Double Materiality Assessment for CSRD: A Practitioner's Methodology Guide (2026)
Every CSRD sustainability statement rests on one gatekeeping exercise: the double materiality assessment. Get it wrong and you either over-report - burning budget on disclosures nobody needed - or under-report, and hand your assurance provider a defensibility problem in year one. Yet the guidance preparers are working from was written for a different version of the standards than the one now in force.
This is a working methodology for running (or re-running) a double materiality assessment in 2026: what the two dimensions actually mean, what EFRAG's official guidance requires, where that guidance has not caught up with the revised ESRS 1, and a four-stage process you can defend to an auditor.
The two dimensions, precisely
Double materiality is not one test - it's two independent ones, joined by "or."
Impact materiality ("inside-out") asks what your company does to people and the environment: actual and potential effects, positive and negative, across your own operations and your value chain. A topic is impact-material based on the severity of the effect (scale, scope, and whether it's irremediable) and, for potential impacts, likelihood.
Financial materiality ("outside-in") asks what sustainability matters do to your company: risks and opportunities that could reasonably be expected to affect cash flows, access to finance, or cost of capital over the short, medium or long term. This is scored on magnitude and likelihood.
A topic clears the bar if it's material on either dimension. Most contested calls in practice aren't about the scoring mechanics - they're about scope: how far into the value chain you looked before concluding a topic wasn't there.
What EFRAG's IG 1 actually requires
EFRAG finalized its Materiality Assessment Implementation Guidance (IG 1) on 31 May 2024. It's still the reference document, and three things in it matter more than the rest of the detail:
- Whole value chain, deliberately unspecified process. The assessment has to cover the undertaking's entire value chain, upstream and downstream. But the ESRS do not mandate a specific process or sequence of steps to get there - EFRAG built in flexibility so companies could design an approach that fits their size, sector and data maturity.
- IROs are scored, not eyeballed. Impacts, risks and opportunities (IROs) are identified individually and rated - severity and likelihood for impacts, magnitude and likelihood for financial effects - against thresholds the company sets and documents.
- Silence is a disclosure. If you don't report a datapoint, that's read as a statement that the underlying topic or metric was assessed as not material. There's no neutral "we skipped this" option once the assessment is finalized.
The 2026 gap nobody has closed
Here's the part that doesn't get said plainly enough: the European Commission adopted the revised ESRS 1 on 3 July 2026 as part of the Omnibus simplification package, and it changed how far into the value chain companies are expected to dig for data - introducing a clearer proportionality mechanism around the "undue cost or effort" concept (we covered the mechanics of that change in detail in our companion piece on value chain data).
IG 1, meanwhile, is still the 2024 version. As of this writing, EFRAG has not issued a formal update to the materiality assessment guidance that reflects the July 2026 changes. That leaves preparers in an odd spot: running a 2026 assessment, under simplified 2026 standards, using a process guide written for the pre-simplification value chain rules.
This is worth flagging honestly rather than papering over. Treat it as an open question to watch, not a solved problem - and document your own reasoning wherever you've had to extend 2024-era guidance to fit the 2026 proportionality rules, because that's exactly the kind of judgment call an assurance provider will ask you to walk through.
A defensible four-stage methodology
None of this is an EFRAG-mandated sequence - IG 1 explicitly leaves the process open - but this is a working structure that holds up under scrutiny:
1. Understand the business. Map your operations, business relationships and value chain before you touch a single IRO. This isn't a formality; it's what lets you later justify why you did or didn't extend the assessment to a given supplier tier or downstream use case.
2. Identify actual and potential IROs. Combine desk research (sector materiality maps, peer disclosures, regulatory trackers) with direct stakeholder engagement - affected communities, workers, investors, customers. Both current and reasonably foreseeable effects go on the list at this stage; scoring comes later.
3. Assess and score each IRO. Apply the two-track scoring: severity (scale, scope, irremediability) and likelihood for impacts; magnitude and likelihood for financial effects. Set your thresholds in advance, in writing, and apply them consistently - this is the single most-tested judgment call in an assurance review.
4. Determine and document the material topics list. The output isn't a slide - it's the IRO register: the living document that maps each material IRO to the ESRS disclosure requirements and datapoints it triggers. This register is what you'll maintain, not just produce once.
What assurance providers will actually test
Auditors and assurance providers aren't going to re-run your materiality assessment from scratch. They're going to test whether the one you ran is defensible:
- Can you show a traceable path from stakeholder input to specific IROs on the list?
- Are your severity/likelihood/magnitude thresholds written down, dated, and applied the same way across topics?
- Is the IRO register maintained, not archived after publication - with a clear trigger for when something gets re-scored mid-year?
- Where you relied on the 2026 proportionality rules to limit value chain depth, is that reasoning documented at the time, not reconstructed after the fact?
FAQ
Do I need to redo the whole assessment every year? No - but it should be revisited at least annually, with interim updates whenever a material change in the business or its context (a new market, a major supplier change, a new regulation) could plausibly move a topic across the materiality threshold.
What happens if I don't disclose a datapoint? Under IG 1's logic, the absence of a disclosure is read as evidence you assessed the topic or metric as not material - so the omission itself needs to be traceable back to your assessment, not silent.
Should I wait for updated EFRAG guidance before finalizing my 2026 assessment? Given the reporting timelines most preparers are working against, waiting isn't realistic for most companies. The safer path is to run the process above, document every place you've had to interpret how the 2026 proportionality rules interact with 2024-era process guidance, and be ready to show that reasoning if and when EFRAG updates IG 1.
Related reading

How to Structure a CSRD Sustainability Statement: A Design Guide for ESRS 1 (2026)
ESRS 1 (2026) gives preparers real structural choices for the first time. This guide covers where the statement lives, the new options in paragraphs 103-111, cross-referencing rules, connectivity, and a recommended skeleton you can use.

EU Pay Transparency Directive Meets ESRS S1: Why 2026 Is the Year Your Pay Data Gets Checked Twice
2026 is the reference year for both the EU Pay Transparency Directive and ESRS S1 pay gap metrics. If your two numbers differ and you can't explain why, that's a credibility problem in front of regulators, assurance providers, and works councils simultaneously.

"Undue Cost or Effort" Under ESRS 1 (2026): What Actually Changed for Value Chain Data
The revised ESRS 1 (adopted 3 July 2026) rewrites value chain data rules. Here's what changed, what the proportionality mechanism actually means, and how to document it for assurance.