
CSRD Wave 1 lessons from FY2024 are now clear: the hardest part of sustainability reporting was never the standard itself. It was the data. First-wave filers discovered that environmental and social disclosures depend on product, material, and supplier information that most organizations had never collected in a structured, auditable way. With Omnibus I (Directive (EU) 2026/470) reshaping scope and the simplified ESRS finalizing for FY2027, incoming filers have a rare advantage: they can fix the data foundation before their first report is due.
This guide breaks down what Wave 1 actually experienced, what Omnibus I changed, and how Wave 2 preparation should start now.
Key Takeaways
๐ Omnibus I (Directive (EU) 2026/470, in force 18 March 2026) narrowed CSRD scope to companies with more than 1,000 employees and over โฌ450M net turnover, removing an estimated 80% of previously in-scope companies.
โณ The new scope applies to financial years beginning on or after 1 January 2027, with first reports due in 2028. There is no separate "Wave 2" report in 2027.
๐ The simplified ESRS propose a 61% cut to mandatory datapoints and over 70% to total datapoints. Final adoption is expected before September 2026, with optional early adoption for FY2026.
โ ๏ธ Wave 1 friction was concentrated in three areas: value-chain data gaps, supplier response lag, and limited-assurance readiness.
๐ ESRS E2 (pollution) and E5 (resource use and circular economy) draw on the same BOM-level substance data that already drives REACH, RoHS, and PFAS compliance.
๐ Double materiality and mandatory limited assurance both remain. The move to reasonable assurance was scrapped, with a limited assurance standard due by 1 July 2027.
๐ค Continuous, BOM-level data collection converts CSRD from an annual scramble into audit-ready documentation maintained year-round.
What CSRD Wave 1 FY2024 Filers Actually Learned
Wave 1 covered large public-interest entities already reporting under the prior NFRD regime. Their FY2024 reports, published in 2025, were the first real-world test of the European Sustainability Reporting Standards. The recurring lesson was structural, not editorial. Teams that treated CSRD as a disclosure-writing exercise underestimated the effort required to source, validate, and evidence quantitative datapoints. Organizations that had invested in a centralized compliance data backbone moved faster, because the underlying product and supplier data already existed in a governed system rather than scattered across spreadsheets and email threads.
The second lesson was interdependence. ESRS environmental disclosures reach into the value chain, so reporting quality depended on suppliers that had no direct CSRD obligation of their own. This is the same multi-tier supply chain transparency challenge that manufacturers already face under REACH and conflict minerals rules, now applied to sustainability data.
How Omnibus I Reshaped CSRD Scope and ESRS
Omnibus I significantly narrowed who must report and how much they must disclose. The changes are substantive and were finalized through 2025 and early 2026.
Change | Before Omnibus I | After Omnibus I |
|---|---|---|
Scope threshold | 250 employees / โฌ50M turnover / โฌ25M balance sheet | >1,000 employees AND >โฌ450M net turnover |
Companies affected | ~50,000 (broad NFRD-plus expansion) | ~80% fewer in scope |
ESRS datapoints | ~1,073 total (many voluntary) | ~61% fewer mandatory, >70% fewer total (proposed) |
Sector-specific ESRS | Under development | Dropped |
Assurance | Limited, with planned move to reasonable | Limited only; reasonable-assurance transition scrapped |
Double materiality | Required | Retained |
Two points matter for planning. First, the datapoint reduction is proposed, not yet law. The Commission published the draft revised ESRS on 6 May 2026 and is expected to adopt the final delegated act before September 2026. Second, double materiality survives. Companies still must assess both impact materiality and financial materiality, which continues to drive demand for structured product and value-chain evidence.
CSRD scope thresholds before and after Omnibus I for sustainability reporting
Click on image to view full
Internal design note: This is the shareable asset. Must work standalone so a CSO can screenshot and send it internally with zero context. Two panels only, high contrast, no more than 8 text elements. No decorative borders or gradients.
The Corrected CSRD Timeline for 2026 and 2027
Accuracy on timing matters, because the "wave" language has shifted. The verified sequence is straightforward.
18 March 2026: Omnibus I (Directive (EU) 2026/470) enters into force. CSRD scope narrows to >1,000 employees and >โฌ450M turnover.
FY2025 and FY2026: Member States may exempt Wave 1 companies that fall below the new thresholds. Wave 1 companies that remain in scope continue reporting.
By September 2026: Final revised ESRS delegated act expected to be adopted, with optional early adoption for FY2026.
Financial years beginning on or after 1 January 2027: The narrowed CSRD scope applies. First reports under the new regime are due in 2028.
There is no EU-wide June 30 statutory filing date. CSRD disclosures are published inside the annual management report, on each member state's financial-reporting timeline. Teams tracking multiple entities benefit from regulatory intelligence and horizon scanning that maps each jurisdiction's actual filing window rather than assuming a single deadline.
Where Wave 1 Reports Broke Down
Three friction points appeared consistently across Wave 1 filers. Each is a data problem before it is a reporting problem.
Value-chain data gaps
ESRS E2, E5, and social standards require information that lives with suppliers and inside product records. Many first-wave teams had no source system for substance-level or material-level data and had to reconstruct it under deadline pressure. A BOM-level compliance intelligence foundation removes this scramble by tying disclosures back to specific parts and materials.
Supplier response lag
Suppliers received sustainability questionnaires that duplicated existing REACH, RoHS, and PFAS requests, often in incompatible formats. Response rates suffered and timelines slipped. Automated supplier data collection through standardized portals reduces this by consolidating requests and validating responses on intake.
Limited-assurance readiness
Auditors tested evidence, not narrative. Filers without time-stamped, traceable source data struggled to support figures during limited assurance. This is why continuous audit-ready documentation matters more than a polished report.
CSRD Wave 1 reporting friction points for ESRS data collection and assurance
Click on image to view full
What Wave 2 Companies Should Do Now
Incoming filers reporting from FY2027 have roughly a year of runway. The most effective preparation focuses on data infrastructure, not report drafting.
โ Confirm scope. Verify whether the entity meets the >1,000 employee and >โฌ450M turnover thresholds on a consolidated basis. Scope is now a threshold question, not an assumption.
โ Run a double materiality assessment early. Identify which ESRS topics are material so data collection targets the right datapoints.
โ Map ESRS datapoints to source systems. Link each required figure to a system of record, especially product and supplier data feeding E2 and E5.
โ Consolidate supplier requests. Replace overlapping sustainability, REACH, and RoHS questionnaires with a single supplier engagement workflow.
โ Build the evidence chain before the report. Capture who submitted each data point, when, and under what authority, so limited assurance is defensible.
โ Consider early adoption. Optional FY2026 adoption of the simplified ESRS lets teams rehearse under lower complexity.
For context on why this is a supply-chain problem first, see Why ESG Failure Is a Supply Chain Risk, Not Just a Reporting Issue.
The Product-Data Advantage for ESRS E2 and E5
This is where product-centric compliance data becomes a reporting differentiator. ESRS E2 (pollution) and E5 (resource use and circular economy) require substance-level and material-level information: substances of concern, resource inflows and outflows, and product composition. That is the same data manufacturers already manage for REACH, RoHS, and PFAS obligations.
Generalist ESG reporting tools collect narrative and corporate-level metrics, but they do not maintain BOM-level substance data. A platform that already performs BOM substance and threshold management can feed ESRS E2 and E5 disclosures from the same source that drives chemical compliance. This connects sustainability reporting to the Digital Product Passport and EU CBAM data workstreams manufacturers are building in parallel, reducing duplication across frameworks.
BOM-level product data feeding ESRS E2 and E5 disclosures for CSRD reporting
Click on image to view full
Audit Readiness for Limited Assurance
CSRD retains mandatory limited assurance, and a limited-assurance standard is due by 1 July 2027. Preparing for it means understanding what assurance actually tests. No platform can make a report "audit-proof," and findings are always possible. The realistic objective is audit-ready: fewer surprises and faster response.
Different audit contexts stress different evidence:
Internal audits check process discipline and data completeness.
Customer audits, often OEM-driven, request proof tied to specific products.
Regulatory inspections by bodies such as ECHA or national market-surveillance authorities test substance-level accuracy.
Certification audits (ISO 14001, ISO 9001, IATF 16949) test system integrity.
Assurance readiness depends on evidence-chain integrity: who provided a data point, when, and with what authority, plus historic state tracking through immutable, time-stamped records that support point-in-time queries. Leading manufacturers already expose this through customer trust-center models. A system of record for product compliance that maintains versioned, time-stamped declarations makes limited assurance a retrieval exercise rather than a reconstruction.
How AI-Native Compliance Automation Supports ESRS Reporting
Manual, spreadsheet-based ESG data collection cannot keep pace with datapoint mapping, supplier follow-up, and evidence retention across FY2027 and beyond. AI-native compliance automation addresses the structural workload directly.
CORA-powered regulatory intelligence tracks changes across CSRD, the simplified ESRS, CSDDD, and the EU Taxonomy, then maps them to affected products and suppliers. CORA-enabled analysis parses supplier certificates and declarations, flags gaps on intake, and validates data before it reaches the report. The result is a shift from reactive, annual reporting toward continuous, defensible readiness. For a practical view of this in ESG specifically, see How Certivo Streamlines ESG Data Collection Across Your Supply Chain.
If your team is preparing its first ESRS report or strengthening a second, a structured audit-readiness review is the fastest way to find data gaps before assurance does. Request a Compliance Risk Assessment to map your ESRS data foundation across products and suppliers.
Hariprasanth
Hariprasanth is a Chemical Compliance Specialist with nearly four years of experience, underpinned by a degree in Chemical Engineering. He brings in-depth expertise in global product compliance, working across key regulations such as REACH, RoHS, TSCA, Proposition 65, POPs, FMD, and PFCMRT.
Hariprasanth specializes in reviewing technical documentation, validating supplier inputs, and ensuring that products consistently meet regulatory standards. He works closely with cross-functional teams and suppliers to collect accurate material data and deliver clear, audit-ready compliance reports that stand up to scrutiny.



