Tag: Value Chain

  • The Value Chain Cap Is Now Law: What Customers Can Require

    The Value Chain Cap Is Now Law: What Customers Can Require

    Sustainability manager reviewing a customer ESG data request against a single evidenced dataset

    For most of this year, the value chain cap was something you could mention to a customer but not cite. It had been agreed, then adopted, then it sat waiting for publication. That wait ended on 21 September 2026, when the Voluntary Standard appeared in the Official Journal of the EU as Commission Delegated Regulation (EU) 2026/1560. It entered into force on 24 September.

    If you run sustainability at a company with 1,000 employees or fewer, and your week goes on customer questionnaires, this is the most useful regulatory change of the year for you. There is now a published legal text setting out what a CSRD-reporting customer can require from you, and a free official format for answering it. This post covers what the regulation says, where its limits are, and how to use it in the next request that lands.


    What was published, and what it is called

    The regulation is the Voluntary Standard (based on VSME), the European Commission’s reporting standard for companies outside mandatory CSRD scope. It builds on EFRAG’s earlier VSME standard for smaller companies, which is why you will see the two names used interchangeably. Expect procurement portals to start quoting the legal name and the regulation number.

    The standard does two jobs at once:

    • It is a reporting framework you can use now. Any undertaking outside mandatory CSRD scope can report against it from 24 September 2026. It gives you a recognised structure for energy, emissions, workforce, policies and governance.
    • It is the reference point for the value chain cap. The Omnibus I Directive, in force since 18 March 2026, limits what CSRD reporters can demand from smaller partners by reference to this standard. Until the standard was law, that limit pointed at a document still in draft. Now it points at a fixed text.

    EFRAG has said it will release an updated digital template in November 2026, including improvements to its Excel to Inline XBRL converter. If your customers ask for machine-readable data, that is the format to watch.


    What your customer can now require

    The cap is narrow and precise, which is what makes it usable. As summarised by Linklaters from the published text, it works like this:

    • Who it protects: value chain undertakings with an average of 1,000 employees or fewer in the preceding financial year.
    • Who it restricts: companies in CSRD scope, meaning more than 1,000 employees and more than EUR 450m net turnover since the Omnibus, roughly 5,000 companies across the EU.
    • What it restricts: requiring information beyond what the Voluntary Standard covers.
    • What purpose it covers: only information gathered for the requester’s own CSRD reporting.
    • When it bites: from financial years beginning on or after 1 January 2027.

    That last date matters for timing. The standard is available to you today, while the cap applies to your customers’ FY2027 reporting cycle. Requests arriving this autumn for FY2026 data are outside it, though pointing to the regulation now still sets expectations for next year.

    The difference between “require” and “ask”

    The cap stops a CSRD reporter from requiring more. It does nothing to stop them asking. A customer can still send you a 200-question portal. What changes is the status of the questions beyond the standard: you are entitled to decline them for CSRD purposes.

    We covered the buyer’s side of this in what the value chain cap lets companies still ask suppliers, written before publication. The substance has held; what has changed is that you can now cite it.


    What the cap does not cover

    This is where suppliers get caught out. The cap is tied to one purpose, and most of your inbox serves other purposes.

    • Requests required by other laws. The cap does not restrict requests a customer needs to comply with other EU or national obligations. A CBAM importer asking for embedded emissions in the goods you ship them is working under a separate regulation, and the cap does not reach that request.
    • Bank and insurer requests for their own processes. A lender’s credit review or an insurer’s renewal questionnaire is usually about their risk assessment. Those requests sit outside a cap built around a customer’s CSRD statement.
    • Voluntary target programmes. If a customer’s SBTi supplier engagement target means they want your emissions and your reduction plan, that request is driven by their climate target. Our post on SBTi Net-Zero Standard V2 explains why those asks are about to get more demanding.
    • Anything you choose to volunteer. The cap is a right to decline. Using it is always your commercial call.

    How to use it in the next request

    1. Check your headcount on the right basis

    The test is average employees over the preceding financial year. If you sit close to 1,000, confirm the figure with HR and keep the working. A customer’s compliance team may ask for it.

    2. Build your dataset on the Voluntary Standard

    Maintain one dataset structured on the standard, with the evidence attached to each datapoint: the meter reading, the invoice, the policy document, the payroll extract. That is the dataset you can be required to provide, so it should be complete, current and ready to send the same day. Everything else becomes a mapping exercise from it.

    3. Ask what each request is for

    Log every incoming request with its sender and purpose. When the purpose is the customer’s CSRD reporting, the cap applies. When it is a tender, a loan, a CBAM declaration or a climate target, it does not, and you decide on commercial grounds. Asking the question politely often shrinks the request on its own.

    4. Invoke it with a helpful tone

    Something like:

    “We average fewer than 1,000 employees, so for your CSRD reporting our disclosures follow the Voluntary Standard under Delegated Regulation (EU) 2026/1560. Our complete dataset on that basis is attached and answers most of your questionnaire. For the remaining items, could you let us know which you need for purposes other than CSRD reporting? We are happy to look at those.”

    You have answered quickly, answered most of it, cited the law accurately and handed the question of the extra items back to the requester. Our guide to answering customer and lender ESG data requests covers what to do when a customer pushes past the cap anyway.

    5. Put 1 January 2027 in the diary

    Review your standard response in December so it is ready when customers start collecting FY2027 data. If EFRAG’s November template changes the file format your customers expect, that is the moment to switch.


    One dataset, answered once

    The cap rewards the supplier who has a Voluntary Standard dataset ready to send, and it does little for the one who has to assemble answers from spreadsheets each time. Horizon ESG for sustainability teams is built around exactly that: one evidenced dataset, mapped to the standard and to the questionnaire formats you actually receive. Nova, the built-in assistant, drafts answers from that dataset with each figure linked to its source, and nothing is sent until you approve it.

    The same numbers will eventually meet your finance team’s figures, and they need to match. If your CFO is asking how sustainability data is controlled, our page for finance teams covers that side.

    If questionnaires are eating your week, book a short demo and bring the longest one you have. We will show you how much of it one dataset answers.

    Sources: Commission Delegated Regulation (EU) 2026/1560, published in the Official Journal on 21 September 2026; Linklaters, “EU CSRD: revised ESRS and voluntary reporting standard are published in the Official Journal”, 21 September 2026; XBRL International, 27 September 2026. Checked 29 September 2026.

  • How to Answer Customer and Lender ESG Data Requests

    How to Answer Customer and Lender ESG Data Requests

    One ESG dataset mapped to multiple reporting frameworks and questionnaire formats in Horizon ESG

    Somewhere in your inbox right now there is an ESG questionnaire you have not opened yet. It might be from a customer’s procurement portal, from your bank’s annual credit review, or from an insurer’s renewal pack. Each one uses a different format, asks slightly different versions of the same questions, and lands with a deadline that has nothing to do with any regulation.

    If that describes your week, this piece is for you. It covers why the requests keep multiplying even though the EU just cut its reporting rules back, the legal ceiling on what your customers can now require of you, and how to stop answering every request from scratch.


    Why the requests keep coming when the regulation went away

    On 18 March 2026 the Omnibus I Directive came into force and CSRD shrank dramatically. The threshold is now more than 1,000 employees and more than EUR 450m net turnover, both tests together, which cut the reporting population from roughly 50,000 companies to roughly 5,000 across the EU.

    If your company fell out of scope, you might reasonably have expected the questionnaires to slow down. They have not, and the reason is structural. The 5,000 companies still in scope are the largest buyers, banks and insurers in Europe, and their obligations cover their value chains: your emissions, your energy mix, your workforce data, your policies. Banks need supplier and borrower data for financed emissions. Insurers ask at renewal. Procurement teams have embedded ESG scoring in tender processes that are not going to be unwound because a directive changed.

    The obligation did not disappear. It moved, from the regulator to your customers. And that changes the nature of your deadline: it is a tender date, a contract renewal, a credit review. Nobody in Brussels set it, and nobody in Brussels will extend it.


    The value chain cap: the ceiling on what they can require

    Here is the part most suppliers still have not heard. The same Omnibus package that shrank CSRD also gave you a statutory ceiling. If your company has fewer than 1,000 employees, a CSRD-scope customer cannot require you to provide sustainability information beyond what the voluntary VSME standard covers. The European Commission adopted the VSME-based voluntary standard on 3 July 2026, and for CSRD reporters the cap bites from financial year 2027.

    We unpacked the legal mechanics in our earlier piece on what the value chain cap lets buyers still ask suppliers, written for the company sending the questionnaire. This post is the other side of the conversation: what to do when you are the one receiving it.

    Three things to hold onto. First, the cap limits what a customer can require for their CSRD reporting; it does not stop them asking for more, but they must identify which parts of a request go beyond the cap and tell you that you are entitled to refuse those parts. Second, the cap does not stop you volunteering more if it is commercially worth it. Third, the cap is only useful to you if you actually have a VSME dataset to point at, which is the real work.

    How to invoke it without souring the relationship

    The cap is a boundary, not a weapon, and the tone that works is helpful-with-a-ceiling. Something like:

    “We have fewer than 1,000 employees, so under the Omnibus I value chain cap we maintain our sustainability data against the VSME standard. Our full VSME dataset is attached and covers most of your questionnaire. Could you confirm which of the remaining items you need for purposes other than CSRD reporting, and we will see what we can do?”

    You have answered fast, answered most of it, stated the legal position without threatening anyone, and moved the burden of justifying the excess back to the requester. That is a very different conversation from either silence or a flat refusal.


    One dataset, many formats

    The deeper fix is to stop treating each questionnaire as a document to be written and start treating it as a view of a dataset you already maintain.

    The VSME standard is the natural spine for that dataset, because it is now the reference point for what you can be required to provide. Build it once: energy and emissions, workforce basics, policies, certifications, incidents. Attach the evidence to each datapoint, not to a folder, so that every answer you send out carries its source with it. Then each new request, whatever the format, becomes a mapping exercise rather than a writing exercise.

    The consistency matters as much as the speed. When five people answer five portals from memory and spreadsheets, the same question eventually gets five slightly different answers, and one of them ends up contradicting the number your company published elsewhere. One maintained dataset is what prevents that.

    This is the problem Horizon ESG’s sustainability team workspace is built around: one evidenced dataset, mapped to the frameworks and questionnaire formats you actually get asked for. Nova, the built-in assistant, drafts questionnaire answers from that dataset, with every figure traced to its source and every draft held for your approval before anything leaves the building.


    When a customer asks for more than the cap allows

    It will happen, usually because the person running the portal has never heard of the cap. A short sequence to work through:

    • Check the purpose. The cap governs requests made for CSRD reporting. Data requested for contract qualification, product compliance or the customer’s own risk management sits outside it. Ask which is which; the question itself often shrinks the request.
    • Ask them to flag the excess. A CSRD-scope buyer asking beyond the cap is supposed to identify which items exceed it and tell you they are optional. If they have not, asking them to do so is entirely reasonable.
    • Decide commercially, not defensively. The cap gives you a right to decline, not a duty. If a strategic customer wants two extra datapoints and you can produce them from your dataset in an hour, volunteer them.
    • Counter-offer the dataset. “Here is our complete VSME dataset now; the remaining items would take us six weeks” gives the requester something to bank immediately and usually ends the conversation.

    The commercial cost of answering slowly

    It is tempting to treat questionnaires as overhead to be minimised. The evidence in front of most sustainability officers points the other way: the requests you are receiving are attached to revenue and to the cost of capital. A tender response that misses the portal deadline is a bid not scored. A slow answer to a bank’s ESG review does not usually lose the loan, but sustainability-linked facilities increasingly tie margin to data quality, and “supplier could not evidence their numbers” is a phrase that shows up in credit files.

    Being easy to buy from is the quiet advantage here. The supplier who returns a complete, evidenced, consistent dataset in two days is doing more for renewal season than most marketing budgets.


    One dataset, two audiences

    A last point worth raising internally: the numbers you send to customers and lenders need to match the numbers your finance team publishes. When the two are produced separately, they eventually diverge, and a customer noticing the difference is the worst possible way to find out. If your CFO is starting to ask assurance-flavoured questions about sustainability data, that is the same problem from the other end; our page for finance teams covers that side.

    If your week is currently being eaten by questionnaires, book a short demo and bring your worst one. Answering it from one dataset is the fastest way to see the point.

  • CSRD Value-Chain Cap: What You Can Still Ask Suppliers

    Most of the coverage of the European Commission’s 3 July package led with the same number: a 60% cut in mandatory ESRS datapoints. That is the headline, and it is real. But buried in the second delegated act is a change that will reshape more programmes than the datapoint cut ever will — and almost nobody is briefing their procurement team on it.

    It is called the value-chain cap. In short: from financial year 2027, a CSRD-scope company will no longer be able to require its smaller suppliers to hand over sustainability data beyond a defined ceiling. If your supplier-engagement programme is built on a 200-question ESG questionnaire pushed down the chain, that programme now has a legal boundary running through the middle of it.

    What the Commission adopted on 3 July 2026

    The Commission adopted two delegated acts. The first is the revised set of European Sustainability Reporting Standards — the concrete landing of the Omnibus I simplification agenda. It cuts mandatory datapoints by over 60%, total datapoints by over 70%, and is expected to reduce reporting costs by more than 30% per company.

    The second is the one to read carefully: a Voluntary Sustainability Reporting Standard, built on the VSME, giving companies outside CSRD scope a single proportionate framework to report against. It is voluntary in the sense that no smaller company is obliged to use it. It is emphatically not voluntary in its effect on the companies above them in the chain — because it sets the ceiling.

    Both acts are now in a two-month scrutiny period before the European Parliament and Council, extendable by a further two months. If neither institution objects, they are published in the Official Journal and enter into force. That caveat matters, and we return to it at the end.

    The value-chain cap, precisely

    The cap protects companies with 1,000 employees or fewer that sit in the value chain of a CSRD reporter. Under the Omnibus I Directive, those companies are entitled to decline requests for sustainability information that go beyond what the Voluntary Standard covers. Micro-enterprises of ten employees or fewer get further relief on top. For CSRD-scope companies, the cap bites from financial year 2027.

    Read plainly, that inverts a decade of supplier-engagement practice. The implicit deal until now was that a large buyer could ask its suppliers for whatever its own reporting obligations demanded, and commercial leverage did the rest. From FY2027, the supplier has a statutory answer: no, and here is the standard that says so.

    Three things the cap does not do

    This is where the early commentary is getting it wrong, so it is worth being exact.

    • It caps what you can require, not what you can ask. The Commission has confirmed that a CSRD reporter may still request information beyond the cap — provided it clearly identifies which parts of the request exceed the cap and informs the supplier of their right to refuse. The cap creates a duty of transparency in the ask, not a prohibition on asking.
    • It applies only to CSRD reporting. The cap operates when fulfilling CSRD reporting obligations. It does not govern information you request for other purposes — commercial qualification, contractual assurance, product compliance, or your own risk management.
    • It does not stop a supplier volunteering more. Plenty of smaller suppliers will keep sharing data, because being easy to buy from is a competitive advantage. The cap removes the obligation, not the incentive.

    Together those three points reframe the cap. It is not a wall. It is a consent boundary — and crossing it now requires you to say out loud that you are crossing it.

    Where the cap collides with CSDDD

    Here is the tension nobody has resolved. The Corporate Sustainability Due Diligence Directive still requires in-scope companies to conduct risk-based human rights and environmental due diligence across their chain of activities — an approach Omnibus I preserved rather than narrowing to tier one. You cannot discharge a risk-based due-diligence obligation without information from the chain. Yet the ESRS package has just capped what you may require from a large part of that same chain.

    The reconciliation is in the scoping: the cap is tied to CSRD reporting obligations, and CSDDD due diligence is a separate legal duty. In principle, a due-diligence request is not a CSRD reporting request, and the cap does not extinguish it.

    In practice, that distinction is going to be tested hard — because it is usually the same supplier, receiving the same questionnaire, from the same buyer, in a single email. If your data requests do not distinguish their legal basis, you invite a supplier to refuse the whole thing on cap grounds, including the parts you are entitled to insist on. The operational bar for all of this is still being written: the Commission’s consultation on CSDDD implementation guidelines closes on 24 July 2026, with the guidelines expected in principle by July 2027. If your supplier programme is material to your business, that consultation is a genuine, closing opportunity to shape it.

    What to do in the next 90 days

    FY2027 sounds distant. It is not — supplier programmes have long lead times, and the contracts you sign this year will still be running when the cap bites.

    1. Re-baseline your supplier questionnaire against the Voluntary Standard. Every question you currently push down the chain now sorts into one of two buckets: inside the cap, or outside it. You cannot manage the boundary until you can see it.
    2. Get headcount into your supplier master data. The 1,000-employee line is now a legal boundary, and most procurement systems do not hold supplier headcount at all. This is the least glamorous item on the list and probably the one with the longest lead time.
    3. Redesign the ask, not just the question set. Beyond-cap requests need to be explicitly flagged as such, with the right to refuse stated. Build that into the template now rather than retrofitting it under deadline.
    4. Separate your legal bases. Split CSRD-reporting requests from due-diligence and commercial requests, and label them. This is the single change that most protects your CSDDD position.
    5. Plan for refusal. Assume a meaningful share of smaller suppliers will exercise the cap. That means leaning harder on estimation, sector averages and spend-based proxies for value-chain data — and being able to document why an estimate was used and how it was derived.

    Prepare — but do not decommission

    One final discipline. Both delegated acts are still in scrutiny, and the revised ESRS are set to apply to financial years beginning on or after 1 January 2027, with early application permitted. Nothing is in the Official Journal yet.

    So the correct posture is prepare, don’t freeze — and above all, don’t switch anything off. The most expensive mistake available right now is to read “60% fewer datapoints” as permission to dismantle data pipelines that a scrutiny objection, an early-adoption decision, or an investor’s own SFDR-driven data request could make you rebuild in eighteen months. Simplification is not the same as less work. A 70% datapoint cut creates a migration project before it creates a saving.

    The companies that will handle this well are the ones that can see, in one place, which datapoints they collect, which regime each one serves, and where in the value chain it came from. That is a data-architecture question long before it is a compliance one — and it is exactly what our CSRD readiness checklist is built to help you work through. If you would like to see how Horizon ESG maps a single data foundation across CSRD, CSDDD and the voluntary standard, book a short demo — we will walk your own supplier data through it.

  • SEC Climate Rollback Won’t Free US Multinationals

    The headlines are tempting: the SEC is moving to scrap the climate-disclosure rules it adopted in 2024, and some commentators have read that as the end of mandatory climate reporting for US companies. For any business with revenue in California or operations in Europe, the opposite is closer to the truth. The federal rule was only ever one of several overlapping regimes — and the others are advancing, not retreating.

    If your reporting plan hinges on the SEC standing down, this is the moment to stress-test it. Below is what is actually happening in Washington, why it changes less than it appears to, and what reporting teams should do while the noise settles.

    What the SEC is actually doing

    On 3 June 2026, the SEC’s proposed rescission of its 2024 climate-related disclosure rules was published in the Federal Register, opening a comment period that runs through 3 August 2026. Two points are easy to miss in the headlines. First, this is a proposal in its comment window, not a settled outcome. Second, the plan is to eliminate the dedicated framework rather than replace it — reverting issuers to principles-based, materiality-focused disclosure under existing securities law. The Commission has pointed to compliance savings of roughly $4.9bn a year.

    Removing a prescriptive rulebook is not the same as removing the obligation to disclose. Material climate risks that affect a reasonable investor’s decision can still require disclosure under long-standing materiality principles. What changes is the how and the how much — not the underlying duty. And for most multinationals, the SEC was never the binding constraint anyway.

    Why “no SEC rule” doesn’t mean “no disclosure”

    Three other regimes keep mandatory climate and greenhouse-gas disclosure firmly alive for US companies of any size that trade across state or national borders. None of them depend on the SEC.

    California: the de facto US standard

    California’s climate-disclosure laws reach far beyond the state’s borders because they apply to companies “doing business in California,” regardless of where they are headquartered. Two statutes matter:

    • SB 253 (Climate Corporate Data Accountability Act) requires companies with total annual revenues above $1bn to report Scope 1, Scope 2 and, in a later phase, Scope 3 greenhouse-gas emissions.
    • SB 261 (Climate-Related Financial Risk Act) requires companies with revenues above $500m to publish a climate-related financial-risk report aligned with the TCFD recommendations.

    Because the revenue thresholds are low relative to the size of a typical multinational, the practical effect is that a large share of US companies that would have reported to the SEC are captured by California instead — and California explicitly requires Scope 3, which the federal approach was always more cautious about. For most large filers, the toughest disclosure bar in the US now sits in Sacramento, not at the SEC.

    The EU: CSRD reaches across the Atlantic

    The EU’s Corporate Sustainability Reporting Directive pulls in non-EU groups through their European operations. A US parent with substantial EU subsidiaries or branches can fall directly within scope, and even companies that sit outside mandatory scope routinely receive value-chain data requests from European customers who need the numbers for their own ESRS reports. The recent “Omnibus” simplification narrowed who must report at the top of the chain, but it did not switch off the demand for emissions and sustainability data flowing down global supply chains.

    In other words, even a US company with no EU listing can find itself assembling ESRS-grade data because a major European buyer asks for it. If you sell into Europe, CSRD is part of your reality whether or not your own name is on a filing.

    The UK: anti-greenwashing and SDR

    For US groups with UK-regulated financial arms, the FCA’s Sustainability Disclosure Requirements regime adds a third layer. Its anti-greenwashing rule applies to all FCA-authorised firms, and from 30 June 2026 the remaining in-scope asset managers above £5bn in assets must publish entity-level disclosures. The throughline is consistent: any claim you make about sustainability has to be substantiated, and the supporting data has to exist.

    Fragmentation, not freedom

    The real consequence of the SEC’s retreat is not less work — it is less harmonisation. A single US-federal climate rule would at least have given multinationals one reference point that broadly tracked the global ISSB and EU baselines. Without it, a company can find itself reconciling California’s emissions thresholds, the EU’s double-materiality model, and the UK’s disclosure expectations, each with its own scope, boundary and timing.

    That is an argument for building disclosure on a single, well-governed dataset rather than chasing each regime with a separate project. The metrics underneath — Scope 1, 2 and 3 emissions, climate risk, governance and targets — overlap heavily. The expensive mistake is collecting them three times.

    What reporting teams should do now

    • Map your real obligations, not the federal one. Test your revenue and operations against California’s SB 253 and SB 261 thresholds and against EU value-chain exposure before assuming the SEC change lets you scale back.
    • Keep your GHG inventory live. Scope 1, 2 and 3 data feeds California, CSRD and customer requests alike, so a robust carbon accounting foundation is the one investment that pays off under every regime.
    • Build once, report many times. Structure your data so a single source can be mapped to multiple frameworks rather than rebuilt for each.
    • Watch the comment window, but don’t wait on it. The SEC proposal closes for comment on 3 August 2026; nothing about that date pauses California or Europe.

    The companies that handle this period well will be the ones that treated the SEC rule as one input among several, not the keystone. The disclosure expectation has not gone away — it has simply spread out, and it now rewards teams with clean, reusable data more than ever.

    Reporting under more than one rulebook? Horizon ESG helps teams collect emissions and sustainability data once and map it to CSRD, California and other frameworks from a single source. See how it works.

  • CSRD for Medium-Sized Businesses: 2026 Guide

    CSRD for Medium-Sized Businesses: 2026 Guide

    If you are running or advising a medium-sized business based in the UK or EU, you may be asking: Are we affected by CSRD? When do we need to start preparing? What if we are not directly reporting, but our clients are?

    As of 2026, the Corporate Sustainability Reporting Directive (CSRD) is reshaping how sustainability data flows through the entire European business ecosystem. Even with shifting deadlines and ongoing exemptions, medium-sized businesses are already feeling the impact.

    This guide is for business owners, CFOs, operations leads and sustainability managers who want clear answers and practical next steps — without getting lost in regulatory language.


    Who Needs to Report Under CSRD — and When?

    Here is a simple breakdown of the current timeline:

    • Large EU companies and those listed on EU-regulated markets began reporting in 2025.
    • Listed medium-sized companies (SMEs) were originally required to start reporting in 2027 (based on FY2026), The Omnibus Directive of 18 March 2026 removed them from scope: CSRD now applies only to companies with more than 1,000 employees and more than EUR 450m net turnover.
    • Non-listed medium-sized companies are not directly in scope, but many are indirectly affected through their roles in the supply chains of larger reporting entities.

    Bottom line: Even if you are not mandated to publish a CSRD report yet, your customers or investors might already be asking you for sustainability data.

    And if you are UK-based? You are not subject to CSRD directly, but if you have EU subsidiaries, clients or investment relationships, expect similar expectations and data requests.


    Why Medium-Sized Businesses Cannot Afford to Wait

    You may not have to publish a report in 2026, but that does not mean you are off the hook. CSRD requires large companies to report ESG data across their entire value chain — and that includes you.

    If your business provides products or services to CSRD-regulated companies, they will need data from you to meet their obligations. Already in 2025:

    • Over 60% of mid-size EU suppliers were asked to provide ESG metrics aligned with CSRD.
    • Sustainability questionnaires are now being embedded into procurement and vendor onboarding processes.

    Whether you are in manufacturing, logistics, B2B services or technology — if you are in the value chain, you are in the frame.


    What You Should Be Doing in 2026

    The biggest risk for medium-sized businesses is waiting too long to prepare. Here is how to start:

    1. Assess Your Status

    • Are you listed in the EU?
    • Do you operate in EU countries or serve EU-headquartered clients?
    • Are you receiving ESG data requests from customers or investors?

    2. Evaluate Your Current Data

    • Do you know your Scope 1 and 2 emissions?
    • Do you have any supplier data for Scope 3?
    • Are you tracking employee data such as diversity, turnover and training?
    • Do you have policies in place on governance, anti-bribery and sustainability?

    3. Talk to Key Stakeholders

    • What are your top customers or investors asking for?
    • Are banks or lenders requesting ESG disclosures?

    4. Outline a Simple CSRD Roadmap

    • Begin with a materiality assessment.
    • Identify your key data gaps.
    • Assign responsibility internally — even if it is just one person coordinating efforts.

    This Is Not Just About Regulation — It Is Strategy

    Many companies start CSRD preparation because they feel they have to. But the businesses that benefit the most see it as an opportunity:

    • Stronger customer relationships: Show key clients that you are reliable and future-ready.
    • Competitive advantage: Meet ESG expectations ahead of competitors.
    • Operational clarity: Build a clearer view of your business’s risks and impacts.
    • Future-proofing: Position your company to respond to future UK or EU regulatory shifts.

    By investing early — even with simple steps — you reduce risk, avoid late-stage panic and gain control over your sustainability narrative.


    Where to Start Today

    If you have read this far, you are likely looking for practical guidance. We recommend starting with:

    • A 60-minute materiality workshop to define what matters most for your business.
    • A data gap assessment — what you already track, what you will need and what can wait.
    • A client-focused strategy — identifying who will be asking you for data and when.

    The rules may still evolve, but the direction of travel is clear. Whether you are in scope today or not until 2028, your customers and partners will expect CSRD-aligned data soon.


    Final Takeaway

    Sustainability reporting is not just for the big players anymore. If you are a medium-sized company in Europe or the UK, now is the time to take small, smart steps. Do not wait for a formal obligation to start preparing. Start with what you can control — clarity, data and planning.


    Get Your Free CSRD Readiness Check

    Horizon ESG helps medium-sized businesses build tailored, low-friction sustainability reporting strategies aligned with CSRD and other frameworks. Book a free CSRD readiness check — no fluff, just clear next steps.

Book Your Free Demo