
Game Testing and Certification: What Your Licence Requires
GLI, BMM, eCOGRA, iTech Labs, Quinel, Trisigma -- who certifies what, which standards each regulator recognises, when re-testing is triggered, and how certification quietly sets your launch date.
- Certification splits into three jobs: game and RNG testing (is the maths fair and the randomness sound), system or platform certification (is the PAM, wallet and reporting layer sound), and information security auditing (usually mapped to ISO/IEC 27001).
- The recognised labs are a short list -- Gaming Laboratories International, BMM Testlabs, eCOGRA, iTech Labs, Quinel, Trisigma, Gaming Associates -- and which ones count depends entirely on your regulator, not on the lab's reputation.
- GLI-19 covers interactive gaming systems; GLI-33 covers event wagering. Both are technical standards, not licences, and regulators adopt, adapt or ignore them independently.
- The UK runs on approved test houses plus a major/minor change model, an annual games testing audit and live RTP monitoring. Malta runs on approved Audit Service Providers doing a systems audit at onboarding and compliance audits thereafter. Brazil requires certification by an SPA-recognised lab with annual revalidation.
- The schedule risk isn't the first certificate. It's re-testing: a "major change" to a certified system pulls you back into the lab, and platform vendors ship major changes on their release calendar, not yours.
Game Testing and Certification: The Line Item That Sets Your Launch Date
Ask a first-time operator what stands between them and go-live, and you'll hear about the licence, the platform contract and the payment accounts. Certification usually gets a shrug -- a box the vendor ticks somewhere in the background.
Then the licence application asks for a system test report from an approved lab, and the vendor's existing certificate turns out to cover a different jurisdiction, an older platform release, or a game set that doesn't match what you plan to launch. Now there's a queue, a scope document, a bill nobody budgeted, and a launch date sliding by weeks.
Certification isn't the hard part of building an operation. It's the part that's least visible until it's on the critical path. Here's how it actually works: who the labs are, which standards mean what, how the major regulators differ, and where the schedule risk hides.
The three things that get certified
Operators conflate these constantly, and vendors let them, because a certificate in the deck looks the same either way.
Game and RNG certification. Does the random number generator produce statistically sound output, and does each game's actual RTP match its declared maths under sustained simulation? This is usually the studio's obligation, not the operator's -- but if you're running proprietary or white-labelled content, it becomes yours.
System / platform certification. Does the platform handle player accounts, wallets, bet and transaction logging, bonus mechanics, session limits and reporting to the standard the regulator expects? This is the layer GLI-19 addresses, and it's the one that trips up operators who assumed "the platform is certified" without asking for which jurisdiction and which release.
Information security. Most regulators want an independent security audit, typically benchmarked to ISO/IEC 27001, covering the systems that touch player funds and data. The UK requires an annual security audit by an independent, suitably qualified auditor for applicable remote licensees.
A fourth item shows up increasingly: responsible gambling and player protection controls -- deposit limits, self-exclusion propagation, time-outs, reality checks. These are sometimes tested as part of the system certification, sometimes assessed separately in a compliance audit. If you're building these controls yourself rather than inheriting them, budget for the scrutiny. Our guide to responsible gambling tools covers what regulators expect from the functionality itself.
Who the labs are
| Lab | Founded / base | Best known for | Where it carries most weight |
|---|---|---|---|
| Gaming Laboratories International (GLI) | 1989, US | GLI standards series (GLI-11, GLI-19, GLI-33), device and system testing | North America, LatAm, broad international recognition |
| BMM Testlabs | 1981, US | Longest-running independent lab; land-based heritage plus online | North America, Asia-Pacific, Europe, LatAm |
| eCOGRA | 2003, UK | RNG and RTP audits, safe-and-fair certification, system testing | Europe, UK, and an SPA-recognised lab in Brazil |
| iTech Labs | 2004, Australia | RNG and game certification, widely used by studios | Australia, Europe, offshore jurisdictions |
| Quinel | Malta | System and game certification with a Malta focus | Malta and EU markets, recognised in Brazil |
| Trisigma | Netherlands | System audits and certification | EU markets, recognised in Brazil |
| Gaming Associates | Australia | RNG, game and system compliance | Australia, Asia-Pacific, several offshore regimes |
Two things to take from that table. First, the list is short -- this is a concentrated market, and lead times move together across the industry when a big regulatory deadline lands. Second, "accredited" is not a global property. A lab is accredited by a regulator, for a scope. eCOGRA being excellent tells you nothing about whether your target regulator will accept its report.
The GLI standards, decoded
Operators hear "GLI-19 certified" and read it as a general seal of quality. It's narrower and more useful than that.
- GLI-11 -- gaming devices. Land-based machine heritage; relevant if you're touching cabinets or server-based gaming.
- GLI-19 -- interactive gaming systems. Covers player account management, platform security, operational controls, game integration and the core online technology stack. This is the online operator's standard.
- GLI-33 -- event wagering systems. The sportsbook equivalent: bet placement, settlement, trading controls and risk management on the wagering side.
A recent example of how these get used in practice: in July 2026, platform supplier Bede Gaming announced GLI-19 and GLI-33 certification, with the testing performed by eCOGRA -- one lab, certifying against another organisation's published standards. That combination confuses people, but it's normal. GLI publishes standards; multiple accredited labs test against them.
What certification does not do: it doesn't make you licensed, it doesn't cover changes made after the test, and it doesn't transfer between jurisdictions automatically. A GLI-19 certificate issued for one market's requirements may need supplementary testing for another's.
How the major regulators differ
United Kingdom
The Gambling Commission runs a testing strategy built on its Remote gambling and software technical standards (RTS). The mechanics that matter operationally:
- New products must be tested by an approved test house before release, with the test report supplied to the Commission. The Commission publishes the list of approved houses.
- Changes are classified as major (external re-testing required) or minor (internal processes suffice). Getting that classification wrong is itself a compliance failure.
- An annual games testing audit by an approved test house checks that you're classifying and handling changes correctly.
- Live RTP monitoring applies -- the declared return has to hold up in production, not just in simulation.
- Security standards map to ISO 27001, with an annual audit by an independent qualified auditor.
That major/minor model is the single most underestimated piece of the UK regime. It turns certification from a one-off project into a standing process. Anyone operating in Britain should read it alongside the wider UKGC regulatory picture.
Malta
The MGA works through approved Audit Service Providers rather than a test-house list. A systems audit is carried out as part of licensee onboarding or whenever the Authority deems it necessary; compliance audits run through the licensed period. Licensees choose any approved ASP; the MGA reviews audit reports through a quality assurance team and can suspend or remove providers whose work doesn't hold up.
The practical difference from the UK: Malta's model is auditor-centric and relationship-based, the UK's is standard-centric and test-report-based. Neither is lighter. Malta's framework has been under strain for other reasons -- see our coverage of the Bill 55 dispute -- but the audit machinery itself is well-established.
Brazil
The newest major regime and the most schedule-sensitive. The SPA recognises a defined list of certifying entities -- Gaming Laboratories International LLC, Trisigma BV, Quinel Limited, eCOGRA Limited and BMM North America Inc among them -- and requires platforms and games to be certified against technical standards for randomness, fairness and security. Certification reports must be revalidated annually and whenever critical components change.
Two Brazil-specific realities worth planning around. First, lab capacity became a genuine bottleneck as the market opened; the regulator has previously issued ordinances to work around certification delays. Second, the annual revalidation means Brazil is not a one-and-done market -- it's a recurring line item. Our Brazil SPA licensing guide covers the surrounding requirements.
Offshore jurisdictions
Curaçao's post-reform regime under the CGA, along with Anjouan and Nevis, each set their own expectations, and they've been moving. The pattern across the offshore tier is convergence upward: RNG certification and some form of system attestation are increasingly requested where they once weren't. If you're comparing regimes, our offshore licensing comparison sets out the trade-offs; treat any "no certification required" claim in a broker's pitch as a statement about last year.
What certification costs and how long it takes
Anyone quoting you a single number is guessing, and iGamingHub won't publish a price it can't source. What can be said structurally:
- Cost scales with scope, not with your size. The same platform certification costs roughly the same for a startup and a mid-tier operator, which makes it regressive for new entrants.
- Multi-jurisdiction is where budgets break. Each regulator's recognised-lab list, standard set and report format differs, so the second market rarely costs half the first.
- Annual recurrence is the part people forget. UK annual games testing audit, UK annual security audit, Brazil annual revalidation, MGA compliance audits -- certification is an operating expense, not a launch cost.
- Lead time is the real currency. Lab capacity is finite and clusters around regulatory deadlines. Booking a slot months ahead costs nothing; needing one in three weeks costs everything.
Get written quotes with scope, timeline and re-test policy from at least two recognised labs before you commit to a launch date. Then add contingency, because the timeline you're quoted assumes your documentation arrives complete.
Getting certification off the critical path: a sequence
- Confirm the regulator's recognised-lab list first -- before choosing a lab, before signing a platform contract. The list is the constraint; everything else adapts to it.
- Get your platform vendor's certificate scope in writing -- which jurisdiction, which standard, which platform release, which date. "We're certified" is not an answer; a PDF with a scope statement is.
- Map your game portfolio against existing certifications -- studio content usually arrives pre-certified for common jurisdictions, but not all of it, and not everywhere. The gaps are yours to close.
- Agree the major/minor change protocol with your vendor -- who classifies a change, who pays for re-testing, and what notice you get before a release that resets your certification status.
- Book lab capacity before you need it -- a provisional slot is cheap insurance against a deadline that everyone in the market hits at once.
- Schedule the recurring items into the compliance calendar -- annual audits, revalidations and RTP monitoring reviews belong in the same calendar as licence renewals, owned by a named person.
That fifth point deserves emphasis. Certification is the classic dependency that looks like someone else's job until the week it becomes yours. Our go-live checklist puts it in sequence with the other launch dependencies.
The vendor angle: certification as a product
One genuinely useful development is that certification support has become a service line rather than an afterthought.
Comtrade Gaming sells game testing as a named service alongside its platform and remote game server products, which reflects its long history in land-based systems where certification discipline is older and stricter. GammaStack markets compliance readiness across a wide list of regulated markets, which is the sort of claim to verify certificate by certificate rather than accept from a coverage map. Larger platform suppliers like Playtech and SOFTSWISS maintain certification portfolios across many jurisdictions, and that portfolio is a real part of what you're buying -- often a bigger part of the value than the feature list.
The question to put to any platform vendor: when you ship a major release, what happens to my certification status, who pays for re-testing, and how much notice do I get? Answers vary more than you'd expect, and the answer tells you whether the vendor treats regulated markets as a core business or an export.