Medical device manufacturers keep asking us when ESPR will force a Digital Product Passport on them. Short answer: there is no date. Medical devices are not in the first ESPR working plan, and anyone selling you urgency on a fixed MedTech DPP deadline is selling you something. The more interesting question is why several MedTech companies run device-level passports anyway, years before any obligation. The answer has to do with a regulation the industry already knows well, and with service economics.
Where MedTech actually stands with ESPR
The Ecodesign for Sustainable Products Regulation (Regulation (EU) 2024/1781) has been fully applicable since 19 July 2026, and its central DPP registry is live. Product categories are pulled in through delegated acts, and the Commission's first working plan for 2025 to 2030 starts with textiles, furniture, tyres, mattresses, iron and steel, and aluminium. Medical devices are not on that list. The working plan will be revised over time, and sustainability pressure on the sector is real, but today there is no delegated act and no deadline.
The regulation MedTech already lives with
Here is the twist: medical device manufacturers already operate the closest thing to a product passport that exists in EU law. The Medical Device Regulation (Regulation (EU) 2017/745) requires a Unique Device Identification for every device, registered in the EUDAMED database, with the UDI carrier printed on the label. Device identity, structured product data, registry submission: the mechanics of a DPP, mandated since 2021 and rolled out by risk class.
The UDI system even mirrors the DPP's granularity debate. The UDI-DI identifies the device model, roughly what a model-level passport covers. The UDI-PI adds production identifiers: lot, serial number, expiry. Class III and implantable devices have carried UDI labels since 2021, Class IIa/IIb since 2023, Class I since 2025. In other words, the industry has already worked through the identifier strategy, label real estate, and data pipeline questions that other sectors are just now discovering.
The two systems compare like this:
| UDI under MDR | DPP under ESPR | |
|---|---|---|
| Purpose | Traceability, vigilance, recalls | Sustainability, circularity, transparency |
| Audience | Authorities, hospitals | Public, recyclers, authorities |
| Identity level | Device model (UDI-DI) plus production unit (UDI-PI) | Model, batch, or item, by category |
| Data carrier | Barcode or DataMatrix on label | QR code or similar, publicly resolvable |
| Registry | EUDAMED | EU central DPP registry |
The practical consequence: a MedTech company has already done the hard cultural work. Structured device data exists, identifier discipline exists, and regulatory data submission is routine. Extending that foundation to a customer-facing passport is a small step, not a transformation.
The use case with a legal basis today: electronic IFU
Instructions for use are a concrete entry point. Regulation (EU) 2021/2226 allows manufacturers to provide instructions for use in electronic form for defined device categories, provided availability and access requirements are met. A QR code on the device resolving to a maintained, versioned device page satisfies exactly that pattern.
Manufacturers who do this stop shipping printed manuals into hospital drawers where nobody finds them. The current IFU version, in the reader's language, sits one scan away from the device. Update the document once, and every device in the field points at the new version. For manufacturers with frequent labeling updates, the printing and distribution savings alone are a five-figure annual line item.
Why the business case runs ahead of the regulation
A hospital device generates service events for a decade or more: installations, maintenance, error states, spare parts, retraining of staff. Every one of those events needs device context that today lives in the manufacturer's CRM, if anywhere. A device-level passport turns the physical device into the entry point:
- A technician scans the device and sees its service history, not the model's
- A nurse scans it and gets the IFU and a support channel, not a hotline queue
- A service request arrives with the device identity attached, so triage happens in minutes
Put numbers on the triage point, because it is where the money sits. A field service organization handling 5,000 service requests per year typically burns 20 to 40 minutes per request on identification and context gathering: which device, which configuration, which contract, what history. At a blended 60 euros per hour, that is 100,000 to 200,000 euros per year spent finding out what the technician could have known at scan time. Add the second-order effects, fewer wrong spare parts shipped and fewer repeat visits, and the service case alone routinely beats the platform cost by an order of magnitude.
This is the layer dpp.cloud is built on. The underlying platform has run device-level digital identities in regulated MedTech environments for over five years, including global deployments. The passport is the same infrastructure with a compliance data layer on top. When ESPR eventually reaches medical devices, the passport is already in the field. Until then, it earns its keep through service. We described that motion in turning a compliance project into a competitive advantage.
Procurement is the nearer deadline
One more force worth naming. Hospital groups and buying consortia increasingly score suppliers on sustainability data, driven in part by their own reporting duties under the Corporate Sustainability Reporting Directive. MedTech suppliers get questionnaires about material composition, packaging, take-back, and repairability. A manufacturer whose device data is structured and passport-ready answers those in hours. One whose data lives in regulatory PDFs does not. In tenders, that difference shows up before any delegated act does.
How a MedTech passport pilot actually looks
The pilots that work stay small and specific. The pattern from our deployments:
- Pick one device family with service pain. Not the flagship, the one that generates hotline calls. Fifty to two hundred units in the field is plenty.
- Wire up the existing data. Device master data from the PIM or regulatory system, IFU documents, spare parts lists. The mapping mechanics are the same as in creating a DPP from PIM data, and UDI identifiers slot directly into the passport identity.
- Put the QR where the service event starts. On the device housing, next to the type plate. Not in the box, not in the manual.
- Measure two numbers for a quarter: triage time per service request, and share of requests arriving with device identity attached. Those two numbers make the rollout decision for you.
Timeline for that pilot: two to four weeks to live, because the data exists and the identifier discipline is already there. This is the one industry where we rarely find data gaps; MDR closed them years ago.
What a MedTech manufacturer should do now
- Nothing panicked. There is no ESPR deadline for medical devices. Ignore anyone claiming otherwise.
- Leverage your UDI foundation. Your device master data is passport-grade already. Mapping it into a customer-facing passport takes weeks, not a program.
- Start where money leaks. eIFU delivery and service routing are live use cases with today's legal basis and today's ROI.
Next step
If you run devices in the field and want to see what a device-level passport does to your service operation, book a 30-minute strategy session. We know the regulated side of this industry well and will not waste your time with invented deadlines.

.jpeg)



%201.png)

.png)