Live· ·Issue N°
CO₂ ppm·Temp anomaly°C·CH₄ ppb
The EU ESG Rating Regulation Is Now Live: What Rated Companies and Non-EU Providers Need to Do
ArticleEU
Governance

The EU ESG Rating Regulation Is Now Live: What Rated Companies and Non-EU Providers Need to Do

The EU ESG Rating Regulation applied from 2 July 2026. Authorisation deadlines, endorsement and recognition routes for non-EU providers, and what rated firms can do.

10 min read04 Sept 2026

Three dates matter here, and they are frequently conflated.

Regulation (EU) 2024/3005 began applying on 2 July 2026. That is the date ESG rating activities became a regulated financial service in the European Union for the first time.

2 August 2026 was the notification deadline. Providers already operating in the EU on 2 January 2025 had to tell the European Securities and Markets Authority they intended to continue. That date has passed.

2 November 2026 is the one still ahead. Legacy providers must submit a full application for authorisation or recognition within four months of the application date. Miss it and they must cease EU activities.

So the regime is two months old, the first gate has closed, and the second is two months out. Here is what it requires, how non-EU providers get access, and what rated companies can actually do with it.

 

How The Regulation Came About

 

ESG ratings had grown into a significant input to capital allocation without any dedicated regulatory framework. Providers used divergent methodologies, disclosed little about them, and frequently sold other services to the same companies they rated. Two firms could score the same company very differently, and neither the company nor the investor could see why.

The regulation was adopted on 27 November 2024, published in the Official Journal on 12 December 2024 and entered into force on 1 January 2025, with an 18-month runway to the 2 July 2026 application date. Its architecture borrows visibly from the credit rating agency regime: mandatory authorisation, ongoing supervision by a single European regulator, methodology transparency, and structural separation of activities that create conflicts.

Being a regulation rather than a directive, it applies uniformly and simultaneously across every Member State. There are no national transposition variations to track, which is a welcome change from most of the recent sustainability files.

 

What Counts As An ESG Rating

 

The definition is broader than many organisations assume, and this is where scope surprises happen.

An ESG rating is an opinion, a score, or a combination of the two, based on an established methodology and a defined ranking system of rating categories, concerning the ESG profile of, the exposure to ESG risks of, or the impact on ESG of a legal person, a financial instrument, a financial product or a public authority.

Two consequences follow.

The regime is not limited to financial markets. It reaches corporate reporting, public disclosures and supply chain assessment activities. A platform that issues ESG scores to assess supplier sustainability, for use in business-to-business procurement or due diligence, falls within scope where it operates on a professional basis using a defined methodology. Plenty of procurement technology vendors have not registered that they are now regulated entities.

Public authorities can be rated subjects, not just companies and financial products.

Size determines the weight of the obligations. Providers with annual turnover from ESG rating activities above 50 million euro face the full set of requirements from the application date. Providers below that threshold benefit from a lighter regime with longer compliance timelines for certain requirements.

 

Three Routes For Non-EU Providers

 

A provider established outside the EU cannot simply continue serving EU users. Three routes exist, and they are not interchangeable.

Equivalence. The European Commission may determine that a third country's regulatory framework is equivalent, opening access to providers authorised there. This is the cleanest route and the least available: as of spring 2026, no equivalence decisions had been made. Non-EU providers should not build a compliance plan around it.

Endorsement. An ESMA-authorised EU provider formally endorses ratings issued by a non-EU provider within the same corporate group, and takes responsibility for those endorsed ratings. This is the practical route for global rating houses with an EU entity, and the responsibility transfer is the key point: the endorsing EU entity is accountable, which means it will impose its own standards on the affiliate.

Recognition. Available only to smaller non-EU entities, with annual net turnover below 10 million euro in each of the last three consecutive years. Where the entity belongs to a group, the group's consolidated annual net turnover must also fall below that threshold, which closes the obvious workaround. Recognition requires an EU legal representative and submission to ESMA oversight.

The gap in the middle is worth naming. A mid-sized non-EU provider, above 10 million euro turnover but without an EU group entity to endorse it, has no available route until an equivalence decision covers its jurisdiction. That is a structural problem for a category of specialist providers, and the practical answer is usually to establish an EU entity and seek authorisation directly.

 

Transparency Obligations

 

The transparency requirements are the part rated companies will feel most directly, because they make the machinery visible.

Providers must disclose on their website, at minimum, the methodologies, models and key rating assumptions used in their rating activities, presented clearly and in a separate identified section of the site. The detail required is specified in the regulation's annexes, and disclosure must be in place at the latest when the provider starts issuing ratings.

Several specifics matter for anyone reading a rating.

Which materiality dimension the rating addresses. Providers must state whether a rating captures financial risk to the rated entity, the entity's impact on the environment and society, or both. This single requirement resolves years of confusion, because ratings measuring fundamentally different things have been compared as though they were equivalent.

The weighting of E, S and G factors. Providers must disclose how much each pillar contributes.

Separate E, S and G ratings, unless an aggregated rating is accompanied by detailed information on weighting and comparability.

Data sources, assumptions, use of proxies and estimated data, and whether the rating is expressed in absolute or relative terms.

Published disclosures are also intended to be accessible through the European Single Access Point, alongside CSRD and SFDR disclosures.

 

Conflicts Of Interest And Prohibited Activities

 

The conflict rules are structural rather than merely procedural.

Providers must avoid conflicts of interest, manage those that are unavoidable, and disclose existing or potential conflicts to ESMA. They must maintain internal policies and due diligence procedures designed to keep the rating function independent of political and economic influence. Employees involved in rating activities are prohibited from engaging in activities that could compromise integrity. Records must be retained for at least five years.

The sharper provision prohibits certain activities from being carried on within the same legal entity as ESG rating activities, including developing benchmarks, issuing credit ratings and providing consulting services to investors or undertakings. Two qualifications apply. The restrictions bite at legal entity level and are not intended to reach the provider's wider group. And some can be lifted where a provider has adopted specific conflict management measures or holds separate authorisations.

ESMA has intervention powers where conflicts are inadequately managed, and can require mitigation measures or cessation of the conflicting activity.

The practical effect is that the long-standing complaint about rating providers selling advisory services to rated companies is now addressed structurally rather than by disclosure alone.

 

What Rated Companies Can Actually Do

 

Set expectations correctly, because this is where commentary tends to overpromise.

The regulation does not give companies a right to negotiate their rating or to challenge the rating outcome. Methodological judgement remains with the provider, and a company that dislikes its score has no appeal mechanism.

What the regulation does provide is transparency and a factual correction pathway. Companies gain the ability to see the methodology, models, assumptions, data sources and weightings behind a rating, and to identify factual inaccuracies in the underlying data where they exist. The rated entity's ability to access and contest the data used to assess it is part of the framework.

That distinction is the whole game. You cannot argue that your governance score should be higher. You can establish that the provider used a superseded board composition, missed a disclosure you published, or applied an estimate where actual data exists.

Four things follow for rated companies.

Read the methodology disclosures for the providers that rate you. They are now required to be public and in a dedicated section of the provider's website. Most companies have never seen the weighting scheme applied to them.

Check which materiality dimension each rating measures. A rating assessing your impact on the environment and a rating assessing climate risk to your business are different instruments, and comparing them or being benchmarked across them is a category error you can now identify and push back on.

Audit the data inputs for factual errors. This is the actionable route. Where a provider has used outdated, incomplete or estimated data and you have published better, that is a correctable inaccuracy rather than a disagreement.

Watch for absence penalties. Some methodologies treat non-disclosure as a negative scoring outcome rather than a neutral one. Where that is the published approach, the remedy is disclosure rather than dispute.

 

The Obligation That Reaches Beyond Providers

 

One requirement extends past rating providers to their users, and it is easy to miss.

A regulated financial undertaking that discloses an ESG rating in its marketing communications must publish on its own website the information specified in the regulation's annex, covering methodologies used, data sources, limitations, the scope of E, S and G factors assessed and their weighting, conflicts of interest, and reference to the Paris Agreement objective, among other items.

The regulation also amends the Sustainable Finance Disclosure Regulation, so financial market participants and advisers referencing ESG ratings in their disclosures face additional information requirements.

If your marketing materials cite an ESG rating, that citation now carries a disclosure obligation attached to it. Asset managers and banks should audit their marketing collateral against this rather than assuming the obligation sits solely with the provider.

 

What To Do Now

 

Non-EU providers should have notified already. If you were operating in the EU on 2 January 2025 and did not notify ESMA by 2 August 2026, take advice immediately on your position. The 2 November application deadline is the harder gate, and authorisation applications require documented governance structures, methodology disclosures and conflict frameworks to be in place before submission rather than promised in it.

Non-EU providers without an EU entity should decide their route now. Endorsement requires a group affiliate. Recognition requires turnover below 10 million euro including at group level. If neither fits, establishing an EU entity and applying directly is the remaining path, and it takes time.

EU providers should confirm their size classification, since the 50 million euro turnover threshold determines whether the full obligations apply immediately or a lighter regime with longer timelines.

Procurement and supply chain platforms should test whether they are in scope. If you issue supplier ESG scores on a professional basis using a defined methodology, you may be a regulated ESG rating provider and may not have realised it.

Rated companies should build a rating engagement process. Identify which providers rate you, read their newly published methodologies, check which materiality dimension each measures, and establish a channel for correcting factual errors. This is a modest amount of work with a direct effect on how your company is represented to investors.

Financial undertakings should audit marketing materials that cite ESG ratings against the annex disclosure requirement.

The broader read is that this regulation does something unusual in sustainable finance: it regulates the assessors rather than the assessed. Companies have spent a decade being scored by opaque methodologies they could not see, using data they could not verify, by firms that sometimes sold them advice on how to improve. That arrangement is now constrained. The scores themselves remain the provider's judgement, and nothing here makes ratings comparable overnight. But for the first time, a rated company can find out how the number was built.

 

Compliance Checklist

 

  1. Note the three dates: application from 2 July 2026, notification deadline of 2 August 2026 now passed, and full authorisation or recognition applications due by 2 November 2026.

  2. Confirm whether your activity meets the ESG rating definition, which covers opinions and scores based on an established methodology and defined ranking system.

  3. Test scope beyond financial markets, including supply chain and procurement scoring platforms operating on a professional basis.

  4. For EU providers, establish whether annual turnover from rating activities exceeds 50 million euro, which determines full or lighter obligations.

  5. For non-EU providers, select your route from equivalence, endorsement or recognition, noting that no equivalence decisions had been made as of spring 2026.

  6. For endorsement, confirm an ESMA-authorised affiliate in the same corporate group is willing to take responsibility for your ratings.

  7. For recognition, verify net turnover below 10 million euro in each of the last three consecutive years, including at consolidated group level, and appoint an EU legal representative.

  8. Publish methodologies, models and key rating assumptions in a dedicated section of your website, including materiality dimension and E, S and G weightings.

  9. Provide separate E, S and G ratings, or accompany aggregated ratings with detailed weighting and comparability information.

  10. Review activities carried on in the same legal entity, given prohibitions covering benchmarks, credit ratings and consulting services.

  11. Retain records for at least five years and disclose existing or potential conflicts to ESMA.

  12. Rated companies should read provider methodology disclosures, confirm which materiality dimension applies, and audit data inputs for factual inaccuracies.

  13. Financial undertakings citing ESG ratings in marketing communications should publish the required annex information on their own websites.

  14. Check the additional SFDR information requirements where ESG ratings are referenced in disclosures.

Position as of early September 2026. Regulation (EU) 2024/3005 applies from 2 July 2026, with transitional deadlines of 2 August and 2 November 2026 for providers already operating in the EU. Article references and detailed requirements should be confirmed against the regulation text, as secondary summaries vary. Confirm current requirements with ESMA and take professional advice for your circumstances.

 

Sources

Regulation (EU), EUR-Lex, European Securities and Markets Authority, European Single Access Point, Skadden Arps Slate Meagher and Flom, WilmerHale, Charles Russell Speechlys, LSEG Data and Analytics regulatory disclosure mapping, Synesgy, Obsidian Regulatory Intelligence

 

This article is intended for general professional information and does not constitute legal, financial, or investment advice.

 

 

Subscribe to our newsletter for more insights, case studies, and ESG intelligence.

 

Explore ESG Solutions on our marketplace - OneStop ESG Marketplace.

 

Keep abreast of the top ESG Events on OneStop ESG Events.

 

OneStop ESG Educate: Your go-to source for top ESG courses and training programs tailored to your needs.

 

Stay informed with the latest insights on OneStop ESG News.

 

Discover meaningful career opportunities on OneStop ESG Jobs.

Related Resources