← Back to CSRD Insights
Insights

CSRD Software Buyer's Guide 2027: What the July 2026 ESRS Revision Changed - and What to Buy Now

Generated image

Most CSRD software shortlists were built against a standard that no longer exists.

On 3 July 2026, the European Commission adopted the delegated act containing the revised ESRS, cutting mandatory datapoints by more than 60% and total datapoints by more than 70% compared with the 2023 originals. A platform scoped in 2024 against 1,000-plus datapoints is now materially over-specified for the data model - yet the requirements that actually drive implementation complexity (iXBRL tagging, audit trails, limited assurance evidence) went nowhere. Many Wave 2 buyers are about to sign contracts optimised for the wrong problem.

This guide is vendor-neutral. It does not rank, score, or endorse any product. It will not tell you which tool to buy. It will tell you what to look for, what to skip, and what questions to put in your RFP.


1. Why the Buying Requirement Changed in July 2026

The revised ESRS apply for financial years beginning on or after 1 January 2027, with voluntary early adoption available for FY2026. The Council and Parliament have a two-month scrutiny period (extendable by a further two months) before the act is published in the Official Journal and enters into force. The practical implication: you are specifying systems against a standard whose text is adopted but not yet finally published. Contract for change - any vendor that cannot demonstrate a clear process for updating its datapoint model when the final text lands is a risk.

The simplification matters for your data model in a specific way. The revised ESRS delegated act reduces the mandatory datapoint list to approximately 320 items and removes all voluntary datapoints - a roughly 60% cut to mandatory items and over 70% reduction overall. A platform sold on the breadth of its ESRS datapoint library is now selling you capacity you will not use. What you need instead is a platform that tracks the revised standard cleanly, versions its datapoint model as the taxonomy evolves, and does not charge you to maintain fields you are not required to populate.

Tools that have already updated to reflect the amended ESRS demonstrate regulatory agility. Platforms still showing the old 1,100-plus datapoints are a red flag. Our guide to the revised ESRS datapoint cuts covers what was removed and what survived.

Two other Omnibus I changes reshape the buying requirement directly:

  • EU Taxonomy templates. The 2026 revision introduced a 10% materiality threshold and cut EU Taxonomy template datapoints by roughly 64%. Evaluate taxonomy modules against the new templates, not the old ones. See our EU Taxonomy 2026 changes guide for the full picture.
  • Value chain cap. Under Omnibus I, large reporters are legally prohibited from requiring value chain partners with 1,000 or fewer employees to provide information beyond the Voluntary SME Standard (VSME). The delegated act clarifies the application of the value chain cap and indicates which datapoints are included under it - specifically, only disclosures labelled as "necessary" in the Voluntary Standard. Supplier-questionnaire modules must support proportionate, VSME-shaped asks. Unlimited data-demand templates are now non-compliant by design. See our value chain cap explainer for what you can and cannot ask.

2. Build vs. Buy vs. Extend What You Have

There is no universal answer. The right frame depends on three variables: number of reporting entities, ERP fragmentation, and whether you already own a disclosure-management tool for financial reporting.

Build / Buy / Extend Decision Frame
ScenarioSignalLikely direction
Single legal entity, low ERP fragmentationMateriality assessment is narrow; data lives in one or two systemsExtend: add an ESRS module to your existing disclosure-management or ERP platform first
Group with 5–20 entities, mixed ERPsData collection across subsidiaries is the hard problemBuy: a purpose-built ESG data collection and reporting platform with multi-entity workflow
Group with 20+ entities, complex value chainScope 3 and supplier data dominate the effortBuy: a platform with strong data-collection orchestration and supplier portal; consider a separate carbon-accounting layer
Already own Workiva, SAP DM, or equivalentDisclosure management and iXBRL tagging already solvedExtend: add an ESG data-collection layer that feeds your existing disclosure tool rather than replacing it
Greenfield, limited internal IT resourceSpeed to first report matters more than integration depthBuy: a SaaS-native platform with guided workflows; avoid heavy implementation projects

The build option - assembling a workflow from spreadsheets, a BI tool, and a tagging add-in - is rarely viable for a group reporter. The assurance requirement alone (see Section 3, capability 6) demands documented lineage that spreadsheets cannot provide.


3. The Seven Capabilities That Actually Matter

Vendors need a platform that helps sustainability data meet the same standards of accuracy and auditability as financial data. That framing is useful. Below are the seven capabilities that determine whether a platform actually delivers it - each with a "what good looks like" line.

CSRD Software Capability Matrix
CapabilityWhy it matters nowWhat good looks like
1. Versioned ESRS datapoint modelThe July 2026 revision changed the mandatory set; the ESRS taxonomy will be updated again when the final text is publishedVendor can show you the diff between ESRS 2023 and ESRS 2026 in the platform; datapoint updates do not require a new implementation project
2. Double materiality assessment workflow with audit trailDMA is the gateway to the rest of the report; an unauditable DMA is an assurance problem from day oneStakeholder inputs, scoring rationale, and topic decisions are captured in-platform with timestamps and version history — not in a linked spreadsheet
3. Multi-entity data collection with ownership and sign-offGroup reporters need data from subsidiaries; each datapoint needs an owner and an approval chainConfigurable collection campaigns per entity; named data owners; sign-off workflow with deadline tracking; clear escalation path
4. Calculation transparency for GHG and EU TaxonomyAssurance providers will test emission factor sources, allocation methods, and taxonomy alignment logicEmission factor library is versioned and auditable; taxonomy alignment calculations are visible and exportable; methodology notes are attached to outputs
5. iXBRL/ESEF tagging against the ESRS taxonomyMachine-readable XHTML output is a hard legal requirement, not a nice-to-haveNative tagging against the EFRAG ESRS XBRL taxonomy; vendor has a published plan for updating the taxonomy version when the revised ESRS taxonomy is released; tagging is reviewable before submission
6. Evidence and lineage for limited assuranceAssurance is locked at limited assurance; auditors need to trace every disclosed figure back to its sourceSource documents attachable at datapoint level; lineage view shows data origin, transformation, and approval chain; export package suitable for assurance provider review
7. Proportionate value-chain/supplier collectionThe value chain cap limits what you can demand from suppliers under 1,000 employeesSupplier questionnaire templates are VSME-aligned; the platform enforces the cap rather than leaving compliance to the user; supplier portal is accessible without a paid licence

A note on iXBRL specifically, because it is the capability most often deferred or misrepresented. Under the CSRD, companies are legally required to prepare their management reports in ESEF format - the entire document rendered in XHTML, with sustainability information digitally tagged using iXBRL. The ultimate destination for this data is the European Single Access Point (ESAP), a centralised platform where stakeholders can pull, compare, and benchmark ESG performance across thousands of companies. The sustainability section of your annual report must be tagged with iXBRL using the ESRS taxonomy - not the IFRS taxonomy used for financial data. Any vendor whose tagging capability is "on the roadmap" or handled by a third-party add-in deserves a hard question about timeline and contractual commitment. See our ESRS digital tagging guide for the full technical picture.

On limited assurance: Assurance is locked at limited assurance under Omnibus I. That makes evidence trails, lineage, and control documentation a hard requirement. When evaluating CSRD software, check specifically whether it includes a built-in double materiality workflow - most companies end up managing this in Excel, which creates a serious audit trail problem when the auditor arrives. Our limited assurance guide covers what assurance providers will actually test, and the CSRD data collection playbook covers the process the platform has to support.


4. What You Can Safely Not Buy

The simplification removed requirements that drove significant platform complexity in 2024-era specs. You can deprioritise - or negotiate out of - the following:

  • Voluntary datapoint libraries. The revised ESRS removes all voluntary datapoints. A large library of optional disclosures is now a maintenance overhead, not a feature.
  • Sector-specific ESRS modules (for now). Sector-specific standards have been deferred. Do not pay for sector modules that do not yet have a published standard behind them.
  • AI-narrative generation for mandatory disclosures. Assurance providers will scrutinise narrative disclosures closely. Auto-generated text that cannot be traced to a human-reviewed source creates more audit risk than it saves effort.
  • Unlimited supplier data-demand templates. The value chain cap makes these non-compliant for suppliers under 1,000 employees. A platform that sells "comprehensive supplier ESG data collection" without VSME-alignment is selling you a compliance liability.
  • Overly broad GRC integrations. If your primary use case is CSRD/ESRS reporting, a full GRC suite adds cost and implementation complexity without proportionate benefit. Buy for the reporting requirement; integrate with GRC later if needed.

5. Cost and Effort Realities

Licence cost is usually the smaller half of the total investment. Implementation and change management typically adds 30-50% of the software cost in year one. Internal staff time - project management, data collection, stakeholder engagement, and review cycles - is often 1.5-3x the external consulting cost in terms of time invested.

The honest budget breakdown for a Wave 2 group reporter looks something like this:

  • Licence: The visible line item. Most enterprise platforms do not publish pricing; expect significant variation by entity count, user seats, and module scope.
  • Implementation: Configuration, data mapping, integration with source systems (HR, ERP, energy management), and workflow design. This is where projects overrun.
  • Internal ownership: A named internal owner - typically a sustainability controller or finance systems lead - is not optional. Platforms do not run themselves.
  • Assurance preparation: Your assurance provider will need to understand the platform's evidence architecture before the engagement starts, not during it.
  • Ongoing taxonomy updates: When the revised ESRS taxonomy is published, your platform's datapoint model and tagging library will need updating. Clarify whether this is included in the licence or billed separately.

Data ownership assignments, approval workflow design, and stakeholder engagement all take internal effort regardless of which platform you choose. The platform does not solve the organisational problem of getting 20 subsidiaries to submit data on time. That requires process design, not software.


6. The RFP Question List

Use these verbatim or adapt them. They are designed to surface the answers that vendor marketing will not volunteer.


7. Before You Sign: A Short Checklist

star Important

Before you sign any CSRD software contract, confirm:

  • The vendor has demonstrated the updated ESRS 2026 datapoint model live in the platform — not on a roadmap slide.
  • iXBRL tagging is native or contractually bound to a named third party with a published taxonomy-update SLA.
  • The contract includes a change-management clause covering taxonomy updates when the revised ESRS XBRL taxonomy is published.
  • Supplier questionnaire templates are VSME-aligned and enforce the value chain cap.
  • EU Taxonomy templates reflect the 2026 revised structure.
  • Data portability and exit terms are explicit: format, timeline, and cost.
  • You have a named internal owner committed before go-live, not after.
  • Your assurance provider has been consulted on the platform's evidence architecture before you sign — not after implementation.

The Market Landscape (Illustrative Only)

The market can be divided into three broad categories: pure reporting software focusing on ESRS datapoints and the report itself; carbon accounting software focusing on Scope 1-3 emissions; and broad ESG management platforms combining reporting with supply chain compliance, EU Taxonomy, or EHS management. The market ranges from broad enterprise platforms (such as Watershed, Workiva, and others) and carbon accounting specialists (such as Normative and others) to integrated solutions and supply chain specialists.

Names that recur in market roundups include Workiva, IBM Envizi, Diligent ESG, Novisto, Position Green, Persefoni, Watershed, Sphera, Sweep, Greenly, Normative, and Coolset. This publication has not tested any of these products and does not rank or endorse them. They are listed solely to illustrate the category breadth. The ESG reporting software market in 2026 is one of the fastest-moving categories in enterprise technology - which means the vendor you evaluate today may look materially different by the time you go live.

The consolidation trend matters for contract terms. A platform acquired mid-contract may change its pricing model, support quality, or taxonomy-update cadence. Data portability clauses are not paranoia; they are standard procurement hygiene in a consolidating market.


This article is for information purposes only and does not constitute legal, professional, or procurement advice. Confirm all regulatory requirements against primary sources and seek qualified advice before making tooling decisions. The CSRD and ESRS framework continues to evolve; subscribe below for updates.

For related reading: ESRS digital tagging and iXBRL explained · CSRD limited assurance guide · The revised ESRS: what the datapoint cuts mean · EU Taxonomy 2026 changes · The value chain cap explained · CSRD data collection playbook