III.2.7.

III.2.7.

Do we need to have a valid ISO 27001 certificate if we want to register as a third party RRM?


Answer: There is no requirement to acquire a valid ISO 27001 certificate. Nevertheless, nothing prevents RRMs from doing so. It can be proven useful when demonstrating compliance to the technical and organisational requirements.

Please note that, by 8 May 2025, the European Commission is expected to adopt a delegated act further detailing the authorisation and supervision of RRMs. A new authorisation process is foreseen which will replace the current registration process.

Updated: 
12/03/2025