A luxury watch leaves the factory floor. Somewhere between the production line and the consumer’s wrist, counterfeiters photograph its QR code, clone its packaging, and list a replica online. The watch had a digital identifier. It just had the wrong kind. Four technologies compete to give products a verifiable digital identity: NFC chips, QR codes, RFID tags, and digital watermarks. They differ fundamentally in security architecture, consumer interaction, supply chain utility, cost, and regulatory fitness. Choosing wrong means paying twice.
The pressure is not hypothetical. It is structural, regulatory, and accelerating.
The technology choice determines whether a brand solves one of these problems or all four simultaneously.
A cryptographic chip embedded in or on the product. Each smartphone tap triggers a challenge-response exchange: the chip generates a unique, one-time cryptographic proof using a secret key stored in protected memory. A monotonic counter prevents replay attacks. The backend validates the response. Security lives inside the chip, not on any visible surface. The dominant chip class for phone-tap authentication is NTAG 424 DNA (ISO/IEC 14443-A, NFC Forum Type 4), which uses AES-128 encryption and SUN (Secure Unique NFC) messaging.
A printed code encoding a URL. In the GS1 Digital Link standard, the URL contains a GTIN and optionally a serial number. Scanned by smartphone camera. When serialised (one unique code per unit) and connected to a backend, it supports authentication workflows. The code itself is static, visible, and copyable. Security depends entirely on backend logic, not on any intrinsic property of the printed mark.
A passive tag that broadcasts a unique identifier when energised by a reader’s electromagnetic field. UHF Gen2, the dominant supply chain standard, enables bulk scanning: hundreds of tags read simultaneously without line of sight. Most RFID deployments are not cryptographic. The tag broadcasts its EPC identifier to any reader. RFID is a supply chain efficiency and inventory technology. It is not consumer-facing.
An invisible, machine-readable identifier embedded into printed packaging artwork. Decoded by a dedicated app or specialist scanner, not by a native smartphone camera. The HolyGrail 2.0 initiative uses watermarks for recycling sortation. As an authentication tool, watermarks share QR’s core limitation: the identifier is in the printed surface and can be replicated by scanning and reprinting.
| Dimension | NFC | QR / GS1 Digital Link | RFID (UHF Gen2) | Digital Watermark |
|---|---|---|---|---|
| Security basis | AES-128 cryptography, per-tap unique response | Backend serialisation, static printed code | EPC identifier, cloneable in most deployments | Printed into surface, replicable |
| Consumer interaction | Native smartphone tap, no app | Camera scan, requires lighting and deliberate aim | Requires specialist reader, not consumer-facing | Requires dedicated app |
| Supply chain scanning | NFC reader, standard in modern logistics | Existing barcode infrastructure | Excellent: bulk read, no line of sight | Conveyor scanner infrastructure |
| Data per scan event | Timestamp, geography, tap counter, unit identity | Timestamp, geography (if backend configured) | Identifier and timestamp at reader | Identifier only |
| Product integration | Embedded during manufacture, invisible, non-removable | Printed on surface, visible | Label or hangtag, removable | Embedded in printed artwork |
| Per-unit cost | Higher (viable above ~£30 unit value) | Near zero marginal print cost | Low to moderate (reader infrastructure required) | Moderate (encoding and app ecosystem) |
| DPP data carrier | Yes, durable and consumer-scannable | Yes (GS1 Digital Link), less durable than chip | No, not consumer-scannable per ESPR | No, requires dedicated app |
| Grey-market detection | Yes, real-time geographic scan events | Limited, only with backend configuration | No consumer scan events | No |
The critical distinction: a QR code is a photograph of an address. An NFC chip is a lock that generates a new, unrepeatable key every time someone knocks.
The security gap between NFC and QR is not a matter of degree. It is architectural.
A serialised QR code can be authenticated on the first scan. The backend checks whether the serial number exists and whether it has been scanned before. But the code is visible on the product surface. A counterfeiter who photographs a genuine QR and prints it onto a fake product has a valid identifier. The backend sees a real serial number. It can flag duplicates over time, but only after the counterfeit is already in circulation and consumers have already been deceived.
An NFC chip cannot be photographed. The secret key never leaves the chip’s protected memory. Even if someone reads the chip’s public data, they cannot generate a valid cryptographic response. Each tap produces a unique, unrepeatable proof. Cloning requires physical extraction of the AES-128 key, which is computationally infeasible.
| Attack vector | NFC (NTAG 424 DNA) | Serialised QR |
|---|---|---|
| Photographing / copying identifier | Impossible: key is in protected memory | Trivial: code is visible on surface |
| Replay of previous authentication | Blocked by monotonic counter | Possible until backend flags duplicate |
| Cloning the carrier | Requires breaking AES-128 | Requires a printer |
| First-scan deception | Not possible | Possible if counterfeit is scanned first |
The counterpoint that matters: this level of security is unnecessary for every product. A €3 FMCG item on a supermarket shelf does not face the same threat model as a €300 bottle of single malt. The security architecture should match the risk.
QR wins on three fronts: cost, universality, and infrastructure compatibility.
Cost. A printed QR adds near-zero marginal cost per unit. The real expense is serialisation and the backend platform, not the carrier itself. For high-volume, low-unit-value product lines, NFC’s per-unit cost (published converter prices for NTAG 424 DNA-class labels cluster around $0.45-0.65 at five-figure volumes) is difficult to justify.
Volume and speed. Products manufactured in millions of units per month, where the primary need is serialisation, traceability, and consumer information rather than cryptographic proof, are well served by GS1 Digital Link QR codes. The supply chain already reads barcodes. No new hardware.
DPP compliance carrier. For products where the regulatory requirement is a consumer-scannable data carrier linking to DPP data, GS1 Digital Link QR is emerging as the de facto default. The ESPR is carrier-neutral, but QR satisfies the “consumer-scannable” requirement at minimal cost.
QR is the right sole technology when: unit value is low, secondary market risk is negligible, the product is consumed quickly (no long-term ownership lifecycle), and the primary objective is compliance or supply chain serialisation rather than authentication.
RFID is not a competing authentication technology. It solves a different problem.
Bulk inventory counting. Warehouse receiving without opening cartons. Automated replenishment in retail. Loss prevention at store exits. These are RFID’s domain. A single reader can enumerate hundreds of tags per second without line of sight. No other technology matches this for supply chain throughput.
RFID does not replace NFC or QR for consumer-facing use cases. Consumers do not carry UHF readers. The tag is typically on a hangtag or label, removable from the product. Most deployments do not use cryptographic authentication. RFID tells the supply chain where the product is. It does not tell the consumer whether it is real.
Digital watermarks occupy a niche: recycling sortation and packaging-level identification where no additional label or tag can be applied. The HolyGrail 2.0 initiative demonstrates genuine value for automated waste stream sorting, enabling recycling infrastructure to identify material type and brand from the printed surface itself.
For authentication, watermarks inherit QR’s fundamental weakness: the identifier exists in the printed surface and can be replicated by high-resolution scanning and reprinting. They add a further barrier: decoding requires a dedicated app, not a native smartphone function. Consumer adoption for authentication workflows is limited.
| Category | Recommended primary | Recommended complement | Rationale |
|---|---|---|---|
| Luxury watches, jewellery | NFC | None required | High unit value, long ownership lifecycle, active secondary market, metal housing (on-metal NFC tags with ferrite layer solve detuning) |
| Wine and spirits | NFC (closure) | QR (label) | Tamper evidence via TagTamper variant, authentication of sealed vs. opened state, compliance data on label |
| Cosmetics and fragrance | NFC | QR (outer packaging) | Unit value supports NFC, consumer engagement post-purchase, QR for retail-facing compliance |
| Leather goods, fashion | NFC | RFID (supply chain) | Authentication plus inventory management, NFC embedded invisibly, RFID on hangtag for logistics |
| FMCG, high-volume consumer goods | QR (GS1 Digital Link) | Digital watermark (recycling) | Unit value too low for NFC, serialisation and DPP compliance via QR, watermark for sortation |
| Cigars | NFC | None required | High unit value, collector and secondary market, authentication of provenance |
| Furniture, premium audio | NFC | QR (DPP compliance) | Long product lifecycle, ownership transfer, warranty management, DPP data via QR |
Yes, and for regulated products with authentication needs, the combination is increasingly the reference architecture.
The logic: NFC for trust, QR for compliance. The GS1 Digital Link QR code satisfies the DPP data carrier requirement, is consumer-scannable, and integrates with existing retail and supply chain infrastructure at near-zero marginal cost. The NFC chip provides cryptographic authentication that the QR code cannot. Both can resolve to the same backend, the same product identity, the same consumer experience.
A wine bottle illustrates the pattern. The QR code on the back label carries the GS1 Digital Link URL with GTIN and serial number: regulatory data, provenance, tasting notes, recycling information. The NFC chip in the closure proves the bottle is genuine, detects whether it has been opened, logs every authentication event with timestamp and geography, and enables the brand to identify grey-market diversion in real time.
Neither technology alone covers both requirements. Together, they do.
Published converter prices for NTAG 424 DNA-class labels, the chip family used for phone-tap cryptographic authentication, cluster around $0.45-0.65 per unit at five-figure order volumes. On-metal variants (required for watches, metal closures, audio equipment) add 7-30% due to the ferrite shielding layer. At 50k+ volumes, pricing is quote-only and typically lower.
For comparison, standard non-secure NFC tags (NTAG213-class, suitable for data transfer but not cryptographic authentication) list around €0.19-0.23 at 1-10k units.
The tag cost is one component. Total cost of ownership includes encoding, provisioning, integration into the manufacturing line, and the backend platform. But for a product with a retail price above €30, the authentication cost per unit is a fraction of a percent of revenue, and a fraction of the cost of a single counterfeit reaching market.
The ESPR mandates a durable, consumer-scannable data carrier linked to the product’s DPP data in the central registry. NFC qualifies. So does GS1 Digital Link QR.
In practice, GS1 Digital Link QR is emerging as the default compliance carrier because it is printed, universal, and zero marginal cost. NFC adds a trust layer that the regulation does not strictly require but that authentication, grey-market detection, and post-sale engagement demand.
The pragmatic approach: deploy GS1 Digital Link QR as the DPP carrier. Deploy NFC as the authentication and engagement layer. Both resolve to the same digital identity. Compliance and commercial return from a single infrastructure investment.
40+ brands · 12+ years · €1.5B in product value protected.
Selinko helps brands choose, deploy, and operate the right digital identity architecture for their products, from NFC chip selection through production-line integration to consumer-facing authentication.
NFC is fundamentally more secure. An NTAG 424 DNA chip generates a unique cryptographic proof on every tap using AES-128 encryption. The secret key never leaves protected memory. A QR code is a static, visible identifier that can be photographed and reprinted onto a counterfeit product.
Yes. iPhone XS/XR and all later models read NFC tags natively in the background. Android phones read NFC natively with the screen on. No app download, no camera aiming, no special lighting required. The consumer simply holds the phone near the product.
Published prices for NTAG 424 DNA-class secure labels cluster around $0.45-0.65 per unit at five-figure volumes, with on-metal variants adding 7-30%. At 50k+ volumes, pricing is quote-only. The tag is one component alongside encoding, provisioning, and backend platform costs.
Standard NFC tags detune on metal surfaces. On-metal NFC tags incorporate a ferrite shielding layer that prevents detuning, enabling reliable reads on watches, metal closures, audio equipment, and other metal housings.
No. RFID (UHF Gen2) is a supply chain technology optimised for bulk scanning without line of sight. Most RFID deployments are not cryptographic. Consumers do not carry RFID readers. NFC is the consumer-facing authentication standard using cryptographic challenge-response.
A GS1 Digital Link QR code encodes a structured URL containing a product GTIN and optionally a serial number according to GS1 standards. It enables serialisation, traceability, and regulatory compliance while remaining scannable by any smartphone camera.
Yes. The combination is the emerging reference architecture for regulated products: QR carries the DPP-compliant data carrier at near-zero cost, while NFC provides cryptographic authentication, tamper evidence, and post-sale engagement that a printed code cannot deliver.
The ESPR is carrier-neutral but mandates a durable, consumer-scannable data carrier. GS1 Digital Link QR is emerging as the de facto compliance default. NFC qualifies and adds an authentication layer. The central EU DPP registry has been live since 20 July 2026 (European Commission).
Talk to our team