The assurance-escalation penalty in CSRD limited-to-reasonable assurance transition for Wave 1 and Wave 2 filers

The assurance-escalation penalty in CSRD limited-to-reasonable assurance transition for Wave 1 and Wave 2 filers
Here's the issue: Wave 1 and Wave 2 Corporate Sustainability Reporting Directive (CSRD) filers submit their first limited assurance reports in 2025 and 2028 respectively, with the understanding that reasonable assurance—if adopted—begins in 2028 or later. Most compliance officers budget for limited assurance engagement costs: evidence gathering, materiality assessments, European Sustainability Reporting Standards (ESRS) alignment. The forecast looks manageable. However, the assurance transition conceals a structural penalty that boards discover too late.
However, CSRD assurance consists of two things: the limited engagement you perform in 2025 or 2028, and the reasonable escalation your auditor performs in 2028 or 2030. The first is what you budget for. The second is what determines total audit cost over the reporting cycle.
Limited engagement on its own has no persistent value. Reasonable escalation is what the European Commission, investors, and capital markets are actually pricing in. Under the Corporate Sustainability Reporting Directive as amended by Omnibus I in March 2026, the Commission committed to assess the feasibility of moving from limited to reasonable assurance by October 2028. If that transition proceeds, auditors will re-examine every methodology choice, every data boundary, every estimation assumption you locked in during your limited engagement. If those choices were not designed with reasonable assurance in mind, the cost of reasonable escalation will exceed the savings you captured by treating limited assurance as a standalone compliance exercise.
While limited assurance has become cheaper under the simplified European Sustainability Reporting Standards published in May 2026—mandatory data points cut by over 60 percent, total data points by over 70 percent—reasonable escalation has become more expensive. If your 2025 or 2027 limited engagement relies on proxy data, sector averages, or third-party estimates without reproducible lineage, the cost of reasonable escalation in 2028 might outpace the entire budget you allocated to limited assurance in the first wave. For a Wave 1 filer with €2 billion in revenue, the difference between a reasonable-ready limited engagement and a retrofit could represent €150,000 to €300,000 in additional audit fees in 2028 alone, compounding annually thereafter.
How do you solve this? I think the operators who will navigate the assurance transition most efficiently are those who treat limited assurance as a dry run for reasonable assurance, not as a one-time compliance exercise. That means designing evidence chains, calculation methodologies, and data governance in 2025 or 2027 as if reasonable assurance were already in force. For now, that's the only approach that avoids the escalation penalty.
The shape of the argument, visualised below.
What the CSRD Omnibus I changes mean for assurance escalation
The CSRD Omnibus I package, approved by the European Parliament in December 2025 and in force since March 2026, narrowed the directive's scope but left the assurance escalation framework intact. The employee threshold rose from 250 to 1,000, cutting approximately 80 percent of regulated entities [1]. Listed small and medium enterprises were eliminated entirely from mandatory reporting. The Commission committed to simplifying ESRS data points—reducing mandatory disclosures by 61 percent, from roughly 1,100 to 430—and scrapping planned sector-specific standards [2].
Crucially, however, the Commission did not remove the planned escalation from limited to reasonable assurance. Instead, it deferred the decision to October 2028, subject to a feasibility assessment [3]. This means Wave 1 filers, who reported for the first time in 2025 for the 2024 financial year, will learn in October 2028 whether their 2029 reports must meet reasonable assurance. Wave 2 filers, who report for the first time in 2028 for the 2027 financial year, may face reasonable assurance as early as their second filing in 2030.
The simplified ESRS standards, published in draft form on May 6, 2026, reduced reporting burden by over 60 percent and total data points by over 70 percent, with reporting costs per company expected to fall by over 30 percent [4]. But the simplification applies to disclosure requirements, not to the underlying assurance standard. A company that reports fewer data points under limited assurance will still face reasonable assurance on those data points if the October 2028 assessment proceeds. The cost reduction applies to the numerator—number of data points—but not to the denominator: the assurance intensity per data point.
The five assurance gaps that escalation exposes
Reasonable assurance is not limited assurance performed twice. It is a different engagement, with different evidence thresholds, different materiality boundaries, and different professional standards. The table below compares the two standards across five dimensions that matter for compliance officers.
| Dimension | Limited assurance | Reasonable assurance | Escalation penalty if not planned for |
|---|---|---|---|
| Evidence threshold | Plausible, inquiry-based, review procedures | Sufficient and appropriate, audit-grade, substantive testing | Auditor re-performs evidence gathering from base year forward |
| Materiality boundary | Assessment-level materiality, topic-by-topic | Line-item materiality, data-point-by-data-point | Every estimate and proxy must be re-justified at granular level |
| Data lineage | Source documentation sufficient for limited review | Full audit trail from source document to disclosure, reproducible by third party | Retrofitting lineage for multi-year inventories, no safe harbor |
| Scope 3 methodology | Secondary data and proxy factors acceptable if documented | Primary data preferred, proxies require explicit justification and sensitivity analysis | Cost of supplier primary data collection retroactively applied to 2025 base year |
| Assurance report | Negative assurance: "nothing came to our attention" | Positive assurance: "presents fairly, in all material respects" | Auditor liability increases, premiums increase, engagement hours increase |
The escalation penalty is the cost of re-engineering your 2025 or 2027 limited engagement to meet 2028 or 2030 reasonable standards. For Wave 1 filers, that means three to four years of Scope 3 emissions data, greenhouse gas (GHG) inventory methodologies, and materiality assessments must be rebuilt to meet the higher standard. For Wave 2 filers, that means two to three years. Neither timeframe is short.
Why Scope 3 methodology consistency matters more than Scope 3 totals
The European Financial Reporting Advisory Group (EFRAG) revised ESRS standards place stronger emphasis on relevance, fair presentation, and proportionality, but they also introduce a new risk: increased flexibility in reporting shifts the burden on companies—and their directors—to make reasonable materiality judgements [5]. Auditors are more likely to scrutinise why certain industry-relevant topics were deemed not material, rather than demanding justifications for why others were included.
This shift matters most for Scope 3 emissions under ESRS E1. The revised ESRS removed the requirement for "direct value chain data," allowing companies to use estimates and proxy data for Scope 3 [2]. That makes limited assurance cheaper in 2025 or 2027. But it also means that if reasonable assurance proceeds in 2028, auditors will examine every proxy, every sector average, every estimation assumption you used in your limited engagement. If you cannot reproduce those estimates—if the lineage from source data to disclosure is not deterministic—the auditor will require you to re-perform the calculation using primary data. That cost falls entirely in the reasonable assurance year, not the limited assurance year.
For a Wave 1 filer with 15 Scope 3 categories, the cost of retrofitting primary data collection across three to four years of reporting could represent €200,000 to €500,000 in audit fees, supplier engagement costs, and internal staff time. For a Wave 2 filer, the cost is lower—€100,000 to €300,000 across two to three years—but still material. Neither figure appears in the limited assurance budget. Both appear in the reasonable assurance invoice.
What auditors will look for in the October 2028 feasibility assessment
The Commission will adopt European Union (EU) limited assurance standards by October 2026, via delegated act [6]. Member States may apply national assurance standards until then. The Commission will provide reasonable assurance standards by October 2028, following a feasibility assessment to determine whether reasonable assurance is practicable for auditors and undertakings [3].
The feasibility assessment will likely consider three factors: auditor capacity, data availability, and cost proportionality. Auditor capacity is not in your control. Data availability is. Cost proportionality depends on data availability. If your 2025 or 2027 limited engagement is designed to minimise cost by using secondary data, proxy factors, and industry averages, you are signalling to the Commission—and to your auditor—that reasonable assurance is not yet feasible. That signal may delay the escalation, but it will not prevent it. When reasonable assurance arrives, you will pay the full cost of retrofitting deterministic data governance across every year since your first limited engagement.
"Auditors must have objectivity and complete independence from the company, be free from any conflicts of interest and external influence, whether direct or indirect, and shall refrain from any action incompatible with their independence. They must have experience and competence in environmental or human rights matters and shall be accountable for the quality and reliability of the verification they carry out." [6]
That independence requirement applies equally to limited and reasonable assurance. But the "quality and reliability" threshold is higher for reasonable assurance. An auditor who accepts proxy data under limited assurance may reject the same proxy under reasonable assurance, not because the data changed, but because the standard changed. If you cannot reproduce the proxy—if the calculation is not deterministic—the auditor cannot issue a positive assurance opinion. The engagement fails. You revert to limited assurance, and you pay for both engagements.
Head-to-head: CSRD assurance approaches for Wave 1 and Wave 2 filers
The table below compares five assurance strategies that compliance officers are considering for the 2025 to 2030 reporting cycle. Each strategy is scored against five criteria: limited assurance cost, reasonable escalation risk, auditor acceptance, board oversight burden, and total cost of ownership over five years.
| Strategy | Limited assurance cost (2025/2027) | Reasonable escalation risk (2028/2030) | Auditor acceptance (2028+) | Board oversight burden | Five-year total cost of ownership |
|---|---|---|---|---|---|
| Proxy-first: use secondary data, sector averages, defer primary data collection until reasonable assurance is confirmed | €50k–€100k per year | High: full retrofit required, no lineage | Low: auditor will require re-engineering | Low in 2025, high in 2028 | €300k–€600k (includes retrofit) |
| Hybrid: primary data for Scope 1 and 2, secondary for Scope 3, with documented estimation methodology | €80k–€150k per year | Medium: Scope 3 retrofit required, Scope 1 and 2 audit-ready | Medium: auditor will accept Scope 1 and 2, challenge Scope 3 | Medium throughout | €250k–€450k (partial retrofit) |
| Reasonable-ready: treat limited assurance as dry run, build deterministic lineage from year one | €120k–€200k per year | Low: minimal retrofit, evidence chain already in place | High: auditor can escalate without re-engineering | High in 2025, low in 2028 | €200k–€350k (no retrofit penalty) |
| In-house build: custom internal system, spreadsheets, manual evidence packs | €30k–€60k per year (staff time only) | Very high: no audit trail, no reproducibility, full rebuild required | Very low: auditor will reject lineage, demand external system | Very high throughout | €400k–€700k (includes rebuild and audit fees) |
| External assurance platform with deterministic calculation engine (e.g., Emission3) | €100k–€180k per year | Very low: platform generates evidence lineage, auditor can replay calculations | Very high: auditor treats platform output as source of truth | Low throughout | €180k–€320k (no retrofit, audit efficiency gains) |
The reasonable-ready and external platform strategies have higher upfront costs but lower total cost of ownership. The proxy-first and in-house strategies have lower upfront costs but higher total cost of ownership, driven by the escalation penalty. The hybrid strategy is the median: acceptable limited cost, acceptable escalation risk, but no efficiency gains over the five-year cycle.
How Emission3 fits
Emission3 is positioned as productized CBAM implementation backed by compliance infrastructure, but the infrastructure extends to CSRD assurance. The platform's deterministic calculation engine—every number is reproducible, with full lineage from source document to filing—means that limited assurance and reasonable assurance use the same evidence base. There is no retrofit penalty. Auditors can replay calculations, review source documents, and trace line-item emissions back to utility bills, invoices, and bills of material without manual evidence packs.
For Wave 1 and Wave 2 filers, that means you build the evidence chain once, in 2025 or 2027, and it scales to reasonable assurance in 2028 or 2030 without re-engineering. The platform exports evidence packs, calculation lineage, and submission-oriented outputs that auditors and registry officials can verify independently. The AI layer parses invoices, utility bills, and supplier declarations into structured data, but the calculations are deterministic—auditors can replay them without relying on the AI's judgement [7].
If you're a Wave 1 filer preparing for your second limited assurance engagement in 2026, or a Wave 2 filer preparing for your first in 2028, book a CBAM readiness call to map your suppliers, gaps, and implementation timeline [8]. We'll show you how to build the evidence chain now, before the escalation arrives.
The escalation decision you make in 2025 or 2027
The October 2028 feasibility assessment is not in your control. The methodology decisions you make in 2025 or 2027 are. If you treat limited assurance as a standalone compliance exercise—minimise cost, use secondary data, defer lineage—you will pay the escalation penalty in 2028 or 2030. If you treat limited assurance as a dry run for reasonable assurance—build deterministic lineage, use primary data where feasible, design for audit-grade evidence—you will avoid the penalty.
The choice is not between limited and reasonable assurance. It is between paying for reasonable assurance once, in 2028 or 2030, or paying for it twice: once in 2025 or 2027 when you perform limited assurance without lineage, and again in 2028 or 2030 when you retrofit the lineage for reasonable assurance. The first approach costs more upfront. The second approach costs more in total. For compliance officers with five-year budgets, the first approach is cheaper. For compliance officers with one-year budgets, the second approach looks cheaper until the invoice arrives in 2028.
Book a CBAM readiness call to map your suppliers, gaps, and implementation timeline. All customers start with a readiness conversation—we map suppliers, gaps, and implementation, no anonymous self-serve onboarding [8].
References & Sources
External Sources
- [1]CSRD Omnibus Changes (Feb 2025) - Continuuiti
The CSRD Omnibus proposal raised the employee threshold from 250 to 1,000, cutting approximately 80% of regulated entities. Listed SMEs were eliminated entirely.
- [2]CSRD Explained (2026): Requirements, Scope & How to Comply - Normative
EFRAG's revised ESRS draft sees a 61% reduction in mandatory datapoints (from ~1,100 to roughly 430). The requirement for 'direct value chain data' was removed, allowing companies to use estimates and proxy data for Scope 3.
- [3]CSRD Assurance | Limited and Reasonable Assurance Engagement
By October 2028, the EU will provide the Reasonable Assurance standards, following an assessment to determine whether reasonable assurance is feasible for auditors and undertakings.
- [4]CSRD Omnibus: What the EU proposal means for companies | CSR Tools
The revised ESRS draft published 6 May 2026 cuts mandatory data points by over 60% and total data points by over 70%. Reporting costs per company are expected to fall by over 30%.
- [5]CSRD reporting post-Omnibus I: what directors need to know in 2026 - Commonwealth Climate and Law Initiative
The revised ESRS places stronger emphasis on relevance, fair presentation and proportionality. Increased flexibility in reporting shifts the burden on companies—and their directors—to make reasonable materiality judgements.
- [6]CSRD & CSDDD: key provisions and concepts - Accountancy Europe
The EC shall adopt, via delegated acts, an EU limited assurance standard by 1 October 2026. MSs may apply national assurance standards until then. Verifiers must have objectivity, independence, experience in environmental matters, and accountability for quality.
Related Content
- [7]The Emission3 AI layer
The deterministic LLM layer that auditors can replay. Parses invoices and utility bills into structured data, but calculations remain reproducible.
- [8]Book a CBAM readiness call
All customers start with a readiness call: we map suppliers, gaps, and implementation, no anonymous self-serve onboarding.