Your ESG Rating Agencies Are Now Regulated: What the EU ESG Ratings Regulation Means for CSRD Reporters

For most of the last decade, ESG ratings worked like this. An agency consumed your public disclosures, applied a methodology you could not see, filled the gaps with estimates you were never shown, and published a score that influenced index inclusion, cost of capital and procurement decisions. If you disagreed, you could write a letter.
That arrangement ended on 2 July 2026.
Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities entered into force on 2 January 2025 and has applied since 2 July 2026. ESMA now authorises and supervises ESG rating providers directly, as part of its expanded supervisory mandate. Providers must publish their methodologies, must say which dimension of double materiality they are measuring, and must present E, S and G separately rather than collapsing them into one number.
Most commentary on the Regulation has been written for rating providers. This piece is written for the companies they rate.
What is actually in scope
The Regulation applies to ESG ratings issued by providers operating in the Union. Critically, a provider is treated as operating in the Union regardless of where it is established, when it distributes ratings under contractual arrangements to EU-regulated financial undertakings, or to undertakings required to publish annual financial statements, or to entities that have issued securities in the EU.
That is a wide net. It captures the large global raters that serve European asset managers, not just EU-domiciled boutiques.
There are carve-outs, and they matter when you are working out whether a particular score you have been assigned is covered. Ratings produced purely for internal use, and private ratings that are not intended for public disclosure or distribution, sit outside the regime. So do certain adjacent products that are not, on the Regulation's definition, ESG ratings at all. If a rater tells you a given output is out of scope, that may well be correct. Ask them to say which exemption they are relying on.
Third-country providers reach the EU market through one of three routes: equivalence, endorsement by an authorised EU provider, or recognition. Each has different conditions and different consequences if it lapses.
Where the authorisation pipeline actually stands
This is the part to be careful about, because a lot of coverage has flattened it.
Providers already operating in the Union at entry into force had to notify ESMA by 2 August 2026 if they intended to continue, and must apply for authorisation or recognition within four months of 2 July 2026. ESMA issued a public statement on 1 July 2026 addressing publication and distribution of ESG ratings by third parties in the window between 2 July 2026 and authorisation or recognition being granted.
In other words: there is a transitional window, and it is still open. Do not assume that every rater covering you is already authorised, and do not assume that a provider still operating is therefore non-compliant. Check the status of each one individually rather than reasoning from the application date.
The three obligations that give rated companies leverage
Methodology transparency. Providers must publicly disclose the methodologies, models and key rating assumptions they use, including the limitations of the analysis. For the first time, you can trace which of your disclosures a rater consumes, how it handles a gap, and what it does when you do not report something.
The double materiality declaration. Providers must explicitly disclose which dimension of double materiality a rating addresses: impact on society and the environment, financial risk to the company, or both.
This is the single most useful provision in the Regulation for a rated company, and it is underrated because it sounds technical. In practice, a very large share of rating disputes are category errors. The company answers an impact question with financial-risk data, or is penalised on impact grounds for something it manages as a risk, and neither side ever names the mismatch because the rating never declared which question it was asking. Once the dimension is on the record, the mismatch becomes arguable.
Separated E, S and G. Separate E, S and G ratings must be provided rather than a single aggregated ESG metric. A strong environmental profile can no longer be quietly netted against weak governance inside a composite, and vice versa.
This has second-order effects worth thinking about. Index methodologies, ESG-linked loan margin ratchets and procurement screens that were built on a single composite number now have to choose which component they mean. Some of those instruments will be repapered. If your sustainability-linked financing references an external ESG score, look at the definition clause.
There are also organisational, governance and conflict-of-interest requirements on providers, including restrictions designed to keep rating activity separate from other services. The precise scope of those separation rules is worth confirming with your own advisers before relying on it, but the direction is clear: the rater selling you advisory services while scoring you is a structure the Regulation is designed to constrain.
Why this matters more after the Omnibus, not less
Here is the connection most readers will not have made.
Roughly 90% of previously in-scope companies fell out of mandatory CSRD reporting after the Omnibus. The demand for corporate ESG data did not fall with them. SFDR-driven disclosure obligations on financial market participants are still there, and those participants still need company-level data to satisfy them.
When the corporate disclosure supply shrinks and the downstream demand does not, the gap gets filled with modelled data. Raters estimate. That has always been true, but it is now true at much larger scale, and it is now true for a large population of mid-sized companies that have never engaged with a rating agency because they assumed ratings were a listed-company problem.
If you dropped out of CSRD scope, you may currently be carrying a score built substantially from proxies and sector averages you have never seen. The methodology transparency obligation is what lets you find out.
This is also where the VSME voluntary standard becomes strategic rather than merely virtuous. A proportionate voluntary disclosure of a handful of datapoints can displace a rater's estimate with an actual figure. That is a much cheaper intervention than a full reporting programme, and it is targeted at exactly the places where estimates hurt you most.
What the Regulation does not fix
Be clear-eyed about this, because the marketing around the Regulation has overpromised.
It does not standardise methodologies. Two authorised providers can still rate the same company very differently, and both can be fully compliant.
It does not make ratings comparable. Comparability would require a common definition of what is being measured, which the Regulation deliberately does not impose.
It does not give companies a right to have a rating corrected. There is no appeal to ESMA over a score you think is wrong.
And it does not regulate the underlying ESG data vendors on the same terms as raters, even though a great deal of what ends up in a rating originates there.
The honest summary is that the Regulation makes rating divergence explicable rather than smaller. That is still a substantial improvement over a black box, but it is a different thing from convergence, and anyone telling you ratings are about to align is selling something.
A practical programme for Q4 2026
Inventory your raters. List every ESG rating provider that covers your company, and record whether the rating is solicited or unsolicited. Unsolicited coverage is common and often invisible to the company until a customer or lender cites it.
Check each provider's regulatory status. Authorised, recognised, endorsed, or still inside the transitional window. Do this per provider and record the date you checked, because the pipeline is moving.
Pull the newly published methodologies. For each provider, extract and file: which materiality dimension the rating addresses, which disclosures it consumes, how it treats non-disclosure, where it uses proxies or sector averages, and how often it refreshes.
Build a gap file. Every place a rater uses an estimate where you hold, or could publish, an actual figure. Rank by the size of the scoring impact, not by how easy the number is to produce.
Decide the closing route for each gap. Options are the sustainability statement itself, a VSME-based voluntary disclosure, or targeted supplementary disclosure outside the statement. They have different assurance and liability consequences, so this is a judgement rather than a default.
Flag conflicts. Where a provider's affiliate also sells you services, note it. The Regulation gives you a basis for asking how that is managed.
Move rater engagement onto your reporting calendar. The recurring failure mode is reacting to a score after publication, when the data window has closed. Engagement should happen when the rater is collecting, which is usually months before you hear anything.
The point
The Regulation did not make ESG ratings accurate. It made them accountable, in a narrow and specific sense: providers now have to say what they are measuring and how.
That only helps companies that read what the providers now publish. The methodologies are out there. Most rated companies have not opened them.
General information for reporting and investor relations teams, not legal or investment advice. The authorisation pipeline was mid-flight at the time of writing; verify the current regulatory status of any individual provider directly.
Related reading

Your Sustainability Statement and Your Packaging Are Now Legally Coupled: What EmpCo Means for CSRD Reporters
From 27 September 2026, EU consumer law reads your ESRS E1 data against your marketing claims. Here's what the EmpCo Directive bans, what it requires, and why your sustainability statement is now evidence.

ESAP European Single Access Point: What CSRD Reporters Need to Know Before 2028
ESAP goes live in July 2027. CSRD sustainability data follows in January 2028. Here's what the phased rollout means for your reporting process - and what to fix now.

CBAM's Definitive Period Has Started: What CSRD Reporters Need to Do Now
CBAM's financial obligations began 1 January 2026. If you import CBAM goods and report under CSRD, your embedded-emissions data pipeline should be feeding both - not running in parallel.