Six steps, the same six you see on the process diagram — click any of them there and you land here, on that step. Order the seal first; everything else is quick.
None of this touches your products yet. The Registry only wants to know, with cryptographic certainty, that you are who you say you are.
Create an EU Login — free, a few minutes, and it is the Commission’s own account system, so you will meet it again elsewhere. Then enrol your organisation: legal name, registered address, country, one identifier (national trade register is preferred, but LEI, VAT or eID work) and a compliance contact. Copy these from your company register, not from memory — every one of them has to match your certificate later, character for character.
Once your details are saved you ask the Registry for a declaration. It locks your data into a PDF and seals it with the Commission’s own institutional seal, then hands it to you. Two things to know: the file takes seconds to generate, and editing your organisation details afterwards restarts the whole verification, so get them right before you press the button.
Start this first — it is the only part with a queue, and it is where onboardings stall. You can order the seal through us: dpp.gs is an authorised reseller, so the certificate and the signing of the declaration happen in one place. A qualified trust service provider still issues it and verifies your company, and it must arrive on a smart card, a USB token or as a remote signing service — a certificate emailed as a .p12 file produces only an advanced signature and is refused. Your legal representative then counter-seals the exact file the Registry gave you, changing nothing else; we run that session with you and validate the result before it goes back in.
Back in the Registry, you bring the sealed file in. Before you do, run it through the Commission’s free DSS validator — it tells you in advance whether the Registry will accept it. The line to read is Qualification: it must say QESeal for a company or QESig for a sole trader. PDF only, under 1 GB, filename under 100 characters and without spaces or slashes.
The outcome lands on your Activity Dashboard: processing, then success or failure. Success makes you the administrator of your organisation in the Registry, and the report tells you the day your seal expires — your verified status runs exactly that long. Failure gives you a report naming each problem, which you fix and resubmit; there is no penalty for trying again.
The last step is the one that connects the two halves. Your passports live on our platform, the Registry holds the link to them, and this is what lets you publish from dpp.gs without leaving our dashboard. You remain the responsible economic operator throughout — that part cannot be handed over, and we would not claim otherwise.
Pick the amount of help you want. You can move between them at any point — plenty of people start on their own and call us at the seal.
Everything above, free and in writing, including the parts the official manual leaves you to discover. Most companies with an in-house compliance person need nothing more.
We do it with you, in one working session — and we can supply the QSeal itself, as an authorised reseller, so you are not chasing a trust service provider in parallel. We check your company data against the certificate before you type it, prepare the declaration, run the signing, validate the file, and stay on the call until the Registry says verified. If it is rejected, we fix it and resubmit.
Your team hands over the data; we act as your DPP service provider, host the passports, hold the backup link and publish to the Registry under your operator identity. You stay the responsible economic operator — that part cannot be outsourced, and we will not pretend otherwise.
Nothing about building your passports on dpp.gs waits for verification. Set them up now, publish the moment you are verified.