Socious
Compliance

Four EU Filings Need the Same Supplier Data. None of Them Ask for It the Same Way.

Socious Team
Four EU Filings Need the Same Supplier Data. None of Them Ask for It the Same Way.

A supplier of aluminium components gets four emails in the same quarter, all from the same customer, all asking about the same shipment.

One is from the sustainability team, building the CSRD Scope 3 inventory and the EU Taxonomy alignment KPIs — it wants activity codes, revenue splits, and an emissions factor. One is from procurement, building the EUDR due diligence file for a downstream wood-composite input — it wants plot-level geolocation. One is from legal, running the CSDDD supply-chain risk assessment — it wants a human-rights and environmental questionnaire. One is from trade compliance, filing the CBAM declaration on the aluminium itself — it wants installation-level embedded emissions, not an estimate.

Four teams, four spreadsheets, four deadlines, one supplier who does not work for the company asking. This is not a hypothetical: BDO’s guidance on CBAM implementation already documents suppliers who “lack the technical means” to answer even one of these requests, and who show “unwillingness to cooperate” when a fifth one arrives. The compliance cost of 2026-vintage EU sustainability law is increasingly not the reporting itself — it is the number of times the same supplier gets asked.

It helps to separate what is actually being asked, because “ESG data request” flattens four legally distinct obligations into one blur.

FilingLegal basisWhat it needs from a supplierFormat / precision
CSRD + EU Taxonomy KPIsDirective (EU) 2026/470 (Omnibus I); Delegated Regulation (EU) 2021/2178, Art. 8Activity classification, revenue/CapEx/OpEx split by Taxonomy-eligible activity, DNSH evidencePercentage KPIs, narrative disclosure, ESRS taxonomy
EUDR due diligence statementRegulation (EU) 2023/1115, Art. 9; amended by (EU) 2025/2650Geolocation of every production plot, commodity, production dateLatitude/longitude to six decimal digits; polygon data above 4 hectares (EUR-Lex, Art. 2(28), Art. 9(1)(d))
CSDDD due diligenceDirective (EU) 2024/1760, as amended by Omnibus IAdverse human-rights and environmental impact mapping across own operations, subsidiaries, and business partnersRisk-based questionnaire and corrective-action plan, no fixed schema
CBAM declarationRegulation (EU) 2023/956; Implementing Regulation (EU) 2023/1773Installation-level direct and indirect embedded emissions, production route, operator identityActual measured data per tonne — “importers are now required to report actual embedded emissions for each CBAM product… rather than default values” (BDO)

Three of the four already govern live obligations. CBAM’s definitive regime has applied since 1 January 2026 (covered in our earlier piece); EU Taxonomy KPI reporting for in-scope companies has run since FY2021; CSDDD is mid-transposition — Omnibus I moved the transposition deadline to 26 July 2028 and narrowed the in-scope population to a single tier: EU companies with more than 5,000 employees and over €1.5 billion in net worldwide turnover, or non-EU companies with over €1.5 billion in EU turnover, with the threshold needing to hold for two consecutive financial years (DLA Piper). That single-tier threshold replaced the original three-phase rollout (5,000+/3,000+/1,000+ employees at descending turnover) — worth flagging explicitly, because our own earlier CSDDD article still describes that original three-phase schedule and predates the Omnibus I finalization.

EUDR sits closest to the calendar most companies are watching: application now runs from 30 December 2026 for large and medium operators, pushed a year by Regulation (EU) 2025/2650, while the underlying deforestation cut-off of 31 December 2020 did not move at all (as we covered here).

Where the data genuinely overlaps

Strip away the legal language and four fields recur across all four filings:

  1. Supplier legal identity. Every regime needs to know precisely which counterparty, at which corporate level, is responsible.
  2. Site or plant location. EUDR wants coordinates; CBAM wants the installation; CSDDD wants the operating geography for risk-mapping; the Taxonomy’s DNSH assessment increasingly wants the same for water and biodiversity screens.
  3. Product or activity classification. What was made, using what process, under what NACE or commodity code.
  4. An environmental or emissions figure tied to that specific product. CBAM wants it precisely, at installation level, per tonne; the others want it at varying resolution.

A company that asks for these four facts once, in a structured supplier record, has done most of the collection work for all four filings before a single regulator-specific field is added.

Where it genuinely does not overlap — and why the shortcut fails

The temptation is to build one questionnaire and route the same answers everywhere. That breaks on three points.

Granularity. EUDR’s six-decimal geolocation and CBAM’s installation-level emissions factor are legally exact requirements — a rounded or estimated figure is a compliance gap, not an approximation. CSRD’s Taxonomy KPIs, by contrast, are portfolio-level percentages built from many suppliers’ data, and CSDDD’s due-diligence questionnaire is risk-based and qualitative, not a fixed schema. A field precise enough for CBAM is overkill for a Taxonomy KPI; a field vague enough for a CSDDD risk questionnaire is useless for a CBAM declaration.

Legal basis, and therefore who can be asked what. This is where the EU’s own value chain cap matters, and where it is easy to misapply it. Since the Commission adopted the Voluntary Standard on 3 July 2026, undertakings with fewer than 1,000 employees are legally entitled to decline sustainability information requests that go beyond that voluntary standard, and the company asking has to tell them so (Linklaters; we covered the mechanics here). That cap constrains requests made because of CSRD/ESRS reporting obligations. It does not touch EUDR’s geolocation requirement or CBAM’s embedded-emissions requirement, both of which sit on their own statutory basis and apply regardless of the supplier’s size or the requester’s ESRS materiality assessment. A compliance team that assumes the value chain cap shields a small supplier from every data request will find that assumption is wrong for two of the four filings in this piece.

Deadlines don’t line up. CBAM data has to be right now, for a declaration due September 2027 covering all of 2026. EUDR geolocation has to be ready by December 2026. CSDDD due diligence doesn’t bind anyone until the 2028–2030 window. Building one intake process that ships data to four different deadlines is a scheduling problem as much as a data-modeling one.

What a shared schema looks like in practice

The fix is not one questionnaire. It is one supplier master record — collected once, at onboarding and at each material change — with fields tagged to which filing consumes them and at what precision:

  • Legal entity and site-level geolocation, serving EUDR at full precision and CSDDD/Taxonomy DNSH at lower precision.
  • Product, commodity, and activity classification, mapped once to NACE, HS, and EUDR commodity codes.
  • An emissions or environmental performance figure, collected at the highest precision any consumer needs — CBAM’s installation-level standard — then aggregated down for lower-precision uses.
  • A due-diligence response set, kept separate from the factual fields above and versioned against CSDDD’s own risk-based schema rather than forced into it.

Collected this way, a supplier answers once. What differs downstream is not the intake — it is which fields each filing’s engine pulls, at what precision, on what deadline. That is a mapping problem, and mapping gets easier, not harder, as more filings share the same underlying facts.

If your team is still running the CSRD, EUDR, CSDDD, and CBAM asks as four separate supplier processes, our free CSRD readiness check takes about three minutes and flags where your current data collection already has the shared fields this piece describes — and where it doesn’t. From there, Socious Report is built to ingest supplier data once and map it to the frameworks that actually apply to your filings.