CSRD Readiness Checklist 2026: 12 Steps from Gap Analysis to First Disclosure
CSRD is no longer a future problem. Here is the exact 12-step checklist EU-listed companies, large private firms, and non-EU groups with €150M+ EU revenue are using to move from "we should look at this" to a board-approved sustainability statement that survives limited assurance.
Reviewed by The QHSE Standard editorial team
Fact-checked against ISO 45001, OSHA, EU OSH Framework Directive, and CCPS guidance. Independent of vendor influence — see our review methodology.
The Corporate Sustainability Reporting Directive (CSRD) has stopped being a compliance horizon and become a quarterly board agenda item. If your first reporting year is FY2025 or FY2026, the runway is shorter than it looks: most teams underestimate data collection by 4–6 months and double materiality by another 2.
This is a practical readiness checklist — not a legal interpretation. It assumes you already know whether you are in scope (large EU undertakings, EU-listed SMEs, or non-EU groups generating >€150M in the EU with at least one EU subsidiary or branch). What follows is what to actually do, in order, with the artefacts each step must produce.
Quick facts
- In scope (Wave 1): ~11,700 large EU PIEs reporting on FY2024 data in 2025
- In scope (Wave 2): ~50,000 large EU undertakings reporting on FY2025 in 2026
- Datapoints: ~1,144 across 12 ESRS standards (E1–E5, S1–S4, G1, plus ESRS 1 & 2)
- Assurance: limited assurance from year 1, moving to reasonable assurance later this decade
- Penalties: member-state-defined; e.g. France up to €75,000 for non-publication, plus director liability
Step 1 — Confirm scope and reporting boundary
Document, in writing, whether your group reports under CSRD on a consolidated basis or per legal entity. List every subsidiary, branch, joint venture, and material associate. The boundary you fix here will drive every Scope 3 calculation, every workforce S1 datapoint, and every governance disclosure for the next decade.
Deliverable: signed scoping memo, reviewed by legal and group finance.
Step 2 — Run a double materiality assessment
Double materiality is the single biggest deviation from voluntary frameworks. You assess both:
- Impact materiality — how your activities affect people and the environment
- Financial materiality — how sustainability matters affect your enterprise value
You cannot copy a peer's matrix. EFRAG's IG 1 Materiality Assessment Implementation Guidance requires a documented process with stakeholder input, value-chain mapping, and quantified thresholds. Most companies need 8–14 weeks for a defensible first run.
See our companion guide: Double Materiality Assessment: A Step-by-Step Guide for CSRD.
Step 3 — Map material topics to ESRS datapoints
Once the matrix is signed, translate each material topic into the specific ESRS datapoints that apply. ESRS 2 (general disclosures) is mandatory regardless. The other 10 topical standards apply only where material.
Tip: The EFRAG XBRL taxonomy lists every datapoint with an ID (e.g. E1-6_01 for gross Scope 1 GHG emissions). Use these IDs as the primary key in your data architecture — auditors will thank you.
Step 4 — Gap-analyse current data availability
For every material datapoint, score data availability on a 0–3 scale:
| Score | Meaning |
|---|---|
| 0 | Not collected anywhere |
| 1 | Collected, but in spreadsheets without controls |
| 2 | Collected in a system, but not reconciled or audit-ready |
| 3 | Collected, controlled, audit-ready |
Anything scoring 0 or 1 needs a remediation owner, a deadline, and a data source decision before you start drafting the sustainability statement.
Step 5 — Build the GHG inventory (E1)
E1 is where most assurance findings will land. You need:
- Scope 1: direct emissions, by gas, by facility
- Scope 2: location-based and market-based, with the methodology disclosed
- Scope 3: all 15 categories assessed for materiality, material categories quantified
Spreadsheets break at Scope 3. A modern carbon accounting / ESG platform with supplier portals, emission-factor libraries, and audit trails is effectively mandatory at this stage.
Step 6 — Workforce data (S1)
S1 is the second-most assurance-heavy standard. You will need headcount in the average annual full-time equivalents definition (not month-end snapshots), broken down by gender, country, employment type, and contract type. Pay-gap calculations need a documented methodology, and collective-bargaining coverage must reconcile to your HRIS.
If your HRIS cannot export this without a manual rework every quarter, fix that integration now. Auditors will ask.
Step 7 — Value-chain workers, communities, consumers (S2–S4)
These standards require disclosures even when you have no direct contractual relationship. Plan stakeholder engagement well in advance — Indigenous community consultation, in particular, has long lead times in extractive industries. See our industry guide for mining for sector-specific patterns.
Step 8 — Governance and business conduct (G1)
G1 covers anti-corruption, whistleblowing, lobbying, and payment practices. Most groups already have policies; the gap is evidence of operating effectiveness. Pull case-management data from your ethics line, training completion from your LMS, and supplier due-diligence records — and reconcile them.
Step 9 — Choose the software stack
A defensible CSRD stack typically combines:
- A data layer — for raw activity data (energy bills, fuel cards, HRIS exports, supplier data)
- A calculation layer — emission factors, financial materiality scoring, pay-gap math
- A disclosure layer — XBRL tagging, narrative drafting, version control
- A controls layer — assignment, evidence, sign-off, audit trail
Some platforms cover all four; most groups end up with two integrated tools. Compare options in our ESG reporting software directory and our vendor comparison engine.
Step 10 — Draft the sustainability statement
The statement sits in the management report, in a clearly identifiable section. Structure it around ESRS 2 first (general), then each material topical standard. Use a single source of truth for every number — duplicated metrics in different sections are the most common assurance finding.
Step 11 — Pre-assurance dry run
Before the auditor arrives, run an internal dry run with the same scope as limited assurance. Test:
- Datapoint completeness against the materiality matrix
- Methodology disclosures (every estimate, every proxy, every emission factor)
- Internal consistency between narrative and tagged datapoints
- XBRL tagging against the EFRAG taxonomy
Budget 4–6 weeks. You will find issues. Better now than in March.
Step 12 — Board approval and publication
The sustainability statement is approved alongside the financial statements. Build the same governance routine: audit committee review, board approval, signed-off minutes. Publish in the management report and in the European Single Access Point format when available.
What to do this quarter
If you have not started, the highest-leverage actions in the next 90 days are:
- Sign off scope and reporting boundary (1 week)
- Kick off double materiality (8–14 weeks)
- Score data availability for the top 200 likely-material datapoints (4 weeks)
- Shortlist three ESG reporting platforms and run scoped demos against your real data (6 weeks)
CSRD rewards companies that treat it as a multi-year operating model change — not a one-off reporting project. Start the operating model conversation now and the FY2026 disclosure becomes a process step, not a fire drill.
Software covered in this category
Browse all platforms →- ESG & Sustainability4.5
Persefoni
AI-powered carbon accounting and climate management platform
Read review - ESG & Sustainability4.5
Novisto
Intelligent ESG data management
Read review - ESG & Sustainability4.4
Datamaran
AI-powered ESG risk and materiality analysis
Read review
Looking for the Right QHSE Software?
Take our 60-second quiz and get personalized recommendations.
Get Matched — Free