How to Evaluate Carbon Footprint Software When Your Reporting Obligations Keep Moving

Bottom line: the CSRD Omnibus removed roughly 80% of companies from mandatory scope, but it did not remove the demand for carbon data.

Buyers should now evaluate platforms on whether they can serve several masters at once rather than on how well they produce one regulator’s report.

Sustainability teams that specified a tool against a fixed 2025 compliance deadline are re-examining that decision.

The obligation may have moved, and in many cases the underlying data requirement has not.

Key Takeaways

  • Revised CSRD thresholds now apply mainly to EU companies with more than 1,000 employees and over €450 million net turnover.
  • Wave 2 first reports moved to financial year 2027, published in 2028, and listed SMEs were removed from scope entirely.
  • Falling out of mandatory scope rarely removes the data requirement, because customers, banks and investors still ask.
  • Value chain partners under 1,000 employees can now refuse requests exceeding a voluntary standard, which changes how Scope 3 primary data is collected.
  • Multi-entity consolidation and audit trail are the two capabilities that break first at enterprise scale.
  • Evaluate against several frameworks at once rather than the single regulation driving today’s deadline.

The scope question changed; the data question did not

The Omnibus package landed in February 2025 and reached final publication in February 2026. Revised thresholds now capture EU companies above 1,000 employees and €450 million net turnover, alongside non-EU groups exceeding €450 million of EU turnover, which reduced the in-scope population by roughly 80%.

The timeline shifted with it. Wave 2 companies now report on financial year 2027 rather than 2025; listed SMEs came out of scope, and non-EU groups begin with financial year 2028 for publication in 2029.

Several things did not change. Wave 1 companies continue reporting for financial years 2025 and 2026 unless their member state legislates an exemption, and member state transposition is not due until March 2027.

More importantly, the reasons carbon data gets requested are largely independent of CSRD. California SB 253, ISSB adoption across a growing list of jurisdictions, CDP disclosure, SBTi validation, and customer procurement questionnaires all continue on their own timetables.

What actually breaks at enterprise scale

Most platforms calculate emissions competently. The failures happen elsewhere, and they cluster in four places.

Multi-entity consolidation is the first. A group with subsidiaries across several countries needs rollups by entity, region, and currency, and tools built around a single legal entity require manual reconciliation that eats the time savings.

Audit trail is the second and the most commonly underestimated. Assurance requires tracing a filed figure back to its raw input, the emissions factor applied, the methodology version, and who approved it, and a platform that produces a number without that lineage creates work rather than removing it.

Framework mapping is the third. Reporting the same dataset to CSRD, CDP, GRI, ISSB, and SB 253 should be a mapping exercise from one trusted source rather than five separate collection cycles.

Scope 3 supplier data is the fourth, and the hardest. Spend-based estimates satisfy an early baseline but rarely an assurance process, and replacing them requires a workflow that thousands of suppliers across dozens of markets will actually complete.

This is where the distinction between a calculator and a platform becomes practical rather than semantic.

Carbon footprint software evaluated only on calculation accuracy will pass the demo and fail the second reporting cycle, which is why Sweep, the sustainability intelligence platform, is built around the data model, traceability and supplier workflow rather than the calculation engine alone.

Its approach reflects that emphasis. Multi-entity, multi-region and multi-currency rollups, emissions factors drawn from the GHG Protocol, IPCC, EPA, ADEME and Exiobase, full traceability from filed figure to original source with version history, and supplier interfaces designed for primary Scope 3 collection at scale.

The Scope 3 problem just became harder

One Omnibus provision deserves more attention than it has received. Value chain companies with up to 1,000 employees can now refuse information requests that exceed the content of a voluntary reporting standard, based on the existing VSME framework.

The intent was to protect smaller suppliers from disproportionate requests. The effect is that in-scope companies have less leverage to obtain granular primary data from exactly the suppliers where Scope 3 emissions concentrate.

That raises the value of supplier engagement done well. A portal that makes submission straightforward, reuses previously submitted data and asks only for what is needed will outperform a spreadsheet request that a supplier is now entitled to decline.

Questions worth asking a vendor

Ask how the data model handles your organisational structure rather than accepting a generic answer about flexibility. A group that reorganises, acquires or divests needs a structure that adapts without a re-implementation.

Ask to see the audit trail on a single figure, end to end. Request a live trace from a filed disclosure back to source data, factor, methodology version, and approver, because this is the capability most likely to be described well and demonstrated poorly.

Ask which frameworks map from one dataset, and how new ones get added. Regulatory requirements are still moving, and the cost of a platform that requires separate collection per framework compounds every year.

Conclusion

The regulatory picture will keep moving, which is itself the most useful planning assumption available. 

A platform chosen against one deadline will be evaluated against several others within a few years.

Assess the capabilities that survive regulatory change. A data model that matches your organisational structure, an audit trail that holds up under assurance, supplier workflows that suppliers will actually complete, and framework mapping from a single trusted dataset.

Those four hold their value whether your next report is mandatory, contractual, or investor-driven. 

The specific regulation driving today’s deadline is the least durable thing to build a decision around.

Frequently asked questions

Are we still required to report under CSRD? It depends on size and member state transposition. Revised thresholds apply mainly to EU companies above 1,000 employees and €450 million net turnover, though Wave 1 companies generally continue reporting for financial years 2025 and 2026 unless their member state legislates an exemption.

If we fall out of scope, should we stop collecting carbon data? Rarely advisable. Customers, banks, investors and other regulatory regimes continue to request the same data, and rebuilding a programme is more expensive than maintaining one.

What is the difference between a carbon calculator and a sustainability intelligence platform? A calculator produces an emissions figure. A platform manages the data model, audit trail, supplier collection, and framework mapping around that figure, which is what assurance and multi-framework reporting require.

How should we handle Scope 3 when suppliers can decline requests? Focus effort on the suppliers representing the largest share of emissions, and make submission as low-friction as possible. Reusing previously submitted data and requesting only what is material improves response rates materially.

Does product-level carbon data matter if we only report at corporate level? Increasingly, yes. Retailers and business customers request verified product carbon footprints and Environmental Product Declarations independently of corporate disclosure obligations.

When will simplified ESRS apply? EFRAG published draft simplified standards in December 2025, with application expected from financial year 2027. Assurance standards are due by July 2027.