Junction®

how-to

One code, two jobs: a passport and a proof that the product is real

Sustainability data on a product anyone can copy is data about a category. Binding authenticity to the passport closes a gap the regulation leaves open.

The digital product passport (DPP) rules are about sustainability and compliance. They say nothing about counterfeiting.

That is a reasonable scope for a regulation and a problem for a brand, because the two questions meet on the same physical object and the answer to one is worthless without the other.

The gap, stated plainly

A passport tells a buyer what a product is made of, where it came from and how to repair it. It does not tell them whether the item in their hand is the product it claims to be.

Now consider a counterfeit. It carries a copied code. The code resolves to a real passport, belonging to the genuine product line, showing genuine sustainability data. The counterfeit has just been authenticated by your compliance system.

This is not hypothetical reasoning about a distant risk. It follows directly from how carriers work: a QR code is a printed pattern, and printed patterns copy perfectly.

Why the regulation leaves it open

Because authenticity is not a sustainability requirement, and the regulation is doing something else. Verification of passports is handled through market surveillance authorities checking data accuracy and customs checking registration, both of which operate on the economic operator rather than on the individual item in a consumer's hand.

Notably, the CIRPASS-2 reference architecture contains no building block for consumer-facing authenticity verification either, and does not treat counterfeiting as a use case. The scan is modelled as a way to reach data. That is an observation about the scope of that model, not a claim that no one else addresses the problem.

What closing it requires

Two capabilities. The first is where the money goes.

Per-item identity. A code that identifies an individual object rather than a product line. This is the hard boundary described in the two pricing models: without it, every unit looks identical to the system, so a copy is indistinguishable from an original by definition.

A code lifecycle. A code that can be issued, enriched with product data, verified, consumed at the point of sale, and reactivated for a legitimate resale. A code that is only ever readable proves nothing about the state of the item.

With both, a scan answers two questions at once: is this genuine, and what is it made of. Without per-item identity, it only ever answers the second.

Why this is worth paying for outside compliance

Because the compliance budget and the brand protection budget are usually separate, and this is one build that serves both.

The passport is a cost centre justified by market access. Authenticity has a return: recovered revenue from counterfeits and grey market diversion, faster and more precise recalls, and a resale market you can participate in rather than watch.

Companies that build the two separately end up with two codes on one product, two systems to keep current, and a compliance record that still cannot tell a copy from an original.

Junction was built this way from the start: one code per item, working as both a certificate of authenticity and a passport.

Sources

  • CIRPASS-2, *D4.1 Reference Architecture*, version 1.1, 9 June 2026: no building block for
  • consumer-facing authenticity verification; counterfeiting is not treated as a use case.
  • European Commission, *Digital Product Passport: FAQ*, January 2026 update, questions 30 and 31 on
  • enforcement and verification.

Get DPP-ready before your category

One code: DPP and authenticity | Junction®