The PeepalRooted in Wisdom.
Growing with Purpose
← All insightsGHG & Reporting

Scope 3 Reporting Under CSRD: A Practical Guide for Organisations

August 14, 2024

The EU’s Corporate Sustainability Reporting Directive (CSRD) extends mandatory sustainability disclosure — including Scope 3 emissions — to a far broader set of companies than its predecessor, the Non-Financial Reporting Directive. For many organisations, this is the first time value-chain emissions reporting stops being voluntary and becomes an auditable, penalty-backed obligation.

Why Scope 3 is the hard part

Scope 1 (direct operational emissions) and Scope 2 (purchased energy) are, by comparison, straightforward to measure — a company controls the activity data and the emission factors are well established. Scope 3 covers everything else: purchased goods and services, upstream transport, business travel, use of sold products, end-of-life treatment, and more, spread across fifteen distinct categories under the GHG Protocol.

The difficulty is structural. Scope 3 data usually lives with suppliers, customers, and logistics partners — parties a reporting company doesn’t control and often can’t compel to share primary data. CSRD’s double materiality requirement compounds this: companies must report not only how sustainability issues affect their own financial position, but also their own impact on people and the environment across the value chain.

A practical sequencing

Organisations that manage this well tend to follow a similar sequence. First, a materiality assessment under the European Sustainability Reporting Standards (ESRS) to establish which of the fifteen Scope 3 categories are actually material — not every category deserves equal reporting effort. Second, a data-maturity map: for each material category, is primary supplier data available, or will estimation via spend-based or activity-based emission factors be necessary as an interim measure? Third, a supplier engagement plan that prioritises the highest-emitting categories first, since primary data collection is resource-intensive and cannot realistically be pursued across an entire supply base simultaneously.

Assurance requirements are being phased in — starting with limited assurance and moving toward reasonable assurance over time — which means the underlying data trail needs to be defensible from the first reporting cycle, not retrofitted once an auditor asks for it.

Who’s affected, and when

CSRD’s scope extends well beyond companies headquartered in the EU: non-EU parent companies with a sufficient EU subsidiary or branch presence and revenue threshold fall within its reach too. The phased timeline means the specific reporting year varies by company size and listing status, but the direction of travel is the same for everyone in scope — Scope 3 is no longer optional, and the reporting infrastructure it requires takes longer to build than most organisations initially budget for.