77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
ESG sustainability criteria: obligations, ESRS and operational implementation
ESG & Sustainability

ESG sustainability criteria: obligations, ESRS and operational implementation

16 July 202613 min readBy Dr. Henrik Bauer
CIVAC

ESG sustainability criteria are no longer marketing, but rather measurable obligations from CSRD, ESRS and the Taxonomy Regulation. This guide explains the relevant criteria, double materiality and how to document operational implementation in a resilient workspace.

In Germany, since the CSRD (Directive (EU) 2022/2464) and the Delegated Regulation (EU) 2023/2772 with the ESRS standards came into force, ESG sustainability criteria are no longer voluntary key figures, but rather mandatory information that requires attestation. From the 2025 financial year, capital market-oriented large companies will report, from 2026 large corporations in accordance with Section 267 Paragraph 3 of the German Commercial Code (HGB) and from 2027 listed SMEs will report. The EU Taxonomy Regulation (EU) 2020/852 supplements this reporting with six environmental objectives and provides for a technical assessment based on quantitative thresholds, supplemented by a do-no-significant-harm test and minimum protection according to OECD guidelines.

This article explains the structure of the ESG sustainability criteria, the central ESRS data points, the double materiality methodology and the operational implementation in the company. It shows what role the ESG officer plays, how the evidence is documented in an audit-proof manner and how CIVAC, as a compliance platform and officer-as-a-service, bundles the ESRS data points in a central workspace. Anyone who underestimates ESG obligations not only risks auditor problems, but also reputational damage, increased credit costs and exclusion from tenders, because major customers and public clients are increasingly demanding ESG data points from suppliers before contracts are concluded and banks are integrating ESG risk premiums into the loan conditions. The federal government has decided to implement CSRD into German law; the draft bill has been available since summer 2024 and is the basis for the ongoing balance sheet preparations of many listed companies. Anyone who doesn't build up the structures now will be overrun in the first reporting cycle.

Key Takeaways

  • From 2026, the CSRD will require large corporations to report according to 12 ESRS standards with over 1,100 possible data points, checked by the auditor.
  • The double materiality (impact and financial materiality) is mandatory and must be documented methodically, otherwise the reporting in the audit will be tilted.
  • CIVAC bundles ESRS data points, supplier scoring and taxonomy assessment in a workspace with EU data residency and audit-proof trail.

What are ESG sustainability criteria and where do they come from?

ESG stands for Environmental, Social and Governance and describes the three dimensions according to which the sustainability of a company is assessed. The associated criteria are no longer a free choice, but are derived from European law. The central legal sources are the CSRD (Corporate Sustainability Reporting Directive, Directive (EU) 2022/2464), the Delegated Regulation (EU) 2023/2772 with the European Sustainability Reporting Standards (ESRS), the Taxonomy Regulation (EU) 2020/852, the SFDR (Regulation (EU) 2019/2088) for financial market participants, the Supply Chain Due Diligence Act (LkSG) and from 2027 the CSDDD (Corporate Sustainability Due Diligence Directive). The Empowering Consumers Directive and the planned Green Claims Directive also have an impact on advertising ESG statements.

The criteria are divided into twelve ESRS standards: two cross-standards (ESRS 1 General Principles and ESRS 2 General Information), five environmental standards (E1 Climate Change, E2 Environmental Pollution, E3 Water and Marine Resources, E4 Biodiversity and Ecosystems, E5 Resource Use and Circular Economy), four social standards (S1 own workforce, S2 workers in the value chain, S3 affected communities, S4 consumers and end users) and a governance standard (G1 business conduct). Each standard contains requirements on strategy, governance, risks, measures, objectives and quantitative metrics.

In total, over 1,100 data points are potentially relevant, of which the most important ones are identified using the double materiality analysis. CIVAC structures these data points in a workspace, assigns them to those responsible and versions the answers for the later auditor audit. You can find a more in-depth description of the role at ESG and Sustainability Officer, including ordering logic and reporting line to management. This creates a central file that is created in the first reporting period and updated in subsequent years without any structural breaks. This significantly reduces the effort in the second and third reporting cycle because the methodology is saved and only updates, corrections and new regulatory requirements need to be maintained.

Double materiality as a methodological basis

Double materiality is the methodological heart of the ESRS. It requires that a topic be evaluated from both an impact perspective (the company's impact on people and the environment) and from a financial materiality perspective (the impact of sustainability issues on the company). Both perspectives are assessed based on severity, scope, irreversibility and probability of occurrence. A topic is essential if it meets the defined thresholds in at least one perspective. This methodology is significantly more demanding than previous NFRD practice and requires consistent documentation.

Methodologically, the analysis begins with a long list of around 100 possible ESG topics, which are derived from ESRS 1. The topics are evaluated and weighted in workshops with the departments, supplemented by stakeholder interviews with investors, customers, suppliers, employees, authorities and NGOs. The result is a short list of key topics that serves as the basis for reporting. The methodology itself, i.e. thresholds, scales and stakeholder selection, must be disclosed in the report, as well as the selection of the actors involved and the justification for the final weighting.

Anyone who works methodically incorrectly here risks a restricted certificate or a request for rework by the auditor, with corresponding time pressure shortly before the balance sheet is published. CIVAC delivers a materiality module that pre-populates the long list, structures stakeholder surveys and provides the assessments with comprehensible scales. Each assessment is documented with justification, source and date so that the auditor can trace the methodology in an audit trail. Others run compliance like a filing cabinet. We run it like software. This applies to ESG as well as to data protection or IT security because the requirements for traceability and versioning are identical.

The twelve ESRS standards at a glance

ESRS 1 and ESRS 2 are cross-standards and are binding for all reporting companies. They regulate basic principles, governance, strategy, risk management and materiality analysis. The topic-specific standards only apply if the topic was identified as material in the materiality analysis. An exception is ESRS E1 Climate Change: Here it must be demonstrated why the topic may not be material, because the presumption of materiality exists and is likely to be practically always met for listed companies. This reversal of the burden of proof is one of the most important detailed regulations of the ESRS.

The five environmental standards cover climate, pollution, water, biodiversity and the circular economy. ESRS E1 in particular requires detailed information on Scope 1, Scope 2 and Scope 3 emissions according to the GHG Protocol, transition plans according to the Paris Agreement, internal CO2 prices and climate scenario analyses. ESRS E5 calls for material and water flows as well as recycling quotas, ESRS E2 concerns pollutant emissions in air, water and soil. The four social standards address our own employees (diversity, compensation, occupational safety, training hours, gender pay gap), value chain workforce (supplier audits, grievance mechanisms), affected communities and end users.

ESRS G1 asks about business ethics, corruption prevention, political commitment, payment practices towards suppliers and diversity in management. The requirements overlap with Section 33 of the German Commercial Code (HGB), the Whistleblower Protection Act and the LkSG. CIVAC maps these requirements to the representative roles that the company already maintains, thereby avoiding duplication of work between the ESG report, the LkSG due diligence report and internal risk management. An overview of all 25 supported roles can be found at CIVAC Roles, including supply chain, money laundering and whistleblower protection officers as related functions with a high overlap of data points. A well-coordinated role architecture reduces duplication of work and prevents contradictory statements between the ESG report, compliance report and due diligence report, which auditors and supervisory authorities examine regularly and with increasing depth. The platform logs every data point centrally and links it to the responsible representative.

Data points, collection logic and data quality

The ESRS define around 1,100 quantitative and qualitative data points that EFRAG has coded in an XBRL taxonomy. The principle of materiality applies to reporting: only data points on material topics are mandatory; others can be reported voluntarily. Quantitative data points include emissions, energy consumption, water withdrawals, waste volumes, employment numbers, training hours, accident rates and animal compensation. Qualitative data points address strategy, governance, measures and interactions with the business model and risk management.

Data sources are heterogeneous: SAP and ERP systems provide financial and quantity data, HR systems provide the key personnel figures, energy bills provide consumption data, travel management provides mobility emissions and suppliers provide Scope 3 contributions. The challenge lies in the consolidation across locations, subsidiaries and joint ventures as well as in the delimitation of the reporting group from the financial group according to IFRS or HGB. Data quality here specifically means: source documented, method specified, estimates marked, comparison with previous year comprehensible, scope of consolidation defined.

CIVAC records the data points in a workspace structure that assigns each data point a person responsible, a source, a methodology, a due date and a version status. Supplier data is collected via a supplier portal, which is also used for LkSG due diligence, so that each supplier is only surveyed once. The clock starts on awareness. ISO/IEC 27001:2022 with its 93 controls and EU data residency ensure data integrity. In this way, an abstract data collection becomes reliable evidence that supports the auditor's opinion and supports the statements in the annual report. Ideally, the data points flow directly from ERP, HR and energy data systems into the workspace via standardised interfaces, eliminating manual double entry and avoiding version conflicts.

EU taxonomy: thresholds and technical assessment

The EU Taxonomy Regulation (EU) 2020/852 defines six environmental objectives: climate protection, adaptation to climate change, water and marine resources, circular economy, pollution prevention and protection of biodiversity. An economic activity is considered ecologically sustainable if it contributes substantially to at least one goal, does not significantly harm any other goal (Do No Significant Harm), meets minimum protection standards (OECD Guidelines, UN Guiding Principles on Business and Human Rights, ILO Core Labour Standards) and complies with the technical assessment criteria from the delegated regulations.

Three key figures are required to be reported according to the taxonomy: sales share, capex share and opex share taxonomy-capable and taxonomy-compliant activities. The assessment requires a mapping of operations to NACE codes, a technical check against the thresholds (around 100 g CO2/kWh for certain power generation technologies) and a DNSH check against pollution, water and biodiversity requirements. Minimum protection is demonstrated through compliance programs. The methodology has been refined annually since 2024 through delegated legal acts of the Commission.

The taxonomy calculation is methodologically demanding and is often the biggest hurdle for medium-sized companies because it requires data that classical accounting does not show. CIVAC structures the assessment using workflow modules that record business activities, assign NACE codes, store technical criteria and document DNSH tests. Licence the workspace for your internal representatives, or have our representatives order it. The auditor calls, the evidence is ready. This means that the taxonomy rate becomes a reproducible key figure, not a one-off consultant estimate, and the reporting can be continued in the following year without additional effort because the methodology is saved and only updates to new delegated legal acts need to be maintained. CIVAC integrates the taxonomy data with the management report and the ESG report, ensuring consistency across all three publications and auditors not finding contradictory values.

The ESG officer: role, tasks, appointment

There is currently no explicit legal obligation to appoint an ESG officer in Germany outside of regulated areas. In fact, however, the role is necessary because CSRD reporting requires cross-sectional data from finance, human resources, purchasing, production and risk departments and fails in practice without a coordinating function. In listed companies, the role is often as Chief Sustainability Officer (CSO) or Head of Sustainability, in medium-sized companies as ESG officer with a reporting line to management or the CFO. The scope of tasks is therefore similar to that of classic representative roles from the GDPR or AMLA.

The core tasks are controlling the materiality analysis, coordinating data collection, maintaining the methodology, training the specialist departments, processing investor and rating inquiries (CDP, MSCI, ISS, EcoVadis, Sustainalytics) and preparing the auditor's report. In addition, there is the interface to the LkSG officer, the compliance officer and the data protection officer as well as maintaining the taxonomy quota. The appointment is made in writing with a clear task description, reporting line, authorities and resources, ideally supplemented by a representation regulation.

CIVAC offers the role as an external appointment or as an internal function via the licence model. The appointment certificate, signed, filed, verifiable. An external ESG officer is appointed via the platform within 2 working days, instead of 2 to 6 weeks for traditional consultations, and is integrated into a standardised methodology that covers ESRS and taxonomy identically across industries. The dual-model approach allows the representative to be started externally and, once internal competence has been built up, to be handed over to one of your own employees, without the file management having to be migrated because all data remains in the same workspace and versions are retained. In this way, the organisation ensures continuity in reporting, even if there are personnel changes in the ESG team, and avoids typical migration breaks between external consultants and internal structures.

Audit-proof documentation and auditor's certificate

With the CSRD, sustainability reporting becomes subject to attestation for the first time. Limited Assurance applies in the first stage, Reasonable Assurance will follow from a later date. The audit is carried out by the auditor or an independent provider of confirmation services. The audit includes materiality analysis, methodology, data quality, internal controls and consistency with the management report. Anyone who does not provide reliable documentation risks a limited or failed audit, which has significant consequences for the capital market and, in the worst case, leads to the balance sheet date being adjusted.

Audit-proof documentation specifically means: every statement in the report can be traced back to a data point, every data point has a source, a methodology, a person responsible and a version date. Changes are logged in a comprehensible manner, deleted content remains visible in the history. Controls are documented and their effectiveness checked, for example through the dual control principle, authorisation separation and completeness checks. ISO/IEC 27001:2022 with 93 controls provides the security foundation, EU data residency protects against extraterritorial access from third countries according to the US Cloud Act or Patriot Act.

CIVAC meets these requirements from a single source. The workspace logs every data change with user ID, timestamp and IP address, exports audit trails in CSV or PDF format and provides read-only access for auditors. Audit proof, documented, ESRS proof. This creates a compliance backbone that not only supports ESG reporting, but also covers LkSG, data protection and IT security evidence at the same time. Further details on how to connect to LkSG reporting can be found on the LkSG Officer page, as ESG and supply chain data points overlap significantly and can be collected together via a single supplier survey. The platform also supports export in XBRL format, as required by the ESRS taxonomy for machine-readable reporting, thereby reducing the effort for electronic submission to the European Single Access Point.

Common mistakes and how to avoid them

First: materiality analysis without documented methodology. Many companies carry out a gut feeling analysis and then enter it into a table. The auditor questions thresholds, scales and stakeholder selection, and without documented methodology the result is tilted. Solution: standardised evaluation matrix with stored thresholds, documented stakeholder survey, versioned workshop output, supplemented by a written justification for the chosen threshold.

Second: data points without a source. Anyone who assumes Scope 3 emissions based on industry averages risks complaints. Solution: mark each estimate as an estimate, indicate the source (e.g. EcoInvent, ifeu, UBA, GHG Protocol), show estimation uncertainty, describe a plan for data improvement in subsequent years. Third, taxonomy as an exercise in advertising. Anyone who declares activities as taxonomy-compliant without a DNSH check risks greenwashing accusations and EU sanctions from the DMA, the DSA or the Empowering Consumers Directive. Solution: complete DNSH check with documented technical criteria and a formal approval by the ESG officer.

Fourth: duplication of work between ESG, LkSG, compliance, data protection and occupational safety. If each team maintains its own Excel lists, the effort multiplies and the data contradicts each other. Solution: integrated platform with common data model and common supplier master database. Fifth: no clear order and reporting line. Solution: Appointment certificate with tasks, reporting line and resources. CIVAC addresses all five points through an integrated platform where ESG, LkSG, compliance and data protection data share a common model. Licence the workspace for your internal representatives, or have our representatives appoint one, and avoid typical stumbling blocks in the first reporting cycle, which experience shows is the most complex. Sixth, avoid last-minute reporting: If you only start collecting data two months before the balance sheet date, you lose the opportunity to request supplier data and have to work with rough estimates, which are regularly highlighted in the audit.

Turn reading into an assignment

ESG sustainability criteria are no longer optional, but mandatory with certification. CSRD, ESRS, Taxonomy Regulation and LkSG require an integrated data architecture, a documented materiality analysis, reliable data collection and audit-proof reporting. Anyone who tries to do this without a platform will fail at the latest with the first auditor's report or the first rating audit because the documents are in different systems and versions contradict each other. Classic consultants deliver a nice PDF, but no repeatable process for the following year and no reproducible methodology for the materiality analysis.

There is also economic pressure: loan interest rates are increasingly linked to ESG ratings, major customers require ESG data as a prerequisite for supplier approvals, and public clients evaluate sustainability information as an award criterion according to Sections 97, 122 GWB. Anyone who does not master ESG loses access to the capital market, sales and reputation. Those who master it gain differentiation because many competitors still stumble when it comes to the basics and the market for reliable data is undersupplied.

CIVAC is the compliance platform and officer-as-a-service that covers ESG, LkSG, data protection, IT security and 21 other roles from a single source. 25 representative roles are live, 490 audit templates are immediately ready for use, 93 controls according to ISO/IEC 27001:2022 as a security foundation, EU data residency for compliance security. Licence the workspace for your internal representatives, or have our representatives order it. Turn reading into a mandate.: Write to info@civac.de or use the contact form on civac.de. We will respond within one business day with a specific proposal for your ESG reporting cycle, order date and methodology setup for the materiality analysis. The first workshop for the materiality analysis can take place within two weeks, the workspace is productive and prepared for the first CSRD reporting cycle after 10 working days.

FAQ

Which companies will have to report according to CSRD in 2026?

From the 2025 financial year, large capital market-oriented companies, and from 2026, large corporations in accordance with Section 267 Paragraph 3 of the German Commercial Code (HGB) will report with at least two of the three thresholds: 25 million euros in total assets, 50 million euros in sales, 250 employees. From 2027, listed SMEs will follow, and from 2028, large third-country companies with EU subsidiaries will follow. The reporting requirement applies to around 15,000 companies in Germany and cannot be postponed voluntarily.

What does double materiality mean specifically?

Double materiality evaluates each ESG topic from two perspectives: Impact Materiality (the company's impact on people and the environment) and Financial Materiality (the topic's impact on the company). A topic is essential as soon as it reaches the defined thresholds in at least one perspective. The methodology must be disclosed in the report and is the subject of the auditor's audit, otherwise the certificate will be overturned in the limited assurance level.

How many ESRS data points does a medium-sized company actually have to report?

In total, the ESRS contain around 1,100 data points, of which around 270 are binding as cross-standards in ESRS 1 and 2, the rest follow the materiality analysis and can vary greatly depending on the industry. In practice, typical medium-sized companies report 350 to 600 data points, depending on the industry and value creation. CIVAC prefills the data point structure and filters according to materiality so that the effort remains calculable.

What role does the EU taxonomy play alongside CSRD and ESRS?

The Taxonomy Regulation (EU) 2020/852 complements the ESRS with a technical assessment of environmental performance based on six environmental objectives. Three key figures are required to be reported: sales, capex and opex shares from taxonomy-compliant activities. The test requires mapping to NACE codes, compliance with technical thresholds, DNSH testing and minimum protection according to OECD guidelines. It is methodologically more demanding than the ESRS and is often the biggest hurdle for medium-sized companies.

Who is liable if ESG information is incorrect?

The management bears responsibility in accordance with Sections 264, 289 of the German Commercial Code (HGB) and Sections 91, 93 of the German Stock Corporation Act (AktG), with personal liability if necessary in accordance with the Business Judgment Rule. In addition, there are sanctions from the CSRD implementation in Germany as well as civil law claims from investors due to incorrect capital market information. The ESG representative and the auditor are subordinately liable in accordance with Sections 280 and 823 of the German Civil Code (BGB) as well as for professional obligations and may be subject to recourse.

How does CIVAC specifically support ESG reporting?

CIVAC provides a workspace with a materiality analysis module, ESRS data point structure, supplier portal for Scope 3 data, taxonomy calculator with NACE mapping, audit trail for every change and read-only access for auditors. In addition, an external ESG officer can be appointed within 2 working days, with standardised onboarding, reporting line to management, integrated LkSG reporting and interface to the compliance officer, all in an EU data residence according to ISO/IEC 27001:2022.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles