Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Decision guide·EU Voluntary Standard 2026 · Disclosure guides

Do SMEs Need Sustainability Reporting Software, or Is Excel Enough?

Who this is for A 6-minute read for reporting teams working through Preparing, controlling and releasing the report, and for reviewers testing whether the evidence behind it holds.

Short answer

The answer, before the reasoning

Excel can be enough for a first EU Voluntary Standard reporting cycle if the undertaking has a small team, a limited number of requesters, a disciplined evidence repository and clear version control. The standard does not prescribe specialist software.

The practical risk is not the spreadsheet itself; it is uncontrolled reuse, weak evidence, inconsistent answers and unapproved releases. Move to a specialised platform when several users, repeated customer and bank requests, multi-framework outputs, workflow approvals, access restrictions or system integrations make spreadsheet controls too fragile.

Direct answer

Figure 1. Branded implementation visual for Do SMEs Need Sustainability Reporting Software, or Is Excel Enough?.

Why this question matters

Many SMEs start voluntary sustainability reporting because a customer, bank or investor asks for information, not because they want to build a full reporting department. The instinct is therefore sensible: use the tools already available, usually Excel, shared folders and Word.

That approach can work. The EU Voluntary Standard is proportionate and modular. It is not a software implementation standard. However, the information still has to be relevant, faithful, comparable, understandable and verifiable. A spreadsheet that cannot show where a number came from, who approved it, which version was released, or why a datapoint was marked not applicable can create rework and reputational risk.

The decision is therefore not 'Excel versus software'. It is whether the organisation has a controlled reporting system appropriate to its scale, users and risk.

Quick orientation

Quick orientation

Question
Practical answer
Applies to
Undertakings preparing first-cycle voluntary reporting, customer ESG packs or lender responses.
Primary decision
Whether to operate with spreadsheets and a document repository, or adopt a specialised platform.
Key distinction
A calculation tool is not the same as an evidence repository, approval workflow or release control.
Common confusion
Assuming that software creates compliance, or that Excel is automatically inadequate.

Three layers: calculation, evidence and release

A useful reporting system has three layers. First, the calculation layer stores data fields, formulas, assumptions and status. This may be Excel in the first year. Secondly, the evidence layer stores utility bills, HR extracts, policies, approvals, methodology notes, and explanations for estimates or omissions. Thirdly, the release layer controls what is shared publicly, what is sent to a bank, what is sent to a customer and what remains restricted.

Problems occur when these layers are collapsed into one spreadsheet. The workbook may contain a number, a draft answer, a confidential note and an unapproved customer response in adjacent cells. That is easy to build and difficult to govern.

In practice

Spreadsheets, repositories and platforms compared

Criterion Spreadsheet plus repository Controlled workbook — Specialised platform
Best fit First cycle, few users, low request volume. Recurring requests and functional owners. — Large supplier bases, assurance-like review and repeated outputs.
Evidence Folder links and manual references. Evidence IDs, mandatory fields and review columns. — Document management, access controls and audit logs.
Controls Naming conventions and manual sign-off. Locked formulas, data validation and version register. — Workflow, permissions, automated tasking and logs.
Integrations Manual import from finance, HR and operations. CSV exports and structured upload templates. — APIs, ERP/HRIS/energy systems and multi-framework reporting.
Main risk Version drift and lost evidence. Workbook becoming over-engineered. — Buying before process, ownership and data definitions are mature.

Buying triggers: when Excel stops being enough

A specialised system becomes worth considering when the following triggers start to appear:

More than three functional owners regularly edit the dataset.

The same answers are reused across banks, investors, customers and tenders.

Different entities, sites or subsidiaries require separate boundaries and roll-ups.

Evidence is requested repeatedly and must be restricted by audience.

The organisation needs a response history showing what was sent, when and to whom.

Version control is failing: old files continue to circulate externally.

Management wants dashboards, quarterly updates or year-on-year comparatives.

The same data must support the EU Voluntary Standard, ESRS requests, GRI, CDP or rating questionnaires without changing the facts.

The clearest buying trigger is not reporting ambition; it is control failure. When people no longer trust which number is current, which claim has been approved, or which customer received which version, the system needs to mature.

Minimum system requirements for the first cycle

Whether the organisation uses Excel or software, the minimum system should include:

A stable data dictionary with definitions, units, boundaries and methodology.

A disclosure register covering B1-B11 and, where used, C1-C9.

A status field for each datapoint: applicable, not applicable, unavailable, estimated, voluntary or omitted under an approved basis.

A named owner and reviewer for every datapoint.

Evidence IDs that link every metric and narrative claim to source records.

Separate release status: internal only, approved for lender, approved for customer, approved for public report.

A version register for reports, questionnaire exports and evidence packs.

Access controls for personal data, confidential commercial information and trade secrets.

A change log for restatements, methodology changes and late corrections.

Lean first-year Excel architecture

A pragmatic first-year workbook should not try to imitate enterprise software. It should be simple enough for non-specialists to maintain and strict enough to prevent uncontrolled answers.

In practice

Sheet Purpose Control point
Start Here Scope, reporting period, module option, entity basis and release rules. Approved by reporting owner.
Applicability Matrix B/C datapoints, Annex II status, owner and response status. No blank status cells.
Data Dictionary Definitions, units, periods, boundaries and calculation methods. Locked definitions after approval.
Evidence Register Evidence ID, source, owner, period, method, confidentiality and review status. Every published answer has evidence.
Request-Response Log Requester, purpose, mapped datapoint, response version and approval. No external response without release approval.
Disclosure Index Report location, completeness, omissions and reviewer notes. Matches final report and packs.

Hypothetical example: spreadsheet is enough - until it is not

A 60-employee manufacturer receives one annual ESG questionnaire from a strategic customer and a separate request from its bank. In year one, it uses the Basic Module, records utility bills, HR data and policies in a controlled folder, and maintains one Excel workbook with evidence IDs and approval status. This is proportionate.

In year two, three customers ask for slightly different versions, the bank asks for updated climate-risk information, and the sales team starts reusing last year's answers in tenders. The organisation now has version and release risk. It does not necessarily need a large platform, but it needs at least a controlled response log, role-based access to evidence and a formal release workflow.

In practice

Common mistakes

Mistake Why it is a problem Better approach
Buying software before defining the dataset The platform digitises confusion. Agree period, boundary, definitions, owner and evidence first.
Treating Excel as the evidence system A workbook can store references, not all evidence safely. Use an evidence register and controlled repository.
Letting each requester create a new answer Creates inconsistent statements and uncontrolled claims. Reuse approved answer blocks and record deviations.
Using one public worksheet for confidential notes Personal data and trade secrets may leak. Separate internal evidence from external response outputs.
Assuming a dashboard equals readiness Visual completeness may hide weak evidence. Track review status, evidence and release approval.

Readiness

Practical checklist

  • Can you identify the current approved answer for each datapoint within one minute?
  • Can you show the source evidence behind each published number?
  • Can you tell which customer or bank received which version?
  • Can you prevent unapproved staff from changing released numbers?
  • Can you reproduce the report next year without rebuilding the whole system?
  • Can you separate public information from restricted evidence?
  • If the answer to most of these questions is yes, Excel may be sufficient for the current cycle. If not, the issue is not merely software; it is reporting governance.

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · EU Voluntary Standard 2026

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See course formats
/en/knowledge-hub/disclosure-guides/eu-voluntary/eu-voluntary-preparing-the-report/do-smes-need-sustainability-reporting-software-or-is-excel-enough/