Spherity Strategy Paper

Spherity Strategy and Market Positioning Update

Digital Product Passports, European Business Wallets and the agentic internet

Author
Affiliation
Spherity GmbH
Published
Updated
Research cut-off
· market and regulatory facts reviewed to this date
This version
https://spherity.github.io/spherity-research/spherity-dpp-dbp-strategy-market-positioning.html
Latest version
https://spherity.github.io/spherity-research/spherity-dpp-dbp-strategy-market-positioning.html
Browse this paper

In brief

What does this research establish?

Gartner published the Emerging Market Quadrant for Digital Product Passport — Established Vendors on 6 July 2026 and positioned Spherity as the sole vendor in the Pioneers quadrant. The paper treats that placement as one independent market perspective, then sets out Spherity's own identity-first strategy: batteries first, horizontal DPP and DBP scale, European Business Wallet control-plane convergence, cyber-secure evidence, and a longer-term AI Service Passport outlook.

Key takeaways

  • Gartner positioned Spherity as the sole vendor in the Pioneers quadrant of its 2026 Emerging Market Quadrant for Digital Product Passport — Established Vendors.
  • Spherity treats the Gartner placement as one independent market perspective; its own leadership claim rests on identity-first architecture, regulated production experience, and its partner ecosystem.
  • VERA provides the Digital Product Passport data plane, EIDA provides reusable European Business Wallet identity and access-control capabilities, and CARO demonstrates regulated production delivery.
  • Execution begins with traction batteries, commercial vehicles, public-transport fleets, BESS, and light-means-of-transport batteries before horizontal expansion across industrial sectors.
  • The same two-plane trust architecture can support product DPPs and DBPs, the EU DPP Registry, cross-company lifecycle workflows, and future AI Service Passports.
  • Cyber-secure DPPs require legal-person identity, verifiable authority, policy-based access, revocation, provenance, resilient service operation, and auditable evidence—not signatures alone.
  • The 2026–2029 priorities are to industrialize VERA, productize VERA/EIDA convergence, reuse trust components across sectors, scale through partners, and develop agent-ready and crypto-agile services.
Download the complete seven-page strategy paper

This page is an indexable research summary. The final PDF is the authoritative publication, including its exact market-position statement, source attribution, Gartner rights notice, and full references.

First page of Spherity Strategy and Market Positioning Update.
Paper cover. Spherity Strategy and Market Positioning Update, final publication, August 2026.

About the paper

Spherity combines product identity and lifecycle data with verified enterprise identity, authority, and access control. The paper explains how VERA for Digital Product Passports, EIDA for European Business Wallets, and CARO for regulated enterprise verification form a reusable trust architecture for regulated supply chains, circular business models, machine-to-machine interaction, and agentic commerce.

Its core position is that trustworthy product data needs two coupled planes. The data plane carries or resolves product and lifecycle evidence. The control plane establishes the legal person, role, mandate, representation right, policy, and delegated authority behind an action. That separation makes DPP and DBP information suitable for regulated cross-company workflows and accountable automation.

Market position

Gartner® published the Emerging Market Quadrant for Digital Product Passport — Established Vendors on 6 July 2026. Spherity is positioned as the sole vendor in the Pioneers quadrant. [1]

Spherity sees this identity-first position as the foundation for a wider trust architecture that can extend from physical-product DPPs to AI Service Passports for AI systems and services. This extension is Spherity’s strategic outlook and was not part of Gartner’s DPP evaluation.

Spherity treats the Gartner placement as one independent market perspective. Spherity’s own view is that its technology leadership in identity-first and cyber-secure DPP infrastructure rests on its architecture, regulated production experience and partner ecosystem. The strategic objective is to make product data trustworthy, usable across company boundaries and suitable for automated decisions.

Read the Gartner report overview

Emerging Market Quadrant for Digital Product Passport — Established Vendors, Kevin Lawrence, Marta Muñoz, and Rajan Saini, published 6 July 2026, Gartner document 8098797. Access to the complete Gartner research may require an entitlement.

Strategy and capabilities

Capability Strategic role Operational evidence
VERA Digital Product Passport and Digital Battery Passport data plane. Product onboarding, supplier data collection, regulatory data models, lifecycle events, analytics, and enterprise integration.
EIDA European Business Wallet control plane. Verified legal-person identity, market roles, licences, mandates, powers of representation, selective disclosure, status, and delegated authority.
CARO Regulated enterprise verification and delivery pattern. Production master-data and authorized-trading-partner workflows, current licence checks, interoperable credentials, APIs, monitoring, and auditability in the US pharmaceutical supply chain.
Evidence graphs Agent-ready provenance and validation layer. Source, issuer, transformation, validation, freshness, conflict, uncertainty, status, and auditable evidence paths.
Partner ecosystem Implementation and horizontal scale. Sector delivery, supplier onboarding, systems integration, co-selling, reseller capacity, and reuse across data spaces.

The strategy separates a reusable horizontal trust core from sector-specific data models and workflows. Product identity, legal-entity identity, provenance, authority, access policy, and verifiable lifecycle evidence remain stable even when the product group or regulation changes.

DPP and EBW convergence: one architecture, two planes

Plane Primary question Main functions
DPP / DBP data plane What product evidence supports the action? Product, SKU, batch, and serial identity; materials and components; certificates; provenance; manufacturing, service, software, sustainability, and end-of-life events; verifiable credentials.
EBW control plane Who is authorized to perform the action? Enterprise identity, market role, licence, mandate, representation, selective disclosure, policy-based access, credential status, revocation, and auditable delegation to people, machines, and AI agents.

The same control plane can secure interaction with the operational EU DPP Registry. The Registry remains a common EU registration and discovery layer for product and operator identifiers and associated metadata. EIDA can provide verifiable organizational identity and authority at that interface; VERA can provide product and lifecycle evidence without forcing all detailed product data into one centralized store.

This enables practical policy decisions. A recycler can prove eligibility before receiving restricted disassembly data. A regulator can verify who submitted a compliance statement. A service provider can update a maintenance event within a defined mandate. An AI agent can act only within narrow, revocable authority.

Execution: batteries first, then horizontal scale

Spherity is executing programmes across traction batteries, commercial vehicles and public-transport fleets, battery energy storage systems (BESS), and light-means-of-transport batteries. Batteries are the first large-scale proving ground because they combine defined regulatory deadlines, valuable and safety-critical assets, complex bills of materials, long service lives, and opportunities for maintenance, warranty, recall, second-life, and recycling services.

The next step reuses the same trust components across industrial products and steel with Manufacturing-X partners, energy assets with energy data-X partners, chemicals with Chem-X partners, and consumer products. Sector data models differ; identity, credential, policy, provenance, and lifecycle controls can remain reusable.

Regulatory regimes beyond ESPR compliance

A DPP can become a reusable evidence and workflow layer across related EU product, chemical, safety, AI, and cybersecurity rules. It does not replace the accountable economic operator, conformity assessment, technical documentation, or regulatory reporting.

Regulatory regime Reusable DPP or AISP evidence
EU Batteries Regulation Battery identity, responsible operator, composition, performance, due diligence, lifecycle events, safety, second-life, and recycling evidence.
General Product Safety Regulation Product, batch, or serial identity linked to the responsible operator, warnings, incidents, recalls, and consumer remedies.
Product Liability Directive Product version, software updates, warnings, modifications, and lifecycle state.
REACH and CLP Substance, SVHC, hazard, safe-use, and supplier evidence with controlled access and traceable updates.
Detergents and Surfactants Regulation Mandated DPP, digital labelling, operator identifiers, Registry interaction, and customs verification.
Machinery Regulation Conformity, technical documentation, safety instructions, maintenance, modifications, software versions, and AI-related safety evidence.
EU AI Act Provider and operator identity, intended purpose, version, TEVV, logs, post-market monitoring, and incident evidence through a future AISP.
Cyber Resilience Act Product versioning, vulnerability status, secure updates, support periods, incidents, and auditable cybersecurity maintenance.
Construction Products Regulation Declarations of performance and conformity, safety information, technical documentation, identifiers, and access rights in the construction DPP system.

Cyber-secure DPPs and the CIRPASS-2 risk baseline

The CIRPASS-2 Risks and Mitigations study identifies data, security, operational, and governance risks across the DPP lifecycle. Its significance is architectural: false provenance, unauthorized updates, service discontinuity, over-disclosure, weak revocation, and inaccurate lifecycle claims cannot be mitigated by a signature alone.

Spherity’s approach combines cryptographic product and enterprise identity, verifiable credentials, selective disclosure, credential status and revocation, policy-based access, resilient availability, tamper-evident event histories, and signed audit evidence. EIDA establishes whether an actor is authorized. VERA and evidence graphs establish whether the product evidence supporting an action is fit for purpose.

These controls matter more as procurement agents, service agents, customs systems, regulators, and circular-economy platforms read and act on DPP data at machine speed.

Trusted AI outlook: AI Service Passports

Spherity’s strategic outlook extends the DPP and EBW architecture to AI systems and services through an AI Service Passport (AISP). The AISP is a forward-looking research and product direction, not a current regulatory requirement. It is conceived as a DPP-like, verifiable lifecycle record that can link an AI service to its provider or operator and record model family, version, configuration, guardrails, testing, evaluation, verification and validation (TEVV), operational controls, incidents, and updates.

The architecture separates three accountable subjects:

This separation supports Trusted AI in agentic commerce, cross-company Industrial AI, and Physical AI acting through machinery, vehicles, robots, and energy assets.

The micro-ERP: a product-centric execution layer

The micro-ERP is Spherity’s concept for a governed, product-centric execution layer: a DPP combined with bounded lifecycle business logic, identity, rights, and security. It is not a replacement for ERP, MES, PLM, or PIM systems. Those remain systems of record and execution inside organizations.

The micro-ERP changes the unit of cross-company coordination. A product identity can resolve to current state, evidence, obligations, permissions, and authorized services. Business logic can determine which data must be requested, who may update a record, when a certificate expires, when a safety event triggers notification, or which end-of-life path is permitted.

Spherity strategy priorities for 2026–2029

  1. Industrialize VERA deployments and supplier onboarding for regulated battery production.
  2. Productize VERA and EIDA convergence as a repeatable two-plane offering for DPP Registry and cross-company workflows.
  3. Reuse identity, credential, policy, integration, and evidence-graph components across product sectors and European data spaces.
  4. Scale delivery through implementation, co-selling, and reseller partners while preserving interoperable architecture and accountable governance.
  5. Develop agent-ready lifecycle services and crypto-agile trust infrastructure once trustworthy product and enterprise identities are in place.

The sequence is deliberate: compliance creates the initial demand and minimum data set; operational services create recurring value; the trust layer makes both scalable across firms and jurisdictions. Execution should be measured by production conversion, supplier-onboarding time, recurring service revenue, partner-sourced deployments, cross-sector component reuse, and the proportion of transactions that verify both evidence and authority.

Evidence boundaries and third-party rights

The paper distinguishes external market research, enacted law, deployed Spherity capabilities, and forward-looking Spherity strategy. The Gartner placement is an independent market perspective, not an endorsement. The extension from physical-product DPPs to AI Service Passports is Spherity’s strategic outlook and was not part of Gartner’s DPP evaluation.

The third-party Gartner material cited or reproduced in the paper is excluded from the paper-level CC BY 4.0 license and remains subject to Gartner’s rights. GARTNER is a trademark of Gartner, Inc. and/or its affiliates. Other trademarks remain the property of their respective owners.

References

  1. Gartner. Emerging Market Quadrant for Digital Product Passport — Established Vendors. Kevin Lawrence, Marta Muñoz, and Rajan Saini. 6 July 2026. Gartner document 8098797.
  2. European Commission. The Digital Product Passport Registry is now live. 20 July 2026.
  3. European Union. Regulation (EU) 2024/1781 establishing a framework for ecodesign requirements for sustainable products.
  4. European Union. Regulation (EU) 2023/1542 concerning batteries and waste batteries.
  5. CIRPASS-2 Consortium. Risks and mitigations: a companion to D4.1 Reference Architecture, version 1.1. 5 June 2026. DOI: 10.5281/zenodo.20670585.
Read or download the final paper

The PDF contains the complete strategy argument, product and market context, regulatory mapping, source attribution, and third-party rights notice.

Creative Commons Attribution 4.0 International

Open research

License and citation

Spherity Strategy and Market Positioning Update is licensed by its named author under the Creative Commons Attribution 4.0 International License (CC BY 4.0), except for the third-party material identified below. Reuse must credit every named author, link to this canonical version and the license, and indicate whether changes were made.

Third-party rights: Gartner material cited or reproduced in the publication, and Gartner trademarks, are excluded from the paper-level CC BY 4.0 license and remain subject to Gartner's rights.

How to cite this work

Dr. Carsten Stöcker (2026-08-05). “Spherity Strategy and Market Positioning Update: Digital Product Passports, European Business Wallets and the agentic internet.” Spherity GmbH. https://spherity.github.io/spherity-research/spherity-dpp-dbp-strategy-market-positioning.html. Licensed CC BY 4.0.

Direct answers

Questions this research answers

What is Spherity's position in the 2026 Gartner Digital Product Passport Emerging Market Quadrant?

Gartner published the Emerging Market Quadrant for Digital Product Passport — Established Vendors on 6 July 2026. Spherity is positioned as the sole vendor in the Pioneers quadrant. Spherity treats that placement as one independent market perspective rather than as an endorsement.

Why does Spherity combine Digital Product Passports with European Business Wallets?

A DPP or DBP data plane provides product and lifecycle evidence. A European Business Wallet control plane can establish the legal person, role, mandate, representation right, access policy, and delegated authority behind a transaction. Together they make product data both machine-usable and accountable.

What does batteries first, then horizontal scale mean?

Spherity first industrializes VERA in regulated battery and BESS programmes, where deadlines, safety duties, complex bills of materials, and long service lives create a demanding proving ground. It then reuses the same identity, credential, provenance, policy, and lifecycle controls across industrial products, steel, energy, chemicals, and consumer products.

What is a cyber-secure Digital Product Passport?

A cyber-secure DPP combines cryptographic product and enterprise identity, verifiable credentials, selective disclosure, status and revocation, policy-based access, resilient availability, tamper-evident event history, and signed audit evidence. The controls address the full lifecycle risk surface identified by CIRPASS-2, not only data signatures.

What is Spherity's AI Service Passport outlook?

Spherity proposes an AI Service Passport as a forward-looking, DPP-like lifecycle record for an AI service. It can link provider and operator identity to model family, version, configuration, guardrails, TEVV evidence, incidents, updates, and operating limits, while an EBW anchors legal responsibility and authority.

What is the micro-ERP concept?

A micro-ERP is Spherity's product-centric execution concept: a DPP combined with bounded lifecycle logic, identity, rights, and security. It coordinates evidence and permitted actions across organizations without replacing ERP, MES, PLM, or PIM systems.

Which regulatory regimes can reuse DPP evidence beyond ESPR?

The paper maps reusable product evidence and workflow controls to the EU Batteries Regulation, General Product Safety Regulation, Product Liability Directive, REACH and CLP, Detergents and Surfactants Regulation, Machinery Regulation, EU AI Act, Cyber Resilience Act, and Construction Products Regulation. A DPP supports evidence reuse but does not replace accountable operators, conformity assessment, technical documentation, or regulatory reporting.