III.2.7.
Do we need to have a valid ISO 27001 certificate if we want to register as a third party RRM?
Answer: There is no requirement to acquire a valid ISO 27001 certificate. Nevertheless, nothing prevents RRMs from doing so. It can be proven useful when demonstrating compliance to the technical and organisational requirements.
Please note that, by 8 May 2025, the European Commission is expected to adopt a delegated act further detailing the authorisation and supervision of RRMs. A new authorisation process is foreseen which will replace the current registration process.
Updated:
12/03/2025