Most of the coverage of the European Commission’s 3 July package led with the same number: a 60% cut in mandatory ESRS datapoints. That is the headline, and it is real. But buried in the second delegated act is a change that will reshape more programmes than the datapoint cut ever will — and almost nobody is briefing their procurement team on it.
It is called the value-chain cap. In short: from financial year 2027, a CSRD-scope company will no longer be able to require its smaller suppliers to hand over sustainability data beyond a defined ceiling. If your supplier-engagement programme is built on a 200-question ESG questionnaire pushed down the chain, that programme now has a legal boundary running through the middle of it.
What the Commission adopted on 3 July 2026
The Commission adopted two delegated acts. The first is the revised set of European Sustainability Reporting Standards — the concrete landing of the Omnibus I simplification agenda. It cuts mandatory datapoints by over 60%, total datapoints by over 70%, and is expected to reduce reporting costs by more than 30% per company.
The second is the one to read carefully: a Voluntary Sustainability Reporting Standard, built on the VSME, giving companies outside CSRD scope a single proportionate framework to report against. It is voluntary in the sense that no smaller company is obliged to use it. It is emphatically not voluntary in its effect on the companies above them in the chain — because it sets the ceiling.
Both acts are now in a two-month scrutiny period before the European Parliament and Council, extendable by a further two months. If neither institution objects, they are published in the Official Journal and enter into force. That caveat matters, and we return to it at the end.
The value-chain cap, precisely
The cap protects companies with 1,000 employees or fewer that sit in the value chain of a CSRD reporter. Under the Omnibus I Directive, those companies are entitled to decline requests for sustainability information that go beyond what the Voluntary Standard covers. Micro-enterprises of ten employees or fewer get further relief on top. For CSRD-scope companies, the cap bites from financial year 2027.
Read plainly, that inverts a decade of supplier-engagement practice. The implicit deal until now was that a large buyer could ask its suppliers for whatever its own reporting obligations demanded, and commercial leverage did the rest. From FY2027, the supplier has a statutory answer: no, and here is the standard that says so.
Three things the cap does not do
This is where the early commentary is getting it wrong, so it is worth being exact.
- It caps what you can require, not what you can ask. The Commission has confirmed that a CSRD reporter may still request information beyond the cap — provided it clearly identifies which parts of the request exceed the cap and informs the supplier of their right to refuse. The cap creates a duty of transparency in the ask, not a prohibition on asking.
- It applies only to CSRD reporting. The cap operates when fulfilling CSRD reporting obligations. It does not govern information you request for other purposes — commercial qualification, contractual assurance, product compliance, or your own risk management.
- It does not stop a supplier volunteering more. Plenty of smaller suppliers will keep sharing data, because being easy to buy from is a competitive advantage. The cap removes the obligation, not the incentive.
Together those three points reframe the cap. It is not a wall. It is a consent boundary — and crossing it now requires you to say out loud that you are crossing it.
Where the cap collides with CSDDD
Here is the tension nobody has resolved. The Corporate Sustainability Due Diligence Directive still requires in-scope companies to conduct risk-based human rights and environmental due diligence across their chain of activities — an approach Omnibus I preserved rather than narrowing to tier one. You cannot discharge a risk-based due-diligence obligation without information from the chain. Yet the ESRS package has just capped what you may require from a large part of that same chain.
The reconciliation is in the scoping: the cap is tied to CSRD reporting obligations, and CSDDD due diligence is a separate legal duty. In principle, a due-diligence request is not a CSRD reporting request, and the cap does not extinguish it.
In practice, that distinction is going to be tested hard — because it is usually the same supplier, receiving the same questionnaire, from the same buyer, in a single email. If your data requests do not distinguish their legal basis, you invite a supplier to refuse the whole thing on cap grounds, including the parts you are entitled to insist on. The operational bar for all of this is still being written: the Commission’s consultation on CSDDD implementation guidelines closes on 24 July 2026, with the guidelines expected in principle by July 2027. If your supplier programme is material to your business, that consultation is a genuine, closing opportunity to shape it.
What to do in the next 90 days
FY2027 sounds distant. It is not — supplier programmes have long lead times, and the contracts you sign this year will still be running when the cap bites.
- Re-baseline your supplier questionnaire against the Voluntary Standard. Every question you currently push down the chain now sorts into one of two buckets: inside the cap, or outside it. You cannot manage the boundary until you can see it.
- Get headcount into your supplier master data. The 1,000-employee line is now a legal boundary, and most procurement systems do not hold supplier headcount at all. This is the least glamorous item on the list and probably the one with the longest lead time.
- Redesign the ask, not just the question set. Beyond-cap requests need to be explicitly flagged as such, with the right to refuse stated. Build that into the template now rather than retrofitting it under deadline.
- Separate your legal bases. Split CSRD-reporting requests from due-diligence and commercial requests, and label them. This is the single change that most protects your CSDDD position.
- Plan for refusal. Assume a meaningful share of smaller suppliers will exercise the cap. That means leaning harder on estimation, sector averages and spend-based proxies for value-chain data — and being able to document why an estimate was used and how it was derived.
Prepare — but do not decommission
One final discipline. Both delegated acts are still in scrutiny, and the revised ESRS are set to apply to financial years beginning on or after 1 January 2027, with early application permitted. Nothing is in the Official Journal yet.
So the correct posture is prepare, don’t freeze — and above all, don’t switch anything off. The most expensive mistake available right now is to read “60% fewer datapoints” as permission to dismantle data pipelines that a scrutiny objection, an early-adoption decision, or an investor’s own SFDR-driven data request could make you rebuild in eighteen months. Simplification is not the same as less work. A 70% datapoint cut creates a migration project before it creates a saving.
The companies that will handle this well are the ones that can see, in one place, which datapoints they collect, which regime each one serves, and where in the value chain it came from. That is a data-architecture question long before it is a compliance one — and it is exactly what our CSRD readiness checklist is built to help you work through. If you would like to see how Horizon ESG maps a single data foundation across CSRD, CSDDD and the voluntary standard, book a short demo — we will walk your own supplier data through it.

Leave a Reply