Logotipo Datanet iot

CSRD Timeline: Every Deadline That Still Matters

The CSRD timeline you planned around in 2024 is wrong. The four-wave rollout is legally dead. The scope contracted by roughly 80%. The reporting standards lost over 60% of their mandatory datapoints. And yet the first wave already reported, the directive is binding law, and the second application period starts for financial years beginning 1 January 2027.

If you’re building your compliance roadmap on a phase chart published before February 2026, you’re navigating with an expired map. Here is the CSRD timeline as it actually stands after Directive 2026/470 (Omnibus I) and the revised European Sustainability Reporting Standards adopted in July 2026. Dates, thresholds, and what they mean for your next 36 months of planning.

The Full CSRD Timeline After Omnibus I

The table below separates what has already happened from what comes next. This distinction matters because most compliance guides still blend original milestones with current law, creating phantom deadlines that no longer bind anyone.

Date Event Practical Impact
14 Dec 2022 CSRD published in the Official Journal Legal foundation for the entire EU sustainability reporting regime
FY 2024 (reports in 2025) First-wave companies report under original ESRS Large public-interest entities already publishing; live precedent, not theory
2025 “Stop the clock” directive adopted Postponed reporting obligations for companies originally due in FY 2025 and FY 2026
11 Jul 2025 Quick-fix delegated act First-wave reporters get flexibility; no extra disclosure demands for FY 2025 and FY 2026 beyond what FY 2024 required
26 Feb 2026 Directive 2026/470 (Omnibus I) published New scope thresholds, listed-SME provision deleted, limited assurance retained, reasonable assurance removed
3 Jul 2026 Revised ESRS and voluntary standard adopted by the Commission 60%+ reduction in mandatory datapoints; transmitted to Parliament and Council for scrutiny
FY beginning 1 Jan 2027 Second application period starts Companies meeting new thresholds begin collecting data for this financial year
19 Mar 2027 Member State transposition deadline (first tranche) National law must implement certain Omnibus I provisions
1 Jul 2027 Limited-assurance standards deadline Commission must adopt limited-assurance standards (moved from Oct 2026)
26 Jul 2028 Member State transposition deadline (second tranche) Remaining Omnibus I provisions transposed into national law

One detail that trips people up: Directive 2026/470 entered into force on the twentieth day after its publication. It is binding EU law. But your company’s specific reporting obligation depends on when your Member State transposes the directive into national legislation. Those are two different dates. If you operate across multiple EU countries, you may face different national timelines for the same directive. Track both the EU effective date and each relevant national operative date.

Close up of a technician checking a carbon sensor as part of the operational steps in the CSRD timeline for reporting.

What Omnibus I Actually Changed

The Commission described the reform as removing around 80% of companies from the CSRD’s direct scope, projecting EUR 4.4 billion in annual administrative-cost savings. The Commission’s impact analysis estimated the original reporting population at somewhere between 30,673 and 76,556 undertakings (the range depends on how subsidiaries use available exemptions) and placed the proposed reduction at 75% to 82%.

To see how deep the changes run, compare the original framework with the current one side by side:

Dimension Original CSRD After Omnibus I
EU scope test Large companies and listed SMEs, phased over four waves Both conditions required: >EUR 450M turnover AND >1,000 employees
Non-EU scope test EUR 150M EU revenue + subsidiary/branch criteria EUR 450M EU revenue over 2 consecutive years + EUR 200M subsidiary/branch
Listed SMEs Included in Wave 3 Deleted from the directive entirely
Second reporting wave FY 2025 FY beginning 1 January 2027
ESRS mandatory datapoints Full 2023 set Reduced by more than 60%
Assurance trajectory Limited assurance, with possible escalation to reasonable Limited assurance only; reasonable assurance requirement removed
Estimated companies in direct scope ~50,000+ ~80% fewer

The political rationale is competitiveness and cost relief. Not everyone agrees that’s worth the trade. Accountancy Europe supports simplification but warns that narrowing the scope could reduce visibility into sustainability performance and financial risk, potentially undermining the EU’s own industrial-transformation goals. That tension is not resolved. It’s built into the framework.

Scope Thresholds: EU Companies, Non-EU Groups, Listed SMEs

The scope question is the first thing every CFO and compliance officer needs to settle. Get this wrong and everything downstream (budgets, staffing, system procurement, auditor selection) is either premature or dangerously late.

EU undertakings

Both conditions must be met simultaneously: net turnover exceeding EUR 450 million, and an average of more than 1,000 employees during the financial year. The directive applies these tests at entity or consolidated-group level. A company with 2,000 employees but EUR 300 million in turnover is outside scope. A company with EUR 600 million in turnover but 800 employees is also outside scope. Both tests pass, or neither applies.

Non-EU groups

A third-country parent falls within scope if it generated more than EUR 450 million in the Union in each of the last two consecutive financial years, and has at least one EU subsidiary or branch exceeding EUR 200 million in net turnover in the preceding year. Legal teams should test the group revenue condition, the subsidiary condition, and the branch condition independently. Borrowing the EU-company thresholds by analogy is a common mistake.

Listed SMEs

Gone. The final directive deletes the listed-SME provision entirely. No phase-in. No opt-in route through the main directive.

But deletion from the legal scope does not equal deletion from the information ecosystem. A listed SME that supplies a reporting customer, seeks green financing, or competes in a market where sustainability credentials matter will still face data requests. The Commission’s new voluntary standard and the value-chain cap are designed to make those requests proportionate. The requests themselves will not disappear.

Revised ESRS: Fewer Datapoints, Higher Bar

On 3 July 2026, the Commission adopted revised ESRS that reduce mandatory datapoints by more than 60%, total datapoints by more than 70%, and expected reporting cost per company by more than 30%. EFRAG confirmed the revised standards apply to financial years beginning on or after 1 January 2027, with early adoption for FY 2026 permitted once the delegated act enters into force.

That reduction sounds like pure relief. It is, in volume. But it carries a hidden expectation: the datapoints that remain are the ones regulators and auditors consider most important. Fewer fields to fill means more scrutiny per field.

The first-wave evidence supports this. KPMG reviewed 50 first-wave sustainability statements and found that 88% reported data-quality challenges, with Scope 3 emissions as a recurring weak spot. Companies identified between 9 and 93 material impacts, risks, and opportunities (median: 28). Many disclosures lacked cohesion. Some focused on metrics while neglecting policies and actions entirely.

The lesson: volume was never the core problem. Control was. A company can collect fewer datapoints and still fail the audit test if it can’t explain where each number came from, who approved it, how it was calculated, and what it connects to in the double materiality assessment.

The revised framework also introduces a voluntary reporting standard for smaller companies outside the CSRD’s direct scope. The value-chain cap prevents in-scope companies from demanding more information from suppliers than the voluntary standard covers. This creates a standardized floor. A smaller firm can build one reusable data package instead of responding to a different custom questionnaire from every customer.

Assurance Under the New Rules

The original CSRD envisioned a progression: start with limited assurance, then escalate over time to reasonable assurance. That escalation path is gone.

Directive 2026/470 retains limited assurance as the required level and removes the obligation to move toward reasonable assurance. The Commission’s deadline for adopting limited-assurance standards moved from 1 October 2026 to 1 July 2027. Practitioners still must meet national qualification and registration requirements under applicable Member State law.

Limited assurance is less extensive than reasonable assurance. It is not, however, a rubber stamp. An auditor performing a limited-assurance engagement still examines evidence, tests controls, and evaluates whether the sustainability statement is free from material misstatement. The difference lies in the depth of procedures, not in whether professional skepticism applies.

The readiness gap remains wide. PwC’s 2024 global survey of 547 professionals across more than 30 countries found that only 33% had completed a double materiality assessment, 30% had completed an EU Taxonomy analysis, and 29% had completed a disclosure gap analysis. Companies expected an average of eight business functions to participate in implementation. The legal deadline moved. The data-readiness gap did not close on its own.

Digital reporting adds another layer. The management report must use an electronic format and sustainability data will eventually require XBRL mark-up. But EFRAG has confirmed that digital tagging is not mandatory until the Commission adopts the XBRL taxonomy through ESEF regulatory technical standards prepared by ESMA. The taxonomy work is ongoing. Companies should structure data with stable identifiers now (it will save painful retrofitting later) without assuming any vendor’s current tagging feature matches the final legal taxonomy.

Outside the New Scope? Your Planning Doesn’t Stop

This is the part most CSRD timeline guides skip entirely.

If Omnibus I moved your company outside the mandatory reporting perimeter, you face a strategic decision, not a compliance holiday. The regulation changed. The market dynamics around sustainability data did not.

Three forces keep sustainability information relevant even for companies that are technically exempt:

  • If your largest customer reports under CSRD, their materiality assessment may require data from your operations. The voluntary standard caps what they can ask for. “Capped” is not “zero.”
  • Lenders and insurers increasingly use sustainability information in credit decisions and underwriting. Groupe Bruxelles Lambert’s CSRD preparation, which started in 2023 and included over EUR 2 million in investment across controlled entities, explicitly linked sustainability reporting to access to financing and value creation.
  • Thresholds can be revised downward. Member States can exceed the directive’s minimum requirements. The governance records, materiality logic, emissions methodology, and supplier definitions you built during preparation retain value if the scope widens again.

In the same PwC survey, 38% of respondents expected CSRD implementation to produce direct revenue growth and 34% expected cost savings. The companies treating reporting as strategic infrastructure rather than a regulatory cost center are the ones who benefit regardless of where the scope line lands next year or five years from now.

The practical recommendation: don’t continue every original datapoint. But preserve your materiality framework, emissions calculation methodology, supplier engagement process, and evidence trail. Those are operational assets, not disposable compliance artifacts. For companies building ESG compliance infrastructure from the ground up, these frameworks become the foundation of all future sustainability governance.

Where the Data Actually Comes From

Every CSRD implementation challenge eventually points to the same root cause. Not legal interpretation. Not framework selection. Data. Where does it come from? How is it collected? Is the process repeatable? Can an auditor trace a reported figure back to a verifiable source?

KPMG’s first-wave findings make this concrete: 88% of reviewed companies reported data-quality challenges. Scope 3 emissions (supply chain, logistics, downstream use) were the most cited problem. And Scope 3 is exactly where operational data intersects with sustainability disclosure. You cannot report supply-chain emissions from a spreadsheet built on estimates if an auditor expects traceable source evidence.

This is where operational technology plays a role that most CSRD guides ignore. Environmental monitoring (temperature, humidity, energy consumption, water quality), asset lifecycle tracking, and supply-chain visibility all feed directly into the datapoints that ESRS requires. Companies that already collect this information through sensor networks, IoT infrastructure, or automated telemetry have a structural advantage: their sustainability figures come from systems with timestamps, device IDs, and audit logs, not from annual estimates assembled under deadline pressure.

At Datanet, our work with environmental tracking devices and asset tracking solutions across aviation, logistics, and industrial operations puts us at this intersection every day. The same sensor data that optimizes fleet utilization or monitors cold-chain integrity can serve as auditable evidence for sustainability reporting. If your CSRD data pipeline depends on manual collection and you want to fix that before your reporting year begins, talk to our team.

A wide view of a sustainable industrial park under a sunset sky representing the evolving CSRD timeline for corporations.

Frequently Asked Questions

When does the next CSRD reporting period begin?

The second application period covers financial years beginning on or after 1 January 2027. Companies meeting the Omnibus I thresholds will collect data for FY 2027 and publish sustainability statements the following year. The revised ESRS apply from this date, with early adoption for FY 2026 permitted once the delegated act enters into force.

What are the updated scope thresholds for EU companies?

Two conditions must both be met: more than EUR 450 million in net turnover and more than 1,000 average employees during the financial year. These are tested at entity or consolidated-group level. Falling below either threshold places the company outside mandatory scope.

Does the CSRD still apply to non-EU companies?

Yes, with revised thresholds. A third-country group must have generated more than EUR 450 million in the EU in each of the last two consecutive financial years, and must have an EU subsidiary or branch exceeding EUR 200 million in net turnover in the preceding year. Test each condition independently.

Are listed SMEs still required to report?

No. Directive 2026/470 deleted the listed-SME provision entirely. However, listed SMEs may still receive sustainability data requests from customers, lenders, and investors. The Commission’s voluntary standard provides a proportionate response framework for those requests.

Has the assurance requirement changed?

Yes. The final Omnibus text retains limited assurance but removes the requirement to progress toward reasonable assurance. The deadline for the Commission to adopt limited-assurance standards moved to 1 July 2027. Auditors still perform evidence-based procedures under professional standards.

How much simpler are the revised ESRS?

The Commission reports reductions of over 60% in mandatory datapoints, over 70% in total datapoints, and over 30% in expected reporting cost per company. The standards still require double materiality, value-chain consideration, and auditable evidence. Fewer fields, but each one carries more weight.

5 Responses

Leave a Reply

Your email address will not be published. Required fields are marked *

Other related articles

Your Cart