Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · DPP: data, identifiers and standards

Updated

DPP security standards (EN 18239:2026 and EN 18246:2026)

Also known as: EN 18239, EN 18246, EN 18239:2026, EN 18246:2026, DPP access and integrity standards, prEN 18239, prEN 18246

The DPP security standards are two final European standards for the digital product passport, made available by CEN/CENELEC on September 16, 2026: EN 18239:2026 on access rights management, information system security and business confidentiality, and EN 18246:2026 on data authentication, reliability and integrity. As of September 27, 2026 their references were not cited in the Official Journal of the European Union, so they do not confer presumption of conformity with the ESPR requirements they address.

  • EU
  • DPP
  • Data governance

In one sentence

EN 18239:2026 (access, security, confidentiality) and EN 18246:2026 (authentication, integrity) are final DPP standards, not yet cited in the OJEU.

Example

A company designing its passport access model applies EN 18239:2026, records the edition in its documentation and adds its own risk-based justification, because the standard is not yet cited and gives no presumption of conformity.

How it applies

  • Status: Both are final European standards. Their references are not cited in the Official Journal — Implementing Decision (EU) 2026/1736 lists only EN 18216 and EN 18219–18223 — so they do not confer presumption of conformity. Re-check the citation status before stating it.
  • Subjects: EN 18239:2026 addresses access rights, information system security and business confidentiality; EN 18246:2026 addresses authentication, reliability and integrity of passport data.
  • Using them now: Teams can apply the standards before citation, but they still justify their access, security and trust mechanisms on their own responsibility. Record the edition applied, and re-check the implementation when the references are cited. Most of the organizational work lies there anyway.
  • Security law: Passport systems and connected products may also fall under the Cyber Resilience Act; the DPP standards do not replace its requirements.

Compared with the USA, Canada and China

No other of the four has security standards for a product passport. Access and security for traceability data follow general cybersecurity rules and frameworks, such as the NIST frameworks in the USA or China's data security and cybersecurity laws.

Read more on AI TechDoc Press

The in-depth analysis behind this entry, in the AI TechDoc Press newsletter. Subscribe for free

By knowledge.aitechdoc.world · Published September 25, 2026 · Last reviewed

Source: CEN/CENELEC JTC 24, EN 18239:2026 and EN 18246:2026 (made available September 16, 2026); Commission Implementing Decision (EU) 2026/1736 and the Official Journal of the European Union (citation status as of September 27, 2026)Source updated

Updates to this entry — previous versions in the editors’ archive:

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!