Operations and procurement leaders at a mid-sized business reviewing supplier ESG data and governance metrics after the 2026 EU Omnibus changes to CSRD scope

Why Do Mid-Sized Businesses Need Operational Control to Scale Sustainably?

In March 2026, thousands of European mid-sized businesses were told they no longer had to publish a sustainability report.

Their largest customer sent the questionnaire anyway.

That gap between what the law now requires and what the market still demands is where operational control earns its keep. Operational control is an organization’s ability to govern, evidence, and improve how work gets done across its own operations and its supply chain, consistently enough to satisfy customers, lenders, and auditors without slowing the business down.

For operations, procurement, and compliance leaders at companies of roughly 250 to 1,000 employees, this is an awkward middle: large enough that informal process and personal knowledge have quietly stopped holding, but not large enough to fund a dedicated ESG function to replace them. The headlines about Brussels simplifying everything make that position feel more comfortable than it is.

What actually changed in 2026

The Omnibus I Directive, Directive (EU) 2026/470, was published in the Official Journal on 26 February 2026 and entered into force on 18 March 2026. It rewrote both the CSRD and the CSDDD in a single act.

Three changes matter for a growing business:

●      CSRD mandatory scope narrowed sharply. Reporting now applies only to companies with more than 1,000 employees and net turnover above €450 million. The original second wave moved to 2028 (covering financial year 2027). Listed SMEs, the old third wave, dropped out of mandatory scope entirely.

●      CSDDD narrowed and delayed. Due diligence obligations now reach only companies above 5,000 employees and €1.5 billion turnover. Member States must transpose by 26 July 2028, and in-scope companies comply from 26 July 2029.

●      A statutory ceiling on supplier data requests appeared. In-scope companies can no longer require business partners with fewer than 1,000 employees to disclose sustainability information beyond the Voluntary Standard, where the request relates to CSRD reporting.

All of which reads like a reprieve, and for anyone whose only concern was filing a report, it is one. For anyone who sells to large customers, the pressure has not disappeared so much as changed address.

Why being out of scope is not the same as being off the hook

Your CSRD-reporting customers still have to account for their value chains, and that obligation does not dissolve because your own company falls below the reporting thresholds. It travels down the chain until it reaches you, usually as a spreadsheet with a deadline attached.

The value chain cap gives suppliers under 1,000 employees a statutory right to refuse requests that exceed the Voluntary Standard for SMEs, which the Commission endorsed by recommendation in July 2025 and moved to codify through a draft delegated act on 6 May 2026, with adoption expected during the year. The protection is real, and most suppliers who open a 200-question survey have no idea they are entitled to decline it. But it is also narrower than the headlines suggest, in four ways that matter commercially.

It does not cover requests made for other reasons. The ceiling applies only to data requested for CSRD reporting purposes, which leaves a great deal sitting outside it: a customer running supplier due diligence, a bank pricing a loan, a tender evaluation, or an EcoVadis assessment.

It does not cover everyone. The cap protects undertakings below 1,000 employees, while CSRD scope requires more than 1,000 employees and more than €450 million turnover. A company with 1,200 employees and €200 million turnover therefore falls into neither category, which leaves it neither required to report nor protected from being asked. Check where your own headcount and turnover actually place you before assuming the cap covers you.

It does not remove the commercial consequence of a slow answer. A supplier who can produce clean energy, emissions, and workforce data within a fortnight tends to keep the contract, while one who needs two months tends to find the renewal quietly going elsewhere. The cap limits what a customer may demand of you, but nothing in it obliges them to keep buying from you.

It does not do the work for you. The Voluntary Standard’s Basic Module runs to roughly 50 data points, which sounds modest until you try to assemble them across four sites from spreadsheets that nobody owns.

The CSDDD cascade behaves the same way. Very large companies only start formal due diligence in July 2029, but they will spend the years before that getting ready, and supplier questionnaires are how that preparation reaches you. The deadline belongs to them; the work arrives at your desk well ahead of it.

Where growth without operational control breaks down

A weak process is easy to miss while a business is growing, because growth pays for it. Something falls through, somebody works a late night and catches it, and the fix never gets written down anywhere. Nobody minds, because the numbers are good.

That arrangement holds until the business crosses a line it does not notice at the time: a second site, a new tier-2 supplier, a first enterprise customer whose procurement team asks its questions in writing and expects them answered the same way twice. Improvisation stops scaling at roughly that point, and the failures start becoming visible to people outside the company:

●      Customer onboarding stalls because nobody can evidence a supplier screening process

●      The same ESG questionnaire is answered three different ways by three different people

●      An audit finding at tier 2 surfaces a subcontractor nobody knew existed

●      A tender is lost on a documentation gap rather than on price or quality

●      Decisions slow down because ownership is unclear

●      A lender asks for structured sustainability data and receives a PDF of good intentions

What catches leadership teams off guard is that none of these is a compliance failure. They are commercial ones, and for a mid-sized business today, weak operational control shows up on the P&L long before it ever shows up in an enforcement letter.

What operational control looks like in practice

None of this requires a governance department, which is the objection we hear first. Four capabilities carry most of the weight, and a mid-sized team can build all four.

Governance you can evidence

This comes down to clear ownership, documented decision rights, and one named person accountable for supplier data. The test is whether you can produce it on demand: when a customer asks who signed off on a supplier assessment, the answer should take seconds rather than an afternoon spent excavating old email threads.

Risk awareness that reaches past tier 1

Most real exposure sits at tier 2 and below, in the suppliers you have never met. Mapping dependencies before you need them is the difference between managing a disruption and discovering one. Our work on operational visibility as supply chains scale covers how that mapping holds up under growth.

Standard processes that survive turnover

A process that lives only in someone’s head walks out of the building when they resign, which is why the unglamorous work of writing things down repays itself the first time you lose a good operations manager. Simple and repeatable beats sophisticated and undocumented, every time.

Technology applied to the data burden

The recurring cost for a mid-sized supplier is rarely any single questionnaire; it is answering the same underlying question in eleven different formats for eleven different customers. Digital tools earn their place by letting you collect once and answer many times, so that one structured data set, aligned to the Voluntary Standard, absorbs most incoming requests before they turn into projects. We cover the multi-framework version of this problem in how companies can reduce ESG data fatigue.

What operational control returns

Operational maturity now shows up in outcomes a CFO recognizes. Companies that build it early get through compliance audits without a fire drill, and they score better on EcoVadis and customer scorecards, which increasingly decide who gets onto an enterprise supplier list in the first place. When a bank or an investor asks a sustainability question, they answer with structured data rather than narrative, and when they move into a regulated market they do it without a twelve-month remediation program standing in the way.

Reporting voluntarily under the Voluntary Standard is becoming a sales asset rather than an overhead for much the same reason: a completed report answers a customer’s questions before they think to ask them, and gives a lender something concrete to underwrite.

How VECTRA International Helps

At VECTRA International, we work as an end-to-end resilience partner. Our ecosystem connects advisory expertise, human-centric technology, and practical capability building, sized for organizations that do not have a governance department to spare.

Our integrated solutions include:

●      Compliance, risk, and due diligence advisory, including CSRD compliance services and supply chain due diligence

●      Sustainability and ESG reporting support for CSRD, ESRS, and Voluntary Standard readiness

●      Management system risk assessments

●      Audit preparation and assistance

●      Virtual and onsite training for internal capability building

For more than 20 years we have helped organizations turn operational complexity into resilient performance, supporting 450+ clients with programs validated against recognized standards such as SMETA and IRMA. As an ESG strategy consulting and sustainability consulting partner, we work across supply chains in more than 35 countries.

Teams that want to build the capability in-house can start with our Supply Chain Risk Management course on the VECTRA Marketplace.

Turning complexity into capability

The businesses that win the next procurement cycle will not be the ones that read the Omnibus headlines and relaxed, but the ones that recognized the breathing room for what it was and spent it. Simplification moved the deadline without moving the demand, and the questionnaires are still arriving.

Build your team’s capability. Explore our Marketplace courses on supply chain risk, due diligence, and operational resilience.

Check where you stand. Contact our experts for a specialist assessment of your operational and supplier risk position.

Frequently Asked Questions

What is operational control in a business?

Operational control is an organization’s ability to govern, evidence, and improve how work gets done across its own operations and its supply chain. It covers ownership and decision rights, risk identification, standardized processes, and the data needed to prove all three to customers, lenders, and auditors.

Are mid-sized businesses still in scope for CSRD after the Omnibus?

Most are not. Under Directive (EU) 2026/470, mandatory CSRD reporting applies only to companies with more than 1,000 employees and net turnover above €450 million. Companies in the original second wave now report from 2028 covering financial year 2027, and listed SMEs were removed from mandatory scope.

What is the CSRD value chain cap?

The value chain cap is a legal ceiling on the sustainability data that CSRD-reporting companies may require from smaller business partners. Companies with fewer than 1,000 employees have a statutory right to refuse requests that go beyond the Voluntary Standard for SMEs, where the request relates to CSRD reporting. The Commission published a draft delegated act codifying the cap on 6 May 2026.

Can we refuse ESG data requests from a large customer?

You can refuse requests that exceed the Voluntary Standard when they are made for CSRD reporting purposes and your company has fewer than 1,000 employees. The cap does not cover requests tied to due diligence, lending, tenders, or third-party ratings such as EcoVadis, and refusing does not oblige a customer to continue buying from you.

When does the CSDDD apply?

The amended CSDDD applies from 26 July 2029, with Member States required to transpose it by 26 July 2028. It now covers only EU companies with more than 5,000 employees and net worldwide turnover above €1.5 billion, or non-EU companies with EU turnover above €1.5 billion. Smaller suppliers are affected indirectly, through the due diligence their large customers must perform.

How can a mid-sized business build operational control without a large budget?

Start by mapping supplier dependencies past tier 1, naming a single owner for supplier data, and assembling one structured data set aligned to the Voluntary Standard that can answer most incoming requests. Training an existing team is usually faster and cheaper than a consulting program. VECTRA’s Marketplace courses and specialist assessments are built for exactly this. 


View Related Posts

How European SMEs Can Prepare for CSRD Reporting Requirements

Why Operational Visibility Matters More as Supply Chains Scale

Why Is Operational Resilience More Than Just a Dashboard

VECTRA International is a trusted Business Resilience & Operational Capability Building Partner. Through our ecosystem of integrated solutions, we help organizations transform operational complexity into resilient performance, measurable business impact, and sustainable growth.

Chaussée de Wavre 1517B, 1160 Brussels, Belgium.

A Note on Our Visuals: At VECTRA, we combine human expertise with advanced technology. Some of the supportive imagery in this article was generated using artificial intelligence tools like Google Gemini. We ensure all conceptual AI assets align with our brand standards and accurately reflect our data.

Table of Contents

RECENT BLOGS

LATEST PRESS RELEASE

Grab Your Free eBook Today!

Stay ahead of evolving ESG regulations and learn how to meet compliance requirements while strengthening business resilience.