My bookmarksSign up free

Commission Implementing Regulation (EU) 2025/2358 CHAPTER III — CERTIFICATION REGISTRIES

Article 16 · 1 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Certification registries

Article 16

1.   Certification schemes shall ensure their certification registries fulfil the following requirements: (a) register and track the identity of certified operators and the relevant certificates of compliance; (b) prevent the registration of any activity that is registered under another carbon removal or soil emission reduction certification scheme; (c) prevent the issuance of certified units for a given activity and a given certification period where another certification scheme has issued certified units for the same activity and the same certification period and has not cancelled those certified units; (d) prevent certified units to be accounted by or on behalf of a beneficiary (retired) or definitively deleted from a registry without accounting (cancelled) once they have already been retired or cancelled; (e) require the identification of the beneficiary referred to in point (d) and the purpose for which the unit was retired or cancelled; (f) address erroneous or fraudulent issuance of certified units through remediation measures; (g) the remediation measures referred to in point (f) shall at least include the suspension of the operator’s account and, where relevant, the subsequent compensation for excess issuance of certified units. Such compensation shall take place through either the cancellation by the certification schemes of the corresponding number of issued certified units in the operator’s account, or through the replacement by the operator of an equivalent number of certified units, followed by their immediate cancellation. 2.   The IT security system underpinning the certification registries shall fulfil the following requirements: (a) be based on the principles of legality, transparency, proportionality and accountability; (b) be considered during the whole process of the life cycle development of the system; (c) ensure the appropriate levels of authenticity, availability, confidentiality, integrity, non-repudiation, protection of personal data and professional secrecy; (d) be based on a risk management process; (e) clearly define roles and responsibilities of the different users; (f) enumerate the security requirements and the system dependencies of any other IT system or IT service; (g) be summarised in an IT security plan and an IT security implementation plan; (h) have an IT security implementation plan defining the required projects and processes to reduce risks to an appropriate level and at a proportionate cost, and be compliant with a well-recognised IT security standard.

Back to Commission Implementing Regulation (EU) 2025/2358 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next