Compliance · Certification

iGaming Compliance & Certification

A gambling licence gets you legal standing. Certification — ISO 27001, GLI, RNG — is what aggregators, tier-1 procurement and banks actually ask for next. We run that process; accredited bodies and labs issue.

3-yr
ISO 27001 cycle with annual surveillance audits
2
GLI standards that matter online: GLI-19 (gaming) & GLI-33 (wagering)
4
recognised test labs: GLI · BMM · iTech Labs · eCOGRA
Not sure what your counterparties will ask for? Tell us who you need to onboard with — we'll map the exact certificates and evidence they'll request, free.
Scoping call →

overview

What you actually need.

Certification is the layer after licensing that unlocks commercial deals. Aggregators and platform providers gate integrations on it, tier-1 operators' procurement commonly expects ISO/IEC 27001 from suppliers, and some regulators bake it in: Greece requires accredited ISO 27001 certification, and Denmark waives part of its security-audit requirements for holders. Without the right certificates, a licensed studio or operator still can't close the deals the licence was meant to enable.

The stack splits into two families. Management-system certification — ISO/IEC 27001 for information security, with add-ons for cloud (27017/27018), privacy (27701), business continuity (22301) and anti-bribery (37001) — issued by accredited certification bodies on a three-year cycle with annual surveillance. And technical/game certification — GLI-19 for interactive gaming systems, GLI-33 for event wagering, RNG fairness certification and eCOGRA seals — issued by independent test labs (GLI, BMM, iTech Labs, eCOGRA).

Our role is the honest one: we are not a certification body and not a lab — certificates are issued only by accredited bodies and independent test labs. What we do is run the whole process so it doesn't consume your team: gap analysis, the ISMS and documentation build, evidence preparation, selecting and engaging the right body or lab, and managing the audit dialogue to issuance — then keeping the certificate alive through surveillance and delta testing.

Certification sellsIt's not compliance overhead — it's what unlocks aggregator integrations, tier-1 procurement and better banking terms.
Issued by accredited bodiesOnly accredited certification bodies and independent labs issue — anyone claiming otherwise is a red flag. We coordinate them.
Operators and studios bothStudios certify to sell; operators certify to pass procurement and regulator gates (Greece requires it; Denmark rewards it).

your options

The routes that work.

01ISO/IEC 27001 (+ add-ons)

The information-security backbone counterparties ask for first. Add-ons where your market needs them: cloud (27017/27018), privacy/GDPR (27701), continuity (22301), anti-bribery (37001).

02GLI-19 / GLI-33 + RNG

Technical certification for gaming systems (GLI-19) and sportsbook/event wagering (GLI-33), plus RNG fairness testing through GLI, BMM, iTech Labs or eCOGRA.

03eCOGRA seals & RTP

Independent fairness and player-protection seals operators use as a trust badge — and some markets recognise formally.

head to head

The certification stack at a glance

StandardWhat it provesWho asks for itCycle
ISO/IEC 27001Information-security managementTier-1 procurement · Greece (required) · banks3 years + annual surveillance
GLI-19Interactive gaming system integrityRegulators · aggregators · operatorsPer version — delta testing on changes
GLI-33Event-wagering system integritySportsbook counterparties & regulatorsPer version — delta testing on changes
RNG certificationFairness of randomnessEvery serious counterpartyPer engine/version
eCOGRA sealFairness & RTP, player protectionOperators as a trust badge; some marketsOngoing with periodic review
ISO add-ons (27017/18/27701/22301/37001)Cloud · privacy · continuity · anti-briberyEU-facing and enterprise dealsFollows the 27001 cycle

requirements

Eligibility & docs.

Gap analysis against the target standard — the document everything else prices from
Scope statement: systems, sites and products in scope
Risk assessment and treatment plan (ISO route)
Lab/body shortlist matched to your markets
ISMS documentation and controls build (we draft, your team owns)
Engineering evidence for GLI/RNG: source access, test environments
Policy rollout and internal audit before anyone external looks
Remediation of gap-analysis findings, tracked to closure
Accredited body / lab engagement and audit scheduling
Stage 1 & Stage 2 audit management (ISO) or lab test cycle (GLI/RNG)
Findings handling to issuance
Surveillance audits, delta testing and renewals — we stay on
Check my eligibility →

step by step

From product to licence.

  1. DiscoveryYour products, markets and counterparty requirements — we map which certificates actually unlock revenue and which can wait.Day 1
  2. Gap analysisFixed-fee assessment against the target standards — out of it comes the exact scope, sequence and cost, before you commit to anything.Week 1–2
  3. Build & prepareISMS, documentation, controls, engineering evidence — we drive the build, your team stays on product.Weeks–months by scope
  4. Audit & issueThe accredited body or lab audits; we manage the dialogue and findings to issuance.Body/lab-dependent
  5. MaintainAnnual surveillance, delta testing on releases, renewals — the certificate stays alive without consuming your roadmap.Ongoing

Want the shortlist for your exact product?

Tell us your product, target markets and payment mix — we'll confirm the route that gets you live fastest at the lowest all-in cost, with the number itemised.

Get my quote →

costs

What it costs.

Regulator fee schedules
Gap analysisfixed fee, scoped on the call
Certification body fees (ISO)quoted by the accredited body
Lab testing (GLI / RNG / eCOGRA)lab-quoted per scope
Our management feefixed-scope after gap analysis

We don't quote a flat certification price because honest ones don't exist — body and lab fees depend on your scope. After the gap analysis you get a fixed-scope estimate: exact cost, exact sequence, before committing. Certificates are issued only by accredited certification bodies and independent test labs.

go deeper

Jurisdictions & related services.

FAQ

How much does iGaming certification cost?

Body and lab fees depend entirely on scope — which is why we don't publish a flat figure. The process starts with a fixed-fee gap analysis; out of it you get a fixed-scope estimate covering our management, the body's audit fees and lab testing, before you commit.

Do you issue the certificates?

No — and nobody consulting you should claim to. Certificates are issued only by accredited certification bodies (ISO) and independent test labs (GLI, BMM, iTech Labs, eCOGRA). We manage the entire process to issuance and through maintenance.

Do operators need ISO 27001, or only studios?

Both, increasingly. Tier-1 operators' procurement commonly expects it from suppliers; on the operator side, Greece requires accredited ISO 27001 and Denmark waives part of its security-audit requirements for holders. It's also a banking-diligence asset.

What's the difference between GLI-19 and GLI-33?

GLI-19 covers interactive gaming systems — the RGS/online-casino stack. GLI-33 covers event-wagering systems — the sportsbook side. Suppliers running both product lines typically need both.

How long does a certificate stay valid?

ISO 27001 runs a three-year cycle with annual surveillance audits. GLI and RNG certification is per system version — releases trigger delta testing rather than a full re-test. We manage both calendars so nothing lapses.

other products

Licensing a different product?

Reviewed by the Vantegris licensing team. This page is general information, not legal advice. Fee schedules and timelines mirror our jurisdiction pages and change when regulators change them.

Proven track record
300+ operators licensed across 40+ jurisdictions.

From crypto casinos to B2B platform providers, operators trust Vantegris to move fast without cutting compliance corners.

Itemised feesRegulator schedule shown separately from our service fee.
We stay after issuanceRenewals, reporting and banking, handled long-term.
NDA on requestConfidential from the first message.

Free consultation

Start your licence file.

Tell us the product — we'll map the licence, banking and structure that gets it live. Free, confidential, no obligation — most enquiries get a reply within 24 hours.

Book a free consult Book a call