What has to be true at the origin of a supply chain before a product passport's provenance claim survives an adversarial audit?
A passport's credibility is set at capture. Whether it survives privacy and commercial scrutiny is set by data placement. Everything downstream is real work and late work. GS1 supplies identifiers and resolution, EPCIS supplies the event model and the Core Business Vocabulary its shared semantics, W3C Verifiable Credentials carry signed role claims. Get all of it right, pick the anchoring rail well, and you can still ship a system whose cryptographic integrity is beyond question and whose real-world truthfulness was never examined. Most vendors order this the other way, by selling the ledger first.
The error is not carelessness. Pilot teams build what their first EU customers request: required fields in required format. A schema review asks whether those fields are present; a field audit whether events can be reproduced; a privacy review whether each field has a lawful purpose, audience, and retention model. Architecture designed only for the first often fails the latter two. ESPR introduces product-group requirements through delegated acts, while the Commission's 2025-2030 Working Plan sets the current indicative category schedule, so rework can arrive under compliance pressure.
Start where the evidence is produced. Many supply chains feeding ESPR-priority products begin where the infrastructural assumptions behind a typical DPP fail: cotton for textiles, natural rubber for tyres, and minerals entering metals or electronics. The first signer is often a cooperative member or contractor using a supervisor-owned device that is intermittently offline. Clocks drift, devices change hands, and paper records are transcribed later. Legal pressure is strongest where the preconditions for producing evidence are weakest. That mismatch is the design problem, not a footnote to it.
Which forces honesty about what a signature means. A supplier using an SMS or feature-phone flow should not be represented as personally signing on-chain. The constraint is safe key provisioning and custody, transaction construction, recovery, and usable confirmation, not elliptic-curve compute. A gateway may sign on the supplier's behalf, but the event must record that it did — gateway-signed, as distinct from supervisor-signed or secure-element-signed. I call this an event's trust tier; it is my own convention, not a standard field. UNTP comes closest without arriving: assessorLevel grades assessor independence and sensorIntegrityProof carries a device-signed credential, but no published standard models a gateway as a signing tier at all. The tier must survive in the signed schema through every downstream transformation; if an on-chain action depends on it, the contract must enforce accepted issuer roles. Without that, a passport in a low-infrastructure region widens the fraud surface rather than narrowing it: synthetic supplier injection, batch over-attribution, backdated timestamps, gateway replay, trust-tier laundering, each concentrated differently across the three paths.
Serious programmes run more than one capture path. The allocation rule is consequence and observability: device-sign events whose manipulation would change a compliance or payment outcome and whose underlying signal a sensor can observe directly; supervisor-sign events requiring human judgement; use gateway signing only where individual key custody is not viable. Hardware is justified only where event volume and expected loss can amortise it.
Downstream of capture, the second decision that holds or poisons the system is data placement. A public anchoring chain can make a commitment independently timestamped and tamper-evident. It does not make the underlying event true and does not by itself provide confidentiality, access control, or selective disclosure. The reflex to put GPS, supplier names, and lab results on-chain because on-chain reads as credible fails in ways that compound: an avoidable GDPR data-minimisation and erasure problem, silent disclosure of the sourcing operation to competitors, and permanent storage cost and metadata leakage for no property the system needs. Invert the default. On-chain carries commitments, references, and role attestations. Public off-chain carries what consumers and retailers legitimately need. Encrypted off-chain, with content-encryption keys wrapped per role, carries everything personal or commercially sensitive. Precise geography is encrypted at capture; only a coarsened derivative leaves the restricted tier. Ship the backend-enforced version first if you must, but declare the field-level tier mapping on day one, because retrofitting data minimisation into a system that put everything on-chain is not a migration, it is a rebuild.
Verification is where shallow architectures become visible. A passport showing the same fields to everyone is a product information page. Consumer, retailer, recycler, and regulator should read different slices of the same evidence, gated cryptographically. Decentralised identifiers and verifiable credentials are a natural credential layer for proving role claims to an access-control system; they are not the access-control system itself, and I have written up the DID and verifiable-credential model separately. The role model determines what must be proven; the identity layer carries that proof. The chain gets picked last, for cost of anchoring, tooling maturity, and fit with the standards the supply chain already uses.
What would change my mind
Bad input producing a bad passport is definitional. The contestable claim is that capture design and data placement explain production outcomes better than chain choice, identifier scheme, or standards conformance.
I would revise that ranking if programmes that treated capture as solved and designed field-level access tiers only after the pilot nonetheless passed both independent field audits and data-protection assessments without rebuilding their capture or storage architecture. The result would have to hold across product categories and include low-connectivity source layers. If chain or standards choice explained those outcomes better, my sequencing is wrong.