Graphic of a Product Life Cycle which ist monitored within a LCA, PCF and EPD
02.07.2026

LCA vs. PCF vs. EPD: What Are the Differences and When Do You Need Which Tool?

LCA vs. PCF vs. EPD: Anyone working with product environmental impact will quickly come across these three abbreviations. But what do they mean? When does each tool make sense? This article gives you an overview. Plus: What role does the CCF play?

LCA vs. PCF vs. EPD: an overview

Before we take a closer look at each tool for calculating and presenting product environmental impact, we want to give you a brief overview in table form. This way, you can see at a glance what to consider when comparing Product Carbon Footprint vs. Life Cycle Assessment vs. Environmental Product Declaration.

PCF LCA EPD
Written out Product Carbon Footprint Life Cycle Assessment Environmental Product Declaration
What does it measure? Greenhouse gas emissions from a product, expressed in CO₂e Multiple environmental impacts: climate, water, resources, acidification, land use, and more A product environmental profile, third-party verified and published
Standard ISO 14067 ISO 14040, ISO 14044 ISO 14025, EN 15804 (construction)
Verification Optional Optional Mandatory third-party verification
Impact scope Climate Multiple impact categories Multiple, depending on the product category

LCA vs. PCF vs. EPD: the tools briefly explained

Let’s now take a closer look at PCF, LCA, and EPD. PCF, LCA, and EPD all describe product environmental impacts, but in different ways. One measures only climate impact, another covers a whole set of impacts, and the third presents results in a publicly comparable format. If you mix them up, you may end up providing too much or too little. Here are the three in detail:

Product Carbon Footprint (PCF)

The Product Carbon Footprint (PCF) measures only a product’s greenhouse gas emissions, expressed in CO₂e. The established standard here is ISO 14067. A PCF is especially useful when customers ask for specific CO₂ values, CBAM data is required, or a climate hotspot needs to be identified. By the way: The PCF should not be confused with the Corporate Carbon Footprint, which refers to the entire company. However, the PCF can feed into the CCF.

Life Cycle Assessment (LCA)

When it comes to LCA vs. PCF, one thing is clear: the Life Cycle Assessment goes far beyond the PCF. It looks not only at climate impact in the form of emissions, but also at water consumption, resources, acidification, and land use. Common standards here include ISO 14040 and ISO 14044. When deciding between Product Carbon Footprint vs. Life Cycle Assessment, the LCA is especially useful when you want to make product decisions across several environmental impacts, for example in redesign or material selection.

Environmental Product Declaration (EPD)

When comparing LCA vs. PCF, the EPD also comes into play. An Environmental Product Declaration is a third-party verified, public document based on an LCA. The classic standard for this is ISO 14025, while construction products, for example, are also subject to EN 15804. An EPD is often necessary when you want to communicate environmental data externally — in tenders, for building certifications, or to customers who require verified comparability.

Put simply: The LCA is the comprehensive method for calculating product environmental impact. The PCF is the climate-related part within the LCA. And the EPD is the verified format for public communication.

And the CCF?

The Corporate Carbon Footprint (CCF) does not quite fit into the LCA vs. PCF vs. EPD comparison because it does not look at a single product, but at greenhouse gas emissions from an entire company. It is calculated across Scopes 1, 2, and 3 based on the GHG Protocol, from office heating to the supply chain. PCF and CCF complement each other: product data from the PCF can feed into the Scope 3 part within the CCF. You can learn how to calculate your Corporate Carbon Footprint in our blog post on the CCF.

CCF not yet calculated?

Here is your guide on how to it works!

LCA vs. PCF vs. EPD: Which one do you need when?

Whether a PCF is enough or whether you need an LCA or EPD depends on the reason behind the request: Who is asking, what are the data needed for, and what format must the results ultimately take? This is a good way to determine whether a PCF is sufficient, an LCA is necessary, or an EPD is required. Three questions usually lead you to the answer quickly:

1. Who is asking, and for what purpose?

If the request comes from a customer’s procurement team, it is usually about CO₂ data for that customer’s own Scope 3 inventory or supply chain reporting. A PCF is sufficient. If it is about a public tender or building certification, an EPD is usually required. If it is about internal product decisions, an LCA provides the more robust basis.

2. Is a CO₂-only view enough, or do several environmental impacts need to be considered?

For CBAM, decarbonization strategies, and most customer requests, the PCF is sufficient. Anyone comparing materials, rethinking packaging, or assessing circular solutions will not get far with climate data alone. In those cases, the LCA is the right tool.

3. Do the data need to be publicly comparable in a standardized format?

Not for internal management and most customer requests. But they do for tenders, building certifications, or market communication where products are directly compared. This is exactly where the EPD shows its strength: uniform product category rules make products within the same category truly comparable.

The starting point for all product requests: PCF

A PCF is always a solid foundation for all further calculations related to your products’ environmental impacts. In the PCF guide, you will learn the best way to approach this.

How are PCF, LCA, EPD, and CCF connected?

In brief:

  • LCA vs. PCF is actually the wrong framing, because the PCF is part of the LCA: the LCA covers several environmental impacts, while the PCF focuses on greenhouse gas emissions.
  • And the EPD is not a fully separate tool either. The EPD brings LCA results into a standardized, public format.
  • The CCF sits one level higher, at company level. PCF and EPD provide product data for its Scope 3 inventory.
LCA vs. PCF vs. EPD: How are the tools for calculating product environmental impact connected?

PCF, LCA, EPD, and CCF do not simply stand side by side; they build on each other. The LCA is the method behind the scenes: it assesses a product’s environmental impacts across its entire life cycle. The PCF is one impact category within the LCA, namely global warming potential, expressed in CO₂e. The EPD, in turn, presents LCA results in a standardized, third-party verified, and public format.

The CCF looks at a different level: not a single product, but company-wide emissions across Scopes 1, 2, and 3. This is where the connection to the product closes the loop, because product data from the PCF can feed into the Scope 3 part within the CCF.

One data foundation for PCF, LCA, EPD, and CCF

PCF, LCA, EPD, and CCF do not compete with each other; they answer different questions. Which tool you need depends on the occasion, and over time you will often need several of them: a PCF for a customer today, an LCA for a redesign tomorrow, and later an EPD for a tender. The better you understand the differences, the more precisely you can deliver what is needed without wasting effort.

What connects all four is the data behind them: they rely on largely the same product data or build on one another. Once you have reliably collected a product’s CO₂ value, you have already completed a large part of the work needed for the LCA, and those results in turn form the basis for an EPD. The real effort rarely lies in the individual proof point, but in building a robust, traceable data foundation. If the data is scattered or incomplete, every new request starts from scratch. If it is well-structured and available, the right proof point can be derived depending on the occasion.

This is exactly where the VERSO Climate Hub comes in: It brings product calculations, from PCF to LCA, together on one shared data foundation.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Current ESG topics and legislative changes
  • Individual advice from the VERSO experts
  • News about VERSO
  • Sustainability Events and more
10 CSRD-Tipps
18.06.2026

10 CSRD Tips for
ESG Managers

“CSRD – what exactly do we need to do?” Many companies are faced with this question. The scope of the reporting obligation and the associated ESRS standards is very challenging. Don’t lose your nerve right away – these 10 CSRD tips will help you get started.

10 CSRD tips from our experience

Taking a first look at the requirements of the Corporate Sustainability Reporting Directive (CSRD) and the European Sustainability Reporting Standards (ESRS)—or their revised version, the ESRS Simplified—can certainly raise a sustainability manager’s pulse. The CSRD is challenging, no question, but that’s hardly a reason to panic! Here are 10 CSRD tips to help you as you tackle Europe’s reporting obligation for the first time.

CSRD tip 1: Take a closer look at the ESRS reporting standard

To understand the scope and requirements that the CSRD places on your sustainability report, it’s important to have at least a rough overview of the framework, the ESRS. Don’t worry, you don’t have to read and understand every single data point to do so. The best place to start is by reviewing how an ESRS report is structured. If you’d like to learn more about the revised ESRS, you’ll find everything you need to know in our article on the ESRS Simplified. And if you do want to dig deeper, you can download all ESRS standards in their original version on EFRAG’s website.

CSRD tip 2: Build the resources and know-how for your CSRD project

The CSRD is a major undertaking, not a one-off project. A single sustainability manager often isn’t enough. When preparing your report, you’ll work in close coordination with HR, IT, Finance, Procurement, Risk Management, and other departments. Foster strong, efficient collaboration and take a realistic look at the to-dos: What resources do we need for implementation? Are additional skills or training necessary? Do we need to hire someone? And if it comes down to a lack of know-how: the VERSO Academy is sure to offer the right training for you. Regular courses and workshops also sharpen awareness of sustainability throughout the organization. Bring other departments on board and keep everyone involved informed about the latest requirements.

CSRD tip 3: Plan the process in detail

Several steps in CSRD reporting require a great deal of time, a lot of coordination with internal stakeholders, or both. That’s why it’s essential to keep your process realistic and forward-looking. Be sure to factor in buffer time, too—and feel free to plan a little generously. Keep the following milestones in mind:

  • When do we want to publish the report?
  • Are there any time constraints we need to consider (vacations, other projects)?
  • When will we write the report?
  • Who needs to be brought into the process, and when?
  • When will we collect the data?
  • When will we carry out the double materiality assessment?
  • When do we need to start?

Well-defined, proven workflows lead to faster data collection and reduce the risk of errors. Regularly reviewing and adjusting these processes ensures they hold up even as requirements increase. So those who invest early in clean processes can meet their regulatory obligations far more efficiently and quickly over the long term.

You also need to be aware: data collection in particular is a real time drain. People often underestimate how long it takes to gather the essential information. Don’t forget that for many departments in your company, your request comes on top of their actual day-to-day work. And with business partners and suppliers, you should also allow some time for their responses.

One more tip on this: calculate your deadline “from back to front”! First, determine when the sustainability report should be published—in the case of the CSRD, alongside the management report. From there, work backward through the individual steps—drafting the text, collecting the data, and conducting the double materiality assessment—until you reach the starting point. Add a little buffer for each task, and you’ll know the latest possible date to begin.

CSRD tip 4: The double materiality assessment, the cornerstone of your CSRD report

The foundation of a CSRD report is the double materiality assessment. Materiality assessments have been around for a while, but the principle of double materiality—used to identify the sustainability topics relevant for reporting—only became mandatory with the CSRD. For this, the ESRS prescribe a specific process that must be documented. Here it pays to ask yourself some critical questions: How do we stand in terms of knowledge and capacity for the materiality assessment? Can we manage it in-house, or do we need external help?

The double materiality assessment forms the basis for your data collection, your CSRD sustainability report, and your ESG management. That’s why it deserves special attention. Mistakes can lead to missing or inaccurate data. A substantive assessment, on the other hand, guides you purposefully through the reporting process.

Our experience shows that bringing in external consultants is definitely helpful—if only to draw on their experience when evaluating and selecting topics. Whatever you decide, we’ve outlined the process for the assessment here. You’ll also find a good overview of the methodology in EFRAG’s Implementation Guidance and in the supporting documents from the DNK (German Sustainability Code). Our AI-powered software solution offers valuable support for the double materiality assessment as well, saving you time in the process.

The challenge of the first sustainability report

A company’s first ESG report is always particularly time-consuming.
We have created a practical guide for your first sustainability report.
You will be guided step by step through the process of creating a meaningful sustainability report.

CSRD tip 5: Optimize data collection with digital tools

You’ll need lots and lots of data for your CSRD-compliant sustainability report. That quickly raises the question: How do we collect the data? Set up a process that’s as seamless as possible. And then: Where do we collect the data? Yes, it could be an Excel list — but experience shows those quickly become unwieldy. You’ll find yourself scrolling back and forth between individual data points for ages. It’s a nerve-wracking exercise you’d be wise to avoid. Our recommendation: use a sustainability software instead.

Software-supported reporting is easier, more effective, and more data-driven. And we’re not just saying this from our own experience — EFRAG points it out as well.

Digital tools, especially those with AI support, help you standardize processes and ensure that all material data is captured and processed correctly.

CSRD tip 6: Identify data sources and assign responsibilities

Reporting is teamwork: implementing the CSRD calls on a wide range of areas across the company, not just sustainability managers. Identify your contacts within the teams early on, bring them on board, and clarify responsibilities. We’ve summarized which teams are involved in the CSRD, why, and how in a graphic.

When it comes to data collection in particular, it’s not only important to know which information the CSRD requires, but also who—or which department—can provide it. So build out your processes and communication channels and define clear responsibilities. This creates clarity, avoids delays, and ensures that data collection runs efficiently and smoothly in the future as well.

In the VERSO ESG Hub, for example, you can assign responsibilities for each topic. Every year, when data collection starts up again, each person in charge can enter their data directly into the tool.

CSRD tip 7: Use a gap analysis to identify and close data gaps

Has your company already published a sustainability report? Is it based on a standard such as GRI or the DNK? Then you already have a solid foundation to compare against the CSRD requirements.

Conduct a gap analysis and find out which data you reported in previous years, whether it aligns with the ESRS formulas, and which data is still missing. This tells you which processes already exist and which data collection efforts still need to be established or adjusted.

That said, you can also carry out a gap analysis without a prior report. In that case, you start by reviewing which data you already have available, and then determine where there’s still room for improvement.

CSRD tip 8: Check your data for reliability

High data quality is the key to a CSRD-compliant sustainability report. That’s why it’s important to set up internal control systems that work similarly to those used in financial reporting. These controls ensure that your ESG data is accurate, complete, and reliable. Data quality plays a central role especially with a view to the external assurance required under the CSRD.

To ensure high data quality, you should prepare thoroughly and read the disclosures in the standards carefully. There you’ll find the Application Requirements (AR), which provide detailed instructions. They specify how certain information must be disclosed or measured.

CSRD tip 9: Take a strategic view of sustainability

The CSRD actively asks for a sustainability strategy—you need a policy for each individual material sustainability matter. Beyond that, you must show how sustainability is embedded in your corporate strategy.

So don’t get lost in the reporting tunnel: think of sustainability as part of your corporate strategy from the very beginning, and plan the appropriate resources for it. Not only your CSRD report, but also the future viability of your company, will thank you for it!

CSRD tip 10: Learn from mistakes and from other reports

Many companies have already published a CSRD report. You can learn from them and get a sense of what your own report might look like. That said, every company is so unique that you can’t follow any one of these reports step by step. Each report did different things well.

But here’s a spoiler: the CSRD report will likely sit closer to the financial report than most previous reporting under GRI or the DNK. There’s currently a lot of discussion about which direction sustainability reporting will take.

Now to your own report: your first report doesn’t have to be perfect either—you need to understand and accept that. To start with, it’s about establishing efficient data collection under the CSRD and setting up new processes or improving existing ones. Don’t try to force in descriptions of concepts and measures you haven’t yet introduced. Instead, set yourself a target for when you intend to publish the corresponding data, and communicate that openly in your report.

Overwhelmed by the CSRD?

Make CSRD as easy as possible: Our new CSRD Suite provides tools and support for every stage of CSRD compliance.

Dos & don’ts for your CSRD report

Dos:

  • Structure your sustainability reporting clearly:
    define clear responsibilities for reporting processes, data delivery, review, communication, and so on—much like in financial reporting.
  • Involve internal and external experts:
    run workshops and interviews to gather well-founded input, especially for your material topics.
  • Communicate the scope, goal, and purpose of the report both internally and externally:
    a shared understanding of the CSRD reporting obligation promotes consistent data quality and a coherent, readable report.

Don’ts:

  • Avoid aggregating your data too heavily:
    if you summarize data, processes, and descriptions too broadly or briefly, relevant information can get lost.
  • No purely subjective assessments:
    greenwashing is a thing of the past—the CSRD demands evidence for your claims. Always back up qualitative information with data-based proof.
  • Don’t report superfluous data points:
    avoid including more data points than necessary, as this can distract from the information that matters.

Our bonus CSRD tips:

Finally, we have two bonus CSRD tips for you: How should the process of creating a sustainability report be optimized? The guide with 7 steps to the sustainability report will help you. And if you want to delve deeper into CSRD reporting, we have a comprehensive guide for you: CSRD practice guide.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Pragmatic all-in-one solution for ESG reporting, climate and supply chain management
  • Individual advice from the VERSO experts
  • Developed with expertise from 12+ years of sustainability management
  • Trusted by 250+ customers
Meeresschildkröte, die durch Plastikmüll schwimmt: Mit der neuen EU-Richtlinie gegen Greenwashing sollen solche Bilder seltener werden
10.06.2026

From the Green Claims Directive to EmpCo: The New Rules Against Greenwashing Starting September 2026

The Green Claims Directive was intended to establish clear, EU-wide rules against greenwashing, but it was withdrawn in June 2025. Instead, EmpCo becomes binding. As a result, new requirements take effect on September 27, 2026, governing which environmental claims companies are still permitted to make.

Green claims directive & EmpCo: Tools against greenwashing

The Green Claims Directive was intended to establish clear, EU-wide rules against greenwashing, but it was withdrawn in June 2025. Instead, EmpCo becomes binding. As a result, new requirements take effect on September 27, 2026, governing which environmental claims companies are still permitted to make. In this article, we provide an overview of the developments surrounding greenwashing regulation and take a closer look at the requirements introduced by the new EmpCo.

Many environmental claims do not hold up to scrutiny

In January 2023, DIE ZEIT and The Guardian published an investigation into Verra, the leading provider of carbon credits. According to their findings, a portion of the emission credits that companies used to offset their greenhouse gas emissions did not deliver real reductions. A study by the European Commission painted a similar picture: more than half the environmental claims made by companies in the EU were vague or misleading, and roughly 40% were entirely unsubstantiated. Many green labels are of little help either, since half of them are barely verified, if at all.

The result is something most people know from their own experience: consumers can barely tell which claim actually delivers on its promise. And companies that properly substantiate their statements get lost in the jungle of labels and claims.

Greenwashing: The 5 biggest pitfalls

100% sustainable, climate-neutral, or bioplastic – what’s printed on a product isn’t always accurate. Greenwashing often happens unintentionally. In this article on the five most common pitfalls, you’ll learn what the traps are and how to avoid them.

The green claims directive was meant to adress this, but It’s off the table

On March 22, 2023, the EU Commission presented a draft of the Green Claims Directive (GCD). It was intended to require companies to substantiate their environmental claims scientifically, have them independently verified, and communicate them transparently.

But it didn’t get that far. In June 2025, the EU Commission withdrew the proposal after it lacked a majority in the trilogue and, among others, Italy and the EPP withdrew their support. The main criticism centered on the anticipated bureaucratic burden and the planned inclusion of micro-enterprises.

Anyone breathing a sigh of relief now, however, is mistaken. The Green Claims Directive is not the only regulation against greenwashing, just the best known. The requirements that will actually affect companies starting in fall 2026 have long been settled.

What is now binding: The EmpCo directive

The Empowering Consumers Directive (EmpCo, an EU directive) already entered into force on March 26, 2024. Member states had to transpose it into national law by March 27, 2026, and it must be applied as binding law starting September 27, 2026. In Germany, implementation takes place through an amendment to the Act Against Unfair Competition (UWG).

EmpCo regulates much of what the Green Claims Directive set out to do, just through a different mechanism: not through a new verification procedure, but through existing competition law. Certain environmental claims will henceforth be considered inherently unfair. This means there is no longer any need for a case-by-case assessment of whether a claim is misleading, it is simply prohibited.

Which claims EmpCo prohibits starting September 2026

EmpCo identifies four categories that will no longer be permitted without solid evidence:

  1. General environmental claims without recognized proof of performance
    Terms such as “environmentally friendly,” “green,” “eco,” “sustainable,” “climate-friendly,” or “biodegradable” may only be used if backed by recognized, outstanding environmental performance. This also applies to implicit claims: green leaves, globe symbols, or water droplets on packaging likewise fall under this rule if they suggest an environmental benefit that is not substantiated.
  2. Carbon-neutrality claims based on offsetting
    Statements such as “climate-neutral” or “carbon-neutral” that rely on purchased credits are no longer permitted. Climate-related claims must refer to real emission reductions within the company’s own value chain.
  3. Self-created sustainability labels
    In-house “eco” or “green” logos without an independent basis are prohibited. Only labels based on a system recognized by authorities or certified by independent third parties remain permissible.
  4. Whole-product claims for a partial aspect
    Anyone who prints “made with recycled material” on a product when only the packaging is meant leaves themselves open to challenge. The precise version that transparently states the scope remains permitted, for example, “packaging is made from 90% recycled PET.”

One important point here: forward-looking promises such as “climate-neutral by 2030” are not prohibited outright, but they are subject to conditions. They must be based on a measurable, verifiable implementation plan and monitored by an independent body.

Who does EmpCo apply to?

The directive affects all companies that market products or services to consumers in the EU, regardless of size, revenue, or industry. Manufacturers based outside the EU are also covered as soon as they target EU end customers. Unlike the Green Claims Directive that was under discussion, EmpCo does not exempt micro-enterprises.

What’s at stake for violations of EmpCo

Advertising with unsubstantiated environmental claims will be subject to cease-and-desist actions and can be penalized with fines. In the case of serious violations, fines of up to 4% of annual revenue in the member state concerned are possible. On top of this come reputational risks: a publicly challenged claim often damages credibility more than any fine.

This is not an entirely new risk, by the way. Back in June 2024, the Federal Court of Justice ruled that advertising a product as “climate-neutral” without explaining whether this is based on avoidance or offsetting is misleading. EmpCo merely makes enforcement considerably easier starting September 2026.

What you should do now

The deadline for implementing EmpCo is no longer far off. Anyone planning product packaging, campaigns, or website copy with a longer lead time is already working today on material that will go live in September 2026.

Three steps are worth taking now:

  • Claim inventory: Which environmental claims are you currently using—on packaging, your website, in advertising, and in your sustainability report?
  • Evidence mapping: For each claim, check whether solid evidence exists and where it is located.
  • Approval process: Define who signs off on an environmental claim before it is published, so that marketing, legal, and sustainability work together.

The core principle remains simple: you may only claim what you can prove. And that requires a solid data foundation. Greenwashing rarely stems from intent. It usually arises when sustainability is communicated without a sound data basis.

We support you with your sustainability communication

Solid claims require solid data. With the VERSO ESG Hub, you capture your sustainability data in a structured and traceable way, from the data source through to the reporting basis. This makes it possible to demonstrate what each claim is based on. For the communication itself, our Sustainability Consultants support you. They help you publish meaningful information while staying truthful, whether in your sustainability report or in other internal and external formats.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Current ESG topics and legislative changes
  • Individual advice from the VERSO experts
  • News about VERSO
  • Sustainability Events and more

Sign up now!

Sustainable Development Goals (SDGs)
09.06.2026

Sustainable Development Goals (SDGs): What the Sustainability Goals Mean for Companies

This overview tells you everything you need to know to put the Sustainable Development Goals (SDGs) into context for your company.

Sustainability: Licence to operate

Customers, employees, and other stakeholders are asking about the societal, social, and environmental impacts your business activities have. It is becoming increasingly clear that corporate sustainability is turning into a “license to operate.” ESG management therefore needs to be approached (more) strategically, or even for the very first time. This article explains how the Sustainable Development Goals, or SDGs, can help you do exactly that.

Whenever the implementation of sustainability in companies is discussed today, the United Nations Sustainable Development Goals (SDGs) are a firm part of the agenda. This framework helps to shape ESG management strategically within a company. At the outset, however, it is often unclear how the SDGs can actually be operationalized and integrated into a company’s sustainability strategy.

In this overview article, you will learn everything you need to know to put the Sustainable Development Goals (SDGs) into context for companies for the first time. We introduce the origins of the SDGs as well as the role companies play. Above all, though, we give you answers to one key question: How can your company become a proactive part of sustainable development? But let’s start at the beginning.

The history of the SDGs: From the Brundtland report to the 2030 agenda

The debate around the sustainable development of society, the economy, and the environment, which reached a broader public with the publication of the so-called Brundtland Report “Our Common Future” in 1987 (World Commission on Environment and Development), remains as relevant today as ever. Over several stages of development, the global objectives of this debate have found their way into the Sustainable Development Goals (SDGs) published by the United Nations.

Sustainable Development Goals today: Current status of the SDGs and their relationship to the CSRD

Adopted in 2015, the SDGs are now ten years old, and the midpoint assessment is weak. According to the Sustainable Development Report 2025 and the 2025 UN progress report, not a single one of the 17 goals is on track to be achieved globally by 2030. Fewer than one in five targets is on schedule. Progress is being made primarily on foundational issues such as health and access to electricity, while the structurally difficult goals are lagging behind.

For companies, the role of the SDGs has shifted during this period. Today they serve above all as an understandable, communicable framework: 17 goals, memorable icons, recognized worldwide. This makes them useful for putting your own sustainability work into context and telling its story, whether in reports, on your website, or in your strategy. This connection is still frequently seen.

Actual management, however, now runs through other instruments. The CSRD and ESRS, along with supply chain laws ranging from the LkSG to the CSDDD, the EUDR, and CBAM, now set the pace. These requirements are mandatory; the Sustainable Development Goals are not. Referencing the SDGs alone is therefore no longer a hallmark of a frontrunner. It has largely become standard, and without robust data to back it up, it quickly starts to look like greenwashing.

The SDGs after 2030: What comes next for the UN sustainability goals?

As the name suggests, the 2030 Agenda expires in 2030. This raises the question of what comes next, and the discussion about it has already begun. At the SDG Summit in September 2027, official negotiations on the post-2031 framework will begin, prepared in part by the Pact for the Future adopted in 2024.

A complete break is not to be expected. Most countries are sticking with the Sustainable Development Goals. What is more likely to be added are additional focus areas such as digital cooperation, the handling of artificial intelligence and data, or intergenerational equity. The SDGs are therefore more likely to be sharpened than replaced.

For companies, this changes little about the actual task at hand. Anyone who builds a clean data foundation and clear responsibilities now will also be well positioned for an adapted framework from 2031 onward. The effort pays off through robust ESG data, not through the SDG logo in a report.

SDGs and companies: What role the economy plays

This also establishes a framework that defines companies as important actors in sustainable development and offers them support in implementing measures at the regional and operational level. The SDGs emphasize the need for active participation by private companies and appeal to their creativity and innovation to create value for the common good. This includes, for example, reducing poverty, eradicating hunger, and protecting biodiversity.

The United Nations 2030 Agenda and its 17 Sustainable Development Goals present companies with the new challenge of aligning their operations and strategies with the requirements of the SDGs.

Sustainable Development Goals

Tackling the Sustainable Development Goals (SDGs) in your company

So what exactly do you need in order to meaningfully dedicate yourself to the Sustainable Development Goals and to sustainability in general? Two foundational pillars are decisive to begin with:

  1. Organizational and substantive responsibility assigned to an ESG/sustainability officer.
  2. A single place to consolidate all sustainability-relevant data.

Without these two basic prerequisites, it is virtually impossible for an organization to engage further with the topic.

But even with clear substantive responsibility and consolidated data, tackling the Sustainable Development Goals strategically is a task that should not be underestimated and that must be designed on a highly individual basis, depending on company size, industry, and stakeholders.

Consulting firms in the field of sustainability and sustainability reporting, including us here at VERSO, therefore support companies and ESG managers with practical advice every step of the way.

Implementing the Sustainable Development Goals (SDGs) with the GRI and the UN Global Compact

Various internationally recognized guidelines are available to achieve the implementation of the SDGs and their sub-targets within companies’ supply chains. Two of them:

  1. the Global Reporting Initiative (GRI)
  2. the UN Global Compact

Both guidelines propose indicators and key figures for measuring companies’ sustainability performance for each of the UN Sustainable Development Goals. Companies can therefore work toward implementing the global development goals by taking the route of adopting the GRI indicator system.

How seriously do companies really take the SDGs?

Some companies already integrate the SDGs deeply into their sustainability strategy and underpin them with concrete indicators and data. For many others, the connection remains superficial. This commitment is usually related to a company’s commitment to other sustainability-related topics, as well as to its size and level of sustainability maturity.

From this, one can conclude that commitment to the Sustainable Development Goals stems partly from regulatory reasons, where existing laws are simply being followed. On the other hand, there are often institutional reasons behind such commitment. A qualitative review of individual sustainability reports shows that company participation is largely symbolic and not yet substantial. This suggests that many companies regard the SDGs—much like the Global Compact—as a framework with non-binding implications.

Conclusion: Why the Sustainable Development Goals remain a useful tool

Despite all the shift toward the CSRD and the like, the SDGs have not lost their value. They give sustainability work a tangible framework, help with prioritization, and create a common language for explaining commitment both internally and externally. That is precisely what they are still good for.

What they do not provide is binding management. That requires robust data, clear responsibilities, and the appropriate reporting standards. Anyone who combines the two—the Sustainable Development Goals as orientation and solid ESG data as a foundation—turns sustainability into more than a box-ticking exercise. And is prepared for what comes after 2030.

We guide you through sustainability

Building a sustainability strategy involves real work. VERSO supports you holistically every step of the way. Since 2010.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Current ESG topics and legislative changes
  • Individual advice from the VERSO experts
  • News about VERSO
  • Sustainability Events and more

Sign up now!

Kompass in der Natur, der sinnbildlich dafür steht, dass sich Unternehmen Klimaziele setzen, die zur Dekarbonsierung führen.
27.05.2026

SBTi Climate Targets: How to Get Validated – and What You Need to Know About the Update

Science-based climate targets are among the most credible signals a company can send to the outside world. Investors, customers, and procurement teams specifically check whether targets have been externally validated. Here’s what’s behind the Science Based Targets initiative (SBTi), how validation of SBTi climate targets works, and what’s changing with SBTi V2.

Climate targets under SBTi

Science-based climate targets are now among the most credible signals a company can send to the outside world. Investors, customers, and procurement teams specifically look at whether climate targets have been externally validated. The Science Based Targets initiative – SBTi for short – has established itself as the international reference standard. But what’s behind it, when is the effort worthwhile, how does validation work, and what does SBTi V2 mean for companies planning right now?

Climate targets: Why the framework matters

Many companies set climate targets. Not all of them hold up. Internally developed targets without external review often come across as arbitrary and are increasingly viewed with skepticism by stakeholders. Anyone aiming to communicate credibly needs more than a self-set CO₂ benchmark.

We’ve summarized how to set up climate targets and what really counts in a separate article.

What are SBTi climate targets?

The Science Based Targets initiative (SBTi) is an international standard that supports companies in setting science-based climate targets. Specifically: companies define emissions reduction targets compatible with the 1.5°C goal set out in the Paris Climate Agreement. SBTi then independently reviews and validates these targets, ensuring they are externally credible and comparable.

In short: SBTi makes sure that climate targets aren’t set arbitrarily but are genuinely sufficient to curb climate change. The initiative is also currently working on a new version of its Net-Zero Standard – SBTi V2 – which is expected to be finalized later this year. We’ll explain what that means for companies further down.

Are SBTi climate targets worth it for your company?

SBTi-validated climate targets offer real benefits – but getting there takes effort. Rather than listing pros and cons in the abstract, let’s get specific: when is the step worthwhile, and when is it not yet?

SBTi climate targets are worthwhile if …

  • you need external credibility with investors, customers, or in tender processes. SBTi serves as independent proof that climate targets have been set using sound methodology.
  • you already have a solid data foundation. Scope 1 and 2 should be cleanly recorded, with an initial approximation for Scope 3 in place. Without this, the process quickly becomes frustrating.
  • sustainability is strategically anchored and not treated solely as a reporting topic.
  • you are part of the supply chain serving large companies – many now actively require SBTi targets.
  • you deliberately want to put pressure on yourselves: SBTi forces real reductions, not symbolic measures or offsetting.

SBTi climate targets are not yet worthwhile if …

  • you completely lack a data foundation: no recorded emissions, no defined responsibilities, no established process. In that case, it’s worth building internal structure first – SBTi assumes the basics are in place.
  • you need quick external impact. SBTi takes time and isn’t a fast communication lever.
  • the resources for the process simply aren’t there. Beyond fees, there’s internal effort and often external support involved. If you’d like assistance here, feel free to reach out.
  • you need maximum flexibility. The methodology is strict and leaves little room for individualized approaches.

Corporate carbon footprint not yet calculated?

Our guide walks you through the process step by step and shows you what to watch out for.

Step by step to SBTi validation

You’ve made the decision? Then the formal part begins – and it’s more detailed than many initially expect.

Step 1: Submit climate targets (Submission)

All relevant documentation must be complete and properly prepared: the Target Submission Form, emissions data (CCF, PCF), methodological derivations, and company information. Internal alignment and reviews are part of this stage, before the formal submission to SBTi takes place.

Step 2: Have climate targets validated by SBTi

The initiative reviews whether the targets are genuinely 1.5°C-compatible. So-called Clarification Requests often come up – follow-up questions where data, assumptions, or boundaries need to be refined. This phase is about responding with technical accuracy, supplying additional data and target pathways where needed, and coordinating alignment between internal departments and SBTi.

Step 3: Implement climate targets

Target validated – now it’s about actually walking the reduction pathway.

SBTi validation is achievable. But it’s detail work. With good preparation, it runs significantly faster and more smoothly.

Climate targets under SBTi V2: What companies need to know now

SBTi continuously develops its Net-Zero Standard. The current version, on which targets are submitted and validated today, is to be replaced by SBTi V2 – a fundamentally revised standard that brings, among other things, stricter requirements for Scope 3, transition planning, and the handling of residual emissions.

Following two consultation drafts in 2025, the final standard is expected later this year. A transition phase is likely for companies: new targets can presumably still be submitted under the current version until the end of 2027 before V2 applies to new targets starting in 2028. Already validated targets will generally remain in place until the end of their respective target period.

In other words: no one needs to switch over immediately. But anyone planning now should know where things are heading.

What you can already do today:

Rethink Scope 3

Don’t just calculate it, but properly classify it: which categories truly drive emissions? Where is reliable data missing? Where are assumptions still being used today that are more rough than solid?

Move from target setting to steering

Going forward, how progress is measured will count for more. Are there clear KPIs along the reduction pathways? Are measures reviewed regularly, or were they planned once and then left aside?

Set up the transition plan early

Not as a reporting document, but as a steering instrument. Anyone who cleanly defines measures, timelines, and responsibilities now will be much better positioned later.

Actively involve the supply chain

For Scope 3, it’s no longer enough to request data from suppliers just once. The point is to identify which suppliers and product groups truly carry weight – and to work with them in a targeted way on better data quality and concrete reduction measures.

Clarify how to handle residual emissions

Carbon removals are becoming more important, but not as a substitute for reduction. Even today, a realistic assessment should be made of which emissions might remain in the long term.

Think about evidence early

V2 is clearly moving toward robust evidence. Data should be traceable, consistent, and connectable – progress must be demonstrable, not just roughly plausible.

Anyone who tackles these points now won’t have to start from scratch with SBTi V2 but can build on what’s already in place at the company.

The PCF is becoming more important for SBTi V2. Time to get started.

Clean Scope 3 data already matters for SBTi validation today. With the new version, the focus shifts even more toward supply chain emissions. Now is the time to turn your attention to the PCF. This guide walks you through the calculation step by step.

We’re happy to support you on the path to validated SBTi climate targets

SBTi targets require a robust data foundation: cleanly recorded emissions, clear reduction pathways, traceable progress measurement. If you’d like to approach this path in a structured way, we’ll guide you through it.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Current ESG topics and legislative changes
  • Individual advice from the VERSO experts
  • News about VERSO
  • Sustainability Events and more

CSRD-Nachhaltigkeitsbericht nach den Simplified ESRS
17.04.2026

Simplified ESRS: What Is Changing and What Companies Should Do Now

The new Simplified ESRS are set to replace ESRS Set 1. This will make them the new standards for mandatory CSRD reporting. In this blog article, you will find everything important about the simplified standards for sustainability reports.

The Simplified ESRS

The ESRS (European Sustainability Reporting Standards) are set to become simpler, but not less important. With the planned Simplified ESRS, also referred to as Amended ESRS or ESRS Set 2, the focus is shifting: away from maximum detail and toward sustainability reporting that presents material topics more clearly, more consistently, and in a more practical way. For companies, this raises not only the question of what will be removed in the future. More importantly, it is about what will actually matter in reporting going forward.

The planned changes are linked to the EU’s Omnibus initiative. The aim is to streamline sustainability reporting requirements under the CSRD (Corporate Sustainability Reporting Directive) without abandoning the core logic of the ESRS. For companies, this means fewer mandatory disclosures, but still a clear focus on material information, transparent disclosures, and a robust presentation of their sustainability topics.

At a glance: What the Simplified ESRS mean for you now

Already deep into ESRS? → Map existing data points to the Simplified ESRS instead of starting from scratch.

Just getting started? → Clarify early whether VSME, Simplified ESRS, or another reporting framework is a better fit, then set up data collection directly along that logic.

No longer in scope? → Assess which form of voluntary reporting makes strategic sense.

Still have time until 2028? → Use the additional time to align materiality, data architecture, and responsibilities cleanly with the Simplified ESRS.

Where do the Simplified ESRS currently stand and what can be expected next?

The Simplified ESRS have not yet been formally adopted. So far, EFRAG’s technical recommendation to the European Commission is available. The final version of future ESRS Set 2 still needs to be adopted by the Commission as a delegated act.

Since the EU plans to adopt EFRAG’s draft as it stands, the direction is already clear: fewer data points, fewer redundancies, greater focus on material information, and more principles-based reporting.

For companies, the draft status is therefore not a reason to wait. Those who understand the logic behind the Simplified ESRS now can already begin aligning reporting processes more effectively toward relevance, coherence, and practical data use.

What is new in the Simplified ESRS and what stays the same?

The planned Simplified ESRS are intended to make sustainability reporting leaner and easier to understand. At the core, the aim is to place greater focus on decision-useful information while reducing the burden on companies where previous requirements were particularly extensive, redundant, or difficult to apply in practice.

Was ist neu und was bleibt bei den Simplified ESRS, den Berichtsstandards der CSRD.

What is new?

Focus on material information

Going forward, only material data points are expected to be disclosed. The goal is a sustainability report that is clearer and less driven by formally checking off every single requirement wherever possible.

Significantly fewer data points

According to EFRAG, mandatory data points are expected to be reduced by around 61 percent. At the same time, voluntary disclosures will be removed. So this is not just about less volume, but also about stronger focus on what is truly relevant for users and decision-making.

Shorter and more understandable standards

The standards are expected to be streamlined. Redundant content will be cut back, and overlaps between ESRS 2 and the topical standards will be reduced. This is intended to improve readability and make application easier in practice.

More principles-based narrative reporting

Key governance topics such as SBM-3, IRO-1, as well as Policies, Actions and Targets will be brought together more strongly. At the same time, presentation is expected to become more flexible. As a result, the report should function less like a checklist and more like a coherent overall picture.

Less burden around value chain data

Going forward, there will no longer be an explicit preference for primary data. Estimates and secondary data are also expected to be allowed where robust primary data is unavailable or can only be obtained with disproportionate effort.

Simplified materiality assessment and clearer disclosure logic

Disclosure logic is also becoming more focused. Companies should be better able to distinguish between material and non-material information. This also affects the question of which mandatory disclosures are actually required and where narrative context matters more than completeness for its own sake.

What stays the same?

Despite the simplification, the core logic of the ESRS remains in place. ESRS Set 1 is not being reinvented, but rather condensed, focused, and further developed in the form of the Simplified ESRS. The double materiality assessment (DMA) also remains a central starting point for reporting. The following three points will continue to be central in the new Set 2:

Double materiality remains mandatory.

Companies must therefore continue to systematically assess which sustainability topics are material, both from an impact perspective and a financial perspective. What is new is mainly that application is intended to become more practical: EFRAG refers to clearer guidance, less documentation effort, and stronger focus on truly decision-useful information.

The 12 topical standards remain structurally in place.

The Simplified ESRS continue to build on the same architecture: ESRS 1 and ESRS 2, along with the familiar environmental, social, and governance standards, remain in place. For companies, this means existing structures, responsibilities, and mapping logic can generally continue to be used, while the depth and volume of required disclosures will be reduced in many places.

The objective remains a transparent presentation of material sustainability topics.

Even with simplified requirements, companies are not expected to simply check off data points, but to explain clearly which material topics they have identified and how they manage them. EFRAG emphasizes stronger focus on relevance, Fair Presentation, and reporting that is less purely compliance-driven. Companies therefore still need to provide an internally coherent story around their material topics.

Fair Presentation: Why the report should be less checklist and more overall picture

A central point in ESRS Set 2 is that it does not just shorten individual requirements, but also shifts the logic behind reporting. This is especially visible in the principle of Fair Presentation.

What does Fair Presentation mean?

A report should not merely appear formally complete. It should provide a coherent, balanced, and understandable overall picture of a company’s material sustainability topics.

In other words, it is no longer enough to simply work through individual Disclosure Requirements. What matters is whether the report as a whole makes it understandable

  • which topics are material
  • why they are material
  • how the company is addressing them

What changes in practice as a result?

With the Simplified ESRS, three things move more strongly into focus:

  • Relevance instead of maximum detail
  • Coherence instead of isolated individual disclosures
  • Clarity instead of overloaded reports

Fair Presentation therefore describes quite precisely what good reporting will increasingly be measured against in the future: not just the quantity of information, but its explanatory value.

Undue Cost or Effort: More pragmatism in data collection

The Undue Cost or Effort principle is intended to reduce the burden on companies wherever data can only be collected with disproportionate effort.

Where is the practical relief?

This is especially relevant for data that is hard to obtain, for example in the value chain or where information cannot be gathered reliably in the short term.

Going forward, there is expected to be more flexibility for:

  • estimates
  • secondary data
  • a more pragmatic approach to data gaps

This is a noticeable relief, especially for companies that are still building reliable ESG data structures.

What does this not mean?

Undue Cost or Effort is not a free pass to simply leave out information.

Companies therefore cannot rely on this principle in a blanket way by saying that data collection is difficult or expensive. What remains decisive is that assumptions, methods, and approaches are transparent and understandable.

What matters here:

  • Decisions should be justifiable
  • Estimates should be plausible
  • Data gaps should be contextualized, not hidden
  • the report should still provide a robust overall picture despite simplification

This principle therefore stands for a more realistic approach to data collection. The focus is not on perfection at any cost, but on an approach that remains practical while still being transparent.

Fewer data points, but not automatically lower expectations

Reducing data points is a clear form of relief. According to EFRAG, mandatory data points that must be disclosed when material are expected to decrease by around 61 percent. At the same time, voluntary disclosures will be removed.

What has been reduced in concrete terms?

The simplification mainly affects the volume of disclosures that companies previously had to collect, document, and prepare consistently in addition to core requirements. At the same time, the standards as a whole are expected to become shorter, clearer, and more principles-based. This comes with fewer overlaps, more flexibility in narrative disclosures, and a simplified materiality assessment.

But a reduction of around 61 percent does not mean that sustainability reporting will automatically become 61 percent easier. And it does not mean that companies will only need to prepare a heavily shortened report.

Even with fewer mandatory disclosures, the central task remains the same: companies must transparently explain in the ESG report which topics are material, which information is relevant in that context, and how this results in a coherent report.

What does this mean for companies?

The effort therefore shifts in part:

  • away from pure data collection
  • toward prioritization, contextualization, and clear presentation

The real simplification, then, is not that everything becomes easy. It is that the focus becomes clearer.

VSME or Simplified ESRS: Decision support for mid-sized companies

With the Simplified ESRS, the question becomes more relevant which framework makes sense for companies that are currently not subject to reporting requirements or want to report voluntarily. VSME is not automatically the better choice simply because it is leaner. What matters is what the reporting is intended to achieve: a pragmatic starting point or voluntary reporting with stronger alignment to ESRS logic.

Answer the following questions for yourself. The more often you answer “yes” to a statement, the more likely the respective standard is a good fit.

VSME is more suitable if …

  • You want to start voluntary reporting with the lowest possible effort.
  • You need a pragmatic framework without immediately having to work deeply into ESRS systematics.
  • Your reporting is primarily intended to provide an initial overview and is not yet meant to reflect all strategic management questions.
  • You are still at an early stage when it comes to data, processes, and responsibilities.
  • You first want to establish a solid foundation before expanding reporting and management further.

The Simplified ESRS are more suitable if …

  • You want voluntary reporting that is already closer to future ESRS logic.
  • You want to use sustainability not only for documentation, but also more actively for management and strategic purposes.
  • You are already working with a double materiality assessment or plan to do so.
  • Your sustainability information also needs to be robust and compatible with expectations from banks, business partners, or more complex customer requirements.
  • You want to build reporting today that is more robust and future-proof in the long term.

As a rule of thumb

If you mainly want to get started simply and with minimal use of resources, VSME is usually the more suitable entry point.
If you want to report voluntarily in a more structured way, with greater compatibility and closer alignment to the ESRS, there are stronger arguments in favor of the Simplified ESRS.

How companies should move forward now

Which next steps make sense depends above all on where your company currently stands. For most companies, this is not about rebuilding everything from scratch now. It is about adjusting the current course in a targeted way to align with the logic of the Simplified ESRS.

If you are already reporting under ESRS or have prepared extensively for it

Then you should not discard the work you have already done. A sensible approach is to

  • continue using existing preparatory work
  • map previously collected ESRS data points to the Simplified ESRS
  • assess which disclosures will be removed in the future, merged, or only remain relevant if material
  • review content for opportunities to shorten, improve relevance, and strengthen coherence
  • question where completeness has so far taken priority over materiality

The next step here is therefore not a restart, but a mapping from the previous ESRS approach to the logic of the Simplified ESRS.

If you are just starting with reporting

Then now is a good time to clarify whether VSME, Simplified ESRS, or another reporting framework is a better fit, and then set up data collection directly along that logic.

What matters now:

  • build processes around materiality from the outset
  • avoid creating unnecessarily broad data collection
  • keep the reporting structure clear and flexible
  • assess early whether the Simplified ESRS or a VSME-oriented starting point makes more sense

Anyone starting now should therefore no longer follow the principle of “just collect everything first,” but instead orient themselves early around a more focused framework.

If you have fallen out of CSRD scope

Then you should not automatically stop your preparatory work. Instead, now is the right time to reassess your sustainability reporting:

  • Which ESG information will continue to be expected by customers, banks, or business partners?
  • Is a leaner voluntary approach such as VSME sufficient for that?
  • Or is it worth staying voluntarily closer to ESRS logic?

For these companies, the focus is therefore shifting away from pure compliance and toward the question of which form of voluntary reporting makes strategic sense.

If you still have time until 2028

Then waiting is not the best solution. It is more useful to use the additional time deliberately to

  • set up the double materiality assessment properly
  • align data architecture early with the logic of the Simplified ESRS
  • define internal responsibilities and processes clearly
  • systematically build only the data that is actually relevant for the future sustainability report
  • design the reporting structure to be more focused and easier to understand from the start

Anyone who lays the right foundations early can report far more efficiently later and avoid unnecessary effort caused by overly broad ESG data collection or a setup that no longer fits.

Need support?

If you need support preparing your next sustainability report – or your first one – we are here to help with software and advisory services, depending on your needs.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Current ESG topics and legislative changes
  • Individual advice from the VERSO experts
  • News about VERSO
  • Sustainability Events and more
Bild von Windrädern in der Natur. Sie tragen u.a. dazu bei, die Emissionen von Unternehmen zu reduzieren und ihre Klimaziele zu erreichen.
08.04.2026

Setting Climate Targets for Companies: How to Develop Well-Founded Reduction Goals

In this article, you will learn how companies can set well-founded climate targets, why the base year of the carbon footprint is crucial, and how to develop a reliable emissions reduction pathway.

The carbon footprint is complete. For many companies, the next step seems obvious: setting climate targets.

In practice, however, this step is often more challenging than expected. Because between a completed carbon footprint and robust climate targets lies a key question: what is actually realistic, effective, and strategically meaningful for our company?

Many companies define CO₂ reduction targets before they fully understand their potential. This leads to targets that are either too cautious or unrealistic. Neither is helpful.

In this article, you will learn how companies can set well-founded climate targets, why the base year of the carbon footprint is crucial, and how to develop a reliable emissions reduction pathway.

Common mistakes when setting climate targets

When setting climate targets, many people initially think in terms of a target year and a percentage. This is exactly where the first mistake often begins. A target such as “40 percent fewer emissions by 2030” may sound concrete, but it is only robust if it is clear what it refers to and how it will be achieved.

In practice, three typical mistakes occur when defining targets:

1. Reducing climate targets to a single number1. Klimaziele auf eine Zahl reduzieren

Strong climate targets for companies consist of more than a target year and a reduction value. They also answer key questions:

  • What is the company’s starting point?
  • Which emissions are included?
  • How ambitious yet realistic is the target?
  • How can progress be measured later?

Only then does a target become a manageable foundation for climate management.

2. Defining reduction targets before understanding the potential

A carbon footprint is the foundation for any target setting. Without reliable emissions data, no well-founded climate targets can be developed.

However, the footprint alone is not sufficient. It shows where emissions occur, but not automatically where real reduction potential exists.

The biggest lever is not in the same place for every company. Depending on the business model, it may lie in energy supply, vehicle fleets, production processes, logistics, or the supply chain.

This is why it is important to clarify before defining targets which emission sources are most relevant, what potential arises from them, and what is realistically feasible from an operational perspective.

3. Focusing only on the target year instead of the reduction pathway

Many companies focus heavily on the target year. However, a target for 2030 or 2040 alone says little about how emissions will decrease along the way.

This is why a robust emissions reduction pathway is essential.

A reduction pathway describes how emissions should evolve over several years. It helps define interim targets, measure progress, and avoid pushing achievement to a distant endpoint.

A meaningful reduction pathway helps to

  • make development over time transparent
  • assess interim results more effectively
  • identify deviations earlier
  • manage climate targets more strategically

This turns a climate target from a future promise into a manageable development pathway.

What makes strong climate targets

Robust climate targets consist of more than a number and a target year. They are formulated in a way that provides guidance, is understandable internally, and can be managed reliably over time.

This requires more than ambition. Strong climate targets are primarily defined by clarity and measurability. Key elements include:

  • a clear base year
  • a defined target year
  • a specific reduction value
  • a clearly defined scope
  • a transparent data foundation
  • a realistic reduction pathway

Especially for CO₂ reduction targets, it is important not only to define the target itself, but also to make the underlying logic understandable. Only then can targets be communicated internally, embedded strategically, and monitored reliably.

The base year of the carbon footprint: what companies should consider

To set climate targets, companies need a clear reference point. This is where the base year of the carbon footprint becomes critical.

The base year is the year against which future reductions are measured. If a company aims to reduce emissions by 50 percent by 2030, it must be clear which year serves as the reference.

A suitable base year should:

  • be based on reliable data
  • be methodologically sound
  • be representative of the company
  • not be heavily distorted by one-off effects

This is more important than it may seem at first glance. An unsuitable base year can make target achievement appear artificially easier or unnecessarily difficult. For robust climate targets, this foundation is essential.

CO₂ reduction targets for companies: ambitious but realistic

In practice, companies often face a tension: climate targets should be ambitious but must remain grounded in reality.

A target that is too cautious fails to leverage existing potential. A target that is too ambitious quickly loses credibility if it is not viable internally. Strong target setting lies somewhere in between.

Key questions include:

  • What level of reduction is plausible based on emissions data?
  • Where are the biggest levers?
  • Which conditions limit implementation?
  • What developments are realistic in the short, medium, and long term?

For sustainability managers, striking this balance is critical. Climate targets should not only sound good, but also provide real guidance within the company.

Science-based climate targets for robustness and credibility

In principle, companies are free to choose how they define their climate targets. However, more and more companies are aligning with science-based standards. Science-based climate targets, such as those defined by the SBTi, are characterized by the following:

  • alignment with the 1.5°C pathway
  • clear and measurable structure (base year, target year, reduction percentage, clearly defined scope (1, 2, 3))
  • use of real emissions data
  • inclusion of Scope 3 (if relevant)
  • immediate implementation of measures
  • limited reliance on offsetting

Not every company needs to adopt science-based targets. However, it is often worthwhile to align with the core principles of such frameworks. For companies seeking particularly robust and credible targets, this can provide valuable guidance. Those interested in exploring this further should take a closer look at SBTi requirements.

Setting climate targets in companies: a five-step process to an effective reduction pathway

A practical process for defining targets typically looks like this:

Understand the carbon footprint

The carbon footprint shows where emissions occur and which areas are most relevant.

2. Assess hotspots and potential

Before defining targets, it is essential to understand where realistic reduction potential exists.

3. Define the base year and target framework

Determine which year serves as the reference and which emissions are included in the target.

4. Evaluate target options

Only at this stage should decisions be made about target ambition and time horizon.

5. Align targets internally

Climate targets should not be developed in isolation, but in alignment with strategy, data, and operational realities.

Conclusion: setting climate targets means making reduction manageable

Companies that want to set climate targets should not start with an isolated percentage. The key starting point is a robust carbon footprint, combined with a realistic understanding of internal potential.

A strong target system requires a well-defined base year, a transparent emissions reduction pathway, and a target definition that is ambitious yet achievable.

This turns CO₂ reduction targets into more than a communication statement. They become the foundation for effective, strategically managed climate action.

If you want to develop well-founded climate targets and take the next steps in a structured way, feel free to reach out. We support you with practical and expert guidance.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Current ESG topics and legislative changes
  • Individual advice from the VERSO experts
  • News about VERSO
  • Sustainability Events and more
Cyber-Sicherheit in der Lieferkette
12.03.2026

Cybersecurity in the Supply Chain: Identifying and Systematically Managing Risks

“Cyber insecurity” is one of the biggest risks and affects the entire supply chain. In this article, you will learn why and how to implement cybersecurity across your supply chain.

In its latest Global Risks Report, the World Economic Forum (WEF) ranks “cyber insecurity” among the most significant global risks (ranked 6th in the short term). According to the Hackett Group, it is even the number one risk factor for procurement leaders. At the same time, the new NIS2 directive makes one thing clear: cybersecurity concerns the entire supply chain and does not end at a company’s own factory gates. It is therefore time to take a closer look at cybersecurity in the supply chain and to consistently address cyber risks from a procurement and supply chain perspective.

Key takeaways on cybersecurity in the supply chain

What is cybersecurity in the supply chain?

Cybersecurity in the supply chain refers to all measures that ensure IT security and information security among external service providers, suppliers, and third parties that have access to systems, data, or critical processes. It therefore covers the systematic protection of the entire supply chain against digital threats.

Why is cybersecurity in the supply chain important?

Modern supply chains are highly interconnected: companies collaborate with cloud providers, IT service providers, logistics companies, consultancies, outsourcing partners, and many other actors. Data flows across system boundaries, external partners access internal business applications, and critical processes depend on third parties. In globally connected supply chains in particular, this creates new digital attack surfaces.

This interconnectedness is exactly what makes supply chains vulnerable to cyberattacks. A single weak point—such as a poorly secured service provider with VPN access or a software supplier with inadequate security standards—may be enough to give attackers access to a company’s systems. This so-called third-party cyber risk is now one of the main drivers behind security incidents in companies and therefore a core challenge for cybersecurity in the supply chain.

As Bitkom President Dr. Ralf Wintergerst puts it:

Attackers look for the weakest link. Even in highly protected companies, that weak point is often a less protected supplier. (…) Improving cybersecurity therefore requires raising awareness among business partners across the supply chain, agreeing on protective measures, and implementing them together.

The consequences range from operational disruptions and financial losses to severe reputational damage. Cybersecurity in the supply chain therefore means that not only a company itself must be resilient, but the entire supply chain ecosystem in which it operates.

The challenges of cybersecurity in the supply chain

In theory, it is clear: supply chain risks—including those related to IT security—must be systematically identified and managed. In practice, however, the challenge rarely lies in a lack of willingness, but rather in missing structures. This is exactly where the complexity of cyber risk management becomes apparent.

Typical challenges:

  • Lack of transparency regarding relevant suppliers
    Many companies do not have a clear overview of which suppliers are particularly critical from an IT perspective. System access, data flows, or dependencies are often not centrally documented. As a result, it remains unclear where an attack would cause the most damage.
  • Different maturity levels among suppliers
    While some partners can demonstrate established security standards and certifications, others have little to no documented measures or defined security levels. This heterogeneity makes consistent risk and measure assessment difficult and highlights that there is no one-size-fits-all solution. Instead, dedicated supplier engagement discussions are required.
  • Manual and unstructured data collection
    Information about security measures is often collected via email, Excel files, or individual questionnaires. Such manual risk assessments are time-consuming, error-prone, and not scalable—especially when managing large supplier portfolios.
  • Outdated information
    Once collected, data is rarely updated regularly. As a result, changes—such as updates in a supplier’s IT landscape, security incidents, or new certifications—often go unnoticed.
  • Limited auditability in case of reviews
    Even when measures are implemented, they are often not documented consistently. In the event of audits, regulatory reviews, or security incidents, companies lack a central, reliable overview.

These points highlight a key insight: cybersecurity in the supply chain cannot be addressed through isolated, one-off measures. What is needed are structured, repeatable, and traceable risk assessments that create transparency and enable continuous risk management.

Cyber risk management as the foundation for cybersecurity in the supply chain

Effectively addressing cyber risks in the supply chain requires a holistic approach. Cybersecurity in the supply chain is not an isolated IT topic but part of strategic supply chain risk management.

Key considerations include:

  • Structured supplier risk management
    Suppliers should not only be assessed based on price, quality, and delivery capability, but also on their cyber risk profile. This includes standardized risk assessments, clear criteria, and consistent evaluation frameworks.
  • Binding security requirements for third parties
    Security standards—such as requirements for access control, encryption, incident management, or patch management—should be contractually defined. This is the only way to make cybersecurity a fixed component of collaboration.
  • Clear communication and escalation paths
    In critical situations, every minute counts. Companies need defined contacts, reporting channels, and processes to quickly identify, assess, and jointly address incidents involving suppliers.
  • Regular review and updates
    Threat landscapes evolve, as do IT environments, supplier relationships, and risk assessments. Cyber risks therefore need continuous monitoring, and evaluations must be updated regularly—not only once during supplier onboarding.

How can cybersecurity in the supply chain be ensured?

How can companies take concrete steps to systematically manage cybersecurity as a supply chain risk? A step-by-step approach has proven effective:

1. Identify and prioritize relevant suppliers, access points, and dependencies

The first step is to create transparency regarding which external partners are truly critical from a cybersecurity perspective. The decisive factors are not only contractual relationships but also actual system access, data flows, and operational dependencies—meaning the real potential impact on availability, integrity, and confidentiality. This helps segment the truly relevant partners and dependencies in a targeted way:

  • Centrally document all external system access points (e.g., VPNs, APIs, cloud integrations)
  • Classify suppliers into criticality levels based on their access and data impact
  • Identify particularly sensitive or business-critical dependencies (single points of failure)
  • Consistently reduce unnecessary or over-privileged access (principle of least privilege)

2. Continuously monitor risks and ensure transparency

Cyber risks in the supply chain evolve continuously—due to new threats, changing IT environments, or adjustments in collaboration. Assessments should therefore not only be updated regularly but also be made manageable across the entire supplier portfolio:

  • Establish regular reassessments for critical suppliers
  • Conduct event-driven reassessments in case of incidents or significant changes
  • Introduce aggregated risk dashboards for portfolio management
  • Continuously monitor central KPIs (e.g., open high-risk findings, remediation rate, assessment coverage, security monitoring)
  • Ensure compliance with regulatory requirements, including documentation for NIS2 compliance

3. Document measures and ensure auditability

All assessments, decisions, and measures should be documented centrally. This makes it possible to demonstrate

  • that risks were identified and addressed,
  • which requirements were defined for suppliers,
  • how incidents were handled.

Such auditability is not only important for audits and regulatory requirements, but also for internal confidence in the company’s security approach.

Conclusion: Rethinking cybersecurity – from supply chain risk to strategic management

Cybersecurity today goes far beyond firewalls, virus scanners, and internal IT policies. Companies that want to protect their business must consider the entire supply chain—from selecting critical service providers and defining clear requirements and contracts to conducting recurring assessments and maintaining proper documentation.

The good news: Companies that consistently extend their cybersecurity strategy to include the supply chain gain not only resilience but also control. They know where their biggest dependencies lie, can prioritize risks, and are able to respond faster when incidents occur.

In short: cybersecurity starts within your company—but it does not end at your factory gates.

We are happy to support you in collecting the necessary supplier information centrally and efficiently on one platform.

Contact us to schedule an introductory meeting.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Current ESG topics and legislative changes
  • Individual advice from the VERSO experts
  • News about VERSO
  • Sustainability Events and more
Worker in warehouse surrounded by cardboard packaging boxes – PPWR regulation supply chain compliance
23.02.2026

PPWR Regulation: The Most Important Questions and Answers for Companies

The PPWR (Packaging and Packaging Waste Regulation) introduces comprehensive requirements for companies across the entire packaging value chain. In this article, we answer the key questions about the PPWR regulation and outline which obligations will apply for companies starting in 2026.

The PPWR – also known as the new EU Packaging Regulation – covers packaging design, recyclability, labeling, extended producer responsibility (EPR), and packaging waste reduction. Below you will find answers to the most important PPWR questions, structured by topic.

1. What is the PPWR (Packaging and Packaging Waste Regulation)?

The PPWR regulation is a key component of the European Green Deal. As a uniform, directly applicable framework, it replaces the previous Packaging Directive. The regulation aims to strengthen the circular economy across the EU, reduce packaging waste, increase recyclability and material efficiency, and harmonize existing rules throughout the EU.

2. When does the PPWR apply?

The PPWR entered into force on February 11, 2025. It will apply starting August 12, 2026, and will be rolled out in stages through 2040, with key milestones in 2028 and 2030.

3. Who is affected by the PPWR regulation?

The PPWR applies to all packaging and packaged products placed on the EU market. Starting August 12, 2026, goods packaged in non-compliant packaging may no longer be marketed within the EU.
Exceptions and specific provisions apply to packaging for dangerous goods, medical devices, sensitive food contact materials, and innovative packaging, providing flexibility where safety or innovation considerations justify it.

To the question on PPWR roles: The PPWR has an extremely broad scope. As a result, it affects a wide range of companies, including:

  • Suppliers of packaging or packaging materials
  • Manufacturers of packaging or packaged products
  • Distributors, importers, and fulfillment service providers
  • Brand owners placing packaged goods on the EU market
  • Non-EU suppliers delivering products or packaging to the EU

The following sectors are particularly impacted:

  • FMCG / fast-moving consumer goods (food, beverages, personal care)
  • Retail, e-commerce, and online marketplaces
  • Packaging manufacturing
  • Logistics, fulfillment, and transport packaging
  • Textiles, apparel, and footwear (packaging-related aspects)
  • Hospitality, food service, and take-away (HORECA)

Lernen Sie den Supply Chain Hub in einer kostenlosen Demo kennen

4. Which roles does the PPWR regulation define?

The PPWR establishes clear obligations for each economic operator along the supply chain and generally distinguishes between producers, importers, distributors, and suppliers.

Manufacturer

A natural or legal person that manufactures packaging or a packaged product, or has packaging or a packaged product designed or manufactured under its own name or trademark. (This includes packaging manufacturers as well as companies such as Amazon.)

Supplier

Any natural or legal person that supplies packaging or packaging materials to a producer.

Importer

Any natural or legal person established in the EU that places packaging from a non-EU country on the EU market.

Distributor: Any natural or legal person in the supply chain—other than the producer or importer—that makes packaging or packaged products available on the market.

PPWR regulation: To-Dos across the Supply Chain

Who is affected by the PPWR – and what needs to be done by when? Our concise checklist helps you assess the PPWR regulation in a structured way and define the right next steps.

5. What does the PPWR role “Producer” mean, and how does it differ from “Manufacturer”?

This is a quite often asked PPWR question: Under the PPWR regulation, “Producer” refers to any producer, importer, or distributor—regardless of where they are established—that places packaging or packaged products on the market in a Member State for the first time. Producers assume additional obligations, including extended producer responsibility (EPR) for collection and recycling. The term should not be confused with “Manufacturer.” The Manufacturer is one of the roles covered under the broader term “Producer.” There is also potential for confusion in German terminology: in the regulatory context, “Hersteller” refers to the entity responsible for first placing packaging on the market, while “Erzeuger” refers to the entity that manufactures packaging or packaged products.

It is important to understand that within a packaging value chain, there is only one Manufacturer, but there may be multiple Producers. Whether a company qualifies as a Producer must be assessed separately for each Member State, depending on who places the packaging or packaged product on the market first.

6. What does “Extended Producer Responsibility” mean in the context of the PPWR regulation?

A key element of the PPWR is the principle of Extended Producer Responsibility (EPR). EPR compliance requires producers to take responsibility not only for manufacturing and distributing their products, but also for managing the end-of-life treatment of the associated packaging.

For example, online retailers based in Germany that sell goods to end customers in Austria must appoint an authorized representative in Austria, register in the national producer register, and pay the applicable fees there.

7. How will EPR fees change under the PPWR?

Starting 18 months after publication of the EU criteria, EPR fees will be modulated based on environmental performance. This means the fees will be structured according to how sustainable the packaging is. For example, lower fees will apply to packaging with higher recyclability.

8. What obligations does the PPWR regulation introduce for companies?

The PPWR introduces extensive sustainability and information requirements for companies across the entire value chain. These obligations cover packaging design and material selection as well as documentation, labeling, traceability, and reporting.

Key obligations—depending on the company’s role—include:

1. Compliance & chemical safety (from 2026)

  • Compliance with limits for substances of concern (e.g., PFAS, heavy metals), especially for food contact materials
  • Conducting conformity assessment procedures
  • Preparing technical documentation
  • Issuing an EU Declaration of Conformity (DoC)

2. Labeling & transparency (from 2028 onward)

  • Harmonized labeling on material composition
  • Information on compostability, take-back schemes, or deposit return systems
  • Labeling of reusable packaging
  • Providing information to authorities and market surveillance bodies
  • Registration and compliance within the framework of extended producer responsibility (EPR)

3. Design and sustainability requirements (phased in through 2040)

  • Minimizing weight, volume, and empty space (maximum 50% for transport and e-commerce packaging from 2030)
  • Ban on certain single-use plastic packaging formats
  • Recyclability requirements (at least 70% from 2030, 80% from 2038)
  • Design for recycling to enable material recovery
  • Minimum recycled content in plastic packaging (10–35% from 2030, up to 65% by 2040)
  • Compliance with binding reuse targets
  • Industrial-scale recyclability (from 2035)

4. Specific requirements for certain packaging types

  • Mandatory compostability for specific applications (e.g., tea bags or fruit labels)
  • Reuse options in take-away settings
  • Allowing customers to use their own containers

9. What specific PPWR regulation requirements apply starting in 2026?

If you are the Manufacturer of the packaging or packaged products under the PPWR regulation:

  • You must carry out a conformity assessment procedure and prepare the technical documentation and EU Declaration of Conformity.
  • You may not use substances of concern in packaging materials (e.g., PFAS, heavy metals).
  • You are subject to general labeling requirements.

If you purchase packaging or packaged products downstream from a Manufacturer or from your suppliers, you are subject to due diligence obligations. These include, among other things, verifying compliance of the packaging and ensuring that labeling requirements have been properly fulfilled.

10. What requirements apply regarding empty space and overpackaging?

Starting January 1, 2030, grouped, transport, and e-commerce packaging may contain no more than 50% empty space. Filling material is considered empty space. Packaging weight and volume must be reduced to what is strictly necessary, and cosmetic practices such as double walls or false bottoms are prohibited, with only limited exceptions.

11. What impact does the PPWR have on the supply chain?

The PPWR regulation increases data requirements for suppliers and packaging manufacturers across the entire packaging supply chain. It requires clear allocation of responsibilities within the packaging value chain and leads to greater coordination efforts between procurement, sustainability, quality management, and suppliers. At the same time, risks increase due to incomplete or outdated supplier data. As a result, transparency and a digital, readily accessible data foundation become increasingly important.

12. How should companies prepare for the PPWR regulation now?

Companies should establish transparency at an early stage regarding affected packaging and suppliers, review existing data and supporting documentation, and define clear processes for data collection and maintenance. It is also crucial to involve suppliers in a timely manner and build digital structures to ensure scalable and audit-proof compliance.

Our approach:

  1. Assess PPWR readiness across the supply chain
  2. Raise supplier awareness and provide training – without additional workload
  3. Collect and analyze packaging data in an automated way
  4. Optional advisory services for strategic and operational implementation

Software and consulting services for PPWR compliance

Capture technical documentation and EU Declarations of Conformity from your suppliers in a structured and standardized way with our PPWR module. We are also happy to support you with advisory services on your path to compliance.

13. How does the PPWR relate to other ESG requirements?

Supply chain decarbonization

The PPWR promotes recyclable and material-efficient packaging, reducing the use of virgin raw materials and energy-intensive production steps. This creates a direct lever for lowering Scope 3 emissions.

REACH / RoHS

The PPWR builds on existing chemicals regulations and further specifies substance requirements for packaging, for example by setting limits for PFAS and heavy metals to systematically reduce environmental and health risks.

ESRS E5 – Circular Economy

The PPWR operationalizes ESRS E5 requirements by defining binding criteria for recyclability, material composition, and recoverability of packaging. This enables robust and comparable ESG metrics.

EUDR – Traceability

Similar to the EUDR, the PPWR requires transparent traceability of materials and suppliers to demonstrate regulatory compliance across the supply chain.

Digital Product Passport (DPP)

The PPWR provides key data points for the Digital Product Passport, particularly regarding material composition, substances, recyclability, and compliance. It thus lays the foundation for digital, standardized transparency at product and packaging level.

14. Why should companies implement the PPWR early?

Companies should implement the PPWR at an early stage to reduce compliance, liability, and market access risks, while avoiding last-minute implementation challenges and supply chain bottlenecks. Acting now enables companies to build robust data structures instead of relying on manual, ad hoc solutions and strengthens their positioning toward customers, retailers, and authorities. At the same time, the PPWR can serve as a lever for more efficient and sustainable packaging strategies. Early action also ensures sufficient time for necessary adjustments in research and development, including planning, testing, and scaling.

15. What penalties apply in case of PPWR violations?

In Germany, missing EU Declarations of Conformity, technical documentation, registrations, licensing obligations, or incorrect information may result in fines of up to €200,000. In addition, sales bans may be imposed. Specific penalties for individual PPWR obligations will be further defined through additional legal acts.

Implement PPWR with ease

We hope, we could answer most of your questions! Be aware: Starting in 2026, PPWR compliance will become an operational reality—manual Excel spreadsheets will no longer be sufficient. With the VERSO PPWR software solution, you can centralize and automate data collection, supplier communication, and record-keeping for the PPWR Declaration of Conformity on a single platform.

Want to understand your specific obligations? Take the PPWR Check. In just three minutes and a few clicks, you will see what applies to your company—and receive a practical checklist to help you get started.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Current ESG topics and legislative changes
  • Individual advice from the VERSO experts
  • News about VERSO
  • Sustainability Events and more
Bild von einem Cyber-Angriff mit Computer und Code.
04.02.2026

What Does the NIS-2 Cyber Security Directive Mean for the Supply Chain?

NIS-2 tightens the requirements for cyber security – for the first time, the entire supply chain is in focus, from your service providers to cloud providers. Find out which companies are affected and how you can build effective risk management for your supply chain and NIS-2 compliance step by step.

What is the NIS 2 Directive and what does it mean for the supply chain?

With the NIS 2 Directive, the EU is tightening the requirements for companies’ cyber resilience. The focus is not only on a company’s own IT, but also on the entire supply chain: service providers, suppliers and IT or cloud providers are increasingly becoming a gateway for attacks. Companies must therefore be aware of their dependencies, systematically assess risks and implement suitable security measures for partners and service providers. The supply chain is thus becoming a central lever for compliance with the directive and for the company’s digital resilience.

Which institutions and companies are affected by NIS-2?

This no longer only affects traditional operators of critical infrastructure, but also numerous so-called “particularly important” and “important” facilities – including many companies from industry, production, IT, logistics, energy, healthcare and digital services with 50 or more employees or a turnover of EUR 10 million or more. The “particularly important” facilities, shown in the table, have to implement the strictest requirements.

Particularly important facilities Facilities / Examples
Energy Electricity, gas, oil, district heating/cooling, water supply, charging infrastructure for electric vehicles
Transportation & Logistics Air, rail, road and shipping transportation, including shipping companies and port operators
Finance Banks, trading platforms, market infrastructures, insurance companies
Healthcare Hospitals, research institutions, pharmaceutical companies, medical technology
Water supply Drinking water and wastewater management
Digital infrastructure DNS services, operators of top-level domains
Public administration Authorities and other state institutions

Although the “important” facilities – depending on their size and sector – do not have quite as far-reaching obligations and are not classified as critical per se, they must nevertheless act in a NIS-compliant manner. These include:

  • Food production
  • Postal and courier services
  • Chemical industry
  • Manufacturing industry
  • Digital services
  • Research facilities
  • Waste management

When does NIS-2 apply to companies and their supply chains?

All EU member states should have transposed the NIS-2 Directive into national law by October 17, 2024, but many, including Germany, missed the deadline. In Germany, NIS-2 has therefore only been law since December 2025.

Whether in one country sooner or later, the fact is: companies in the EU must now adapt their security measures in the company and in the supply chain to NIS-2. And they need to be careful: NIS-2 affects significantly more companies than its predecessor, NIS-1. In Germany, around 30,000 organizations are covered by NIS-2, while fewer than 2,000 were affected by NIS-2.

The difference between NIS-2 and ISO-27001

In contrast to established information security standards such as ISO/IEC 27001, NIS-2 goes much further: the focus is not only on securing the company’s own IT, but also on holistic risk management that includes the entire corporate environment, including the supply chain.

Aspect ISO 27001 NIS-2
Regulatory status International standard (voluntary) EU directive (mandatory)
Area of application Industry-independent, for organizations of all sizes Specific sectors and companies
Objective Establishment and operation of an information security management system (ISMS) Increasing the cyber security level of critical and important infrastructures in the EU
Information protection Protection of all types of information (digital, physical, cloud) Focus on IT, OT and network security with critical importance
Risk management Systematic information security risk management Extended and deeper requirements for cyber and information security risks
Asset Management Part of the ISMS Significantly expanded and explicitly required
Supply chain & procurement security Generally addressed Explicit and central requirement (suppliers & partners)
Awareness & training Employee training recommended Training courses planned, especially mandatory for management and the Executive Board
Management involvement Responsibility defined, but limited personal liability Strong involvement of top management including personal liability
Degree of coverage Covers approx. 70% of NIS 2 requirements Goes well beyond ISO 27001

What does NIS-2 require of companies and supply chains?

The NIS 2 directive takes cyber security to a new level – organizationally, technically and strategically. Essentially, the requirements can be divided into three central fields of action:

1. establish systematic risk management: Use of technical protective measures such as multi-factor authentication (MFA), documented cryptography guidelines, established incident response and emergency plans, regular training to raise employee awareness

2. clear responsibilities at management level: active co-design and approval of cybersecurity measures, mandatory further training, personal liability in the event of gross breaches of duty

3. binding reporting obligations & business continuity: early warning report within 24 hours in the event of serious incidents, detailed report after 72 hours with root cause analysis and initial countermeasures, final report within one month including long-term preventive measures

NIS-2 requirements for supply chain management

What is particularly relevant with NIS-2 is that the requirements extend into the supply chain. Companies must be able to clearly demonstrate which suppliers and service providers have access to systems, data or critical processes – and how the associated risks are managed. This applies in particular to IT and cloud service providers, software providers, external service providers with system or data access and suppliers with digitally connected processes.

The specific requirements for supply chain management:

Risk management for third parties

Companies must identify risks arising from collaboration with suppliers and service providers – especially where external partners have access to systems, data or critical processes.

  • Example: An external IT service provider has remote access to productive systems or administers cloud infrastructures. Companies must assess what impact a failure, a security incident or inadequate protective measures at this service provider would have.

Evaluation of security measures at suppliers

It is not enough to rely on contractual assurances. Companies must be able to understand which security measures are actually in place at relevant suppliers and whether they match their own risk profile.

  • Example: A software provider confirms “appropriate security measures”. NIS-2 compliance is only achieved when it is clear whether, for example, access controls, patch management, incident response processes or certifications are in place – and how up-to-date they are.

Documentation and verifiability

Assessments, decisions and measures must be documented in a structured manner. In the event of an audit or incident, it is not just what has been implemented that counts, but that risks have been systematically assessed, decisions justified and measures recorded in a comprehensible manner.

  • Example: Why a certain supplier was classified as an “acceptable risk” – or why additional measures are required – must be explained transparently even months later.

Regular checks instead of one-off queries

NIS-2 understands cyber security as an ongoing process. Information from the supply chain must therefore not be collected once, but must be checked and updated regularly.

  • Example: The risk assessment must be adjusted in the event of contract extensions, new system access, changed services or security-relevant incidents – not just at the next audit.

How companies ensure NIS 2 compliance (also in the supply chain)

NIS-2 can seem complex at first glance, but with a clear roadmap, the requirements can be systematically implemented. This step-by-step guide shows which measures companies should take now – from risk assessment to audit preparation.

Step-by-step guide to NIS-2 compliance: what measures companies should take now — from risk assessment to audit readiness.

1. clarify NIS-2 affectedness

To begin with, you should check whether your company is affected by the scope of the directive. Anyone who is part of the supply chain may also fall under the requirements.

2. carry out a gap analysis

Check risk management and incident response in particular: Are there clear processes for detecting and reporting incidents? Have access rights, encryption and MFA been implemented? How well are your service providers secured and are emergency and recovery plans up to date?

3. develop a risk management strategy

Effective risk management forms the basis of every NIS 2 strategy.
The core components are:

  • Regular risk assessments for early identification of weak points
  • Strong access controls (incl. MFA)
  • Encryption
  • Consistent patch management
  • Regular penetration tests
  • Establish a structured incident response plan and reporting process

Those who proactively implement these measures reduce risks in the long term and strengthen cyber security throughout the company.

4. clarify and strengthen governance and responsibilities

NIS-2 clearly makes cybersecurity a management task. Management is responsible for actively designing, adopting and regularly reviewing security guidelines.

The central elements are:

  • Mandatory training for managers
  • Clearly defined responsibilities (e.g. a designated security officer)
  • a systematic review of the entire security strategy
  • continuously maintained and complete safety documentation

Strong governance not only ensures fewer security risks, but also reduces personal liability risks for management.

5. secure the supply chain

Third-party providers and service providers are increasingly becoming a central cyber risk factor – and with NIS-2, they also have a clear responsibility.

To secure your supply chain, you should in particular:

  • Systematically check the security level and protective measures of your service providers
  • Make NIS 2 and compliance requirements binding in contracts
  • Establish ongoing monitoring and control mechanisms to identify risks at an early stage

This turns the supply chain into an effective protective shield: your company reduces both the real attack surface and the regulatory risk.

Conclusion: NIS-2 does not start in IT, but in the supply chain

NIS-2 makes it clear that cyber risks cannot be managed in isolation in IT. Transparency in the supply chain, uniform assessments and the ability to monitor and verify risks on an ongoing basis are crucial. This is precisely where many companies fail due to manual processes and a lack of structure.

With the VERSO Supply Chain Hub, the NIS-2 guideline and cyber security in the supply chain can be mapped centrally: from structured risk queries with suppliers and a uniform assessment of third parties to the ongoing updating and central documentation of all evidence. In this way, NIS-2 is not only implemented in the supply chain in compliance with regulations, but also in a practicable and scalable manner.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Current ESG topics and legislative changes
  • Individual advice from the VERSO experts
  • News about VERSO
  • Sustainability Events and more