ISSESG decoded: ISSB, ESRS and the ESG representative in German medium-sized companies
ISSESG brings together three worlds: ISSB IFRS S1/S2, ESRS according to CSRD and operational ESG responsibility in the company. Find out which obligations apply to German medium-sized companies from 2025, which data must be provided and how a workspace reflects the ESG reporting requirement without Excel sprawl.
The buzzword ISSESG has appeared in German specialist discussions since 2024 and summarizes three regulatory lines that shape ESG reporting in companies today: firstly, the global ISSB standards IFRS S1 (general sustainability disclosures) and IFRS S2 (climate-related disclosures), which the International Sustainability Standards Board published on June 26, 2023. Secondly, the European Sustainability Reporting Standards (ESRS), which will become mandatory under the Corporate Sustainability Reporting Directive (CSRD) from the 2024 financial year for large companies and gradually until 2028 for medium-sized and capital market-oriented companies. Thirdly, operational responsibility within the company itself, often in the form of an ESG officer or sustainability officer, who translates the reporting obligations into ongoing processes. The combination of these three worlds is what the term ISSESG stands for, and it is precisely this combination that creates the greatest pressure to act in German medium-sized companies today.
This guide organises the three standard worlds, shows which obligations apply in which financial year and how an ESG officer operationally implements the reporting obligation. You will learn which data points need to be collected, how the CSRD double materiality concept works and how ESRS, ISSB and CSRD reporting requirements can be mapped in the workspace instead of ending up in an Excel spreadsheet with 200 tabs. In the end, you know the path from the first materiality analysis to the audit-proof sustainability statement in the management report.
Key Takeaways
- ISSESG combines ISSB IFRS S1/S2, ESRS according to CSRD and the operational ESG officer role, which actually becomes indispensable in Germany with more than 250 employees.
- From the 2025 financial year, the ESRS will require an audit-proof sustainability declaration in the management report with over 1,000 data points for around 15,000 German companies.
- A workspace with an ESRS data model, materiality matrix and audit trail replaces Excel and makes the reporting requirement for medium-sized companies technically and organizationally manageable.
What ISSESG really means: three worlds in one term
ISSESG is not an official standard name, but rather a summary language rule for the intersection of three regulatory lines. First, the ISSB standards. The International Sustainability Standards Board was established in November 2021 under the IFRS Foundation and published the first two standards on June 26, 2023: IFRS S1 for general requirements for sustainability disclosures and IFRS S2 for climate-related disclosures. Both are voluntary in jurisdictions that have adopted them and are either mandatory or recognised as best practice in more than 20 countries as of 2024. They follow an investor perspective and focus on financially material sustainability risks and opportunities.
Secondly, the ESRS. The European Sustainability Reporting Standards were developed by EFRAG and adopted by the EU Commission as a delegated act on July 31, 2023. They are the binding basis for the CSRD reporting requirement and include twelve standards (ESRS 1, ESRS 2, five environmental standards, four social standards, one governance standard). Thirdly, the operational role in the company. While ISSB and ESRS set the standards, practical implementation requires a responsible person with a defined reporting line to management. The function of the ESG/sustainability officer is not prescribed by a single law, but arises from the mix of duties of CSRD, LkSG, EU taxonomy and sectoral requirements. CIVAC as a compliance platform and officer-as-a-service bundles all three worlds in one workspace with an ESRS data model, materiality matrix and 490 audit templates. Anyone who manages the three worlds separately doubles their effort and produces inconsistencies that are noticeable in the exam. The EU Taxonomy Regulation and the LkSG also run in many medium-sized companies without being linked to the ESG function, which makes audit preparation significantly more expensive and reduces the quality of reports.
Scope of the CSRD: which German companies report and when
The Corporate Sustainability Reporting Directive (CSRD) was published in the Official Journal of the EU on December 16, 2022 and is to be implemented in Germany through the CSRD Implementation Act. The scope of application follows a tiered logic. Stage one affects large capital market-oriented companies with more than 500 employees that already reported under the NFRD, from the 2024 financial year (first reports 2025). Stage two affects all large companies that exceed two of the three criteria: 250 employees, 50 million euros in sales, 25 million euros in total assets, from the 2025 financial year (first reports 2026). Stage three affects capital market-oriented SMEs from the 2026 financial year, with an opt-out option until 2028. Stage four affects subsidiaries of third-country groups with significant EU sales from 2028.
For Germany, according to DRSC estimates, this means a multiplication of the number of companies subject to reporting requirements from around 500 under the NFRD to around 15,000 under the CSRD. The biggest jump occurs in level two, i.e. to medium-sized companies with 250 to 5,000 employees. For many of these companies, this is the first regulatory sustainability reporting requirement ever. In addition, there is the indirect impact via supply chains: SMEs that have a large customer that is subject to CSRD must provide data, even if they are not directly required to report. The CIVAC workspace has the right data model for both constellations: full reporting for those directly responsible and SME light reporting for those indirectly affected, each with a documented audit trail. The appointment certificate, signed, filed, verifiable. Anyone who underestimates the indirect impact will lose large customer contracts because the data is not available in the required form. The effects range from exclusion from vendor lists to the customer's explicit request to appoint an ESG officer and to guarantee standardised data delivery, which puts an operational strain on many SMEs.
Double Materiality: the double materiality concept of the ESRS
The heart of the ESRS is the double materiality concept. It requires two perspectives at the same time. Firstly, the outside-in view, i.e. which sustainability issues have a significant financial impact on the company (risks, opportunities, capital costs, reputational value). Secondly, the inside-out view, i.e. what impact the company itself has on the environment, people and society (emissions, supply chain impacts, social standards). A topic is considered essential as soon as it is essential in at least one of the two perspectives. The ISSB standards, on the other hand, are limited to the outside-in view, which is the crucial difference in content between ISSB and ESRS.
The practical implementation of the materiality analysis follows ESRS 1 Section 3 and ESRS 2 IRO-1. You first identify the impacts, risks and opportunities (IROs) along the value chain, assess each IRO according to scale, scope, irreversibility (for inside-out) and probability of occurrence and financial impact (for outside-in). The assessments are documented in a materiality matrix and approved by management. Others run compliance like a filing cabinet. We run it like software. In the CIVAC workspace, the materiality analysis is depicted as a structured process that systematically goes through the ten ESRS topic standards and produces a documented assessment for each IRO with stakeholder participation and management approval. The result is an audit-proof materiality matrix that serves as the basis for the entire report and is checked by the auditor as part of limited assurance. The matrix is updated annually because value chains, regulatory requirements and stakeholder expectations change and an outdated materiality analysis is one of the most common audit findings in the first reporting period. The stakeholder participation typically includes customers, suppliers, employees, investors, authorities and non-governmental organisations, depending on the business model and geographical presence, and is documented in the workspace with the date, format and content of the participation.
The twelve ESRS standards: structure and data points
The ESRS consist of twelve individual standards. ESRS 1 (general requirements) and ESRS 2 (general information) are mandatory for all reporting companies. The ten topic standards are ESRS E1 (climate change), E2 (pollution), E3 (water and marine resources), E4 (biodiversity and ecosystems), E5 (resource use and circular economy), S1 (own workforce), S2 (value chain workers), S3 (affected communities), S4 (consumers and end users) and G1 (corporate governance). The application of the topic standards follows the materiality analysis: Only material topics are mandatory to report, a non-material topic is documented with justification.
The twelve standards together include over 1,100 quantitative and qualitative data points. Of these, around 250 data points are mandatory for all reporting parties, and around 850 are applicable depending on materiality. Climate data according to ESRS E1 includes Scope 1, Scope 2 and Scope 3 emissions according to the GHG Protocol, climate targets in tonnes of CO2 equivalent, transition plan and financial impacts of physical and transitory climate risks. Social data according to ESRS S1 includes employee structure, equal pay, occupational health and safety, training and whistleblower system. The data model of the CIVAC workspace maps the XBRL taxonomy of the ESRS, so that the output can be done directly in the required iXBRL format for the electronic situation report. The auditor calls, the evidence is ready. Experience has shown that cleanly structured data collection in the workspace saves between 30 and 50 percent of reporting time compared to Excel-based procedures. In addition, the reporting can be used interactively: the board of directors and supervisory board see the key key figures on a dashboard that is fed from the same source data as the formal sustainability declaration in the management report, without the data consistency having to be established manually. This reduces the likelihood that the board of directors and the management report will communicate different figures in the audit, which is considered a typical finding of an initial audit.
Climate data according to ESRS E1: Scope 1, 2, 3 and the transition plan
ESRS E1 is by far the most comprehensive topic standard. It includes nine disclosure requirements ranging from climate protection policy to climate targets, transition plan, emissions data and financial effects. Scope 1 emissions include direct emissions from our own facilities and vehicles. Scope 2 includes indirect emissions from purchased electricity and heat, separated into location-based and market-based methodology. Scope 3 includes all other upstream and downstream emissions along the value chain, divided into 15 categories according to the GHG Protocol. For many medium-sized companies, Scope 3 is the biggest data challenge because it requires a systematic supplier query and a robust data model.
The transition plan according to ESRS E1-1 is the strategic answer to the Paris 1.5 degree target. It describes how the company plans to reduce its emissions in line with a 1.5 degree path, with interim targets for 2030 and 2040 as well as a net zero target for 2050. The auditors check the transition plan for plausibility, not achievability, which marks the difference between an ambitious commitment and a wishful formulation. Licence the workspace for your internal representatives, or have our representatives order it. CIVAC provides a complete data model for ESRS E1, including a Scope 3 supplier questionnaire, emission factor library and plausibility checks. Deadline begins as soon as we become aware of it. The workspace documents every data origin, every assumption and every plausibility check, so that the auditor's limited assurance can be completed quickly and without additional requests. Anyone who systematically builds up Scope 3 also gains a valid database for the EU taxonomy and for the LkSG risk analysis because the underlying supplier data is used in all three regulations. The emission factors are obtained from recognised databases (DEFRA, ecoinvent, GHG protocol database) and documented in the workspace with source and status, so that every ton of CO2 equivalent can be traced in the audit.
Supply chain and LkSG: why ESG and human rights belong together
The supply chain is where most ESG risks become visible and where two German regulations interact. The ESRS S2 requires information on workers in the value chain, i.e. on human rights issues, working conditions, health and safety at suppliers. Since January 1, 2023, the Supply Chain Due Diligence Act (LkSG) has required companies with 3,000 or more employees and since January 1, 2024 for companies with 1,000 or more employees to carry out a risk analysis, preventive measures, complaint procedures and an annual report to BAFA. Anyone who is subject to the LkSG covers a significant part of the ESRS S2 requirements, but must manage the data model in such a way that both reporting obligations are served in parallel.
In practical terms, this means: A supplier query must take both worlds into account, i.e. human rights and labour standards (LkSG, ESRS S2), but also emissions (ESRS E1 Scope 3) and environmental impacts (ESRS E2 to E5). Anyone who sends three separate supplier questionnaires loses the compliance relationship with the supplier and produces inconsistent data. The CIVAC workspace uses an integrated supplier questionnaire that consolidates LkSG, ESRS and EU taxonomy in one data model. The function of the LkSG representative is interlinked with the ESG function in the workspace, so that risk analysis, prevention measures and reporting for both duties are served from a single source. Audit-proof, documented, § 6 LkSG-proof. This consolidation saves around 40 to 60 percent of the query effort for medium-sized structures compared to separate procedures. Suppliers also respond more frequently and with higher data quality because they are not contacted multiple times and have a clear addressee for queries who has an overview of the entire data model. A staged query process with risk-based prioritization of high-risk suppliers further reduces the effort because not every C supplier receives the same questionnaire as a strategic A supplier.
Audit of sustainability reporting: Limited Assurance and the auditor
The CSRD requires an audit of the sustainability statement using the limited assurance audit standard. From 2028 at the latest, the EU Commission will decide whether to switch to reasonable assurance (adequate audit security). Limited assurance means that the auditor must, with a critical attitude, come to the conclusion that nothing has come to his attention that speaks against the conformity of the report with the ESRS. Reasonable Assurance, on the other hand, would require a significantly greater level of audit depth, similar to the annual financial statement audit. Both standards are based on the IAASB's ISAE 3000 standards.
Three areas are relevant to the audit: firstly, the materiality analysis with its methodological traceability, secondly, the data points with their data origin and plausibility, thirdly, the qualitative explanations with their consistency with the management report and annual financial statements. A common stumbling block in the initial audit is the lack of documentation of the materiality analysis: Anyone who cannot provide written evidence of the methodology will fail the audit, even if the reported data is correct. The CIVAC workspace documents the materiality analysis with all stakeholder participation, assessments and management approvals in an audit-proof manner, so that the methodology in the audit can be understood in less than an hour. The appointment certificate, signed, filed, verifiable. Proper audit preparation reduces audit costs by ten to thirty percent because there are no follow-up requests. The workspace provides the auditor with a separate audit view with access to all relevant documents without the need to release operational data or personal information, ensuring GDPR compliance of the audit. Most auditors value this form of preparation because it increases their own efficiency and reduces the risk of having to document reservations about data quality in the audit report.
The ESG officer: tasks, reporting path, qualifications
The ESRS do not prescribe a specific role, but they do require a responsible person with sufficient resources, reporting to management and access to all relevant data. In practice, the role of the ESG officer or sustainability officer has become established, depending on the industry and company size, as a full-time or partial function. The central tasks are, firstly, the control of the materiality analysis, secondly, data collection and plausibility checks, thirdly, the preparation of the sustainability statement in the management report, fourthly, the coordination with the auditor, supervisory board and stakeholders, fifthly the integration of ESG topics into the strategy and risk management.
In terms of qualifications, the role requires a combination of sustainability knowledge, business understanding and reporting experience. A pure environmental technician is just as insufficient as a pure controller. In practice, a dual structure works well: an internal ESG officer with functional knowledge and an external consultant or officer-as-a-service with ESRS expertise who brings in the methodological depth. Licence the workspace for your internal representatives, or have our representatives order it. CIVAC delivers both models: a workspace with ESRS data model, materiality matrix and audit templates or an external ESG officer with an appointment certificate, reporting obligation and SLA of two working days. The reporting route formally leads to the board of directors or management, and technically often to the CFO, because the sustainability declaration becomes part of the management report and must be congruent with the annual financial statements. A clearly documented appointment certificate with a clear reporting line is the organisational requirement for the subsequent audit. In group structures, ESG responsibility is often bundled centrally in the holding company, with local ESG coordinators in the subsidiaries who are integrated into the workspace as data suppliers.
From the ISSESG keyword to a productive reporting organisation
ISSESG remains a buzzword as long as the three worlds of ISSB, ESRS and operational responsibility do not converge in one system. Anyone who collects ISSB and ESRS data separately doubles their effort. Anyone who does not clearly regulate operational responsibility loses the ability to audit. Anyone who does the reporting in Excel will fail in terms of version control and data consistency by the second reporting year at the latest. This is exactly why we built CIVAC as a compliance platform and officer-as-a-service: a workspace with ESRS data model, materiality matrix, Scope 3 supplier questionnaire, iXBRL export, 490 audit templates and EU data residency. You decide for yourself how deep you want to go: licence the workspace for your internal representatives, or let our representatives do the work. Both models use the same data model and provide the same audit security.
Setting up a productive reporting organisation takes six to twelve months using a structured approach, depending on the initial situation and reporting level. Turn reading into an assignment. Write to us at info@civac.de or book an initial consultation using the contact form on civac.de. You will receive an honest maturity assessment, a gap analysis against the ESRS, a step-by-step plan for the first twelve months and a transparent offer. The materiality analysis methodology and the appointment document for the ESG officer are created in the first 30 days. In the following 60 to 120 days, the data model will be set up, stakeholder participation will be carried out and the supplier query will be started. The auditor calls, the evidence is ready. A well-prepared initial report not only saves money in the later audit, but also the risk that the sustainability statement in the management report is criticized and the auditor has to issue a limited audit opinion. Anyone who confidently delivers the initial report also gains a reputation among banks, insurers and major customers, because an audit-proof sustainability declaration is considered an indicator of the operational maturity of the company as a whole.
FAQ
What does ISSESG mean exactly?
ISSESG is not an official standard name, but a collective name for the intersection of three worlds: the global ISSB standards IFRS S1 and S2, the European ESRS under the CSRD and the operational responsibility in the form of an ESG officer. Anyone who covers all three worlds consistently meets the essential sustainability obligations in Germany and internationally and reduces the risk of contradictory data.
When is my medium-sized company required to report on CSRD?
Large companies that exceed two of the three criteria (250 employees, 50 million euros in sales, 25 million euros in balance sheet total) are obliged to provide initial reports in 2026 from the 2025 financial year. Capital market-oriented SMEs will follow from the 2026 financial year with an opt-out until 2028. SMEs indirectly affected must provide data to customers subject to CSRD, even if they themselves are not directly required to report.
What is the difference between ISSB IFRS S1/S2 and ESRS?
The ISSB standards follow the investor perspective and focus on financially material topics (outside-in). The ESRS require the double materiality concept, i.e. the company's impact on the environment and society (inside-out). The ESRS are mandatory in Europe, the ISSB standards are voluntary worldwide, depending on the jurisdiction and sectoral adoption by national supervisory authorities.
What data do I need to collect for ESRS E1 (climate change)?
Scope 1, Scope 2 and Scope 3 emissions according to the GHG Protocol, a transition plan in line with 1.5 degrees, climate targets in CO2 equivalents, financial impacts of physical and transitory risks as well as climate protection policy. ESRS E1 includes nine disclosure requirements and is by far the most comprehensive topic standard, especially because of Scope 3 with its fifteen supply chain categories and the obligation to check the plausibility of all emission factors.
What qualifications does an ESG officer need?
A combination of sustainability knowledge, business understanding and reporting experience. A pure environmental technician or pure controller does not cover the role. In practice, a dual structure consisting of an internal manager and an external consultant or officer-as-a-service with ESRS expertise who brings in the methodological depth, routinely supports the auditor and documents the appointment document with a clear reporting line to the management has proven successful.
What advantage does a workspace offer over Excel for ESRS reporting?
A workspace offers a complete ESRS data model, documented materiality analysis, version control, audit trail, iXBRL export, supplier integration and a separate audit view for the auditor from a single source. Excel cannot map these functions in an audit-proof manner and produces inconsistencies in the second reporting year at the latest, which are criticized in the audit, trigger expensive subsequent request loops and worsen the overall data quality.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.