Skip to content
All publications
CSRD / Article7 min read

CSRD Wave 2 Scope Expansion: Why You Should Prepare Now

CSRD's second wave covers large companies from FY 2025. Preparation strategies, supply chain implications, and practical takeaways for Turkish companies.

Reporting Obligations Are No Longer Just a Big Listed Company Problem

When CSRD's first wave — large public-interest entities (PIEs) with more than 500 employees — began their reporting process for FY 2024, many companies considered it a development that did not directly concern them. The second wave is fundamentally changing that perception.

Effective from FY 2025, the second wave covers all EU companies meeting the "large company" definition under Directive 2013/34. Any company meeting at least two of three criteria must now report under ESRS (Directive 2022/2464, Article 5):

  • More than 250 employees
  • Net turnover exceeding EUR 50 million
  • Total assets exceeding EUR 25 million

The scale of the numbers is striking. According to the European Commission's impact assessment, the second wave directly covers approximately 11,000 additional companies (European Commission, 2021). Compared to the approximately 2,000 companies in the first wave, this represents more than a fivefold expansion. But the real impact is not limited to directly covered companies — the hundreds of thousands of companies in their supply chains are also indirectly affected.

What Did We Learn from the First Wave?

As first-wave companies began publishing their reports in the first half of 2025, valuable lessons for the second wave are emerging:

Double materiality assessments took longer than expected. Many first-wave companies planned for the double materiality process to take 3-6 months. However, when stakeholder engagement, IRO (Impacts, Risks, Opportunities) identification, and board approval processes were included, the actual timeline typically extended to 6-9 months. Second-wave companies must account for this realistic timeline.

Value chain data was the biggest bottleneck. Chapter 5 of ESRS 1 clearly states that value chain information is included in the reporting scope (Commission Delegated Regulation 2023/2772). First-wave companies encountered serious difficulties collecting data from suppliers — response rates were low, data quality was heterogeneous, and formats were non-standard.

Assurance audit scope was broadly defined. The mandatory limited assurance under CSRD required a different expertise than financial auditing. Audit firms expected traceability of sustainability data to its source (audit trail). Data without an audit trail was excluded from the scope of the assurance statement.

XBRL tagging created additional workload. The digital reporting requirement evolved from a task added at the final stage to a requirement that influenced data collection process design from the beginning.

These experiences deliver a clear message for second-wave companies: cutting preparation time short is a strategic mistake.

Supply Chain Implications: The Real Agenda for Non-EU Companies

The impact of the second wave extends far beyond EU borders. When each of the 11,000 companies begins collecting value chain data, a massive data demand wave forms — including suppliers outside the EU.

What This Means for Turkish Companies

Turkey is one of the EU's significant trading partners. In automotive parts, textiles, food, iron-steel, and chemicals, Turkish companies form critical links in EU supply chains. With the second wave, data requests from EU customers to these companies will increase concretely.

Expected data requests cover:

Data CategoryTypical RequestRelevant ESRS Standard
Climate / GHGScope 1, 2 emissions; energy consumptionE1 (Climate Change)
Water managementWater withdrawal, discharge, water-stress zone infoE3 (Water and Marine Resources)
Waste and circularityWaste generation, recycling ratesE5 (Resource Use)
WorkforceOHS metrics, pay policy, training hoursS1 (Own Workforce), S2 (Value Chain Workers)
GovernanceHuman rights policy, anti-corruption measuresG1 (Business Conduct)

As noted in EFRAG's implementation guidance (IG 2), transitional provisions for SME suppliers are foreseen under the proportionality principle. However, these provisions do not eliminate the data request itself — they only reduce the level of detail and assurance expectation (EFRAG Implementation Guidance IG 2, 2023).

The Advantage of Proactive Suppliers

Suppliers prepared for data requests gain a strategic advantage in customer relationships. Suppliers who can deliver structured, consistent, and reliable data:

  • Stand out in procurement processes
  • Are preferred in long-term supply agreements
  • Deepen the relationship by contributing to their customer's reporting burden

This advantage is becoming a competitive differentiator, particularly for Turkish exporters selling to EU customers.

Preparation Strategy: Four Pillars

1. Double Materiality Assessment

The double materiality assessment is mandatory under ESRS and forms the foundation of the entire reporting process. This assessment addresses two dimensions together:

  • Impact materiality: The company's actual or potential impacts on people and the environment
  • Financial materiality: The effects of sustainability topics on the company's financial position, performance, and cash flows

Based on first-wave experience, the realistic timeline is 6-9 months. Second-wave companies should have started this process in Q1 2025 (EFRAG Implementation Guidance IG 1, 2023). For companies that have not yet begun, time has become critically tight.

2. Data Infrastructure and Internal Controls

Systematizing sustainability data collection processes is the operational foundation of ESRS compliance:

Environmental data: GHG inventory (ISO 14064-1 compliant), energy consumption data (by fuel type and source), water withdrawal and discharge data, waste management metrics.

Social data: Occupational health and safety incidents and rates, diversity and inclusion metrics, training hours and investments, pay equity indicators.

Governance data: Sustainability governance structure (committees, responsibility assignments), risk management processes, ethics and compliance policies.

Each data point requires the definition of the source department, collection method, verification process, and audit trail.

3. Assurance Readiness

Limited assurance is mandatory under CSRD — and a transition to reasonable assurance is planned in subsequent years (Directive 2022/2464, Article 34). Three pillars of assurance readiness:

  • Audit trail: Traceability of every reported data point to its source
  • Internal controls: Error prevention mechanisms in data collection, aggregation, and reporting
  • Documentation: Recording of calculation methodologies, assumptions, and data quality assessments

The ISSA 5000 standard developed by the IAASB (International Auditing and Assurance Standards Board) establishes the global reference framework for sustainability assurance engagements. The current ISAE 3000 (Revised) standard is used during the transition.

4. Cross-Framework Efficiency

Most second-wave companies report not only to CSRD but to multiple frameworks — CDP, GRI, and in some cases ISSB/TSRS. Feeding multiple frameworks from a single data collection process is the key to avoiding duplicate effort.

The high compatibility between ESRS and GRI (GRI-EFRAG joint statement, 2022) and CDP's alignment work with ISSB facilitate an integrated reporting approach.

Realistic Timeline

PhaseRecommended TimingCritical Dependency
Double materiality assessmentQ1-Q2 2025Stakeholder engagement, board approval
Data collection process designQ2-Q3 2025ESRS taxonomy mapping
First data collection cycleQ3-Q4 2025Cross-departmental coordination
ESRS report preparationQ1 2026DMA results, data completeness
Assurance auditQ1-Q2 2026Audit firm selection, trail readiness
Publication with annual reportQ2 2026Board approval

This timeline is already tight for a company starting from scratch. Second-wave companies that have not yet begun their double materiality assessment must adopt an accelerated approach.

Is There a Postponement Strategy?

Pressure from some sectors and member states in the EU is growing to postpone or simplify CSRD implementation. Under the European Commission's "Omnibus" legislative simplification initiative, narrowing CSRD's scope or deferring certain requirements is being discussed.

However, the current legal framework is in force. Delaying preparation based on postponement uncertainty creates serious compliance risk if a postponement does not materialize. The pragmatic approach is to prepare according to the current timeline and benefit from any simplifications that may emerge.

Action Item: The preparation window for second-wave companies has critically narrowed. Start with the double materiality assessment — it determines which ESRS standards are material for you, which data points you need to collect, and the scope of your report. No downstream preparation work can be efficient without taking this step first.


See how enterprise teams streamline CSRD compliance across multiple frameworks.

Build a foundation for reporting.Talk to our team