
A user's guide to carbon ratings under ESMA regulation
In November 2024, the EU adopted Regulation (EU) 2024/3005, extending the oversight of the European Securities and Markets Authority (ESMA) to ESG ratings for the first time. It applied from 2 July 2026 and from November 2026, only ESMA authorised rating providers will be able to distribute ratings in the EU.
With many carbon rating providers joining BeZero in signing up to be an authorised provider, this has the potential to make project-based carbon markets stronger and more trustworthy through better governance, transparency and independence.
BeZero has created a short, practical guide to help you understand what the regulation means for carbon market participants, and what to ask your carbon rating provider.
Q1. What falls under ESMA ESG rating regulation and why does it matter for carbon markets?
The regulation’s definition of an “ESG rating” is any opinion or score built on an established methodology and a defined ranking system, covering environmental, social or governance factors.
We believe this definition applies to companies offering a ranked form of human-led opinion, automated score, or anything in between, regardless of whether the term ‘rating’ is used. Therefore, we believe carbon ratings fall within scope.
The regulation sets rules for providers on methodology disclosure, independence and conflicts of interest, and separation of certain business lines. ESMA now has supervisory and enforcement powers.
By defining what a carbon ratings agency can and cannot do, and how it must operate, ESMA elevates the credibility of rating providers to a regulatory bar. This ensures that the rater, those rated, and those using the rating all get rights and protections. Non-compliance by rating providers carries real life accountability, i.e. financial penalties.
Clarity and guidance from one of the world’s most trusted and respected financial market regulators will strengthen confidence in the market’s integrity, and should give more confidence to institutional investors.
The EU is one of the first jurisdictions to regulate the carbon ratings market. We believe its approach could become a reference point globally.
Q2. How will regulated ratings benefit project developers, intermediaries and corporate buyers?
If you are a project developer:
Demand within the European market for projects supported by regulated ratings will likely bring far greater credibility to projects compared to those without ratings.
Better rights for project developers in their engagement with carbon ratings agencies are central to this regulation:
Project developers must be notified at least two working days before a rating is first issued. You can flag factual errors before publication.
Developers can request the dataset behind your rating, free of charge. This is a fact-checking right only. It cannot be used to influence the methodology or the outcome.
Every carbon rating provider must run a public complaints process. You can challenge data sources, how a methodology was applied, or whether a rating is representative .
You have a “reasoned concerns” channel. Providers are expected to respond within 30 working days.
Fees charged to you must be fair, reasonable, transparent and non-discriminatory.
If you are an intermediary (banks, insurers, asset managers, brokers):
Authorised rating providers must disclose methodology, data sources and conflicts of interest. That makes providers easier to compare and easier to build into due diligence.
If you are a regulated financial institution and you disclose an ESG rating to a third party in your own marketing, you must link to the same underlying disclosures.
Unauthorised ratings will not be permitted to be distributed within the EU market, at risk of financial penalty.
ESMA keeps a public register of authorised providers. You will be able to check authorisation status directly.
If you are a corporate buyer of carbon credits:
For any corporate looking to mitigate reputational risk in their carbon-related disclosure obligations and sustainability claims, we believe the choice between a regulated rating provider, held to strict rules on transparency, governance, accountability and independence, and an unregulated one without that oversight, becomes simple.
Purchasing and offsetting decisions become easier to defend as ratings must be independent, transparent, and supervised by ESMA.
Buyers will get clearer standards for how a rating provider identifies and manages its own conflicts of interest.
Q3. Does this only apply to European rating providers and projects?
No. If any EU company accesses a provider’s ratings, the provider is in scope.
The regulation applies if a rating provider is “operating in the Union.” It doesn't depend on the host country of the provider, the project, or the buyer.
Both EU-based and non-EU providers are in scope if they publish ratings, or distribute them by subscription to EU-regulated financial firms, companies, or public bodies.
In practice: non-EU project developers and buyers can still be impacted by the regulation if the ratings they use reach EU companies.
Q4. What does this mean for ratings agency business models, conflicts and independence?
Both common payment models are explicitly allowed: user-pays, where investors buy ratings, and issuer-pays, where rated entities pay to be rated.
Every provider operating in the EU must now be authorised, or covered by equivalence, endorsement, or recognition if based outside the EU.
Provider fees must be fair, reasonable, transparent and non-discriminatory. ESMA can request evidence of pricing policy.
Providers must publish their methodologies, models and assumptions, and give more detail to users and rated entities on request.
Providers must meet requirements on conflicts of interest, perceived conflicts, and what makes a carbon rating structurally independent, or risk financial penalty.
Q5. What does this mean for rating providers who provide data for projects and methodologies they then rate?
The regulation lists activities a rating provider cannot combine in one legal entity. These include consulting, credit ratings, and statutory audit.
It requires that non-rating services do not create risks of conflicts of interest within rating activities. Where there are risks of conflicts of interest, rating providers shall refrain from offering such other services.
It also states that providers must manage “any business or other relationship” that could create a conflict of interest, and directs ESMA to take action “where there is a risk of conflict of interest” that is created “due to the ownership structure, controlling interests or activities” of an ESG rating provider.
A provider’s duty is not just to operate conflicting activities out of a separate legal entity, but to avoid conflicts at all levels.
Marking your own homework: a carbon market example
Some rating providers only rate. Others also sell design and dMRV data and services directly to project developers and Standards Bodies — and then rate the same projects using that data.
We believe the second model creates a structural conflict. A provider marking its own inputs has a financial incentive to see its own analytics validated by its own rating. An established rule in financial markets— one that stops an auditor auditing its own books — doesn't yet formally apply here. It should.
BeZero's position
We don't sell dMRV or design data and services to the projects we rate. We sit on one side of the table: we rate, we don't supply inputs to projects or methodologies. We believe every regulated rating provider should be held to the same standard, and that ESMA's forthcoming guidance should make this explicit rather than leave it open to interpretation.
Practical takeaway
Ask any rating provider whether it, or its wider group, also sells services to the projects it rates. If the answer is yes, ask how it manages that conflict — and whether “managing” it is even possible.
Q6. What does this mean for rating providers who provide consulting services?
The regulation bans an ESG rating provider from offering consulting services within the same legal entity.
Some restricted activities can sit in the same entity with safeguards — investment services and benchmarks, for example. This doesn’t apply for consulting or statutory audit.
In practice, a rating provider's consulting arm must be a genuinely separate legal entity. An internal wall inside the same company isn't enough.
Staff who issue ratings also can't personally provide consulting, credit rating, or audit services.
Practical questions for users of carbon ratings
If you are a user of carbon ratings in a business capacity, regardless of whether you are based in or operating in the EU, it is worth seeking clarity on the incoming regulation directly from the rating providers you are working with. Here are three questions to ask:
Three questions to ask your carbon rating provider
1. Does your organisation, or any part of your group, sell dMRV, data, design, or consulting services to the projects or Standards Bodies you rate?
2. Do you or any affiliate facilitate or intermediate the sale of the credits you rate?
3. Will you continue these activities, and if so what specific measures are you taking to ensure you are not required to cease them?
This guide reflects Regulation (EU) 2024/3005 as adopted, and BeZero's understanding as of August 2026. It will be updated as ESMA's supervisory guidance and technical standards develop.