The Corporate Sustainability Reporting Directive (CSRD) is the most significant expansion of corporate reporting in EU history. It replaces the Non-Financial Reporting Directive (NFRD) and pulls roughly 50,000 companies into mandatory, audited sustainability disclosure — up from about 11,700 under the old regime.
For finance leaders, sustainability managers, and SME owners inside supply chains, CSRD is no longer a 2027 problem. Value-chain data requests, lender questionnaires, and procurement scorecards are already driving demand today. This guide breaks down what CSRD requires, who is in scope, and how to build a reporting foundation that scales.
We'll cover the phased timeline, the twelve standards, the double , digital tagging (ESEF/XBRL), assurance requirements, and the practical software and data workflows companies use to comply without derailing operations.
Who has to report under CSRD?
CSRD applies in waves. Large public-interest entities with over 500 employees that already reported under NFRD were first — for financial year 2024, published in 2025. Other large EU companies meeting two of three thresholds (>250 employees, >€50m turnover, >€25m balance sheet) follow for FY2025 published in 2026.
Listed SMEs, small credit institutions, and captive insurance undertakings begin FY2026 (with a possible two-year opt-out through 2028). Finally, non-EU parent companies with significant EU turnover (>€150m) and at least one qualifying EU subsidiary or branch fall in scope from FY2028.
Even if you're a private SME not directly in scope, expect indirect exposure: your customers, banks, and investors will ask for –3 emissions, energy mix, and social data to complete their own CSRD reports. The Voluntary SME () standard was created exactly for this cascade.
The twelve ESRS standards, at a glance
CSRD is operationalized through the (), developed by EFRAG and adopted by the European Commission. There are two cross-cutting standards (ESRS 1 general requirements, ESRS 2 general disclosures) and ten topical standards covering environment, social, and governance domains.
Environmental: E1 Climate change, E2 Pollution, E3 Water & marine resources, E4 & ecosystems, E5 Resource use & . Social: S1 Own workforce, S2 Workers in value chain, S3 Affected communities, S4 Consumers & end-users. Governance: G1 Business conduct.
You don't automatically report on all twelve — only the topics your double identifies as material. E1 (climate) has effectively become mandatory in practice because climate is material for almost every business.
Interactive tool
02 / 03
CSRD & VSME applicability checker
Answer four questions to see which sustainability reporting regime applies to your company and when it kicks in.
Result
In scope
VSME (voluntary standard for SMEs)
Not in scope of CSRD, but VSME is the recommended framework for value-chain requests.
Applicability is our best estimate based on published EU thresholds; consult your auditor for a formal determination.
Double materiality: the hardest part
CSRD introduces : you must assess both how sustainability issues affect your company (financial materiality) and how your company affects people and the environment (impact materiality). A topic is reportable if it is material from either lens.
In practice this means a structured process: identify impacts, risks, and opportunities (IROs) across your value chain, engage internal and external stakeholders, score severity and likelihood, set thresholds, and document the outcome. Assurance providers will test your methodology, not just the result — so the audit trail matters as much as the conclusion.
Digital tagging, assurance, and the reporting file
CSRD disclosures are published inside the management report and must be digitally tagged using the ESEF/XBRL taxonomy. Reports are subject to limited assurance from the first reporting year, moving toward reasonable assurance over time (a step-up aligned with financial audit standards).
Practically, this pushes companies to move away from Word-document reporting and toward structured data platforms where every disclosure point is versioned, linked to source evidence, and machine-readable. This is where sustainability software earns its keep.
A pragmatic 6-step readiness plan
1. Confirm your in-scope year and consolidated reporting boundary. 2. Run a double and document the methodology. 3. Perform a gap analysis against the material datapoints. 4. Build a inventory covering Scope 1, 2, and material Scope 3 categories using the GHG Protocol. 5. Stand up a data collection and evidence platform that maps to ESRS datapoints and supports XBRL tagging. 6. Engage an assurance provider early — waiting until Q1 of the reporting year is the most common (and costly) mistake.
SMEs supplying larger reporters should adopt the : it maps neatly onto while staying proportionate to smaller businesses, and it satisfies most customer/lender data requests in a single format.
FAQ
Frequently asked questions
When does CSRD apply to my company?
Wave 1 (former NFRD reporters) reports on FY2024. Wave 2 (other large EU companies) reports on FY2025. Wave 3 (listed SMEs and small credit institutions) reports on FY2026 with a two-year opt-out to 2028. Wave 4 (non-EU parents with >€150m EU turnover) reports on FY2028.
Do I need to report on all twelve ESRS?
No. You only report on the topical ESRS your double materiality assessment identifies as material. The two cross-cutting standards (ESRS 1 and 2) are always applicable. In practice, ESRS E1 (climate) is material for nearly every company.
What is double materiality in simple terms?
You assess both how sustainability issues affect your business (financial materiality — risks and opportunities) and how your business affects people and the planet (impact materiality). If either lens flags a topic as material, you must report on it.
Is CSRD reporting audited?
Yes. From year one, disclosures require limited assurance from a qualified auditor. The EU intends to move to reasonable assurance (the same level as financial audits) once methodology and taxonomy mature.
What about SMEs that are not directly in scope?
You'll still receive data requests from large customers, banks, and investors who must fill in their own CSRD reports. The Voluntary SME (VSME) standard was designed for this — it is proportionate, aligned to ESRS, and satisfies most upstream data requests in one format.
Get audit-ready without the spreadsheet chaos
Vuneli maps your data directly to ESRS datapoints, runs your double materiality assessment, and produces XBRL-tagged disclosures your auditor can actually sign off on. Purpose-built for EU SMEs and mid-caps.




