top of page

Sustainability Regulation 2026: Between relief and the new rules of the game for small and medium-sized enterprises

21 hours ago
3 min read

Let’s be honest: who can actually make head or tail of the jumble of regulatory acronyms coming out of Brussels? Following a dynamic year in 2025, the EU simplification deal (Omnibus procedure) in particular has noticeably reshaped the landscape of sustainability reporting and supply chain requirements.


The all-too-common reaction – “We’re off the hook for the CSRD, so we’re in the clear” – is a dangerous fallacy. The reality is this: whilst the direct bureaucratic pressure on traditional reporting for the wider SME sector is easing, product- and supply chain-related obligations apply regardless of company size and are now the direct focus of market surveillance.


A look at the current status quo reveals what matters most right now.


1. CSRD & ESRS: The small circle and the underestimated data obligation


The Omnibus I Directive has focused the direct CSRD reporting obligation on companies with more than 1,000 employees and a turnover exceeding EUR 450 million. Capital market-oriented SMEs are excluded for the time being.


However, for those directly affected, the revised ESRS (adopted in July 2026) – whilst reducing the number of mandatory data points by 61 per cent and adopting a pragmatic top-down approach – significantly shifts the audit focus towards dual materiality and the well-founded justification of excluded topics.


The golden rule for 2026: 2026 is the key year for data. As the reports for the 2027 financial year will be audited in accordance with the new ISSA [DE] 5000 standard for the first time in 2028, it is essential that the data collection systems and internal controls (ICS) are in place by 1 January 2027. Anything that is not documented in 2027 cannot be reconstructed retrospectively.


2. Beyond the CSRD: When market and product access is regulated


Even companies that will never be directly affected by the CSRD face strict regulatory constraints. In such cases, it is not the report that is penalised, but market access itself (through sales bans, product recalls or substantial fines):


  • EmpCo Directive (from September 2026): Claims such as ‘climate-neutral’ are prohibited under the Unfair Commercial Practices Act (UWG) without robust evidence; compensation-based climate neutrality for products is effectively banned. This applies to any company with advertising or an online presence.

  • PPWR (since August 2026): Packaging requires immediate conformity assessments and EU-wide EPR registrations.

  • EUDR & CBAM: Strict due diligence obligations apply to imported raw materials (wood, soya, coffee, etc.), with requirements for geodata evidence and drastic sanctions, including the seizure of goods.


3. Relief provided by the VSME and the ‘Value Chain Cap’


There is good news for small and medium-sized enterprises (SMEs) regarding the supply chain cascade: the Voluntary Standard (VS), adopted in July 2026, acts as an effective safeguard. Large companies subject to reporting requirements may not demand anything from smaller partners (< 1,000 employees) that goes beyond this Comprehensive Module.


At the same time, however, the EBA guidelines on ESG risk management for banks require structured data from borrowers. SMEs would be well advised to use this standard as a standardised interface, rather than getting bogged down in uncoordinated Excel queries.


Conclusion: Set up systems now, rather than putting it off


The regulatory changes do not mean the all-clear, but rather a shift in complexity. Any company – whether directly subject to reporting requirements or a key part of the supply chain – that starts 2027 unprepared risks some bitter surprises in the 2028 audit year.


Use 2026 as a strategic dress rehearsal: carry out the materiality analysis now, establish reliable data sources and review your communication and packaging processes.


Do you have any questions about the practical implementation of the new standards or about preparing for the audit in accordance with ISSA [DE] 5000? Please feel free to get in touch; we’ll guide you pragmatically through the regulatory changes.

 

 
 
 

Comments


bottom of page