-and-ignition categories. A stationary battery energy-storage system is expressly an industrial battery. Residential and commercial storage products can therefore fall within the passport requirement when their capacity exceeds 2 kWh.
The passport requirement should not be confused with the general QR-code requirement. From 18 February 2027, all batteries must bear a QR code, but only the three categories in Table 1 use that code to provide access to an Article 77 battery passport. For other batteries, the code provides access to the other information specified by Article 13.6
Incorporation into another product does not remove the battery from scope
The Batteries Regulation applies to batteries sold separately and to batteries incorporated into, added to, or designed to be incorporated into other products. A vehicle manufacturer, machinery producer, appliance supplier, or storage-system integrator cannot therefore treat the passport as irrelevant merely because the customer purchases a larger product rather than a separately packaged battery.
A cell or module supplier is not automatically responsible for the finished-battery passport. The decisive product boundary is whether the supplied object remains a component for further assembly or is itself supplied for end use as the regulated battery. Suppliers of cells and modules must nevertheless provide manufacturers, free of charge, with the information and documentation needed to comply with the Regulation.7
The trigger is first Union placement or first Union use
“Placing on the market” means the first making available of a battery on the Union market. “Making available” includes any commercial supply for distribution or use, whether paid or free. A later distributor sale may therefore be a making-available event without being a new placing-on-the-market event.
“Putting into service” captures the first use of a battery for its intended purpose in the Union where the battery has not previously been placed on the market. It covers, for example, batteries manufactured for an operator’s own use and systems assembled or first tested at their final installation site.
The relevant event is therefore not necessarily the retail sale date. It may be an import, a business-to-business supply, incorporation into a vehicle or system, a free commercial transfer, or first internal use.
Legal roles do not always match commercial labels
Actor or commercial role
Typical position
Important qualification
Battery manufacturer selling under its own name
Often the passport-responsible operator
Responsibility depends on the actual market-placement chain
Private-label or brand owner
May be treated as the manufacturer
Physical production by another company does not prevent manufacturer status
EU importer
May perform the first Union placement
Must not assume that an overseas passport service removes its EU obligations
Vehicle or equipment manufacturer
Must include the incorporated battery in its analysis
Responsibility depends on the finished-product and transaction structure
Distributor or retailer
Usually downstream of first placement
Can become a manufacturer if it rebrands, materially modifies, or changes the battery’s purpose
Cell or module supplier
Normally an upstream information provider
An end-use cell or module may itself be treated as a battery
Passport platform or cloud provider
Supporting contractor
Hosting does not transfer responsibility for data accuracy
Repurposer or remanufacturer
Can become directly responsible
A new linked passport is required when the altered battery is placed on the market or put into service
Repairer or waste operator
Usually a data user or lifecycle participant
Responsibility changes only under the conditions specified by the Regulation
End-user
Information recipient
Ownership or use alone does not create passport responsibility
Table 2: Market roles relevant to battery-passport responsibility.
A manufacturer is not limited to the company operating the factory. The definition includes a person that has a battery designed or manufactured and markets it under its own name or trademark, as well as a person that manufactures a battery for its own purposes and puts it into service.
An importer or distributor becomes subject to manufacturer obligations where a battery is placed on the market under that operator’s name or trademark, is modified in a way that may affect compliance, or has its purpose changed. Commercial labels such as reseller, marketplace seller, or channel partner do not override these legal conditions.
A separate distinction is required between the passport-responsible economic operator and the producer for extended producer responsibility. A company may occupy both roles, but the legal tests are not identical. The passport role is principally connected to the finished battery’s placement on the Union market or first use; producer status is defined in relation to supply within a Member State and the Regulation’s waste-management framework.
What the passport must contain and who may access it
The battery passport is not one public datasheet. It is a structured record containing several information layers. Some fields describe a battery model and may be reused across all batteries sharing that model. Other fields describe one physical battery and change as it is used, repaired, repurposed, remanufactured, or becomes waste.8
Model information and individual information serve different purposes
Dimension
Model-level information
Individual-battery information
Object described
A defined battery design or model
One uniquely identified physical battery
Typical behaviour
Relatively stable until design, evidence, plant, or declaration changes
Evolves during operation and lifecycle transitions
State of health, lifecycle status, cycle count, negative events, operating temperature, state of charge
Main source systems
Engineering, compliance, manufacturing, sustainability, and supplier records
Battery-management, service, inspection, and lifecycle systems
Principal use
Product transparency, conformity, repair, dismantling, and circularity
Residual-value assessment, further use, repurposing, remanufacturing, and recycling
Table 3: Difference between model-level and individual-battery information.
A static product page containing only model characteristics would therefore be incomplete. Article 77 expressly requires both model information and information specific to the individual battery, including information resulting from use.
Public information
The public layer includes general identification and manufacturing information, battery category and model identification, place and date of manufacture, weight, capacity, chemistry, specified hazardous substances, critical raw materials, and usable extinguishing agents.
It also includes applicable sustainability and circularity information, such as material composition, carbon-footprint information, responsible-sourcing information, recycled content, and renewable content. These fields enter the passport only to the extent that the underlying requirement applies to the relevant battery category, subcategory, plant, or date.
Public technical information includes rated capacity; minimum, nominal, and maximum voltage; original power capability; expected lifetime in cycles and the reference test; applicable temperature limits; warranty duration; initial and mid-life round-trip efficiency; internal cell and pack resistance; and the test rate used for the relevant cycle-life assessment. The public layer also includes applicable markings, the EU declaration of conformity, and information concerning waste prevention and management.9
Restricted model and conformity information
Restricted model information includes detailed cathode, anode, and electrolyte composition; component part numbers and replacement-spare sources; exploded diagrams; cell layout; disassembly sequences; fastener types; required tools; warnings; and safety measures.
These fields are relevant to repairers, remanufacturers, second-life operators, and recyclers, but they may also expose commercially sensitive engineering and supplier information. Access must therefore be purpose-limited rather than universal.
A separate restricted layer contains test-report results used to prove compliance. Those results are accessible to notified bodies, market-surveillance authorities, and the Commission rather than to every commercial user.
Individual operating and lifecycle information
The individual-battery layer includes:
performance and durability values at initial placement and when lifecycle status changes;
state-of-health information;
whether the battery is original, repurposed, re-used, remanufactured, or waste;
numbers of charging and discharging cycles;
negative events, including accidents;
periodically recorded operating conditions, including temperature; and
periodically recorded state of charge.
A battery’s state of health describes its general condition and ability to deliver specified performance compared with its initial condition. State of charge describes the currently available energy as a percentage of rated capacity. The two values answer different questions and should not be treated as interchangeable.
Access is differentiated
Information layer
Examples
Principal access class
Public model information
Identity, composition, sustainability declarations, declared performance, conformity declaration, waste information
Commission and qualifying persons with a legitimate interest
Regulatory conformity evidence
Results of compliance test reports
Notified bodies, market-surveillance authorities, and Commission
Individual-battery information
State of health, status, cycles, accidents, temperature, state of charge
Qualifying persons with a legitimate interest
Table 4: Statutory access classes for battery-passport information.
“Legitimate interest” is not a general commercial entitlement to the complete record. Article 77 requires the Commission to specify which persons qualify, which fields they may access, and the extent to which information may be downloaded, shared, published, or reused. The statutory criteria include necessity for residual-value assessment, further use, repair, repurposing, remanufacturing, recycling, or specified energy-market activity, combined with minimisation of commercially sensitive disclosure.10
As of 18 July 2026, that implementing act had not yet been adopted. The Regulation requires adoption by 18 August 2026. Organisations could therefore design the underlying role-based architecture, but the final person-by-field authorisation matrix remained an open implementation item.11
Access rights must be technically enforced
The passport must provide free access according to the requester’s rights. Permissions to read, introduce, modify, or update data must be restricted. The system must also support authentication, reliability, integrity, security, privacy, fraud prevention, open standards, interoperability, machine readability, structure, searchability, and transfer without vendor lock-in.12
Each field should therefore be classified along at least six dimensions:
legal basis;
applicability to the battery category and date;
model, batch, or item granularity;
public or restricted access class;
authoritative data source; and
creation and update trigger.
BatteryPass-Ready’s data-attribute longlist is useful implementation guidance because it consolidates regulatory, technical, and recommended attributes. It is not itself legislation, and it explicitly contains suggested as well as mandatory fields. Implementers should trace every production field to its legal, standardisation, or voluntary basis.13
Who must supply, verify, host, and update the data
The Regulation separates four functions that organisations often confuse: originating information, validating evidence, operating the technical record, and bearing legal responsibility. The economic operator placing the finished battery on the market remains responsible for accuracy, completeness, and currency, even where other organisations perform the work.14
A data originator is the actor or system closest to the measurement, declaration, calculation, or lifecycle event. A material supplier may originate composition data; a manufacturing system may originate place and date information; a battery-management system may originate temperature or cycle information; and a repairer may originate a service event. The passport-responsible operator must decide whether the evidence is sufficient and approve its use.
Actor
Principal contribution
Responsibility boundary
Material, cell, and module suppliers
Supply composition, manufacturing, sustainability, and technical evidence
Providing evidence does not normally create responsibility for the finished passport
Battery or pack manufacturer
Generate design, performance, conformity, production, and item-traceability records
Becomes responsible where it performs the relevant market placement or first use
Vehicle, equipment, or storage-system manufacturer
Integrate battery records with the finished product and market pathway
Must determine whether it places the incorporated battery on the market
Importer or private-label operator
Obtain, evaluate, and maintain evidence from non-EU suppliers
Cannot rely on an overseas database as a substitute for its own responsibility
Sustainability and compliance functions
Produce calculations, declarations, due-diligence information, and conformity evidence
Specialist work supports but does not replace passport accountability
Passport or cloud provider
Host records, provide interfaces, enforce access, and maintain availability
Technical outsourcing does not transfer responsibility for data correctness
Repairer or service operator
Produce authorised service events and condition information
May change only fields for which it has authority
Repurposer or remanufacturer
Assess the altered battery and create a linked successor passport
Becomes responsible when placing the altered battery on the market or putting it into service
Producer, producer responsibility organisation, or selected waste operator
Assume responsibility when the battery becomes waste under Article 77(7)
Must preserve and update the record during the relevant waste stage
Recycler
Complete end-of-life treatment
The passport ceases after recycling
Table 5: Allocation of data-generation and accountability functions.
Supplier information must be evidential, not merely available
Article 39 requires suppliers of cells and modules to provide manufacturers, free of charge, with the information and documentation necessary for compliance. Many required fields nevertheless originate further upstream, particularly material composition, recycled-content evidence, carbon-footprint inputs, and responsible-sourcing information.
A defensible supplier submission should identify:
the model, plant, batch, component, or battery to which it applies;
the unit, method, and reporting period;
the originating organisation and source system;
the supporting declaration, test, calculation, or assurance evidence;
the date and version;
conditions under which the value remains valid; and
the process for notifying and correcting errors or production changes.
Supplier contracts should address data-use rights, permitted disclosure, correction duties, retention, audit cooperation, change notification, evidence access, and support during market-surveillance or lifecycle investigations.
Verification occurs at several layers
Source verification confirms that the supplier, document, laboratory, or system is authentic. Identity verification confirms that the evidence belongs to the correct model, plant, batch, or item. Transformation verification checks calculations, aggregation, allocation, and unit conversion. Semantic verification checks structure, vocabulary, datatype, and unit. Approval verification records which authorised person or system accepted the value for publication.
A passport can pass one layer and fail another. A correctly formatted carbon-footprint value may belong to another manufacturing plant. A genuine supplier declaration may be associated with the wrong battery model. A plausible state-of-health estimate may rely on an undocumented algorithm.
No general rule requires independent certification of every passport field. Some values are subject to conformity-assessment or verification requirements elsewhere in the Batteries Regulation; others remain under the responsible operator’s internal control and potential market-surveillance review. Battery Pass guidance usefully distinguishes statutory conformity assessment from additional assurance that companies may apply to increase trust in data.15
Hosting and registry registration are different functions
The detailed battery information follows a decentralised architecture. It remains under the responsibility of the relevant operator and may be hosted directly or through an authorised service provider. A provider processing the data may not sell, reuse, or process it beyond what is necessary to provide the service. The passport must remain available even if the responsible operator ceases to exist or ceases activity in the Union.16
The EU DPP Registry is an indexing and verification layer rather than a central repository of every detailed passport field. It stores identifiers, registration data, and high-level metadata; provides interfaces for registration; supports verification and logging; and maintains common semantic resources.17
Commission Implementing Regulation (EU) 2026/1778 requires registration through a secure interface or application programming interface. The registry automatically checks matters such as semantic conformity, granularity, identifier coherence, relevant commodity codes, and applicable backup links. It then generates a persistent registration identifier and proof of registration.
Those automated checks are not a substantive certification of the battery’s claims. The implementing regulation expressly leaves the factual correctness of registered information to the responsible operator and market-surveillance framework.
%%{init: {"theme": "neo", "look": "handDrawn", "layout": "elk"}}%%
flowchart TD
A[Material, cell, and module suppliers<br/>source evidence] --> B[Manufacturer and OEM systems<br/>engineering, manufacturing, compliance]
B --> C[Responsible economic operator<br/>approve, publish, maintain]
D[Battery-management and service systems<br/>condition and lifecycle events] --> C
C --> E[Decentralised passport store<br/>operator or authorised provider]
E --> F[QR code and unique identifier<br/>role-based access]
C --> G[EU DPP Registry<br/>identifiers and registration data]
C --> H[Repurposer or remanufacturer<br/>new linked passport]
H --> I[Waste-stage responsible actor<br/>producer, PRO, or selected operator]
I --> J[Recycling completed<br/>passport ceases]
Figure 1: Information and responsibility flow from upstream evidence to the decentralised passport, EU registry, and successor lifecycle operators.
Updates must follow the event and the authorised role
Model information may change because of a corrected declaration, changed supplier, revised manufacturing process, new plant, design modification, or updated conformity evidence. Individual-battery information changes through operation, inspection, accidents, repair, state-of-health estimation, repurposing, remanufacturing, or transition to waste.
The system should preserve the previous value, timestamp the change, identify its origin, and state whether the value was measured, declared, calculated, or estimated.
Event
Required response
Supplier corrects evidence
Identify affected batteries or models, approve the correction, version the field, and preserve provenance
Design or manufacturing characteristics change
Decide whether to update the model record or create a new model identity
Battery-management system produces new data
Introduce values through an authorised interface with item identity, timestamp, and method
Repair changes condition information
Record the service event and update only authorised individual fields
Repurposing or remanufacturing leads to renewed placement or use
Transfer responsibility and create a new passport linked to the predecessor passport or passports
Battery becomes waste
Transfer responsibility to the actor specified by Article 77(7)
Recycling is completed
End the passport
Table 6: Principal battery-passport update and responsibility-transfer events.
The Regulatory Timeline from July 2026 to February 2027
The timetable contains different kinds of milestones. Adoption of a standard does not start the product obligation. Publication of registry rules does not make passports mandatory immediately. The decisive product-compliance date remains 18 February 2027.
Six harmonised standards were cited on 15 July 2026
Commission Implementing Decision (EU) 2026/1736 cited six harmonised European standards for the common DPP system.18
Standard
Subject
EN 18216:2026
Data-exchange protocols
EN 18219:2026
Unique identifiers
EN 18220:2026
Data carriers
EN 18221:2026
Data storage, archiving, and persistence
EN 18222:2026
APIs for lifecycle management and searchability
EN 18223:2026
System interoperability
Table 7: Harmonised DPP standards cited on 15 July 2026.
Conformity with a cited harmonised standard creates a presumption of conformity only for the requirements that the standard covers. It does not prove that a composition declaration, carbon-footprint value, state-of-health estimate, or other substantive claim is factually correct.
Registry rules were published on 17 July 2026
Commission Implementing Regulation (EU) 2026/1778 was adopted on 16 July and published on 17 July 2026. It establishes registry verification, actor onboarding, user-interface and API registration, automated checks, registration identifiers, evidence of registration, versioning, logging, semantic resources, and responsibilities.19
The regulation enters into force on the twentieth day following publication, 6 August 2026. The Commission’s battery and registry pages listed 20 July 2026 as the planned date on which the registry, testing environment, and user guidance would become operational. As this article is dated 18 July 2026, that operational milestone had not yet occurred.20
Access rules remained pending
Article 77 requires the Commission to adopt the legitimate-interest implementing act by 18 August 2026. As of 18 July, Commission webinar material still described the access-rights work as under development.21
Mandatory cutover is 18 February 2027
From 18 February 2027, an in-scope battery placed on the Union market or put into service must have its passport. The battery’s unique identifier must also be uploaded to the DPP Registry under the amended Article 77 framework.22
The passport date does not automatically accelerate every underlying sustainability obligation. Carbon-footprint declarations, recycled-content information, due-diligence disclosures, and related fields enter the passport to the extent that their separate legal requirements apply to the relevant battery category and date.
Date
Milestone
Practical consequence
15 July 2026
Six harmonised DPP standards cited
Recognised technical conformity route becomes available for covered requirements
17 July 2026
Registry implementing regulation published
Final registry operating rules become available
20 July 2026
Planned registry and testing-environment launch
Operators and providers can begin using the Commission infrastructure
Restricted-access categories and reuse permissions are to be specified
18 February 2027
Battery passport becomes mandatory
Each newly placed or commissioned in-scope battery must have a passport and registry entry
After placement
Lifecycle obligations continue
Information must be updated and responsibility transferred where applicable
Table 8: Principal implementation milestones as understood on 18 July 2026.
Operational readiness: a role-by-role action plan
Only 18 February 2027 is the universal statutory product cutover in the schedule below. The intermediate dates are recommended management targets derived by working backward from that obligation. They are not additional legal deadlines.
Readiness should be assessed per battery model and commercial pathway. A company may be ready for a domestically manufactured model but unready for an imported model because the supplier chain, responsible operator, plant evidence, identifier process, or passport interfaces differ.
Establish one governed programme
The accountable operator should appoint a programme owner with authority across regulatory compliance, engineering, manufacturing, procurement, sustainability, information technology, cybersecurity, legal affairs, service, logistics, and end-of-life operations.
The programme should maintain six controlled artefacts:
an inventory of batteries, models, plants, and market pathways;
a field-level passport data dictionary;
a responsibility and approval matrix;
an architecture and interface specification;
a lifecycle-event and responsibility-transfer procedure; and
a model-by-model production-readiness record.
The data dictionary should record the legal basis, applicability, granularity, data type, unit, source, evidence owner, transformation method, approver, access class, update trigger, retention rule, and destination for every field.
Role-based work packages
Role
Required work
Evidence of readiness
Recommended target
Executive sponsor and programme owner
Approve scope, accountability, funding, governance, escalation, and release controls
Programme mandate and readiness dashboard
31 August 2026
Regulatory and legal team
Classify batteries, identify relevant market events and operators, and monitor secondary acts
Approved scope decisions and obligations register
Initial decisions by 31 August 2026
Engineering and product-lifecycle-management team
Define models, specifications, composition, performance, and dismantling records
Approved model data and engineering evidence
30 September 2026
Manufacturing and quality team
Link plants, dates, batches, serialised items, identifiers, and conformity records
Physical-to-digital traceability test
Pilot by 31 October 2026
Procurement and supplier-management team
Amend contracts, obtain structured evidence, and establish correction processes
Supplier coverage and evidence-quality report
Priority suppliers by 30 September; full coverage by 30 November 2026
Sustainability and compliance team
Prepare applicable footprint, recycled-content, sourcing, and conformity information
Versioned declarations and applicability decisions
Integration tested by 30 November 2026
IT and data-architecture team
Implement passport storage, semantics, interfaces, QR resolution, registry integration, and versioning
End-to-end technical test
Production-ready by 31 January 2027
Cybersecurity and identity team
Implement authentication, least privilege, logging, integrity, incident response, and credential controls
Access testing and security assurance
31 January 2027
Service provider
Demonstrate interoperability, continuity, recovery, export, and prohibited-use controls
Recovery, export, and exit tests
Contracted by 30 September; tested by 31 December 2026
Import, logistics, and customs team
Prevent release of batteries lacking valid passports, identifiers, and registration
Shipment-release and blocking test
31 December 2026
Repair and field-service team
Define authorised service events, methods, evidence, and updates
Service-to-passport integration test
31 January 2027
Repurposing and remanufacturing team
Create predecessor-link, successor-identity, testing, and responsibility procedures
Demonstrated linked successor passport
31 January 2027
Waste-management team
Define waste-status transfer and recycling closure
Transfer and termination procedure
31 January 2027
Audit or assurance function
Test completeness, lineage, access separation, continuity, and release controls
Manufacturing and integration teams should distinguish the model identifier, the individual battery identifier, and the economic-operator identifier. The item identifier must remain associated with the physical battery, its QR code, the decentralised record, and the corresponding registry entry.
Release testing should cover duplicate identifiers, QR codes resolving to the wrong record, identifiers that fail registration, reworked batteries linked to obsolete records, and successor batteries that lose links to predecessor modules or packs.
Production release should be blocked where the passport cannot be resolved, the identifier does not match the manufacturing record, mandatory initial fields are absent, or registry submission has failed.
Convert supplier contracts into data contracts
Procurement should issue field-specific requirements rather than ask suppliers generally for “battery passport data.” Each critical submission should be tested through the complete cycle: ingestion, semantic validation, association with the correct model or batch, evidence review, rejection, correction, approval, and publication.
Contracts should cover permitted use, public and restricted disclosure, traceability, formats, retention, change notification, historical correction, market-surveillance cooperation, cybersecurity, and continuity.
Distinguish missing, inapplicable, and restricted information
The data model should distinguish:
not applicable: the requirement does not apply;
not yet applicable: the requirement starts at a later date;
unavailable: required information has not been obtained;
unknown: the value cannot presently be determined;
restricted: the value exists but is not available to the requester.
Using one blank or null state for all five conditions prevents reliable compliance checks and misleads passport users.
Prove portability and continuity
Technology providers should demonstrate more than a working public webpage. The operator should test data export, backup restoration, migration to an alternative environment, credential rotation, administrator revocation, recovery from provider unavailability, and continued resolution of existing QR codes.
A backup is insufficient if it preserves values but loses identifiers, permissions, predecessor links, version history, or audit records.
Rehearse the entire pathway
Implementation window
Required outcome
July–August 2026
Scope, accountable operator, battery inventory, and preliminary field dictionary approved
September 2026
Supplier contracts, provider arrangements, identity model, and architecture established
October–November 2026
Source integration, passport generation, QR resolution, registry connection, and access controls tested
December 2026
Representative pilots completed for manufacture, import, incorporated batteries, repair, and second life
Production configuration frozen; release controls activated; unresolved batteries blocked
From 18 February 2027
Each in-scope battery released only after successful passport and registration checks
Thereafter
Corrections versioned, access governed, lifecycle events recorded, and successor transfers completed
Table 10: Recommended implementation schedule working backward from the mandatory date.
The final rehearsal should begin with a physical battery and end with a correct QR result, appropriate public and restricted views, denial of unauthorised access, successful registration, retrievable evidence, a simulated correction, and a demonstrated lifecycle update.
Open implementation questions and compliance risks
The remaining uncertainty concerns implementation detail rather than the existence of the obligation. Product scope, passport content, principal responsibility, differentiated access, the unique identifier, and the February 2027 date are already established.
Restricted-access rules were still incomplete
The pending Article 77(9) act creates two opposing risks. Over-disclosure may expose detailed composition, supplier, dismantling, safety, or operating data. Under-disclosure may prevent a legitimate repairer, second-life operator, recycler, purchaser, or energy-market participant from exercising a permitted right.
Access policy should therefore be configurable and separate from the stored content. The system should support identity verification, purpose-specific access, field-level permissions, logging, revocation, and distinct rules for viewing, downloading, sharing, publishing, and reuse.
Structural conformity is not factual correctness
A passport may use the correct schema, identifier, API, and vocabulary while containing a value associated with the wrong plant, supplier batch, model, or battery. Registry acceptance proves that specified registration checks succeeded; it does not establish that every claim is true.
Validation layer
Question
Structural
Are required elements present and correctly formatted?
Semantic
Do the values use the expected terms, units, and meanings?
Identity
Do the records belong to the correct model, batch, plant, or item?
Evidential
Is the value supported by an appropriate declaration, test, calculation, or source record?
Substantive
Is the claim factually correct under the applicable method and conditions?
Table 11: Distinct validation layers for battery-passport data.
Dynamic information can create false precision
State-of-health, internal-resistance, temperature, cycle-count, and related values depend on sensors, battery-management logic, sampling frequency, calibration, operating conditions, and estimation algorithms. Two passports may report the same numerical state of health while referring to different methods or reference conditions.
The operator should therefore preserve method provenance: whether the value was measured or estimated, the method or algorithm, software version, reference conditions, timestamp, source system, and relevant quality flag.
The passport should also distinguish an instantaneous value from a period aggregate, a nominal condition from an observed condition, and a manufacturer estimate from a later independent assessment.
Provider concentration creates continuity risk
Dependency
Potential failure
Passport hosting
Existing QR codes stop resolving
Identifier service
New batteries cannot receive valid identities
Registry integration
Product release is blocked
Access-control service
Restricted information is exposed or legitimate access fails
Semantic mapping
Source data are mistransformed or rejected
Cryptographic credentials
The responsible operator loses update control
Proprietary lifecycle model
History cannot be migrated without loss
Table 12: Principal service-provider dependencies.
Continuity planning must preserve the regulatory function of the passport, not only a copy of its data.
Repair, preparation for re-use, repurposing, remanufacturing, transition to waste, and recycling have different legal consequences. A repair may update the original record. Repurposing or remanufacturing followed by a new placement or first use requires a new passport linked to its predecessor or predecessors. Waste status transfers responsibility under Article 77(7), while completed recycling ends the passport.
Ownership transfer alone does not necessarily transfer passport responsibility. The trigger is the regulated lifecycle or market event, not merely a change in title.
Enforcement can interrupt market access
Member States must establish effective, proportionate, and dissuasive penalties. Market-surveillance authorities may also require corrective action, withdrawal, or recall. In practice, an incomplete passport can disrupt trade before a fine is imposed: imports may be blocked, production release may stop, or a second-life operator may be unable to demonstrate lawful lineage.23
Failure mode
Principal exposure
Minimum preventive control
Battery misclassified as out of scope
Unregistered battery placed on the market
Documented classification and capacity decision
Duplicate or incorrect identifier
Loss of physical–digital traceability
Uniqueness check and release-time QR test
Mandatory field missing
Incomplete passport at placement
Applicability-driven completeness gate
Supplier value lacks provenance
Unsupported public or restricted claim
Evidence linked to model, plant, batch, and version
Where the battery passport meets the Cyber Resilience Act
The Batteries Regulation and the Cyber Resilience Act regulate different objects. The battery-passport provisions govern an electronic lifecycle record for specified batteries. The Cyber Resilience Act, or CRA, governs hardware and software products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. A battery passport does not therefore make a battery automatically subject to the CRA, and CRA compliance does not by itself satisfy the passport requirements.24
The two regimes nevertheless intersect wherever an in-scope battery contains or depends on connected digital components. Examples can include battery-management-system hardware and firmware, communications modules, diagnostic software, energy-management interfaces, mobile applications, and remote processing used for monitoring or control. The passport then records information about a battery whose digital functions may separately be subject to cybersecurity requirements.
CRA scope must be assessed separately for each digital product
A product falls within the CRA where it is a software or hardware product, including a separately marketed component, and its intended or reasonably foreseeable use involves a logical or physical data connection. A battery pack with an embedded battery-management system can therefore be a product with digital elements where the pack processes, stores, or transmits digital data and connects directly or indirectly to another device or network.25
The conclusion is not universal. Some batteries contain no relevant connected functionality. Others are incorporated into products governed by sectoral legislation that changes the CRA analysis. In particular, the CRA expressly excludes products with digital elements to which Regulation (EU) 2019/2144 on motor-vehicle type approval and general safety applies. This exclusion may be relevant to digital battery systems covered through the type-approval framework for road vehicles, but it is not a general exemption for every electric-vehicle, light-means-of-transport, or industrial battery.
Object or service
Battery-passport position
CRA scope question
Connected industrial battery with a networked battery-management system
Passport required where capacity exceeds 2 kWh
The battery or BMS can be a product with digital elements if its use includes a data connection
Connected LMT battery
Passport required regardless of capacity
Embedded firmware, diagnostic interfaces, or communications components may bring the relevant product within CRA scope
Electric-vehicle battery or associated digital component
Passport required
Determine whether the relevant product is excluded because Regulation (EU) 2019/2144 applies
Standalone BMS, gateway, diagnostic application, or firmware product
May supply or update passport data
Can be independently subject to the CRA when made available on the market as a connected hardware or software product
Hosted battery-passport database
Operates the regulated electronic record
Not automatically a CRA remote data processing solution; scope depends on its relationship to a product with digital elements
Remote battery-monitoring or control service
May generate individual-battery passport information
Falls within the CRA product boundary where it is developed under the manufacturer’s responsibility and its absence would prevent the connected product from performing one of its functions
QR code printed on the battery
Provides access to the passport
The printed carrier alone is not the relevant product with digital elements
Table 14: Product boundaries at the intersection of the battery passport and the Cyber Resilience Act.
The hosted passport system requires particular care. Under the CRA, remote data processing is included in a product with digital elements only where the remote software is designed and developed by, or under the responsibility of, the product manufacturer and its absence would prevent the product from performing one of its functions. A cloud service that merely stores the legally required passport record does not meet that definition solely because the QR code points to it. A remote service required for battery control, safety management, charging optimisation, or another product function may produce a different result.
A passport platform distributed as a software product can also fall within the CRA in its own right, independently of whether it is integral to battery operation. The relevant inquiry is therefore not whether software is described commercially as a “platform,” “service,” or “passport solution,” but whether a hardware or software product with the required connection is made available on the Union market.
The two regulations impose overlapping controls for different purposes
Article 78 of the Batteries Regulation requires restricted rights to access, introduce, modify, or update passport information; data authentication, reliability, and integrity; a high level of security and privacy; fraud avoidance; continued availability; interoperability; and protection against unauthorised secondary use by service providers.26
The CRA is broader and more prescriptive where it applies. It requires a documented cybersecurity risk assessment and risk-based security throughout planning, design, development, production, delivery, and maintenance. Its essential requirements address known exploitable vulnerabilities, secure default configurations, security updates, authentication and access management, confidentiality, integrity, data minimisation, availability, attack-surface reduction, security monitoring, secure data removal, vulnerability testing, coordinated disclosure, and secure update distribution.27
Control area
Battery-passport requirement
Additional CRA consequence where applicable
Identity and access
Restrict reading and modification according to passport access rights
Implement risk-based authentication, identity management, unauthorised-access protection, and security monitoring
Data integrity
Ensure authentication, reliability, and integrity of passport information
Protect data, commands, software, and configurations against unauthorised manipulation
Confidentiality
Protect privacy and commercially sensitive restricted information
Protect stored and transmitted data using appropriate state-of-the-art measures
Availability
Keep the passport available even after the responsible operator ceases activity
Protect essential product functions against incidents and denial-of-service conditions
Software dependencies
Not a prescribed public passport dataset
Identify components and maintain a machine-readable software bill of materials for vulnerability handling
Vulnerability management
Not comprehensively regulated by Articles 77–78
Identify, document, test, remediate, disclose, and securely patch vulnerabilities throughout the support period
Portability
Use open standards and avoid vendor lock-in
CRA does not replace the passport’s interoperability and portability duties
Incident reporting
No equivalent general cyber-incident notification process in the passport provisions
Notify actively exploited vulnerabilities and severe security incidents through the CRA reporting mechanism
Table 15: Complementary security obligations under the battery-passport rules and the CRA.
The overlap permits reuse of technical controls, but not legal substitution. An access-control system designed for CRA conformity can help satisfy the passport requirement to restrict modification rights. Integrity monitoring and secure software-update mechanisms can protect the systems that generate individual-battery information. A shared incident-response process can investigate unauthorised changes to passport data and vulnerabilities in the connected battery product.
The evidence must nevertheless remain distinguishable. The battery-passport file should show that information is accurate, appropriately disclosed, interoperable, and maintained across lifecycle transfers. The CRA technical file must show that the product with digital elements underwent a cybersecurity risk assessment, meets the applicable essential cybersecurity requirements, and is supported by effective vulnerability-handling processes.
The passport is not a public CRA compliance repository
Some information needed for CRA compliance can be associated with passport identifiers without being published in the passport. The CRA requires manufacturers to identify and document software components through a machine-readable software bill of materials, but it does not require that bill of materials to become part of the public battery passport. Detailed dependency information can itself increase security risk if disclosed without an appropriate purpose and access model.
The same distinction applies to vulnerability records. A battery passport may provide stable product and model identifiers that help determine which batteries are affected by a vulnerability or security update. It should not become a public vulnerability database containing exploit-sensitive information merely because the product identifier is shared.
A defensible architecture uses the battery identifier as a controlled reference between separate records:
the battery passport contains the information required by Articles 77–78 and Annex XIII;
the CRA technical documentation contains the cybersecurity risk assessment, component and vulnerability evidence, and conformity material;
the vulnerability-management system records affected versions, patches, disclosure decisions, and reporting events; and
the service system delivers security updates and user instructions to the affected installed base.
This separation allows the organisation to preserve one consistent product identity while applying different disclosure, retention, evidentiary, and update rules.
Responsibilities may be allocated to different legal actors
The responsible operator under the battery-passport provisions and the CRA manufacturer will often be the same company, particularly where a manufacturer markets a connected battery under its own name. They should not, however, be assumed to coincide.
The battery passport centres on the economic operator placing the finished battery on the market and on later responsibility transfers during repurposing, remanufacturing, waste treatment, and recycling. The CRA manufacturer is the person that develops or manufactures—or has developed or manufactured—a product with digital elements and markets it under its name or trademark.
A battery importer could therefore be responsible for the passport while the non-EU manufacturer retains primary CRA manufacturer obligations, subject to the importer duties imposed by the CRA. A passport-platform supplier may be the CRA manufacturer of its software while acting only as an authorised processor for the battery passport. A repurposer may become responsible for a successor passport and may also assume CRA manufacturer obligations if its modification is substantial and the modified product with digital elements is made available on the market.
The compliance matrix should consequently identify, for every relevant battery configuration:
the operator responsible for the battery passport;
the manufacturer of each potentially in-scope product with digital elements;
the EU importer and distributor roles;
the owner of the cybersecurity risk assessment;
the owner of vulnerability handling and security updates;
the actor authorised to change passport information; and
the actor responsible for reporting vulnerabilities and incidents.
The dates require a staged compliance programme
The battery-passport obligation begins before the CRA becomes fully applicable. The CRA’s Article 14 reporting obligations apply from 11 September 2026. The battery passport becomes mandatory on 18 February 2027. Most remaining CRA obligations apply from 11 December 2027.28
The early CRA reporting date is particularly important. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting in-scope products with digital elements. The reporting obligation also applies to relevant products placed on the market before 11 December 2027. Manufacturers should therefore establish product-security contacts, escalation criteria, affected-product identification, user-notification procedures, and access to the CRA reporting platform before the battery passport enters production.
Date
Battery-passport consequence
CRA consequence
11 September 2026
Passport implementation is still in preparation
Reporting obligations begin for actively exploited vulnerabilities and severe product-security incidents
18 February 2027
Passport becomes mandatory for newly placed or commissioned in-scope batteries
CRA reporting continues where the connected battery product falls within scope
11 December 2027
Passport lifecycle and update duties continue
CRA product, manufacturer, conformity, vulnerability-handling, support-period, and market-surveillance requirements become generally applicable
Table 16: Combined battery-passport and CRA implementation timeline.
The CRA support period must reflect the time during which the product is expected to be used and is normally at least five years, unless the expected use is shorter. For connected battery products expected to remain operational for longer periods, the assessment may require a correspondingly longer vulnerability-handling and security-update commitment. That commitment should be aligned with the passport’s longer lifecycle, including repair, second-life assessment, repurposing, and changes in the responsible operator.
The practical conclusion is that battery-passport security should be designed as part of the connected product’s cybersecurity architecture rather than added as a separate compliance layer. Shared identities, secure update channels, access logs, version control, incident detection, supplier vulnerability information, and continuity arrangements can support both regimes. The organisation must still maintain two explicit scope decisions and two evidence trails: one demonstrating trustworthy battery lifecycle information, and the other demonstrating the cyber resilience of the hardware, software, and remote processing through which that information is created or used.
Conclusion: treat the passport as shared infrastructure
From 18 February 2027, each electric-vehicle battery, light-means-of-transport battery, and industrial battery above 2 kWh that is newly placed on the Union market or put into service must have an individual battery passport.
The directly responsible economic operator must classify the battery, identify the relevant market event, create and maintain the passport, ensure the accuracy and applicability of its information, assign the unique identifier, provide the QR-code link, complete registry registration, enforce access rights, and preserve the record through the relevant lifecycle.
Other actors are affected because the responsible operator cannot perform those duties without them:
Who is affected
What they must contribute
When
Responsible manufacturer, importer, private-label operator, or other market-placing operator
Passport creation, approval, registration, maintenance, and release control
Before placement or first use from 18 February 2027
Material, cell, module, and component suppliers
Traceable technical, composition, sustainability, and conformity evidence
Early enough for validation and production integration
Vehicle, machinery, appliance, and storage-system manufacturers
Incorporated-battery classification, identity, evidence, and system integration
During development and production preparation
Engineering, manufacturing, sustainability, and compliance teams
Model data, plant data, calculations, declarations, test evidence, and approvals
Before release and whenever relevant inputs change
IT, cybersecurity, and passport providers
Interoperability, identifiers, registry connection, access control, continuity, and export
Tested before the February 2027 cutover
Import, logistics, and distribution functions
Prevent supply of batteries lacking the required passport and registration
At import, shipment, and first commercial supply
Repairers and service operators
Authorised condition, service, and event updates
When relevant service events occur
Repurposers and remanufacturers
Testing, new configuration evidence, predecessor linkage, and successor passport
Before renewed placement or first use
Waste and recycling operators
Waste-status transfer, record maintenance, and final closure
When the battery becomes waste and when recycling ends
Table 17: Final summary of who must act, what they must do, and when.
The practical test of readiness is not whether an organisation owns a QR-code generator or has purchased a passport platform. It is whether each battery model and market pathway can pass a controlled release decision: scope decided, responsible operator named, required fields populated, evidence available, identity validated, access enforced, registry submission successful, continuity tested, and lifecycle updates governed.
The battery passport is therefore best understood as shared infrastructure for battery information. It must preserve four properties simultaneously: identity, so that the record belongs to the correct battery; provenance, so that claims can be traced to evidence; authorisation, so that users can access or modify only what their purpose permits; and continuity, so that the record survives changes in use, ownership, operator, provider, and lifecycle status.
The February 2027 deadline is not the end of a software project. It is the beginning of a governed information lifecycle.
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Commission. (2026). Batteries: Digital Product Passport. Directorate-General for Internal Market, Industry, Entrepreneurship and SMEs. Official guidance.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Commission. (2026). The EU Digital Product Passport for Batteries—Webinar 2: Latest Updates, Key Requirements and Industry Perspectives. Directorate-General for Internal Market, Industry, Entrepreneurship and SMEs. Official event materials.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
BatteryPass-Ready. (2026). Battery Passport Data Attribute Longlist, version 1.3. BatteryPass-Ready. Implementation resources.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Commission. (2026). Commission Implementing Regulation (EU) 2026/1778 laying down the implementation arrangements for the digital product passport registry. Official Journal of the European Union. Official text.↩︎
European Commission. (2026). Commission Implementing Decision (EU) 2026/1736 on harmonised standards for digital product passports. Official Journal of the European Union. Official text.↩︎
European Commission. (2026). Commission Implementing Regulation (EU) 2026/1778 laying down the implementation arrangements for the digital product passport registry. Official Journal of the European Union. Official text.↩︎
European Commission. (2026). The DPP Registry. Directorate-General for Internal Market, Industry, Entrepreneurship and SMEs. Official guidance.↩︎
European Commission. (2026). The EU Digital Product Passport for Batteries—Webinar 2: Latest Updates, Key Requirements and Industry Perspectives. Directorate-General for Internal Market, Industry, Entrepreneurship and SMEs. Official event materials.↩︎
European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable products. Official Journal of the European Union. Official text.↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), Articles 2–3. Official Journal of the European Union. Official text. (EUR-Lex)↩︎
European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), Articles 2–3. Official Journal of the European Union. Official text. (EUR-Lex)↩︎
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Articles 3, 13, 38–45, 77–79, and Annex XIII. Official Journal of the European Union, L 191. Official text.↩︎
European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), Articles 13–14 and Annexes I–II. Official Journal of the European Union. Official text. (EUR-Lex)↩︎
European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), Articles 69 and 71. Official Journal of the European Union. Official text; European Commission. (2025). The Cyber Resilience Act—Summary of the legislative text. Directorate-General for Communications Networks, Content and Technology. Official summary. (EUR-Lex)↩︎
@online{montano2026,
author = {Montano, Antonio},
title = {The {EU} {Digital} {Battery} {Passport:} {Who} {Is}
{Affected,} {What} {Must} {Be} {Done,} and {When}},
date = {2026-07-18},
url = {https://antomon.github.io/longforms/eu-digital-battery-passport-who-is-affected-what-must-be-done-and-when`/},
langid = {en},
abstract = {The European Union’s digital battery passport is an
electronic record for individual electric-vehicle batteries,
light-means-of-transport batteries, and industrial batteries with a
capacity greater than 2 kWh. For batteries placed on the Union
market or put into service from 18 February 2027, the passport must
provide prescribed product, sustainability, performance, durability,
conformity, repair, and lifecycle information through differentiated
access rights. Although the central legal responsibility falls on
the economic operator placing the finished battery on the market,
compliance depends on a wider information chain. Material, cell, and
module suppliers must provide reliable source evidence; battery and
vehicle manufacturers must integrate and validate it; importers and
private-label operators must determine whether they assume the
responsible role; technical providers must support interoperable and
durable records; and repair, repurposing, remanufacturing,
waste-management, and recycling operators must update or succeed the
record as the battery changes status. This article argues that the
battery passport should be treated as governed lifecycle data
infrastructure rather than as a QR-code or labelling project. It
distinguishes directly regulated batteries and organisations from
supporting participants, explains the required information and
access structure, reconstructs the implementation timetable as it
stood on 18 July 2026, and translates the legal framework into a
role-based preparation plan. It also identifies areas in which
secondary legislation, technical operation, and industry practice
were still developing.}
}