Supply Chain

Supply Chain Traceability & EPCIS

The DPP requires documented visibility across your supply chain. This guide explains supplier tiers, GS1 EPCIS 2.0 event capture, and how to align with both ESPR and the Corporate Sustainability Due Diligence Directive (CS3D).

ESPR requires supply chain data in the DPP — particularly for critical raw materials and hazardous substances. The Corporate Sustainability Due Diligence Directive (CS3D) extends this to mandatory Tier 2 and Tier 3 mapping for high-risk sectors, with civil liability for non-compliance.

What are supply chain tiers in the DPP?

Three levels: Tier 1 is your direct suppliers, Tier 2 their sub-suppliers, and Tier 3 the primary material sources. The DPP requires visibility past the first.

Tier 1Direct Suppliers
Examples: Component assemblers, contract manufacturers, packaging suppliers
Full supplier identity, certifications, and material declarations required in DPP.
Tier 2Sub-Suppliers
Examples: Raw material processors, sub-component makers, chemical suppliers
Required for critical raw materials (CRMs) and substances of concern. CS3D extends this to high-risk sectors.
Tier 3Primary Material Sources
Examples: Mining sites, agriculture, forestry operations
Required for batteries (cobalt, lithium origin), conflict minerals, and deforestation regulation.

What traceability data does the DPP require?

Supplier name, legal address and identifiers (VAT, EORI, LEI), quality and environmental certifications, country of origin per material, the origin of critical raw materials such as cobalt, lithium and nickel, a conflict minerals declaration, carbon footprint per supplier stage, and the due diligence policy under CS3D Article 5.

Data FieldTier Scope
Supplier name & legal address
T1
VAT / EORI / LEI identifier
T1
ISO 9001 / ISO 14001 certification
T1
Country of origin per material
T1–T2
Critical raw material origin (cobalt, lithium, nickel)
T2–T3
Conflict minerals declaration (3TG + cobalt)
T2–T3
Carbon footprint per supplier stage
T1–T2
Due diligence policy (CS3D Art. 5)
T1
Third-party audit verification
T1–T2
Mine / extraction site ID (for batteries)
T3

What are EPCIS 2.0 event types?

GS1 EPCIS (Electronic Product Code Information Services) is the standard for capturing and sharing supply chain events. EPCIS 2.0 adds JSON-LD support and REST APIs — making it compatible with DPP data architectures.

ObjectEvent
Commission / Decommission
Records when a product is created, activated, or deactivated in the supply chain.
AggregationEvent
Packaging / Palletisation
Captures when items are packed into cases or cases onto pallets — parent/child relationships.
TransactionEvent
Purchase Orders / Receipts
Links EPCIS events to business transactions (POs, invoices, shipping notices).
TransformationEvent
Manufacturing / Processing
Records input materials consumed and output products created in a transformation step.
AssociationEvent
Component Binding
Associates a component (e.g., battery cell) with a product (e.g., EV) in the final assembly.
CS3D — Corporate Sustainability Due Diligence Directive

CS3D (Directive 2024/1760) requires EU companies with 1,000+ employees and €450M+ turnover to map and remediate human rights and environmental risks across their entire supply chain — including Tier 2 and Tier 3 suppliers. For manufacturers, this significantly overlaps with DPP traceability obligations. Aligning both programmes reduces duplicate data collection effort.

CS3D Directive on EUR-Lex
All Guides
Free tool

Where does your product actually stand?

Answer about 20 questions and get a readiness score for your sector, the list of gaps ordered by regulatory urgency, and what to do about each one.

Start free scanner

Free · 5 minutes · no registration