EU omnibus on CSRD: What is really changing for medium-sized businesses
With the EU omnibus package of February 26, 2026, CSRD thresholds and deadlines are shifting. This guide classifies the changes for medium-sized companies and shows how CIVAC structures the preparation of reporting.
On February 26, 2026, the European Commission presented the Omnibus Simplification Package and on April 14, 2026, postponed the deadlines of the CSRD and CSDDD with a first stop-the-clock directive. The reporting landscape is changing fundamentally for medium-sized businesses: thresholds are increasing to around 1,000 employees, waves 2 and 3 are being pushed back by 2 years.
This article explains what the omnibus package means specifically for SMEs and medium-sized corporations, which reporting obligations remain, which are eliminated and how CIVAC, as a compliance platform and officer-as-a-service, structures the transition, thus turning political uncertainty into a reliable roadmap will.
Key Takeaways
- The omnibus package raises the CSRD thresholds to around 1,000 employees and postpones application for waves 2 and 3 by two years.
- The voluntary VSME standard becomes the framework for SMEs that receive data requests from banks, insurers or large customers.
- The CSDDD application obligations are shifting, but material due diligence obligations in the supply chain remain effective.
Background: Why the Commission is unraveling the CSRD
The Corporate Sustainability Reporting Directive 2022/2464 has triggered reporting requirements for around 50,000 EU companies. The first wave in 2025 for 2024 data showed that ESRS data points, double materiality analysis and audit scope are hardly manageable for medium-sized companies.
The Commission responded to this with the Omnibus Simplification Package of February 26, 2026. Goal: Concentrate reporting requirements, reduce duplicate requirements from CSRD, CSDDD, taxonomy and CBAM, reduce administrative burden. Politically, the package was positioned as a response to the Draghi report and the Letta report on competitiveness.
Stop the Clock Directive 2026/794 of April 14, 2026 postponed the application of CSRD waves 2 and 3 for two years. Wave 2 (large companies that are not public interest entities) reports for the first time in 2028 for 2027, wave 3 (listed SMEs) in 2029 for 2028.
The material omnibus package itself, i.e. the increase in the threshold values and the reduction in content of ESRS, goes through the ordinary legislative procedure. Final adoption is expected for autumn 2026. Until then, the original CSRD will apply for the time being, unless suspended by stop-the-clock.
In the CIVAC workspace, we follow the legislative process in a versioned source register. With each change, compliance, ESG officers and management see what specifically changes for the reporting year and data requirements. The appointment certificate, signed, filed, verifiable.
Thresholds: Who reports, who no longer reports
The omnibus package proposes that the CSRD only be applied to companies with more than 1,000 employees and either a turnover of 50 million euros or a balance sheet total of 25 million euros. This means that around 80 percent of the 50,000 EU companies originally recorded fall out of the direct scope.
In Germany, the number of around 15,000 companies required to report is reduced to an estimated 3,000 to 4,000. For medium-sized companies with 250 to 999 employees, this means that the obligation to report according to CSRD will no longer apply as soon as the package has been approved. Wave 2 has already been suspended due to stop-the-clock.
What is important is the indirect impact. Banks, insurers and major customers in the supply chains continue to request sustainability data, due to their own CSRD, EU taxonomy and CSDDD obligations. SMEs are effectively under pressure to request data, even without their own CSRD obligation.
The EFRAG VSME standard (Voluntary Standard for Non-Listed SMEs) will become the intended framework. It bundles data points that are typically requested by banks and large customers into a streamlined reporting format. Anyone who maintains the VSME can answer queries in a standardised manner.
CIVAC maintains a threshold matrix in the workspace that records employees, sales and balance sheet total and derives obligations and relief for each financial year. Anyone who falls out of wave 2 will see this directly in the dashboard with the reasons.
ESRS data points and dual materiality
The omnibus package is intended to significantly reduce the number of ESRS data points. The ESRS set currently includes over 1,100 data points, and a reduction of an estimated 25 to 50 percent is being discussed. The standards are consolidated, options are expanded, and the separation between strongly essential and only expanded essential is eliminated.
The double materiality analysis remains the methodological backbone. It evaluates whether issues from an inside-out perspective (the company's impact on the environment and society) or outside-in perspective (financial impact on the company) are material. Only essential topics need to be reported in detail.
Mandatory data points such as climate targets, Scope 1 and Scope 2 emissions, energy consumption and water withdrawal remain for companies required to report. Scope 3 emissions and supply chain data are becoming easier due to the elimination of many downstream mandatory operations because less data is requested from medium-sized companies.
Limited assurance remains standard for the audit for the time being, the jump to reasonable assurance is postponed. Auditors still need reliable data bases, i.e. data sources, methodology and controls. The burden of proof for data quality lies with the company.
In the CIVAC workspace we structure the materiality analysis, data points and methodology in versions for each financial year. 490 audit templates cover ESRS construction, supplier data queries and audit preparation. Audit-proof, documented, ESRS-proof.
CSDDD and post-omni supply chain care
The Corporate Sustainability Due Diligence Directive (EU 2024/1760) is also being revised. The start of application is postponed by one year, the application threshold increases, and the range of fines is capped. However, the material obligation to carry out risk analysis and care along the supply chain remains.
In Germany, the Supply Chain Due Diligence Act LkSG also applies. With the omnibus, the LkSG and the upcoming CSDDD are no longer in sync; the national legislature must decide whether the LkSG will wait for the European framework or take its own steps. The Bundestag will discuss this in 2026.
For medium-sized companies in the supply chains of large corporations, this practically means: data requests on human rights, the environment and corruption will remain. Major customers will maintain their own supplier codes and require explanations, audits and elimination of defects. Anyone who answers professionally wins orders.
The LkSG representative retains his role. He carries out risk analysis, prevention measures, complaints procedures and reporting. The transitions to the CSDDD are documented in the workspace so that there is no data breach when it comes into force.
CIVAC integrates LkSG, CSDDD and VSME in one platform. The supplier matrix, complaint procedure and catalogue of measures are interlinked. Licence the workspace for your internal representatives, or have our representatives order it.
Taxonomy, CBAM and double burden
The omnibus package also reorganizes the EU taxonomy regulation. Reporting requirements are focused on companies with more than 1,000 employees. There are no direct taxonomy obligations for SMEs, but they remain indirectly relevant through banking requirements from the Sustainable Finance Disclosure Regulation (SFDR).
In the case of the CBAM CO2 border adjustment, the package raises the threshold for importers required to report to 50 tonnes of import mass per year. This means that around 90 percent of the SMEs recorded so far are excluded; large importers continue to cover around 99 percent of the CO2 import volume. The quarterly reporting period remains.
In practice, this reduces the burden twice. Anyone who previously maintained CSRD, taxonomy, CBAM and LkSG in parallel can significantly streamline their compliance work in 2026, provided the thresholds are met or fallen below. Careful threshold analysis for each financial year is mandatory.
The integration with the CSRD remains close. Those who are still required to report integrate taxonomy shares, CBAM data points and supply chain data into the sustainability report. Auditors check consistency between the regimes, deviations are addressed in the audit report.
In the CIVAC workspace we link CSRD, taxonomy, CBAM and LkSG in a common data and audit backbone. 490 audit templates cover the interfaces, EU data residency and ISO 27001:2022 ISMS are standard. Others run compliance like a filing cabinet. We run it like software.
What medium-sized companies should actually do now
First: check thresholds honestly. Record employees, sales, balance sheet total per financial year and per relevant threshold. Pay attention to group logic, as parent and subsidiary companies count differently. Anyone who has just over 1,000 employees plans two scenarios.
Second: Don't discard existing reporting work. Those who collected data in 2025 will retain it for banking inquiries, supply chain questions and voluntary VSME. The investment is not lost, but is transferred to a leaner framework.
Third: Check VSME as the default standard for SMEs. It was developed by EFRAG, is recognised by banks and reduces the data effort to an acceptable level. Those who maintain it respond to data requests in a standardised and quick manner.
Fourth: consolidate reporting lines and responsibilities. Even without a CSRD obligation, sustainability remains part of risk management. An ESG representative bundles inquiries, coordinates with finance, purchasing and sales and carries out reporting even below the mandatory threshold.
Fifth: keep the data architecture clean. Energy consumption, emissions, supplier data and employee numbers should be collected once and used multiple times. CIVAC maintains data and audit templates in one platform so that banks, major customers and regulators see the same status.
Risks: What remains despite the omnibus
The due diligence and reporting obligations are not disappearing, they are concentrating. The omnibus package formally relieves SMEs, but shifts the requirements into the contractual area. Banks, insurers and major customers make their obligations yours through supplier codes and financing contracts.
Greenwashing risks remain under negotiation under the Empowering Consumers Directive (EU 2024/825) and the Green Claims Directive. Anyone who advertises sustainability without a clean data basis risks warnings and fines under competition law. Claims must be verifiable.
The supervisory board is also not allowed to ignore the topic. ESG risks continue to be included in risk reporting in accordance with Section 91 AktG and Section 289c HGB for large corporations. The management's duty of care in accordance with Section 93 AktG and Section 43 GmbHG also covers sustainability-related risks.
Legal disputes regarding climate damage and corporate responsibility are increasing. Investor lawsuits due to incorrect sustainability information are being prepared. A clearly documented database and a reliable materiality analysis protect against later allegations.
In the CIVAC workspace we combine ESG, LkSG, risk management and data protection into a reliable set. 490 audit templates, clear reporting lines and EU data residency turn politically volatile rules into a verifiable list of obligations. The auditor calls, the evidence is ready.
Collaboration with auditors, banks and insurers
The auditor remains a central companion, even if the formal obligation no longer applies. He checks whether voluntary VSME information is consistent with the annual financial statements, whether data points are methodologically comprehensible and whether the double materiality analysis is documented. Comparability between reporting years is required.
Banks use sustainability data in credit assessment, pricing and reporting according to SFDR and CRR III. Anyone who delivers standard formats, for example via VSME or via bank-internal data requirements such as the standardised data form of the ESG Data Requirements Initiative, speeds up decisions and reduces follow-up questions.
Insurers request ESG data for underwriting, property insurance and D&O coverage. Climate risks, supply chain risks and reputational risks are incorporated into premiums and deductibles. Those who provide data transparently win better conditions, those who avoid risk risk premiums.
Large customers build supplier scorecards with sustainability dimensions. These often go beyond VSME and require sector-specific data, for example for pharmaceuticals, automotive or construction. Anyone who delivers proactively is kept in lists; anyone who evades loses orders.
CIVAC structures the data flows to auditors, banks, insurers and major customers in one platform. Requests are managed centrally and responses are versioned. This creates a data archive that compliance, sales and finance use equally. The appointment certificate, signed, filed, verifiable.
Structure the transition with CIVAC
The omnibus reform is both an opportunity and a task. Those who use the transition build sustainability as a resilient data field without suffocating under the weight of the original full CSRD requirement. Anyone who misses the transition will find themselves caught between contractual requirements and unclear obligations.
CIVAC is built as a compliance platform and officer-as-a-service to structure precisely this transition. 25 representative roles run in the same workspace, 490 audit templates cover CSRD, VSME, LkSG, taxonomy and CBAM, EU data residency and ISO 27001:2022 ISMS are standard.
Licence the workspace for your internal representatives, or have our representatives appointed. SLA for the initial appointment: two working days instead of the classic two to six weeks. This means that the ESG officer is able to act before the next bank inquiry or supplier scorecard arrives.
During onboarding, we scan existing reports, data, supplier inquiries and open bank commitments. You can immediately see which thresholds have been reached, which standards need to be maintained and where data gaps exist. Tasks are stored with a deadline and person responsible, reporting lines and escalation paths are anchored.
Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de, and you will have an initial consultation and a timetable that fits your financial year within two working days.
FAQ
Am I still subject to CSRD after Omnibus?
According to the current proposal, only if your company has more than 1,000 employees and either a turnover of 50 million euros or a balance sheet total of 25 million euros. Waves 2 and 3 have also been postponed by two years. The threshold analysis for each financial year is the reliable answer.
What is the VSME standard?
EFRAG's Voluntary Standard for Non-Listed SMEs is a voluntary reporting framework for SMEs. It bundles typical data requirements from banks and large customers in a slim set. CIVAC integrates VSME data points into the workspace and helps with the structured structure of the reporting modules.
What does the stop the clock policy mean?
Directive 2026/794 of April 14, 2026 postpones the start of application of CSRD waves 2 and 3 by two years. Wave 2 reports for the first time in 2028 for 2027, wave 3 in 2029 for 2028. Material threshold increases will only occur with the later main package.
Does the LkSG continue to apply if the CSDDD is postponed?
Yes. The national supply chain due diligence law applies independently of the EU procedure. The German legislature will decide whether the LkSG will be adapted to the CSDDD, suspended or continued in anticipation. Until a decision is made, obligations under Sections 4 ff. LkSG remain in effect.
What should SMEs prioritise now?
Threshold analysis, VSME preparation, clear accountability for ESG data and a central data archive. Even without a CSRD requirement, inquiries come from banks, insurers and major customers. Those who respond in a structured manner win conditions and orders instead of making special runs for each request.
How does CIVAC support Omnibus and CSRD?
With compliance platform and officer-as-a-service. Thresholds, ESRS data points, VSME modules, LkSG, taxonomy and CBAM come together in the workspace. 37 audit templates, clear reporting line, EU data residency and ISO 27001:2022 ISMS. Initial appointment in two working days instead of two to six weeks.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.