Industry guide · Supply Chain

Digital Product Passport Software: How Do You Publish Item Level Claims When the Data Sits With Your Supplier's Supplier?

Digital Product Passport software visual showing qr code, folder tree, and database check.
The short answer

Budget $110,000 to $240,000 and 14 to 20 weeks for a first passport release covering identifier assignment, a supplier claim collection workflow, the passport record store and one public market view. A full programme adding unit level serialisation with factory confirmation, PLM and ERP (Enterprise Resource Planning) integration, evidence extraction and post sale write access runs $300,000 to $750,000 phased across 9 to 18 months. Build when your passport fields have to be assembled from tier 2 and tier 3 suppliers you do not contract with directly, when you already serialise units for another reason, or when several of your categories will fall under different delegated acts. Buy EON or TrusTrace instead when you have under roughly 200 active styles, one EU market, a supply chain short enough to phone, and no serialisation on the production line.

Why the passport request lands on someone who has no data

A compliance director at an apparel brand opens the readiness grid her team built for the autumn range. Three hundred and forty styles down the left. Across the top: fibre composition, country of origin at each processing stage, recycled content, chemical compliance evidence, repair instructions, end of life routing. Most of the grid is empty. The cells that are filled came from a supplier questionnaire sent last spring, answered by a sourcing agent in a hurry, and never checked against a document. The brand does not buy yarn. It buys finished garments from 40 vendors, who buy fabric from mills the brand has never spoken to, who buy yarn from spinners nobody in the building can name.

That is the honest starting position for nearly every passport programme we are asked to cost. The regulation asks for verifiable facts about a physical object. Your systems hold commercial documents about a purchase order. Between the two sit three or four supplier tiers, a testing lab and a customs broker, none of whom work for you. The Ecodesign for Sustainable Products Regulation came into force in 2024 and delivers passport requirements through delegated acts by product group, with textiles named as an early priority. The EU Battery Regulation carries its own battery passport obligation for the categories it names from February 2027. Have your exact scope and dates confirmed by regulatory counsel, because delegated acts move and a blog post does not.

What does not move is the shape of the work: a durable identifier carried on the product, a record behind that identifier, a collection process that pulls facts out of companies who are not on your systems, and a public view that renders correctly in every market you sell into. Each of those is a build decision. The sequencing between them decides whether the programme lands or stalls in year two.

Problem 1: the facts belong to suppliers with no reason to hand them over

Your vendor is a garment maker on a thin margin with a messaging app and a cutting room. You are asking him to chase his fabric mill for a recycled content claim backed by a transaction certificate, and to chase that mill's spinner for fibre origin. He gains nothing from the work and loses a day. So he sends a number that sounds right. This is the exact point where passport programmes fail, and no dashboard fixes it.

TrusTrace and Circularise are both real answers to parts of this. TrusTrace is built around supply chain data collection and chain of custody documents and does that competently. Circularise approaches it from material flow and mass balance, which suits chemicals, plastics and batteries better than a 40 vendor apparel base. What neither can do for you is own the join between a purchase order line, the specific fabric lot cut against it, the mill's lab report and the units that shipped. That join lives across your PLM, your ERP and your vendor's cutting room, and it is precisely what a passport asserts. A platform that stores documents against a supplier is not the same object as a record that stores evidence against a product instance.

What a custom build does: model evidence as a claim with a subject, a source, a document, a validity window and a confidence state. Every field on the passport carries a provenance chain back to the party who asserted it. Requests go out to suppliers as short tasks tied to one purchase order and one claim, not as a 90 field questionnaire, because a 90 field questionnaire gets one honest pass and then autocomplete forever. Document extraction earns its place here: certificates and lab reports arrive as PDFs in a hundred layouts, and a model reads the certificate number, the scope, the issuing body and the expiry, then flags the ones that lapsed or that cover a scope your claim does not match. Nobody on your team is reading 4,000 PDFs a season. A model reads all of them and hands you the 60 that are wrong.

Problem 2: the identifier, and whether you can afford unit level

The passport resolves from a code on the product, so you must decide per category whether that code identifies a model, a batch or a single unit. Unit level is where the rules are heading for categories where repair, resale and recycling matter, and it is also where your factory floor starts to argue. A unique code on a care label means serial generation, allocation to a production order, and reconciliation of what was actually printed and applied. That is a manufacturing execution problem sitting inside a compliance project, and it is usually the part that slips.

EON is genuinely strong on this and deserves a serious look if you are willing to adopt someone else's identity infrastructure and consumer experience wholesale. The trade is that your product identity then lives in their namespace and their data model, and changing your mind later means re-tagging goods already in the market. Protokol will build around you, but you are buying a project either way. GS1 Digital Link is the sensible public standard for making a code resolvable, and a vendor who cannot explain how they handle it has told you something useful.

What a custom build does: keep the identifier and the resolver on your own domain from day one. Serial ranges are allocated to production orders, printed by the factory or your label vendor, confirmed back as applied, and only then activated in the resolver. Batch level identity is a legitimate first step where unit level is not yet required, provided the record model is unit ready so you are not rebuilding it two years later. The resolver itself should be small, boring and extremely available: one job, very high read volume, never coupled to the system that authors the data.

Problem 3: the public view is a legal artefact, not a marketing page

A passport view gets read by a consumer, a repairer, a recycler, a customs officer and a market surveillance authority, and those audiences are entitled to different levels of detail. Some fields are public, some are restricted to authorised parties, some are commercially sensitive and must never surface even though they sit in the same record. Language obligations follow the market of sale. The record must stay available for a defined period after the last unit is placed on the market, which means the resolver has to outlive the product, the campaign and possibly the agency that built the site.

What a custom build does: role scoped views computed from one record rather than four hand maintained copies. Versioning is not optional, because a claim asserted in March and corrected in September must both be retrievable with timestamps and a stated reason. Store the record as an append only event log. When an authority asks what you published on a given date, you answer in a minute instead of reconstructing it out of email threads.

Problem 4: the record keeps changing after the product ships

Repairs, spare part availability, resale events, warranty claims and eventual recycling all write to the passport after the sale. A programme that treats the passport as a document generated at the end of production will be built twice. Resale platforms want to read it. Independent repairers want to write to it. Recyclers want material composition in machine readable form, not a paragraph of prose.

Design the write path early even if you keep it closed in year one. That means an authenticated third party API, a permissions model per party type, and an event store that can absorb a repair record from a partner you have not signed yet without a schema migration.

What this costs and how long it takes

Across the 2,000-plus projects Digital Heroes has delivered, this is the honest shape of passport work. A first release covering identifier assignment, the supplier claim collection workflow, the record store and one public market view runs $110,000 to $240,000 and ships in 14 to 20 weeks. That is a live resolver serving real product data, not a pilot on a slide. The full programme, adding unit level serialisation with factory confirmation, PLM and ERP integration, evidence extraction, restricted party views and post sale write access, runs $300,000 to $750,000 phased across 9 to 18 months.

What drives the number up: the number of supplier tiers you must reach, because tier 3 collection is a change management programme with software attached. Unit level serialisation, especially where labels are printed by vendors rather than by you. Category count, since each product group brings its own field set. Market count, because language and disclosure rules multiply views. And existing PLM quality, which nobody budgets for: if the bill of materials in your PLM does not match what the factory actually cut, the passport publishes that mismatch to the public internet. What keeps the number down: one category, one market, batch level identity, and your top vendors by volume rather than all of them.

Build versus buy, and when buying is the right call

Buy, and do not call us, if you have under roughly 200 active styles, a supply chain short enough that you can phone the mill, no serialisation in production and a single EU market. EON or TrusTrace will get you compliant faster and cheaper than a build, and the platform fee costs less than the discovery phase of a custom project. That is a real answer and we give it regularly.

Build when two or more of these are true. Your passport fields must be assembled from tier 2 and tier 3 suppliers you have no contract with. You already serialise units for another reason, so half the identity work exists and a platform would duplicate it. You sell across several categories that will fall under different delegated acts, so one vendor's data model will fit a single category and fight the rest. Your product data of record sits in a PLM or ERP the business will not replace. Or the passport is commercially interesting beyond compliance, meaning resale, repair or authentication, in which case the record becomes a product feature and you should not rent it.

How to choose a developer for passport work

Ask them to model a claim on a whiteboard before you sign anything. A team that has done this draws claim, subject, evidence document, asserting party, validity window and version, and they will explain why the asserting party matters more than the value. A team that draws a products table with a sustainability column has built a catalogue and is about to learn regulatory data modelling on your budget.

Ask how the resolver stays up and whose domain it sits on. If the answer places your product identity on the developer's infrastructure, walk. Ask what happens when a claim is corrected after 40,000 units are already in the market, and listen for versioning rather than an edit form.

Ask what they have genuinely integrated. Reading a bill of materials out of Centric or PTC FlexPLM is a different problem from reading it out of a spreadsheet. Confirming applied serials back from a label vendor is a different problem again. Ask for the named system and the named document type instead of a general claim of integration experience.

Ask who owns the code, the repository and the cloud accounts, and get it in writing before kickoff. A passport record has to outlive your agency relationship by years. At Digital Heroes the client owns the code from the first commit, and we would tell you to walk away from anyone who hedges on that.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. 48% of private companies cite integration with legacy systems or technical debt as a top obstacle to realizing the full value of their digital and AI investments (behind data quality/availability at 72% and gaps in AI fluency or technology talent/leadership at 53%). Source: Deloitte (2026) →
  2. Poor software quality cost the US economy an estimated $2.41 trillion in 2022, including roughly $1.52 trillion in accumulated technical debt, driven partly by unsuccessful development projects and low-quality legacy systems. Source: Consortium for Information & Software Quality (CISQ) - Herb Krasner (2022) →
  3. Retailers connecting point-of-sale and loyalty data in an omnichannel strategy reported up to 15% lower cost per purchase and nearly 20% higher incremental store revenue. Source: Deloitte (2024) →
  4. The Standish Group 1995 CHAOS Report found only 16.2% of software projects fully succeeded; success varied sharply by size, with large-company projects succeeding about 9% of the time versus far higher rates for small projects - best treated as an industry survey, not an audited dataset. Source: Standish Group (1995) →
James M. · Senior Strategist · Fintech · London

James covers financial services work, where a feature request usually arrives attached to a compliance requirement. He is worth reading if you are scoping payments, lending or account software and need to know which decisions are technical, which are regulatory and which are simply expensive.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom digital product passport software cost for an apparel brand?
A first release with identifier assignment, supplier claim collection, the passport record store and one public market view runs $110,000 to $240,000 over 14 to 20 weeks, based on Digital Heroes delivery experience. The full programme with unit level serialisation, PLM integration and post sale write access runs $300,000 to $750,000 across 9 to 18 months. The largest cost driver is not the software, it is how many supplier tiers you have to reach to collect the underlying claims.
Should we buy EON or TrusTrace instead of building a passport system?
If you have under roughly 200 active styles, one EU market, no serialisation in production and a supply chain you can phone directly, buy. Those platforms will make you compliant faster than a custom build and the licence costs less than a discovery phase. Building makes sense when your claims have to come from tier 2 and tier 3 suppliers you do not contract with, when you already serialise units, or when you sell across several categories that will fall under different delegated acts.
What actually has to be in a digital product passport?
The field set is defined per product group by delegated acts under the Ecodesign for Sustainable Products Regulation, so textiles, electronics and batteries will not carry identical requirements. In practice you should expect material composition, origin at processing stages, recycled content, substances of concern, repairability and end of life routing, with different fields visible to consumers, repairers, recyclers and authorities. Confirm your specific list with regulatory counsel rather than building to a generic template.
Do we need unit level serialisation or is batch level enough to start?
Batch level is a legitimate first step in categories where unit level is not yet required, and it avoids dragging your factories into serial printing during phase one. The condition is that your record model must be unit ready from the beginning, so moving to per unit identity later is a data migration rather than a rebuild. If repair, resale or authentication matter commercially, go unit level immediately because you will end up there anyway.
How long does it take to build digital product passport software?
A first release ships in 14 to 20 weeks in our experience, covering identifier assignment, the supplier collection workflow, the record store and one public view. The engineering is rarely the bottleneck. Supplier onboarding is, because the first honest set of claims from tier 2 and tier 3 requires people to chase companies who are not on your contracts and have no incentive to reply quickly.
How do we collect recycled content data from suppliers we do not contract with?
Send short tasks tied to one purchase order and one claim rather than a long questionnaire, because long questionnaires get answered once honestly and then copied forward. Route the request through your direct vendor with a named counterparty at the next tier, and require a document rather than a typed number. Then run automated extraction over the incoming certificates to check the certificate number, scope, issuing body and expiry, so bad evidence is caught on arrival instead of at audit.
Is the EU battery passport the same build as a textile passport?
The underlying architecture is the same: an identifier on the product, a record behind it, role scoped views and an evidence trail. The field sets, the identity granularity and the parties differ substantially, since battery passports are unit level for the categories named in the EU Battery Regulation from February 2027 and carry performance and state of health data that textiles never will. Build the record model to be category aware from the start if you sell in both.
Where does AI genuinely help in a passport programme?
Document extraction is the one job that pays for itself. Certificates, transaction documents and lab reports arrive as PDFs in endless layouts, and a model can read the certificate number, scope, issuing body and expiry, then flag lapsed certificates and scope mismatches against the claim they are supposed to support. Classification of free text material descriptions into your controlled vocabulary is the second useful job. Anything described as an AI compliance assistant is usually a chat box over data you have not collected yet.
Who owns the resolver and the code if we hire an agency to build our passport system?
You should own the repository, the cloud accounts and the domain the resolver runs on, written into the contract before kickoff. Passport records must remain resolvable for years after the last unit is sold, which is far longer than most agency relationships last. At Digital Heroes the client owns the code from the first commit. Any arrangement that puts your product identity inside a vendor namespace creates a dependency you cannot exit without re-tagging physical goods.
Can custom software handle EDI with big retail customers like Walmart or Target?
Yes, and this is one of the most common reasons distributors go custom, because retailer scorecards penalize late or malformed documents. The typical build covers EDI 850 purchase orders in, 855 acknowledgments, 856 advance ship notices, and 810 invoices out, usually through a network like SPS Commerce or TrueCommerce rather than raw AS2. In Digital Heroes builds, onboarding your first major retailer adds 4 to 8 weeks and $10,000 to $25,000, with each additional trading partner far cheaper once the pipeline exists.
What questions should I ask a development agency on the first call?
Ask who exactly will build it, what happens when scope changes mid-project, what their maintenance terms are after launch, and what they will need from you every week. Then ask them to describe a project that went wrong and what they changed afterward; teams that have shipped at real volume have war stories, and teams claiming a perfect record are hiding something. The scope-change answer matters most: a disciplined shop describes a written change-order process, not a vague promise to be flexible.
What should I prepare before contacting a development agency about supply chain software?
Bring a written list of your workflows from purchase order to delivery, the systems each step touches, and the 3 to 5 pain points costing you the most hours or errors. Export a sample of your real data, SKUs, orders, and locations, because data shape drives half the design decisions. You do not need a formal spec; Digital Heroes scopes most supply chain projects from a two-page problem description plus screen-share walkthroughs of the current process.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
How do I calculate whether custom software will pay for itself?
Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.
What does it cost to keep custom software running after launch?
Budget 15-20% of the original build cost per year, which on a $100,000 system means $15,000 to $20,000 for security patches, dependency updates, bug fixes, and small improvements as real usage reveals what the spec missed. Cloud hosting for a typical business application adds $50 to $300 a month on top. Skipping maintenance does not save the money; in Digital Heroes rescue work, unmaintained systems typically need a far more expensive rebuild within about three years.
Should I hire a freelancer or an agency for my software project?
A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.
Will an app built for 10 users survive growing to 500?
Yes, if it is built on standard cloud infrastructure with a sound data model, because moving from 10 to 500 users is a hosting configuration change, not a rebuild. The scaling decisions that actually hurt are made early and invisibly: how the database is structured, how accounts and permissions are modeled, and whether background work is queued properly. Ask your agency how the system would handle ten times the load; the right answer is boring and specific, and a promise to cross that bridge later means you will pay for the bridge twice.
How much should a small business budget for its first custom app or website?
For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.
Who can build a custom supply chain software system?

Digital Heroes builds custom supply chain software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other supply chain software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?