Intel Feed
Climate DisclosureCSRDSECESRSGHG ProtocolAssurance

Institutional Guide to CSRD & SEC Climate Disclosure Compliance

Sustainability teams are building disclosure infrastructure for two regimes moving in opposite directions. CSRD is active; the SEC's 2024 rule faces proposed rescission. Both still demand parallel data infrastructure.

C100 Editorial Team

Summary

  • 01CSRD is live and enforced; the SEC federal rule is heading toward rescission, but California SB 253 and other state and international mandates fill the gap for US institutions.
  • 02Complete the double materiality assessment before any other ESRS disclosure work — plan 12 months of lead time.
  • 03Assurance procurement is the most under-estimated dependency: contract the provider before data collection begins.
  • 04Compliance tools measure what you emit and report; institutions still need external benchmarking against carbon economy indices.
  • 05Build data infrastructure around the GHG Protocol and ESRS E1 now; treat regulatory template changes as a configuration problem, not a rebuild.

Two regimes moving in opposite directions

Your sustainability team is building disclosure infrastructure for two regimes moving in opposite directions. The EU's Corporate Sustainability Reporting Directive (CSRD) is actively enforced, while the SEC proposed full rescission of its 2024 climate rule in May 2026. At C100, this regulatory split is the defining challenge we see across institutional builds in 2026 — and both regimes still demand parallel data infrastructure regardless of where Washington lands.

What's the difference between CSRD and SEC climate disclosure?

CSRD is a broad sustainability mandate; the SEC rule was a narrower climate-risk disclosure, and its federal future is now genuinely uncertain.

The CSRD, adopted in January 2023, requires large companies to report sustainability data under the European Sustainability Reporting Standards (ESRS). Its defining feature is "double materiality": companies must report both how sustainability issues affect their business financially and how their activities affect society and the environment.

The SEC finalized its climate disclosure rules in March 2024, requiring public companies to report on material climate-related risks, governance, and strategy, including Scope 1 and 2 emissions. The Commission is now proposing to rescind those rules entirely, arguing they exceed the agency's statutory authority. A final rescission vote is unlikely before late 2026 or early 2027.

Who is actually in scope?

The EU's Omnibus I package, finalized through a Council-Parliament agreement in December 2025 and officially published in February 2026, introduced major changes. The scope now applies to EU companies with more than 1,000 employees and over €450 million net turnover. For non-EU multinationals, the mandatory threshold is parent company revenue exceeding €450 million in net EU turnover generated for two consecutive years.

Why institutions can't ignore either regime

The proposed SEC rescission doesn't eliminate climate-reporting obligations for many US companies. State laws, international disclosure regimes, and global reporting standards continue to expand, with several compliance deadlines already close.

California's SB 253 requires Scope 1 and 2 emissions reporting by August 10, 2026 (Harvard EELP, 2026), for companies with over $1 billion in annual revenue. A multinational bank with EU subsidiaries and US operations faces CSRD filing obligations regardless of what Washington does next.

CSRD vs. SEC Climate Rule — Side by Side

DimensionCSRDSEC Climate Rule (2026 status)
StatusActive, enforcedProposed rescission; not enforced
Scope trigger1,000+ employees, €450M+ turnoverUS public companies (stayed)
Emissions requiredScope 1, 2, 3Scope 1 and 2 only (if material)
Materiality standardDouble materialityFinancial materiality only
AssuranceLimited assurance mandatoryPhased-in (if rule survives)
Reporting standardESRSTCFD-aligned

Building disclosure infrastructure for both regimes

The architecture has three layers: data collection, governance, and reporting workflows. Get the order wrong and you'll spend months rebuilding.

Data collection: emissions accounting at scale

The Greenhouse Gas Protocol (GHG Protocol) is the globally accepted methodology for categorizing emissions into Scope 1 (direct), Scope 2 (energy purchased), and Scope 3 (value chain). Both CSRD and the SEC rule reference it, so your measurement methodology should be GHG Protocol-aligned from day one.

Scope 3 is where most institutions hit a wall. CSRD requires Scope 3 data from suppliers, customers, and recyclers, making it both the most material and most difficult element of the corporate carbon footprint. A global asset manager must collect financed emissions data across hundreds of portfolio companies, many of which have no emissions tracking at all. Start with spend-based estimates and build toward primary data over two to three reporting cycles.

Governance: board ownership is not optional

Under both frameworks, board directors must identify any committee responsible for oversight of climate-related risks and describe the processes by which the board is informed about such risk plans. The practical failure mode we see repeatedly: sustainability teams build the data infrastructure while the board receives a one-page summary at year-end. That's reporting theatre, and it fails assurance.

Assign a named board-level owner before the first materiality assessment. Audit committees at large EU banks are increasingly treating climate data with the same review cadence as financial statements.

A concrete illustration: a Wave 2 filer beginning its double materiality assessment in Q1 2025 for a 2025 fiscal year filing needs an assurance provider contracted by Q3 2025 and data locked by October 2025. That leaves roughly 10 weeks for the assurance review before the filing window opens. Teams that treat board sign-off and assurance as sequential steps rather than parallel workstreams routinely discover this too late to recover.

Reporting workflows: the dependency most teams miss

Assurance, starting at limited level and moving toward reasonable assurance, is mandatory under CSRD. This creates a timing trap: CSRD's assurance requirement forces data lock-in 10 to 12 weeks earlier than the filing deadline. Teams that treat assurance as a final-step sign-off rather than a parallel workflow routinely miss it.

The double materiality assessment (DMA) must precede all other ESRS disclosures. It determines which ESRS standards you must disclose, so run it 12 months before your first filing. The stakeholder engagement alone takes longer than most legal teams budget.

The most common compliance failures

Most institutional CSRD failures aren't technical — they're sequencing errors.

  • Scope 3 boundary-setting done too late — teams frequently define their Scope 3 boundary after the DMA, when it should inform it. Regulators accept imperfect data with a plan; they don't accept silence.
  • Misaligned materiality between CSRD and SEC definitions — run the two assessments separately, then map the overlap.
  • Delayed assurance procurement — the first wave of roughly 11,000 companies (Risk Publishing, 2026) consumed significant assurance capacity in 2025. Contract by Q3 of the year preceding your filing.
  • Data quality failures at audit — require activity-level data (not summary-level) for at least Scope 1 and 2, with documented methodology for every Scope 3 category included.

Evaluating climate disclosure software and service providers

The build-vs-buy decision is simpler than vendors make it sound: if your first CSRD filing is within 18 months, buy or license. Building a compliant GHG accounting engine from scratch takes longer than that, and methodology updates alone require ongoing maintenance.

The right questions aren't about dashboards. Ask whether the platform handles both CSRD and SEC workflows natively, or forces workarounds for one. Ask how it ingests supply chain emissions data at scale, particularly for financed emissions under the Partnership for Carbon Accounting Financials (PCAF) standard. Ask whether the DMA workflow is built in or bolted on.

Persefoni has positioned itself as a SaaS-based carbon accounting option for financial institutions, with financed emissions modules aligned to PCAF and audit-grade ledger functionality. Persefoni serves four of the world's 10 largest private equity firms and four of the 20 largest banks — a breadth that reflects genuine institutional demand for specialized tooling.

One limitation worth naming: tools focused on internal compliance reporting measure what you emit and how you report it. They don't measure how your disclosed performance compares to peers or to market benchmarks. That external performance context — tracked through carbon market indices and signals — is what institutional investors use to benchmark disclosed figures against real-world carbon economy performance.

Build vs. Buy vs. Hybrid

ApproachBest forKey riskTypical time-to-first-filing
Buy (integrated suite)First filing within 18 monthsVendor lock-in, limited customisation3–6 months
Best-of-breed point solutionsMature programmes with existing ERPIntegration complexity, data silos9–14 months
Hybrid (platform + consultancy)Complex multinationals, multiple jurisdictionsCost, governance fragmentation6–10 months

Five questions to ask any vendor

  1. 01

    PCAF financed-emissions support

    Does the platform calculate financed emissions natively across asset classes, or does it require manual input and external spreadsheets? Ask for a live demonstration using a sample portfolio.

  2. 02

    DMA workflow

    Is the double materiality assessment module built into the core product, or is it a bolt-on requiring separate configuration? A bolt-on DMA creates data handoff risk at the step that determines your entire disclosure scope.

  3. 03

    Audit trail granularity

    Can the platform produce activity-level evidence for every calculation, traceable to source documents? Summary-level audit trails fail under limited assurance review.

  4. 04

    ESRS template update cadence

    How quickly does the vendor push regulatory template changes after Brussels publishes revisions, and who bears the implementation cost? Omnibus I alone required significant template rework.

  5. 05

    Multi-jurisdiction reporting

    If you have California SB 253 obligations alongside CSRD, can the platform generate both outputs from a single data set, or does it require duplicate data entry?

Frequently Asked Questions

Do CSRD and SEC rules require the same emissions calculation methodology?

No. Both reference the GHG Protocol as a foundation, but CSRD's ESRS E1 requires Scope 3 disclosures and a double materiality assessment, while the SEC rule (as originally adopted) required only material Scope 1 and 2 emissions. Running separate methodology documentation for each regime is essential, even where the underlying activity data overlaps.

What happens if an institution misses a CSRD filing deadline or fails assurance?

Take a large EU bank that submits its sustainability statement without completing limited assurance: the filing is technically non-compliant, and member-state enforcement bodies can impose penalties scaled to the gravity and duration of the breach. For institutions with ESG-labelled funds, the reputational consequence typically arrives before any formal sanction does.

Is third-party assurance required under both CSRD and the SEC rule?

Yes for CSRD, where limited assurance is mandatory from the first filing and reasonable assurance phases in over time. For the SEC rule, assurance was required on a phased basis for larger filers, but with the rule's proposed rescission in May 2026, that requirement is effectively suspended at the federal level.

How often do CSRD requirements change, and how should institutions future-proof their infrastructure?

The Omnibus I Directive, published in February 2026, already narrowed CSRD's scope significantly and reduced mandatory data points by roughly 61% (Normative, 2026) compared to the original ESRS. Build your data infrastructure around the GHG Protocol and ESRS E1 climate standards as the stable core, and treat everything else as configurable.

When does CSRD apply to non-EU multinationals?

Under the Omnibus I update, non-EU parent companies with over €450 million in EU net turnover for two consecutive years fall in scope, with reporting obligations applying to financial years starting on or after January 1, 2028. EU subsidiaries of non-EU groups may already be in scope as large undertakings in their own right, so check your subsidiary structure before assuming 2028 is your start date.

Can a single materiality assessment satisfy both CSRD and SEC requirements?

It can inform both, but it cannot satisfy both. CSRD's double materiality requires assessing impact on society and the environment, a lens the SEC's financial-materiality standard doesn't require. Treating one assessment as sufficient for both filings is the single most common error in cross-jurisdictional compliance programmes.

What is the practical difference between limited and reasonable assurance under CSRD?

Limited assurance is the starting requirement: the auditor concludes that nothing has come to their attention indicating the sustainability statement is materially misstated. Reasonable assurance, phased in later, requires the auditor to positively conclude the statement is materially correct — a much higher evidence bar. Moving from one to the other typically takes two to three years of improving data quality and internal controls.

This Intel Feed post is published by the Carbon Index Protocol editorial team for informational purposes only. It is not legal, tax, or investment advice. Regulatory positions cited are current as of the publication timestamp above and may change.

Data Sources

Where this intelligence comes from

Full registry