Logotipo Datanet iot

ESG Reporting Requirements: Who Owes What in 2026

Ninety-five percent of the world’s 250 largest companies now set carbon reduction targets, up from 80% just two years earlier. The S&P 500 hit 99% sustainability reporting participation in 2023. Those numbers suggest a mature, settled discipline. They obscure the real problem: most companies still can’t trace their reported data back to auditable source evidence. (See also: scope 2 emissions.)

Setting a target and defending the number behind it are different problems. The second one is what ESG reporting requirements actually test in 2026.

The regulatory map shifted fast. California started enforcing emissions disclosure for companies above $1B in revenue. The EU narrowed its CSRD perimeter through the Omnibus directive while keeping the core reporting architecture intact. The UK, Australia, Singapore, and Hong Kong are each building ISSB-based regimes on their own timelines. And the SEC proposed rescinding its 2024 climate disclosure rules while reminding filers that existing securities-law materiality obligations remain in force.

If you’re an ESG manager reconciling five frameworks, a CFO who just inherited sustainability data you didn’t ask for, or a mid-size supplier staring at a 40-page questionnaire from a Fortune 500 client, this is the practical map.

What ESG Reporting Requirements Mean in 2026

ESG reporting requirements are the legal, standards-based, and market-driven rules governing how companies disclose environmental, social, and governance information. Five years ago, that meant a PDF on your website. In 2026, it means a regulated information system with defined scope, controlled data, and external verification.

The system operates in three layers:

  1. Legal scope. A jurisdiction (EU, California, UK, Singapore) determines which companies must report, based on thresholds like revenue, employee count, listing status, or geography of operations.
  2. Reporting standard. A framework (ESRS, ISSB, GRI) defines what must be measured and disclosed: emissions, workforce data, governance structures, risks, targets, transition plans.
  3. Assurance. An auditor or assurance provider tests whether the reported information holds up against evidence, controls, and methodology.

Skip any layer and the report is either legally incomplete or technically indefensible.

The “E” covers climate emissions, energy use, water, waste, biodiversity, pollution, and resource consumption. The “S” covers workforce conditions, health and safety, diversity, human rights, community impact, and supply-chain labor practices. The “G” covers board composition, executive compensation, ethics, anti-corruption, risk oversight, and data governance.

Most regulatory attention in 2026 is concentrated on the E, specifically climate emissions. Social and governance disclosures are expanding, but the compliance machinery (audits, penalties, investor scrutiny) is heaviest around environmental data. That priority shapes which sustainability metrics get resourced first, which tools companies buy, and where enforcement actually bites. It also explains why a credible carbon reduction strategy increasingly sits at the center of these programs.

Close up of a technician using a data sensor on a solar panel to meet esg reporting requirements for technical accuracy.

The Jurisdiction Map: Where Mandatory Reporting Applies

There is no single global ESG reporting law. What exists is a stack of overlapping regimes, each with different thresholds, timelines, standards, and enforcement mechanisms. The first question any company should answer: which jurisdictions put me in scope?

United States: California leads, the SEC pauses

California’s SB253 is the most consequential US climate disclosure law in force. It targets companies doing business in California with annual revenue above $1 billion, requiring Scope 1 and 2 emissions reporting starting in 2026 and Scope 3 beginning in 2027. “Doing business in California” captures far more companies than those headquartered there.

SB261 casts a wider net. Public and private US companies above $500M in revenue doing business in California must file a climate-related financial risk report every two years. The first reports are already public. Radiology Partners published its SB261 climate-risk report covering 2025, structured around the TCFD four-pillar model and submitted to CARB. For private companies new to this obligation, that’s the template to study.

At the federal level, the SEC proposed in 2026 to rescind its 2024 climate-related disclosure amendments, stating that existing SEC requirements still elicit material climate information. The proposal would remove more granular standardized filing requirements, but companies remain obligated to disclose material climate risks under general securities law. This is a proposal, not a final rule. Don’t treat it as a done deal.

A note on politics: in some US states, the term “ESG” has become a partisan flashpoint. The compliance obligation doesn’t care about the label. Whether you call it sustainability reporting, climate risk management, or corporate resilience, the data requirements are the same. California’s law applies based on revenue, not vocabulary.

European Union: narrower scope, same architecture

The EU Omnibus directive adopted in February 2026 raised the CSRD threshold to companies with more than 1,000 employees and more than EUR 450M in net annual turnover. That significantly reduced the number of companies in direct scope compared to the original directive’s ambitions.

For companies that still meet the threshold, the reporting architecture is unchanged: European Sustainability Reporting Standards (ESRS), double materiality assessments, transition plans, and limited assurance. The European Commission confirmed that the first CSRD wave covers financial years starting in 2024, with later waves postponed and a quick-fix limiting extra data demands for 2025 and 2026.

The Omnibus also introduced protections for companies below the 1,000-employee threshold, reducing trickle-down reporting pressure from large buyers. Procurement teams can still request proportionate supplier data, but the blanket “40-page questionnaire for every SME” model now faces regulatory pushback.

The rest of the map

The UK proposes mandatory UK SRS 2 reporting (aligned with TCFD) for certain primary-listed companies from January 1, 2027. Australia began staged climate reporting for Group 1 entities in 2025, with Group 2 from mid-2026 and Group 3 from mid-2027. Singapore requires all listed companies to report, with Scope 3 staged in for STI constituents from January 2026. Hong Kong’s IFRS S2-based climate requirements became effective January 2025, with LargeCap issuers facing Scope 1 and 2 mandates first.

Jurisdiction Key law or standard Threshold Scope 3 required? Assurance
California (SB253) GHG emissions disclosure >$1B, doing business in CA Yes, from 2027 Third-party verification
California (SB261) Climate financial risk >$500M, doing business in CA Risk-based narrative Not specified
EU (CSRD post-Omnibus) ESRS, double materiality >1,000 employees + >EUR 450M If material Limited assurance
United Kingdom UK SRS 2 (TCFD-aligned) Certain primary-listed cos. Phased Phased
Australia Staged climate reporting Group 1, 2, 3 by size Phased Limited to reasonable
Singapore ISSB-based climate All listed; large non-listed phased STI from 2026 External, phased
Hong Kong IFRS S2-based climate Listed; LargeCap first Phased Phased

The common thread across every regime: mandatory is the new default. The voluntary era ended when legislators attached revenue thresholds and audit requirements to sustainability data.

Frameworks Decoded: GRI, ISSB, ESRS, TCFD, and GHG Protocol

Five frameworks dominate the conversation, and they don’t all ask the same question. Understanding which one applies (and when you need more than one) is the difference between a coherent program and a reporting treadmill.

Framework Core question Orientation Typical use
GRI How does the organization impact people, environment, and the economy? Impact and stakeholder Broadest sustainability reporting; founded in 1997, still the most adopted globally
ISSB (IFRS S1/S2) Which sustainability risks could affect enterprise value? Investor and capital markets Global baseline; 36 jurisdictions had adopted or were progressing toward ISSB use by mid-2025
ESRS What are material impacts, risks, and opportunities under double materiality? Both impact and financial Mandatory for EU CSRD-scope companies
TCFD How do governance, strategy, risk management, and metrics address climate? Climate risk structure Embedded in UK, Australian, and many ISSB-aligned regimes
GHG Protocol What are the direct, energy, and value-chain emissions? Emissions measurement The calculation layer used by every framework above

GRI tells you about impact. ISSB tells you about financial risk. ESRS does both through double materiality. TCFD structures the climate conversation. GHG Protocol provides the math underneath all of them.

Companies serving both EU and capital-market audiences will likely need ESRS for impact and ISSB for investor-grade data. The practical advice: don’t choose one framework rhetorically. Build one controlled data model, identify reusable metrics across frameworks, and document where the materiality tests diverge.

Double materiality, explained plainly

EFRAG defines the double materiality assessment as understanding context, identifying impacts, risks, and opportunities, assessing which are material, and documenting the results. In practice, it means two directions of analysis: how sustainability issues affect your financials (financial materiality) and how your operations affect the world (impact materiality).

A company that only considers financial risk might skip water pollution because it doesn’t move the balance sheet. Under double materiality, that pollution is reportable if it materially harms a community or ecosystem, which is why a rigorous environmental impact assessment matters here. The methodology, stakeholder inputs, severity assessments, and management decisions all need to be documented well enough that an auditor can retrace the logic. This is not a workshop exercise. It’s a legal process.

Scope 1, 2, and 3: Where Most Programs Break

The GHG Protocol defines three emission scopes. Scope 1 covers direct emissions from owned or controlled sources: your boilers, your fleet, your manufacturing lines. Scope 2 covers indirect emissions from purchased electricity, steam, heat, or cooling. Scope 3 covers everything else in the value chain: purchased materials, transportation, waste, business travel, employee commuting, downstream product use, and more.

Scope 1 and 2 are manageable for most companies. You control the sources. You have utility bills, fuel invoices, meter readings. The data exists or can be created with reasonable effort.

Scope 3 is where programs collapse.

It spans suppliers and customers who operate on different systems, use different accounting periods, apply different emission factors, and may have no reporting capability whatsoever. In fact, Scope 3 emissions often dwarf a company’s direct operational footprint. California SB253 requires it from 2027. Singapore requires it for STI constituents from 2026. CSRD requires it when it’s material. Investors increasingly expect it regardless of mandate.

The mid-size supplier problem is worth calling out. If you supply a Fortune 500 company in California, expect detailed questionnaires demanding energy data, material sourcing records, and transport emissions for every product category. That pressure will intensify as Scope 3 deadlines arrive, making supply chain sustainability a shared obligation. The EU’s Omnibus SME protections help limit some of these demands, but they don’t eliminate them.

The practical response: start before you need to. Map your major supply-chain categories. Identify which data you can measure directly (fuel records, electricity meters, freight manifests) and which requires industry-average estimates. Document methodology. Flag data gaps explicitly. An auditor would rather see a clearly labeled estimate with transparent assumptions than a precise-looking number with no source behind it.

Assurance: From Add-On to Legal Requirement

A sustainability report without assurance is an opinion. Regulators are making that distinction legally binding.

CSRD requires limited assurance for sustainability reports, with the European Commission mandated to adopt formal limited-assurance standards by July 2027. Statutory auditors, audit firms, or approved sustainability assurance partners can perform the work under the EU framework. The IAASB’s ISSA 5000 standard, effective for periods beginning December 15, 2026, provides a global reference for sustainability assurance across topics, frameworks, and practitioner types.

Limited assurance involves less extensive procedures and a lower confidence level than reasonable assurance. “Lower” doesn’t mean cosmetic. The provider still tests controls, traces samples to source data, evaluates completeness, and challenges estimates. If your Scope 2 emissions rely on a spreadsheet that one analyst updates quarterly with no version control and no second review, that’s a finding waiting to happen.

What “audit-ready” requires in practice:

  • Access controls: who can enter, edit, approve, and export data
  • Change logs and version history for every reported metric
  • Source documentation for activity data (invoices, meter reads, freight records, sensor logs)
  • Emission-factor versioning and documented justification for factor choices
  • Estimation methodology for data gaps, with explicit uncertainty flags
  • Management review and sign-off before disclosure

Companies that wait for the auditor to discover control gaps will face more expensive remediation and risk delayed or qualified reporting. Build the controls before you build the report.

Three Enforcement Cases Every ESG Team Should Study

The lesson from recent enforcement is consistent: the claim must match the process, and the process must match the evidence. Here are three cases that illustrate the pattern.

In 2023, the SEC imposed a $19 million ESG-related penalty on DWS (a Deutsche Bank subsidiary) for materially misleading statements about its ESG investment controls. The firm publicly described an integration process it hadn’t actually implemented. Total penalties reached $25 million when combined with a separate AML matter. The gap was between policy language and operational reality.

Goldman Sachs Asset Management paid $4 million over ESG marketing for mutual funds and a separately managed account. The SEC found that from 2017 through February 2020, the firm either lacked a written ESG policy or failed to follow it consistently. In some instances, ESG questionnaires were completed after securities had already been selected. The marketing said one thing. The investment process did another.

In 2024, the SEC charged Keurig Dr Pepper with inaccurate statements about K-Cup recyclability, resulting in a $1.5 million penalty. The company cited testing that validated recyclability, but didn’t disclose that the two largest recyclers in the country weren’t actually accepting the cups. A favorable lab result, absent real-world verification, became a misleading claim.

Three different industries, three different types of ESG claims, one common failure: the evidence trail couldn’t support what the company told the public. ESG reporting is not branding. It is a controlled information process, and enforcement treats it that way.

How to Build an ESG Reporting Program That Holds Up

Start with jurisdiction scoping, not framework shopping. List every legal entity, its country of incorporation, listing status, revenue, employee count, and where it does business. Map each entity to the applicable regime. Only after that exercise should you select reporting standards and allocate resources.

Run one controlled data model, not parallel spreadsheets. The single most wasteful pattern in ESG reporting is maintaining separate data collection pipelines for GRI, ISSB, CSRD, CDP, and every investor questionnaire. Build one source of truth. Tag each datapoint by framework relevance. Generate different outputs from the same controlled inputs. This also simplifies restatement and reconciliation when (not if) numbers need correction.

Automate the operational data layer. The weakest link in most ESG programs isn’t the reporting template or the framework mapping. It’s the data that comes from operations: energy consumption at facilities, temperature and humidity records in perishable supply chains, water usage, equipment utilization, transport movement. If that data still arrives via quarterly manual readings, forwarded utility bills, or supplier estimates re-keyed into spreadsheets, that’s where audit risk concentrates.

IoT sensors and connected tracking devices close a significant portion of that gap. Continuous, automated wireless environmental monitoring replaces guesswork with timestamped, traceable readings. Asset tracking across supply chains provides the utilization and movement data needed for Scope 3 calculations. The data flows from source to reporting system without a human re-keying step. That’s not a technology preference; it’s a control improvement. If your environmental data infrastructure needs work, our environmental tracking devices are built for exactly this layer of the problem.

Document materiality like a legal proceeding. Record stakeholder inputs, sector context, severity and likelihood assessments, financial-risk channels, management decisions, and exclusions. The board (or a delegated committee) should approve the methodology and sign off on significant scope decisions. This documentation is the first thing an assurance provider will request.

Get assurance-ready before you need assurance. Implement access controls, change logs, source documentation, and review workflows from day one. Retrofitting controls into a system built on trust and email approvals is slower and more expensive than building them correctly the first time.

If you’re navigating this for the first time, or your current program runs on good intentions and duct tape, talk to our team. We build the data infrastructure that makes ESG numbers defensible: info@datanetiot.com.

Wide view of offshore wind turbines and an industrial port illustrating global esg reporting requirements and sustainability.

Frequently Asked Questions

What are ESG reporting requirements?

They are the legal, standards-based, and market-driven rules governing disclosure of environmental, social, and governance information. Depending on the jurisdiction and applicable standard, they can cover greenhouse gas emissions, climate risks, workforce conditions, human rights, governance practices, biodiversity, and transition plans. Requirements range from regulatory filings and public reports to mandatory platform responses.

Which companies must comply with ESG reporting in 2026?

Thresholds vary by jurisdiction. The EU’s post-Omnibus CSRD covers companies exceeding 1,000 employees and EUR 450M in turnover. California SB253 applies above $1B in revenue for companies doing business in the state; SB261 applies at $500M. The UK, Australia, Singapore, and Hong Kong each define scope through listing status, entity size, or revenue. Check every jurisdiction where your legal entities operate or do business.

Is the SEC climate disclosure rule still in effect?

The SEC proposed rescinding its 2024 climate-related disclosure amendments in 2026, but the proposal has not become a final rule. Existing SEC requirements still obligate companies to disclose material climate information under general securities law. Companies should continue assessing material climate risks while monitoring the final rulemaking.

Do companies have to report Scope 3 emissions?

It depends on jurisdiction. California SB253 requires Scope 3 from 2027. Singapore stages it for STI constituents from 2026. Under CSRD, Scope 3 is required when material. Many investors, rating agencies, and target-setting methodologies also expect it regardless of legal mandate. The practical advice: start building supplier data and estimation methods now, not after the deadline.

What is double materiality?

Double materiality assesses sustainability topics from two directions: whether they create financial risks or opportunities for the company (financial materiality) and whether the company’s operations materially impact people or the environment (impact materiality). It’s mandatory under CSRD and ESRS. The assessment methodology, stakeholder inputs, and conclusions must be documented for audit review.

What level of assurance is required for ESG reports?

CSRD currently requires limited assurance, with EU standards due by July 2027. The IAASB’s ISSA 5000, effective December 15, 2026, provides a global standard for both limited and reasonable assurance engagements. Neither level repairs weak source data. Companies should build internal controls (access rights, change logs, estimation governance, source documentation) before the assurance engagement begins, not during it.

5 Responses

Leave a Reply

Your email address will not be published. Required fields are marked *

Other related articles

Your Cart