What the updated ESRS means for your Double Materiality Assessment
The European Commission adopted ESRS 2.0 on 3 July 2026. The headlines are striking: mandatory datapoints down by more than 60%, total datapoints reduced by over 70%, and a move from a granular checklist to a top-down, judgement-led approach.
If your sustainability team has spent two years building a DMA under the original standards, the rules have clearly changed. The real question is whether your existing work still holds up, and what you need to do differently from here.
The short answer: the Double Materiality Assessment is still required, still assured, and still the base of every CSRD disclosure. The simplification changed how you run the process, not whether you run it.
This article covers what changed, what stayed the same, and what Wave 1 and Wave 2 teams should do now. If you'd like a fuller breakdown, download the complete guide here.
The scope changed. The value of a DMA didn't.
The Omnibus I Directive, which came into force on 18 March 2026, raised the mandatory CSRD threshold to companies with 1,000 or more employees and at least €450 million in turnover. If your company sits below that, CSRD reporting is no longer mandatory.
That changes the compliance obligation. The business case for understanding your material impacts and financial risks stays where it was. Investors, lenders, and large enterprise clients ask for this information more often now, not less. A customer running its own value chain analysis will still want to know your material risks and impacts, whether or not you're legally required to disclose them.
The strategic value of a DMA has always been about understanding your business better. The regulatory obligation just made it mandatory.
Four practical DMA changes under ESRS 2.0
The adopted delegated act introduces changes that directly affect how you run a DMA. Each one has practical implications for your methodology and your audit trail.
1. The process is now top-down by default
The original approach was bottom-up: work through every item on the AR 16 list, assess each individual impact, risk and opportunity (IRO) for materiality, then build up to a topic-level conclusion. Thorough, but slow.
The revised approach starts from the business model and strategy. You identify which topics and sub-topics are plausibly relevant, then work down to the IROs that need closer scrutiny. If the business-model analysis supports excluding a topic at that stage, you document the reasoning and move on. You don't have to disprove materiality IRO by IRO.
Two things matter here. First, the Commission explicitly permits a mixed approach: top-down for most topics, bottom-up where the complexity of a specific topic warrants it. Second, the top-down approach cuts documentation volume around the process, but it doesn't reduce the rigour required. A one-line justification for ruling out a topic won't survive an auditor's questions if you never properly worked through the reasoning behind it.
2. The topics list stops at sub-topic level
The old AR 16 list ran to sub-sub-topic level. The new ESRS 1 Appendix A stops at topic and sub-topic. Sub-sub-topics haven't been removed from the framework; they've folded into their parent sub-topic. That's one less layer of detail to document separately, which simplifies how you structure your conclusions.
3. Gross impact is the starting point, always
The revised standards clarify that you always assess impact materiality on a gross basis first: the severity of an impact before any mitigation or prevention measures apply. For a negative impact that has already occurred, remediation taken afterwards has no bearing on whether the impact was material. The assessment is anchored to the gross severity of what actually happened.
The one exception applies to potential impacts. Where a company has supportable evidence (not a stated intention or an ongoing programme) that mitigation does reduce severity or likelihood, it can assess on a net or reduced basis. Without that evidence, you assess the impact as material regardless of how much effort goes into containing it.
4. Aggregation rules are sharper
Companies can't let a consolidated group-level view obscure information that's material at a more granular level. Where IROs vary widely by topic, sector, subsidiary, country, or site, that variation must be disaggregated and reported at the level where it actually arises. A water consumption risk concentrated in one country needs to be disclosed at country level, not diluted into a global average. The specific facts and circumstances behind any disaggregation decision must be documented so the choice is defensible.
What simplification left untouched
The CSRD's double materiality framework is intact. Both impact materiality and financial materiality remain required. The Commission hasn't merged them, and neither is optional. The methodology behind your assessment still needs to be disclosed under ESRS 2. The assessment is still subject to limited assurance, which means an auditor will review your methodology, not just your conclusions.
There's also a new restriction that runs in the opposite direction from what most teams expect. The revised standards prohibit disclosing non-material information. Over-disclosure now reads as a sign of poor process, not diligence. "When in doubt, include it" used to be a safe default. Under ESRS 2.0, that approach will draw questions.
The bar for judgement has gone up. Fewer datapoints means every conclusion you do reach carries more weight, and every exclusion needs to be defensible.
The errors we see most often in DMAs have little to do with which version of the standards a company is using. Impacts get worded as vague statements of concern rather than clear descriptions of what happens, to whom, and how. Human rights impacts get scored on the same likelihood-weighted scale as operational risks, when the standards require severity to take precedence. Dependencies get conflated with impacts: an impact is something your business does to the world; a dependency is the reverse. These mistakes show up across both the original and revised standards, and assurance doesn't distinguish between them.
If you've already done a DMA: what Wave 1 companies should decide now
Wave 1 companies have two distinct decisions to work through. They shouldn't be conflated.
Decision 1: early adoption for FY2026
The finalised text gives Wave 1 companies the option to apply the simplified standards for the current reporting period. You need to make that decision now, because the answer shapes everything you do between now and year end. If you're planning to switch, review your DMA against the top-down approach before you draft disclosures. Reworking a materiality conclusion once disclosures are half-written costs far more than getting the sequence right the first time.
Decision 2: validity of your existing DMA
If you're continuing under the original 2023 ESRS for FY2026, your existing conclusions are likely still valid. "Likely valid" and "audit-proof" are not the same thing. Before your next assurance cycle, check three things:
-
Whether your methodology holds up under the top-down approach's logic, even if you didn't formally use it.
-
Whether you've documented your conclusions at topic and sub-topic level, rather than buried in IRO-level detail.
-
Whether your evidence trail meets current auditor expectations, which have moved on even where standards haven't.
ESRS 2.0 applies to Wave 1 companies for financial years beginning on or after 1 January 2027. Plan the transition from your FY2026 reporting to ESRS 2.0 for FY2027 now, not in the final quarter of 2026.
If you're planning your first DMA: what Wave 2 companies should start now
Wave 2 companies will report under ESRS 2.0 for financial years beginning on or after 1 January 2027. The text is now in its standard scrutiny period before entry into force. No formal objections are anticipated, given how much technical input ESMA, the EBA, and the ECB provided during drafting.
The structural elements of a DMA don't depend on the final wording of individual datapoints. Start now.
Business model analysis
Use the adopted ESRS 2.0 text as your reference. The top-down approach starts here, and the groundwork takes longer than most teams expect.
Value chain scoping
Map your upstream and downstream value chain in parallel with topic identification. Waiting until topics are finalised before you scope the chain adds months.
Aggregation logic
Decide upfront which variations by sector, subsidiary, country, location, or site are likely to be large enough to require separate disclosure. Retrofitting this later is expensive.
Monitor the Official Journal publication as a confirmation point, not a starting pistol. The adopted framework is the right basis for planning today.
The case for acting now
Wave 1 companies who wait until the final quarter to decide on early adoption, or to review their existing audit trails, are setting up expensive late-stage rework. Wave 2 companies who wait for every regulatory detail to be finalised before they start value chain mapping are losing months they won't get back.
Neither delay buys certainty. It just moves the same work closer to the deadline.
The finalised text is enough to plan against today. If you want a second pair of eyes on where your methodology has weak points before your auditor finds them, get in touch.
FAQ's:
What changed in ESRS 2.0 for the DMA?
ESRS 2.0 shifts the DMA from a rigid bottom-up checklist to a more top-down model. Companies still need to assess impacts, risks and opportunities, but they can start from the business model, rule out irrelevant topics earlier, and document the reasoning more efficiently.
Does ESRS 2.0 remove the double materiality assessment?
No. Double materiality is still required. Companies still need to assess both impact materiality and financial materiality, and the assessment still sits at the centre of CSRD reporting. The simplification changes the process, not the obligation.
Do companies still need to review the DMA every year?
Yes. The adopted text makes annual review explicit, and also requires a review when there is a significant change in business model, strategy, or operating context. Treat the DMA as a living process, not a one-off exercise.
What should Wave 1 companies do now?
Wave 1 companies need to decide whether to early adopt ESRS 2.0 for FY2026, then test their existing DMA against the new logic. Focus on topic-level conclusions, gross impact assessment, disaggregation choices, and whether the audit trail is strong enough for assurance.
What should Wave 2 companies do now?
Wave 2 companies should start their business model analysis, value chain scoping, and stakeholder mapping now. The adopted text is detailed enough to plan against, so waiting for the final Official Journal publication is likely to waste time rather than reduce risk.
Get comfortable, there’s more
If you enjoyed this article, there's plenty more media to get your mind into.
Sign up to our newsletter
and we'll report back to you with industry news and updates you'll actually want to know.