Limited vs reasonable assurance under CSRD: what verification bodies need to know in 2026

If you provide sustainability assurance services — or are preparing to — one distinction will structure your engagements more than any other over the next two years:
Limited assurance vs reasonable assurance.
These are not mere technical labels. They imply different levels of work, procedures, fees and risk profiles for you as an assurance provider.
With Omnibus I now in force, the timeline for each level has also shifted.
In this article we clarify:
- what limited and reasonable assurance mean in practice
- where CSRD stands on each level today
- what Omnibus I changes (and what it does not)
- what verification bodies should build now
Also read: ISSA 5000 vs ISAE 3000: which assurance standard for CSRD?
The central distinction: what do these two levels mean?
Definition — Limited assurance: in a limited assurance engagement, the practitioner performs procedures sufficient to reduce the risk of material misstatement to an acceptable level, but that level remains higher than under reasonable assurance. The conclusion is expressed in negative form: “Nothing has come to our attention that causes us to believe that the sustainability information is materially misstated.” Limited assurance relies mainly on inquiry and analytical procedures rather than deep testing of underlying data.
Definition — Reasonable assurance: in a reasonable assurance engagement, the practitioner reduces the risk of material misstatement to a low level. The conclusion is expressed in positive form: “In our opinion, the sustainability information is fairly presented, in all material respects.” Reasonable assurance requires substantially more evidence — detailed data testing, control evaluation, extensive documentation — and approaches the rigour of a financial audit.
In short: reasonable assurance is markedly more demanding than limited assurance, for both the reporting entity and the provider.
That difference translates into:
- more procedures, time and documentation
- deeper examination of data systems and internal controls
- higher competence requirements for the practitioner
- generally higher fees
Where does CSRD stand today?
The original CSRD text, before Omnibus I, foresaw:
- Phase 1 (reports from 2025): mandatory limited assurance
- Phase 2 (reports from 2028): move to reasonable assurance
That trajectory was ambitious. It assumed that within about three years entities would have mature data systems and internal controls, and that the market would have enough qualified providers.
Neither assumption is fully met today.
What Omnibus I changes — and what it does not
Definition — Omnibus I: Omnibus I refers to Directive (EU) 2026/470, which entered into force on 18 March 2026. It amends CSRD to ease certain obligations, postpone deadlines and refocus scope on large undertakings, while keeping strong assurance expectations for entities still in scope.
Omnibus I delays and softens several elements of the original timetable, but does not remove the assurance obligation for companies still covered. Limited assurance remains the near-term baseline; the move toward reasonable assurance is postponed but not abandoned.
For verification bodies the implication is clear: you must be operational on limited assurance now, while preparing the step-up toward reasonable assurance.
Why this matters more than it appears
Many bodies underestimate the gap between the two levels. Moving from limited to reasonable assurance is not a simple procedure extension: it is a model change — internal controls, data traceability, governance, competences and technical-review capacity.
Accreditation bodies and supervisors already look at whether your systems can support both levels without documentary inconsistency or dependence on a few isolated experts.
What verification bodies should build now
- Map current engagements by assurance level and framework (ISAE 3000, ISSA 5000 upcoming).
- Strengthen engagement-file templates so limited assurance is already structured as an extensible base.
- Align competence and authorisation with ISO 14066 and ISO 17029 — reasonable assurance needs more senior profiles and robust independent technical review.
- Anticipate client demand: some entities will voluntarily aim for reasonable assurance before the legal obligation.
- Engage your accreditation body on scope extension and witnesses for reasonable assurance.
In summary
Limited assurance remains the immediate operational standard under CSRD; reasonable assurance is the medium-term regulatory trajectory. Omnibus I changes the timeline, not the direction. Bodies that structure methods, competences and files now will avoid a costly catch-up race.
FAQ — Limited vs reasonable assurance under CSRD
Can an ISO 17029-accredited VVB assure under CSRD?
Yes, by combining an assurance framework (ISAE 3000 or ISSA 5000) with the ISO 17029 / ISO 14065 stack.
Does Omnibus I remove assurance?
Not for entities still in scope; it mainly adjusts timeline and perimeter.
When to prepare for reasonable assurance?
Now: methodology, competences, engagement-file templates and accreditation dialogue.
Support for verification bodies: explore our ISO 17029 & ISO 14065 support or contact us.



