Regulatory Digital Product Passports as a Catalyst for U. S. Supply Chain Visibility
connected lifecycle actions that establish provenance, custody, and operational relationships among organizations, facilities, bundles, and hardware products.
The sc: TransportEvent chain of custody in SPDX 3.1— linking product identity to provenance events through stable, machine-readable identifiers— is structurally equivalent to what the Digital Twin Consortium( DTC) formally defined in October 2024 as the digital thread: " a mechanism for correlating information across multiple dimensions of the virtual representation, where the dimensions include time or lifecycle stage, kind-of-model, and configuration history; the mechanism generally relies on stable, consistent real-world identifiers " [ 4 ]. A DPP serialized in SPDX 3.1 format is a digital thread for the physical product: it correlates identity, composition, custody events, and conformance claims across the product lifecycle using persistent identifiers. Framing DPP implementations this way connects them to the DTC ' s architecture vocabulary and connects the regulatory compliance use case to the broader digital twin design and engineering community. The parallel CycloneDX 1.7 standard has similarly introduced Hardware BOM( HBOM) and Operations BOM( OBOM) types alongside its longstanding SBOM capability.
Additionally, a DPP can be understood as a product-level digital twin in the DTC sense: a virtual representation of a real-world entity( the physical product) synchronized at specified points( manufacturing, custody transfer, end-of-life) to represent past and present states and enable simulation of future states( lifecycle impact, recyclability, failure modes). The DTC ' s Digital Twin Capabilities Periodic Table( CPT v1.1, April 2024) provides an architecture-agnostic requirements framework that implementers can use to map DPP capability requirements to digital twin design choices.
This convergence matters for DPP interoperability because BOM standards provide the serialization formats— JSON-LD, RDF / Turtle, JSON, XML— through which DPP-compliant data can be exchanged across heterogeneous systems without requiring a shared platform.
This paper combines policy forecasting, technical interoperability analysis, organizational adoption analysis, and supply chain architecture assessment to evaluate how DPP ecosystems may alter the availability and strategic utility of supply chain data.
ANALYTICAL FRAMING
MITRE conducted a three-week exploratory survey between March 17 and April 7, 2025, collecting responses from 71 organizations across 13 business areas and multiple global regions. The survey was exploratory rather than statistically representative and was used primarily to identify directional awareness patterns, adoption signals, and organizational concerns rather than to support generalized quantitative conclusions.
SURVEY METHODOLOGY AND LIMITATIONS
The analysis incorporated EU regulatory materials, UNTP specifications and working documents, SPDX 3.1 draft specifications, implementation guidance, public industry discussions, and MITRE
30