top of page

Origin and Traceability: Why Europe's Supply Chains Still Run on Unverifiable Paper

Updated: Aug 26

A shipment of lithium leaves a mine in one jurisdiction, is refined in a second, becomes a cathode in a third, and arrives in an EU factory as part of a battery that must eventually prove to a regulator, a customer, and a recycler exactly where it came from. Along the way it accumulates mining certificates, carbon footprint declarations, due diligence reports and customs declarations; almost all of it as PDFs and email attachments.


The paperwork doesn't prove to be sufficient. A PDF certificate has no cryptographic link to the body that issued it. It can be edited, duplicated, backdated or fabricated, and the receiving party has no way to check it other than phoning the issuer.


The gap that leaves is measurable. In 2024, EU customs and market surveillance authorities detained around 112 million counterfeit goods worth an estimated €3.8 billion — the highest value ever recorded. Meanwhile, the European Public Prosecutor's Office (EPPO) ended 2025 with €45.01 billion in estimated damage under investigation from VAT and customs fraud alone, out of €67.27 billion across all its active cases.


Figure 1 — The verification gap. Source: EPPO


The problem is trust, not data

There is no shortage of supply chain data. The problem is that when data crosses an organisational boundary, it loses its connection to whoever vouched for it. Cross-border goods still travel with documents, PDF declarations, and bilateral agreements.


The workarounds scale badly. Bilateral verification means every pair of trading partners builds its own checking process, with n actors, you approach  relationships. Trusted intermediaries sell verification as a service, which works but concentrates trust in commercial parties. Most of the time, the receiving party simply accepts the document, which is exactly the gap that undervaluation, catch laundering and counterfeit insertion exploit.


The instinctive fix (one shared database) fails for political rather than technical reasons. Competing manufacturers will not accept a single operator as arbiter of truth, and neither will sovereign customs authorities. Criminal networks exploit the siloed nature of existing systems. Suppliers also treat their own supplier relationships as commercially sensitive: a Tier-1 supplier will not disclose its Tier-2 sources just to satisfy a customer's due diligence obligation.


The real requirement is narrower and harder: let any authorised party verify a claim about a product without access to the issuer's systems, without a shared central database, and without revealing more than the claim itself.



Figure 2 — Where provenance breaks. 


What cryptographic proof changes

A verifiable credential is a digital certificate — a carbon footprint declaration, a catch certificate, a trademark record — signed by whoever issued it. Three things follow: you can check that the signature really belongs to that issuer; any edit to the certificate breaks the signature, so it can't be quietly altered after the fact; and checking it doesn't require contacting the issuer directly, only checking against the shared ledger.


The detail that matters most is what the ledger actually holds. It's closer to a notary's logbook than a filing cabinet: it records that an issuer is accredited, that a schema exists, that a credential hasn't been revoked. It does not hold a copy of the certificate's contents. The actual data — the carbon figure, the catch weight, the mining certificate itself — stays with whoever was issued it, in their own wallet, and they choose when to hand it over.

That is what makes confidentiality-preserving verification possible. In the TRACE4EU battery pilot, a supplier who wants to keep its own supply chain confidential can have its lithium supplier get a mining certificate from a recognised body, and pass that certificate upward without revealing who its supplier actually is. The manufacturer checks the certificate against the ledger and confirms a legitimate body issued it — they learn that the claim is backed, not who else is in the chain behind it.


Because the data lives with the holder rather than on the ledger, the holder controls when, or whether, it gets shown. That cuts both ways. Nobody can pull data out of a wallet without the holder presenting it, which protects genuinely sensitive business relationships. But the same design means a lost certificate has to be reissued by the original source, since the ledger only proves the certificate existed — it was never holding a spare copy. And where certificates are represented as NFTs, as in the counterfeit-goods pilot, a holder can discard their own copy, but can't erase the record that it was issued in the first place — a blockchain only adds entries, it doesn't delete them. Discarding a certificate mainly leaves the product unable to prove itself, which is usually the opposite of what anyone trying to avoid scrutiny wants.


EBSI's role here is deliberately narrow: a shared digital trust layer so any actor can verify data directly, across systems and borders. It is operated by participating Member States, which matters more to customs authorities than any technical feature. Institutions can use it as a trust layer while continuing to operate their own systems. Your ERP stays your ERP; what changes is that data leaving it carries proof.


Four projects in the field

Battery materials. The EU battery regulation's supply chain and passport requirements significantly raise compliance costs, and economic operators face difficulty verifying supplier data, heightening liability risk. The pilot authenticates exchanged data so a Battery Passport can carry verifiable data on carbon footprint, responsible mining certifications and due diligence reports, interoperable with Catena-X and UNECE, with the battery's serial number as the credential subject.


Seafood tracing. Norway already tracks vessels, but it remains difficult to track individual products and ensure traceability for the authority and end customer. Working with the Directorate of Fisheries, customs and food safety authorities, EBSI issues and verifies credentials, issues QR codes for each product, and registers supply chain events. The chain runs fisher identity → sales order → packaging → customs clearance → delivery, and the end customer can verify the full history contained within it.


e-Origin. With the Belgian VAT administration, customs authority, Amazon and brokers at Liège airport, a seller issues a shipment credential at dispatch and the broker requests a transaction document directly from the seller. The customs authority verifies it against the ledger and, finding the IOSS number and parcel value reliable, releases the goods. Undervaluation stops being what a broker types into a declaration and becomes a matter of contradicting a signed transaction record.


EBSI-ELSA. With EUIPO, Netherlands customs, KLM Cargo and brand owners including Mercedes-Benz Tech Motion. EBSI signs NFT metadata for authenticity and registers supply chain events, with NFTs as digital twins of products, so any intermediary can scan the serialisation code and verify the Trademark credential.


Figure 3 — Four pilots at a glance 


The paperwork problem in global trade was never really about paperwork. Trust does not survive organisational boundaries, and every workaround either costs too much or fails silently. What cryptographic proof changes is narrow but decisive: a claim about a product can now carry evidence of who made it, when, and whether it has been altered. It is checkable by anyone authorised, without access to the issuer's systems.



bottom of page