Back to News
    Value Chain

    What sustainability reports reveal about value chain control.

    CSRD is often described as a reporting challenge. But when you read the sustainability reports carefully, a different picture emerges. The real challenge is operational — and it lives in the value chain.

    The companies are ready. The data isn't..

    The first wave of CSRD reporters includes some of Europe's most sophisticated organisations. Listed companies with dedicated ESG teams, board-level oversight, external assurance, and in many cases a decade of sustainability reporting experience behind them.

    What their reports reveal is not a lack of ambition or resources. It is something more structural: the further you move from a company's own operations and into its value chain, the harder it becomes to collect reliable data, establish clear ownership, and maintain consistent governance.

    This pattern appears across sectors and company sizes. It is not an outlier problem. It is the default condition.

    Three things the reports consistently show.

    First, primary data from suppliers is the exception, not the rule. Across the reports we have reviewed, companies openly disclose that large portions of their value chain emissions calculations rely on industry averages, standardised factors, or modelled estimates — because actual supplier data is either unavailable or insufficiently granular. In some cases, more than half of the most significant emissions categories are still based on proxies, despite active efforts to improve coverage over several years.

    Second, visibility diminishes rapidly beyond tier one. Companies with tens of thousands of active direct suppliers acknowledge that meaningful control — the ability to collect data, verify responses, and follow up over time — effectively ends at the first tier. What happens further down the chain is, for most organisations, structurally opaque.

    Third, the data collection process itself is still being built. Several of the most mature reporters in Europe describe ongoing work to establish new processes and tools for supplier data collection — not as a future ambition, but as a current operational reality. The infrastructure for CSRD-grade value chain data does not yet exist at most organisations. It is being constructed in parallel with the reporting obligation it is meant to serve.

    Why this is not a reporting problem.

    It is tempting to frame these gaps as a reporting methodology issue — something to be solved by better templates, more standardised frameworks, or updated emission factors. But the reports themselves point to a different root cause.

    The challenge is not knowing what to report. It is having the operational infrastructure to collect, structure, and govern the underlying data consistently — across hundreds or thousands of external parties, across multiple regulatory frameworks, and on a continuous basis rather than as an annual exercise.

    CSRD does not stand alone. The same value chain that needs to be mapped and monitored for sustainability reporting is also the foundation for NIS2 supply chain security requirements, CSDDD due diligence obligations, and an expanding set of product-level regulations. Each framework asks different questions — but they all depend on the same underlying capability: knowing what is happening in your value chain, and being able to prove it.

    A fragmented, regulation-by-regulation approach to this challenge — separate workstreams, separate data requests, separate follow-up processes — produces predictable results: duplicated effort across functions, supplier fatigue from repeated requests, and data that cannot be reused across frameworks.

    What structured value chain control actually looks like.

    The organisations making the most measurable progress share a common approach. They are not solving CSRD, then NIS2, then CSDDD as separate projects. They are building a single operational layer — a structured, continuously updated model of their value chain — that serves multiple regulatory requirements simultaneously.

    This means mapping supplier relationships across tiers, not just tier one. It means distributing requirements to external parties in a structured and traceable way. It means collecting responses systematically, following up consistently, and maintaining an audit-ready record over time.

    It is an operational model, not a reporting exercise. And it is the foundation on which reliable sustainability disclosures — and broader regulatory compliance — are built.

    This is the problem Regweaver is built to solve.

    Key takeaway

    CSRD is not primarily a reporting problem — it is a value chain control problem. Sustainability reports reveal that primary supplier data is rare, visibility ends at tier one, and the underlying infrastructure is still being built. The way forward is a single operational layer that serves CSRD, NIS2, and CSDDD simultaneously.

    This article is for informational purposes only and does not constitute legal advice.

    Related reading