Short answer
The answer, before the reasoning
For most SMEs, the controlled dataset should come first and the designed report should be treated as one output. The 2026 Voluntary Standard is intended to serve counterparties, banks and investors as well as internal management, and it allows the report to be public or counterparty-focused.
A dataset-first approach fixes definitions, boundaries, periods, evidence, ownership and approval before information is reformatted for different users. It does not remove the need for a coherent report, but it prevents the annual PDF from becoming the only place where the organisation’s sustainability information exists.
A practical implementation guide covering users, boundaries, evidence, version control, output formats and the role of the 2026 EU Voluntary Standard.
Technical status
EDUCATIONAL AND LEGAL STATUS
This article explains the Commission-adopted 2026 EU Voluntary Sustainability Reporting Standard. At the source cut-off, Delegated Act C(2026) 5011 was still in the European Parliament and Council scrutiny period and had not yet entered into force through Official Journal publication. The article is educational material, not legal advice, an assurance opinion or a substitute for checking the final OJ text and any contractual information request.
In practice
Article map
| Stage | What the reader will be able to do |
|---|---|
| Answer | Decide why a controlled dataset normally comes before graphic report design. |
| Distinguish | Separate the reporting system, the annual reporting snapshot and each user-facing output. |
| Apply | Define users, boundaries, fields, evidence, controls, versions and output mappings. |
| Evidence | Build traceability from published wording and metrics back to controlled records. |
| Publish | Select proportionate outputs: data pack, public report, management report section or digital report. |
Why the “report first” instinct creates avoidable rework
A voluntary sustainability project often starts with a request to “prepare the report”. That language encourages the team to open a document, choose a design and begin writing. The problem is that the same SME may subsequently receive a bank questionnaire, a customer portal request, a tender schedule and an internal management request for the same information in different formats. If the only controlled object is the finished PDF, every new request becomes a manual extraction exercise and every change risks creating inconsistent answers.
The 2026 Voluntary Standard was designed for more than one audience. Its objectives include meeting the information needs of value-chain partners, banks and investors, improving the undertaking’s own management of sustainability issues and supporting resilience and access to finance. The Standard also states that the report’s primary function is to inform actual or potential business counterparties; public publication is an option rather than the sole purpose. This multi-user design makes a reusable dataset particularly valuable.
Rule
WHY TEAMS GET THIS WRONG
A designed report is visible, finite and easy to present to management. A controlled dataset is less glamorous, but it is the asset that preserves definitions, evidence and comparability. Treating the PDF as the system is similar to treating a printed set of financial statements as the accounting ledger.
Three layers that should not be confused
Figure 1. One controlled dataset can produce several outputs without rebuilding the underlying evidence.
In practice
| Layer | Purpose | Controlled object — Typical owner |
|---|---|---|
| Reporting system | Collect, define, calculate, review and retain information. | Data dictionary, evidence register, calculation files, approvals and change log. — Finance / sustainability process owner. |
| Annual reporting snapshot | Freeze the information for one reporting period and one selected reporting option. | Approved dataset version, boundary statement and unresolved-gap record. — Reporting owner and approver. |
| User-facing output | Present an approved subset in the format needed by a user. | Public report, customer pack, lender response, management dashboard or digital report. — Publisher, relationship owner or system interface. |
Start with users - but do not let each user define a separate truth
Dataset-first does not mean collecting every possible ESG datapoint. It means identifying the legitimate users and then creating one governed source for the information that the organisation decides to report. A user map should distinguish the information need, the permitted use, the timing, the level of detail and whether the request is covered by the value chain cap or arises from another legal or contractual basis.
In practice
| User | Likely need | Output format — Control question |
|---|---|---|
| Corporate customer | Selected value-chain information, often at datapoint level. | Controlled data pack, portal response or digital exchange. — Is the request for CSRD reporting, another legal purpose, due diligence or a commercial requirement? |
| Bank or investor | Credit, transition, risk and performance information. | Lender pack, questionnaire extract or report. — Does the output clearly state period, boundary, methodology and limitations? |
| Management | Operational trends, actions, targets and data gaps. | Dashboard, management paper or annual review. — Does the same approved dataset support external and internal numbers? |
| Public reader | Context, narrative coherence and selected performance information. | Separate sustainability report or management-report section. — Does design preserve the scope and caveats in the approved data? |
| Digital platform | Structured fields and identifiers. | XBRL, CSV/API or template upload. — Is the taxonomy/template version aligned with the applicable Standard? |
Rule
REQUIREMENT VERSUS IMPLEMENTATION PRACTICE
Standard: the 2026 Voluntary Standard identifies users and permits public or counterparty-focused reporting. Implementation practice: maintaining one master dataset with controlled output mappings is not a prescribed software requirement; it is a proportionate way to meet multiple information needs consistently.
Lock the reporting boundaries before collecting numbers
A datapoint is not controlled unless the team knows what it covers. B1 requires the undertaking to state whether the report is prepared on an individual or consolidated basis and, for a consolidated report, to list the subsidiaries covered. The reporting period should be consistent with the financial statements where those are prepared. Beyond that overall basis, individual metrics may require additional operational boundaries, such as the sites included in energy data, the employee population used for workforce metrics or the facilities assessed for biodiversity sensitivity.
In practice
| Boundary field | Question to resolve | Example controlled value |
|---|---|---|
| Reporting basis | Individual undertaking or consolidated group? | Consolidated: parent plus three named subsidiaries. |
| Reporting period | Which dates and cut-off rules apply? | 1 January-31 December 2026; payroll cut-off 31 December. |
| Operational perimeter | Which sites, leases, vehicles or activities are included? | Owned and controlled sites; landlord-supplied electricity separately identified. |
| Workforce population | Headcount or FTE; employees only or additional workers? | Employees in headcount at year-end; temporary agency workers excluded from B8 but tracked separately. |
| Metric-specific condition | Does an “if applicable” trigger apply? | B6 water consumption applies only to production processes that significantly consume water. |
| Output perimeter | Is a counterparty receiving the full report or a selected extract? | Customer receives Annex II datapoints plus context; public report includes the approved full Basic module. |
Design the dataset around datapoints, not pages
The unit of control should normally be the paragraph or subpoint, not the page on which it will eventually appear. The Standard contains essential datapoints, items reported only in specified circumstances, explicitly voluntary datapoints and items that are considered only for sector information. Some environmental datapoints are also voluntary for undertakings with 10 employees or fewer. A data dictionary should therefore record the regulatory category and the organisation’s selection before data collection begins.
In practice
| Minimum field | Purpose |
|---|---|
| Datapoint ID and source anchor | Links the record to the exact paragraph/subpoint and edition. |
| Display label and definition | Prevents the same concept being described differently across outputs. |
| Datapoint category | Essential, if applicable, voluntary, sector consideration, or voluntary for undertakings with 10 employees or fewer. |
| Value type and unit | Narrative, Boolean, integer, percentage, MWh, tCO2e, currency, date or list. |
| Period and boundary | Defines the time and organisational/operational perimeter. |
| Method and assumptions | Records calculations, conversions, estimates and judgements. |
| Evidence and owner | Identifies source records and accountable data owner. |
| Review and release status | Shows whether the record is draft, reviewed, approved, restricted or released. |
| Output mapping | Identifies where the approved fact appears in each report, pack, portal or digital field. |
Build evidence into the dataset rather than adding it at the end
Paragraph 11 requires information to be relevant, faithful, comparable, understandable and verifiable. Verifiability is difficult to achieve when evidence is assembled only after the narrative has been approved. Every quantitative value and material narrative claim should therefore carry a source reference, owner, methodology, review status and retention location. The evidence itself may be restricted; the register can still record its existence and access level.
Quantitative metrics: source-system extract, invoice or register; calculation workbook; conversion factors; boundary reconciliation; reviewer evidence.
Policy disclosures: approved policy, version, effective date, scope, responsible owner, evidence of approval and public-availability status.
Initiatives and targets: authorised plan, baseline, boundary, target date, progress evidence and governance approval.
Conditions and non-applicability: documented facts showing why a paragraph-level trigger was or was not met.
Output claims: evidence that the published wording is consistent with the approved dataset and does not imply a wider scope.
Version control: freeze a reporting snapshot, not a folder of “final” files
The reporting dataset should have a period version and a release status. Changes after approval should be recorded with the reason, preparer, reviewer, date and affected outputs. From the second reporting year, the Standard requires comparative information for the previous year except for metrics disclosed for the first time. A roll-forward process should therefore preserve the prior-year approved value, distinguish restatements from current-year changes and explain methodology changes.
Figure 2. Dataset-first implementation lifecycle and annual control loop.
In practice
| Control | Minimum record | Why it matters |
|---|---|---|
| Source-set version | Standard edition, guidance version, template/taxonomy version and source cut-off. | Prevents an older VSME template from silently driving a 2026 VS report. |
| Dataset version | e.g. FY2026 v1.0 approved 20 March 2027. | Defines the authoritative annual snapshot. |
| Change log | Field changed, old/new value, reason, evidence, preparer and reviewer. | Allows all outputs to be updated consistently. |
| Comparative bridge | Prior-year approved value, restatement flag and explanation. | Supports comparability and avoids overwriting history. |
| Output register | Output name, user, release date and dataset version used. | Shows which recipient received which approved facts. |
| Access and retention | Permissions, retention period and evidence archive. | Protects confidential material while preserving traceability. |
Choose the output format after the data model is stable
The Standard does not force every undertaking to publish a glossy standalone report. The primary function is to inform counterparties; an undertaking may make the report public, place it in a management-report section or issue a separate document. It may also incorporate information by reference where the referenced documents are accessible at the same time and from the same document set. The correct output is therefore a design decision based on users, not a substitute for the selected reporting option and its datapoints.
In practice
| Output | Best use | Strength — Control risk |
|---|---|---|
| Controlled counterparty data pack | Responding to a bank, client or tender with selected approved fields. | Efficient and targeted. — Recipient may misread an extract as a full Option A or B report; label scope clearly. |
| Public standalone report | Communicating context and the full selected reporting option. | Readable narrative and brand visibility. — Design edits may change scope, units or caveats. |
| Management-report section | Combining sustainability and financial context. | Supports coherence with financial statements. — Cross-references and document timing must remain accessible. |
| Digital structured report | Machine-readable exchange through XBRL or another structured format. | Reduces re-keying and supports reuse. — Technical validation does not prove substantive completeness or current-standard alignment. |
| Dashboard / management paper | Internal monitoring and action. | Useful for decision-making and improvement. — Internal metrics may have a different boundary; differences must be reconciled. |
How to use EFRAG’s Digital Template without making it the master system
EFRAG’s June 2026 VSME Digital Template version 1.3.0 supports data entry, checks, paragraph links and conversion to Inline XBRL. Its XBRL taxonomy provides a vendor-independent data model and supports structured exchange. Those features reinforce the value of data-first reporting. However, the June 2026 materials expressly reflect the 2025 VSME Recommendation for SMEs with fewer than 250 employees, and EFRAG indicated that an update would be needed when the future delegated act was released.
The explanatory note also identifies practical limitations: the template does not support comparative roll-forward, does not collect or calculate all underlying data, has no GHG calculator, can be corrupted through spreadsheet modification and may be suitable mainly for first-time reporting. A sensible approach is to maintain the authoritative dataset and evidence register independently, then populate the current template or digital interface as an output once its mapping to the applicable 2026 Standard has been checked.
Rule
DIGITAL VALIDATION IS NOT REPORTING COMPLIANCE
A template status of “COMPLETE” or a successful XBRL validation indicates that specified technical checks have passed. It does not demonstrate that the organisation selected the correct reporting option, classified conditional datapoints correctly, used faithful estimates, retained sufficient evidence or made a justified compliance statement.
Practical implementation plan
Map users and purposes. Record who asks for information, why, when and in what format. Separate CSRD value-chain requests from other legal or contractual requests.
Select the reporting option. Decide whether the organisation will prepare the Basic module only, pursue the Basic and full Comprehensive compliance option, or provide selected additional Comprehensive disclosures without representing a full Option B report.
Lock the reporting basis and period. Record individual/consolidated basis, subsidiaries, period and metric-specific boundaries.
Create the datapoint register. Map each paragraph/subpoint, category, unit, condition, owner and output requirement.
Build the evidence register. Link each datapoint to source, methodology, assumptions, reviewer and confidentiality status.
Collect, calculate and classify. Distinguish reported values, estimates, not-applicable conditions, voluntary non-selections, permitted omissions and unresolved gaps.
Review and freeze the annual dataset. Perform reconciliations, consistency checks, management review and approval before design.
Render each output. Use controlled mappings for the report, customer pack, lender response and digital file; label scope and status.
Roll forward. Preserve comparatives, record restatements and update only changed facts, methods, evidence and conditions.
Hypothetical scenario
ILLUSTRATIVE SCENARIO
Context. A manufacturer with one parent entity and two operating sites receives sustainability requests from its main customer and its bank. Management also wants a short public report. Initial approach. The marketing team commissions a 30-page designed report and asks data owners for numbers by email. Three months later, the bank requests the same energy, GHG and workforce information in a spreadsheet. The team discovers that the public report used calendar-year energy but the bank response uses invoice months; employee figures use headcount in one output and average FTE in another. Dataset-first correction. The organisation selects a reporting basis, creates a paragraph-level register, defines energy and workforce boundaries, stores calculation evidence, and freezes FY2026 dataset version 1.0. The public report, customer pack and bank response are produced from mapped fields. Where the customer requests additional information for another purpose, it is recorded as a separate supplemental field rather than silently changing the Voluntary Standard dataset. Limitation. The example does not determine whether a specific request is legally constrained by the value chain cap; that depends on the requester, purpose, legal basis and final applicable law.
Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.
In practice
Weak versus stronger implementation
| Weak approach | Stronger dataset-first approach |
|---|---|
| The PDF is the only approved record. | An approved dataset version supports every released output. |
| Data owners send numbers by email without definitions. | Each field has definition, unit, period, boundary, source and owner. |
| A new questionnaire creates a new spreadsheet. | New outputs map to existing fields; genuinely additional fields are controlled separately. |
| The designer edits values and caveats directly. | Design works from a locked content pack; changes return through review. |
| Prior-year files are copied and overwritten. | The dataset is rolled forward with comparatives, restatement flags and change history. |
| “Complete” template status is treated as compliance. | Technical validation and substantive reporting review are separate gates. |
In practice
Common mistakes and how to correct them
| Mistake | Why it creates risk | Correction |
|---|---|---|
| Starting with a page plan | The team decides what looks good before it decides what the selected module requires. | Lock the option, datapoint map, boundaries and evidence before design. |
| Creating separate truths for each user | Each questionnaire develops its own definitions and periods. | Maintain one master definition and document controlled user-specific transformations. |
| Treating “voluntary” as “uncontrolled” | The absence of a statutory reporting obligation is mistaken for permission to publish unsupported information. | Apply the Standard’s quality principles and internal approval to every public or counterparty output. |
| Using the current EFRAG template without edition review | A tool reflecting the 2025 VSME is assumed to implement the 2026 Standard automatically. | Record tool version and perform a mapping review before use. |
| Ignoring output scope | A selected data extract is described as “our Voluntary Standard report”. | State whether the output is a full Option A/Option B report or a limited data pack. |
Readiness
Dataset-first readiness checklist
- Users, purposes and recurring requests are documented.
- The selected reporting option and any selected additional disclosures are fixed.
- Individual/consolidated basis, period and metric boundaries are approved.
- Each datapoint has a standard anchor, category, definition, unit and condition.
- Evidence, methodology, assumptions, owner and reviewer are linked.
- Not applicable, not selected, estimated, permitted omission and unavailable are separately classified.
- The annual dataset has an approved version and change log.
- Comparative and restatement rules are established for year two.
- Every output identifies the dataset version and scope used.
- Digital-template and taxonomy versions are checked against the current Standard.
Practical conclusion
For an SME, the most valuable first-year asset is not necessarily a polished report. It is a controlled, reusable and reviewable sustainability dataset that can support the selected Voluntary Standard option and be rendered for different users. The public report still matters: it explains context and makes the information understandable. But when the report is generated from a governed dataset rather than assembled as a one-off publication, the organisation gains consistency, faster responses, clearer evidence and a much stronger starting point for the second reporting year.
Questions
Questions people ask
Should an SME create a report or dataset first?
For an SME, the most valuable first-year asset is not necessarily a polished report. It is a controlled, reusable and reviewable sustainability dataset that can support the selected Voluntary Standard option and be rendered for different users.
Can one dataset support bank and customer requests?
The 2026 Voluntary Standard is intended to serve counterparties, banks and investors as well as internal management, and it allows the report to be public or counterparty-focused. One controlled dataset can produce several outputs without rebuilding the underlying evidence.
Does the EU Voluntary Standard require a public report?
The 2026 Voluntary Standard is intended to serve counterparties, banks and investors as well as internal management, and it allows the report to be public or counterparty-focused. The Standard also states that the report’s primary function is to inform actual or potential business counterparties; public publication is an option rather than the sole purpose.
Can the EFRAG Digital Template be the master dataset?
The explanatory note also identifies practical limitations: the template does not support comparative roll-forward, does not collect or calculate all underlying data, has no GHG calculator, can be corrupted through spreadsheet modification and may be suitable mainly for first-time reporting. A sensible approach is to maintain the authoritative dataset and evidence register independently, then populate the current template or digital interface as an output once its mapping to the applicable 2026 Standard has been checked.
What version controls are needed?
The reporting dataset should have a period version and a release status. Changes after approval should be recorded with the reason, preparer, reviewer, date and affected outputs.
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ LRA AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · EU Voluntary Standard 2026
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.
