EUR-Lex · 01 Sep 2026 · 1 vistas
EU sets authorisation rules for ESG rating providers
Por FactBox Admin

The European Commission has adopted Commission Delegated Regulation (EU) 2026/1119, published in the Official Journal of the European Union on 1 September 2026, laying down the regulatory technical standards on the information that Environmental, Social and Governance (ESG) rating providers must submit to the European Securities and Markets Authority (ESMA). The rules, signed by Commission President Ursula von der Leyen in Brussels on 26 May 2026, apply from 2 July 2026.
The delegated regulation supplements Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities, consolidating the authorisation, registration and recognition requirements into a single legal text. It is based on draft technical standards submitted by ESMA, which ran open public consultations and sought the advice of the Securities and Markets Stakeholder Group.
What applicants must file
An applicant for authorisation as an ESG rating provider must submit to ESMA, alongside the information already required under Annex I to Regulation (EU) 2024/3005, the additional details set out in Annex II of the new regulation. Providers established outside the Union seeking recognition must file the information in Annexes II and III.
- General information, including the applicant’s name, registered office, website and legal entity identifier (LEI) number.
- Contact person details and proof of legal status, such as a commercial or court register excerpt.
- Ownership structure, with capital percentages, the nature of holdings and a chart of parent undertakings and subsidiaries.
- Senior management details, including an organisational chart and, for each member, a certificate of absence of criminal records relating to money laundering, terrorist financing, fraud or embezzlement.
- Staffing resources, covering rating analysts and staff engaged in methodology development, data analysis and IT systems.
- Expected market coverage, procedures and methodologies for issuing ESG ratings, and policies to identify, manage and disclose conflicts of interest.
Format, integrity and data protection
Applications must be submitted in a machine-readable format that keeps the information accessible and allows its unchanged reproduction, and each document must carry a unique reference number identifying the requirement it addresses. A letter signed by a member of senior management must attest that the information is accurate and complete.
In line with the principle of data minimisation under Regulation (EU) 2018/1725, only personal data necessary for ESMA to assess compliance may be requested. Proof of the absence of criminal records for senior management must be retained by the provider and ESMA for no longer than five years after the person concerned has ceased to perform their function. The European Data Protection Supervisor delivered an opinion on the text on 5 May 2026.
Scope and impact
The regulation also covers providers that apply for authorisation to provide benchmarks or for endorsement, requiring additional information in Annexes IV and V, and obliges applicants to estimate their number of employees on a full-time equivalent basis. Because Regulation (EU) 2024/3005 applies from 2 July 2026, the new delegated regulation aligns its own date of application with that framework.
For investors and market participants, the rules give ESMA the detailed information it needs to vet ESG rating providers before they operate in the Union, strengthening confidence in a market whose ratings increasingly steer capital towards sustainable investments.
Source: Official Journal of the European Union, L series, 1 September 2026 (official reference: Commission Delegated Regulation (EU) 2026/1119, CELEX 32026R1119).