The supplier primary-data gap in 2026 Scope 3 Category 1 assurance-ready inventories

Emission 3 Team
The supplier primary-data gap in 2026 Scope 3 Category 1 assurance-ready inventories

The supplier primary-data gap in 2026 Scope 3 Category 1 assurance-ready inventories

Here's the issue: A sustainability manager at a Wave 1 CSRD company launches a supplier data request for Category 1 (Purchased Goods and Services) in Q1 2025, targeting 200 suppliers representing 80% of procurement spend. By Q3 2025, 45 suppliers have responded with primary data. The manager applies spend-based estimation for the remainder, calculates total Category 1 emissions at 42,000 tCO2e, and submits the inventory to the auditor. The auditor asks: how much of the 42,000 tCO2e is based on supplier primary data versus spend-based estimation, and what is your plan to improve data quality year-on-year? Without a documented split and a credible data improvement plan, the auditor flags the inventory as non-compliant with ESRS E1 paragraph 44 disclosure requirements. The limited assurance opinion is qualified, and the company faces a six-month restatement cycle.

However, Scope 3 Category 1 disclosure consists of two things: emissions totals and data-quality documentation.

Emissions totals on their own have no value under limited assurance. Data-quality documentation—the percentage of emissions based on supplier primary data, the methodology for handling non-responders, and the year-on-year data improvement trajectory—is what the auditor is actually verifying. ESRS E1 explicitly requires disclosure of significant categories with methodology documentation, and Category 1 is almost always significant for CSRD-in-scope companies. The GHG Protocol allows spend-based estimation as a fallback, but CSRD expects data quality to improve over time. Indefinite reliance on spend-based estimates is not considered sufficient.

While emissions measurement has become cheaper—supplier engagement platforms, spend-based estimation, third-party carbon accounting tools—data-quality documentation has become more expensive. If you collect primary data from 45 of 200 suppliers in 2025, representing 30% of Category 1 emissions, then collect data from 80 suppliers in 2026, representing 55% of emissions, the year-on-year delta is split between actual reduction and data-quality improvement. The auditor cannot sign off on a trend claim unless you either restate the base year or document the methodology drift with a supplier-level reconciliation table. For a Wave 1 company with 200 Category 1 suppliers, the cost of producing a data-quality reconciliation table under limited assurance is approximately €18,000 per year in additional audit fees, and that cost compounds if you switch emission factor databases or redefine your supplier boundary mid-cycle.

How do you solve this? I think the answer is to lock your data-quality split before you lock your base year. The operators we work with at Emission3 document their supplier primary data percentage in their 2025 base year inventory, then track data-quality improvement as a separate KPI from emissions reduction. For now, that means building a supplier-level data quality register from day one, not retrospectively reconstructing it at audit time.

The shape of the argument, visualised below.

The data-quality documentation requirement under ESRS E1

ESRS E1 (Climate change) is explicitly designed to be consistent with the GHG Protocol's Corporate Standard and the GHG Protocol Scope 3 Standard. Companies reporting under ESRS E1 must disclose Scope 1, 2, and 3 emissions using GHG Protocol methodology, report a base year, describe recalculation policies, and provide a breakdown of Scope 3 by all relevant categories [1]. Crucially, ESRS E1 also requires reporting against the EU Taxonomy for Sustainable Activities and physical climate risk disclosures, extending beyond pure GHG accounting.

For Scope 3, the stable reference point is unchanged: value chain emissions are organized into 15 categories under the GHG Protocol Corporate Value Chain (Scope 3) Standard (2011), a structure reinforced by the Scope 3 Calculation Guidance as a systematic measurement framework [2]. The practical shift in 2026 is not a new category list but increasing pressure—driven by CSRD (ESRS E1), IFRS S2, and SBTi—for supplier-specific primary data over spend-based estimates.

ESRS E1 expects you to report gross Scope 3 emissions by significant category, using GHG Protocol-consistent methods and EFRAG's IG 2 guidance, and to show how you will improve data quality over time beyond pure spend-based estimates [3]. In practice, that means prioritising the most material categories, launching targeted supplier data requests for top emitters, and documenting all assumptions and proxies in a way that your auditors can trace and challenge.

"ESRS E1 requires disclosure of methodology quality—spend-based data must be justified. EPD-first, activity-based calculation delivers less than 10% uncertainty." [4]

The issue is not whether you are allowed to use spend-based estimation—you are, as a fallback under the GHG Protocol—but whether you can demonstrate year-on-year data quality improvement and trace the split between actual emissions reduction and methodology change. Auditors from both CSRD and SBTi processes look for this structure.

The supplier primary data collection problem

The practical 2026 change in Scope 3 is not a rewritten category list but a data-quality shift. Scope 3 calculation methods range from spend-based (monetary value multiplied by environmentally-extended input-output factors), to average-data (physical units multiplied by average factors), to supplier-specific (a supplier's own measured data) [2]. As CSRD, IFRS S2, and SBTi raise expectations, companies are increasingly expected to move from spend-based estimates toward supplier-specific physical data for material categories.

For FMCG companies, the goal is not to calculate everything at once; it is to build a reliable picture over time, starting with your biggest impact areas. The GHG Protocol offers several calculation methods, depending on the quality of data you have [5]:

  • Supplier-specific: Uses primary data from your suppliers. It is the most accurate and highly recommended method.
  • Activity-based: Combines actual activity data (like distance, weight, or energy use) with emission factors. Useful when detailed operational data is available.
  • Average data: Applies industry-average emissions per unit when primary data is not available.
  • Spend-based: Multiplies your financial spend by an emissions factor (e.g., kg CO2e per euro/dollar spent). Least precise, but helpful for rough estimates or when data is scarce.
  • Hybrid: Combines supplier-specific and secondary data to balance accuracy with practicality.

The challenge is that supplier-specific data requires supplier engagement, and supplier engagement timelines are outside your control. A procurement team at a Wave 1 CSRD company sends data requests to 200 Category 1 suppliers in Q1 2025. By Q3 2025, 45 suppliers have responded with primary data, 30 have declined, and 125 have not responded. The procurement team applies spend-based estimation for the 155 non-responders and submits the inventory. The auditor asks: what is your plan to improve the response rate for 2026, and how will you document the data-quality split?

Without a documented supplier engagement plan and a year-on-year data-quality improvement trajectory, the auditor flags the inventory as non-compliant. The issue is not the emissions total—it is the lack of evidence that the company is moving up the data-quality hierarchy.

Comparison: four approaches to Category 1 supplier engagement

ApproachData-quality split documented (2025 base year)Year-on-year improvement planAudit cost impact (2026 limited assurance)
Spend-based onlyNo—all Category 1 emissions are spend-based, no split documentedNo—no supplier engagement plan, auditor assumes indefinite reliance on estimationQualified opinion likely; €25k+ for restatement cycle
Partial primary data, no documentationNo—45 suppliers provided data, but no record of which emissions are primary vs. spend-basedNo—ad hoc supplier engagement, no KPI for data quality€18k/year for retrospective supplier-level reconciliation
Partial primary data, documented splitYes—30% of Category 1 emissions based on supplier primary data, 70% spend-based, documented in base year inventoryYes—target 55% primary data by 2026, documented in supplier engagement plan€8k/year for data-quality reconciliation, base case for limited assurance
Primary data majority, tier-2 visibilityYes—65% of Category 1 emissions based on supplier primary data, with tier-2 emissions flagged for material sub-assembliesYes—target 75% primary data by 2026, with tier-2 data requests for top 10 suppliers€5k/year for data-quality reconciliation, positions for reasonable assurance escalation

The difference between partial primary data with no documentation and partial primary data with a documented split is €10,000 per year in audit fees. The difference is not in the emissions total—it is in the evidence trail that shows you are moving up the data-quality hierarchy.

The tier-2 supplier data problem

Category 1 (Purchased Goods and Services) accounts for 80% to 95% of total emissions for most FMCG companies, including 95.8% for Nestlé and 99% for Solinest [5]. For companies with complex supply chains, tier-1 supplier data is necessary but not sufficient. A tier-1 supplier provides a bill of materials and an emissions total for a finished product. The auditor asks: how much of that emissions total is based on tier-2 supplier primary data versus tier-1 estimation? Without tier-2 visibility, the tier-1 emissions total is still largely spend-based, just one step removed.

ESRS E1 does not explicitly require tier-2 data, but the data-quality improvement expectation creates implicit pressure. If your Category 1 emissions are 65% based on tier-1 supplier primary data, but 80% of that tier-1 data is itself spend-based at the tier-2 level, the auditor will flag the data quality as lower than the 65% headline suggests. For a Wave 1 company targeting reasonable assurance by 2028, tier-2 visibility is not optional—it is the difference between a clean opinion and a qualified opinion.

The operators we work with at Emission3 solve this by flagging tier-2 emissions for material sub-assemblies in their base year inventory. For a steel importer, that means requesting furnace-level electricity data from the steel mill (tier-1), then requesting upstream emissions data for iron ore and coke from the mill's suppliers (tier-2). For a food processor, that means requesting farm-level emissions data for raw ingredients (tier-1), then requesting fertilizer and feed emissions data from the farm's suppliers (tier-2). The goal is not to map the entire supply chain on day one—it is to document which tier-2 emissions are material, then launch targeted data requests for those suppliers.

The methodology-lock problem

One governance point matters most: changing methodology before locking the base year creates restatement obligations under both ESRS 1 and SBTi. ESRS 1 dictates that an undertaking must provide restated comparative figures when it has redefined or replaced a metric or target, identified new information regarding estimated figures from the preceding period, or discovered material prior period errors (omissions or misstatements from a failure to use reliable information) [6]. Switching emission factor databases mid-process creates both problems simultaneously.

For Scope 3, the lock point is not the emissions total—it is the data-quality split. If you use spend-based estimation for 70% of Category 1 in 2025, then shift to 55% spend-based in 2026, the year-on-year emissions delta is split between actual reduction and data-quality improvement. The auditor cannot sign off on a trend claim unless you either restate the 2025 base year with the new data-quality split or document the methodology drift with a category-level reconciliation table.

The GHG Protocol allows both approaches, but ESRS E1 paragraph 44 requires disclosure of significant categories with methodology documentation [1]. If Category 1 is significant—it usually is—the auditor will ask how the 2025-to-2026 delta splits between actual reduction and data-quality improvement. Without a documented reconciliation, the trend claim is unverifiable, and the assurance opinion is qualified.

Decision point (FY2025 base year)Locked early (Q1 2025)Deferred to audit (Q4 2025)Assurance cost impact (FY2026+)
Boundary definition for Category 1ERP procurement data greater than or equal to €50k/supplier/year, excluding employee reimbursementsAll procurement spend, manually filtered post-calculation+€15k/year for boundary reconciliation
Emission-factor hierarchySupplier primary data, then EXIOBASE industry average, then spend-based fallback, documented per categoryMixed: some categories primary, some spend-based, no hierarchy documented+€20k/year for data-quality tier reconciliation
Supplier engagement KPI30% of Category 1 emissions based on supplier primary data, target 55% by 2026No KPI, ad hoc supplier engagement+€12k/year for retrospective data-quality documentation

The cost difference between locking these decisions in Q1 2025 and deferring them to Q4 2025 is approximately €47,000 per year in additional audit fees. The difference is not in the emissions total—it is in the evidence trail that shows the auditor how you made each decision.

How Emission3 fits

Emission3 is built for companies that need assurance-ready Scope 3 inventories with full data-quality lineage. We do not start with a carbon accounting platform—we start with a CBAM readiness call [7] that maps your supplier base, identifies which suppliers can provide primary data, and locks your data-quality split before you lock your base year. Every Category 1 emissions line item traces back to either a supplier invoice with primary data or a spend record with a documented estimation methodology.

Our Scope 3 with primary data solution [8] is built for supply-chain leaders and sustainability managers who are building CSRD or SBTi-compliant inventories. We integrate directly with ERP procurement data, send automated supplier data requests, and track response rates as a KPI. For tier-2 visibility, we flag material sub-assemblies in the base year inventory, then launch targeted data requests for those suppliers. The output is not just an emissions total—it is a supplier-level data quality register that documents which emissions are primary, which are spend-based, and what your year-on-year improvement trajectory is.

For Wave 1 CSRD companies targeting limited assurance in 2026, that means locking your data-quality split in Q1 2025, not retrospectively reconstructing it at audit time. For companies targeting reasonable assurance by 2028, that means building tier-2 visibility into your base year inventory, not adding it as an afterthought in 2027.

Summary: the supplier primary-data gap in one table

Inventory componentWhat teams budget forWhat auditors verifyCost delta (2026 limited assurance)
Category 1 emissions totalSupplier engagement platform, spend-based estimationData-quality split documentation, year-on-year improvement plan+€18k/year if no split documented in base year
Supplier response rateData request campaigns, follow-up emailsEvidence that non-responders were contacted, documented refusal or non-response+€8k/year if no contact log maintained
Tier-2 emissions visibilityTier-1 supplier primary dataEvidence that tier-1 data is not itself spend-based at tier-2 level+€15k/year if no tier-2 flags in base year inventory
Methodology consistencyGHG Protocol complianceEvidence that emission factor hierarchy and boundary definitions are consistent year-on-year+€20k/year if methodology changes without documented reconciliation

The gap is not in the emissions total—it is in the evidence trail that shows the auditor how you moved up the data-quality hierarchy. Spend-based estimation is permitted, but indefinite reliance on it is not.

If you are building a CSRD or SBTi-compliant Scope 3 inventory for 2026, start with a CBAM readiness call [7]. We map your supplier base, identify which suppliers can provide primary data, and lock your data-quality split before you lock your base year. Every emissions line item traces back to source evidence, and every data-quality decision is documented for audit. No anonymous self-serve onboarding—every customer starts with a readiness conversation.

[1] [2] [3] [4] [5] [6] [7] [8]

References & Sources

External Sources

  1. [1]
    GHG Protocol — IT & Telecommunications 2026

    ESRS E1 requires disclosure of Scope 1, 2, and 3 emissions using GHG Protocol methodology, report a base year, describe recalculation policies, and provide a breakdown of Scope 3 by all relevant categories.

  2. [2]
    GHG Protocol Updates 2026: Scope 2 & Scope 3 Accounting Guide

    The practical shift in 2026 is not a new category list but increasing pressure—driven by CSRD (ESRS E1), IFRS S2, and SBTi—for supplier-specific primary data over spend-based estimates.

  3. [3]
    CSRD Reporting Requirements: A Practical Climate & ESRS E1 Guide

    CSRD expects you to report gross Scope 3 emissions by significant category, using GHG Protocol–consistent methods and EFRAG's IG 2 guidance, and to show how you will improve data quality over time beyond pure spend-based estimates.

  4. [4]
    GHG Protocol Scope 3 from Supplier data

    ESRS E1 requires companies to disclose methodology quality — spend-based data must be justified. EPD-first, activity-based calculation delivers less than 10% uncertainty.

  5. [5]
    Scope 3 Emissions: A Complete Guide to the 15 Categories (2026)

    Scope 3 calculation methods range from supplier-specific (most accurate) to spend-based (least precise). Category 1 accounts for 80-95% of total emissions for most FMCG companies.

  6. [6]
    The methodology-consistency requirement in ESRS E1 Scope 3 emissions disclosure

    ESRS 1 dictates that an undertaking must provide restated comparative figures when it has redefined or replaced a metric or target, identified new information regarding estimated figures, or discovered material prior period errors.

Related Content

  1. [7]
    Book a CBAM readiness call

    All customers start with a readiness call: we map suppliers, gaps, and implementation, no anonymous self-serve onboarding.

  2. [8]
    Scope 3 with primary data

    Specific to supply-chain leaders and sustainability managers building CSRD or SBTi-compliant inventories with supplier-level data quality lineage.

Need help operationalizing this for your organization?

Book a CBAM readiness call: we map suppliers, reporting gaps, and a practical workflow using the same infrastructure we deploy for EU registry outputs.