Why ESPR Compliance Risk Doesn't Stop at Your Tier-1 Suppliers
ESPR and CSRD both require supply-chain data that most fashion brands do not currently collect below Tier-1. What Tier-2 and beyond means for compliance risk.
The compliance gap most brands don't see yet
For most fashion brands, the current compliance perimeter is defined by contractual relationships. You have data from your Tier-1 suppliers—the cut-and-sew factories and direct manufacturers. You have their certificates, their audit reports, and their self-declared emissions figures. This data is sufficient for today’s basic reporting, but it creates a significant blind spot for the regulatory frameworks currently being implemented across the EU.
The core issue is that both the European Strategy for Sustainable and Circular Products (ESPR) and the Corporate Sustainability Reporting Directive (CSRD) require data that extends beyond the point of final assembly. When your compliance strategy stops at Tier-1, you are missing the upstream layers where material composition is determined and where the majority of Scope 3 emissions and labor risks reside. This gap is not a minor administrative oversight; it is a structural risk that will become apparent as assurance requirements tighten.
What ESPR actually requires from your supply chain
Under Regulation (EU) 2024/1781, Digital Product Passports (DPPs) for textiles must include specific data points. While the exact supply-chain data fields are not yet fully specified and are pending the late-2027 delegated act, two requirements are already confirmed: material composition and origin.
Material composition is not a Tier-1 data point. A cut-and-sew factory does not determine the fiber content of the fabric; the mill does. Origin data similarly traces back to where the raw materials were sourced and processed. If your DPP relies on Tier-1 suppliers to provide this information, you are asking them to report on data they do not generate. This creates a chain of reliance that is fragile and prone to error, as Tier-1 suppliers often lack the visibility or contractual leverage to verify upstream details accurately.
What CSRD's double materiality pulls in from Tier-2 and beyond
Directive (EU) 2022/2464 mandates a double materiality assessment. For fashion brands, the material topics are typically Scope 3 emissions and S2 (workers in the value chain). By definition, Scope 3 emissions and supply-chain worker data extend beyond Tier-1 direct suppliers to Tier-2 entities, such as fabric mills and dye houses, and further upstream to raw material and fiber producers.
Most brands’ existing supplier data collection today stops at Tier-1 contractual relationships. It does not reach the raw-material tier. However, the bulk of a garment’s carbon footprint and the highest risks regarding labor conditions often lie in these upstream stages. If your materiality assessment identifies these topics as material, your reporting must reflect data from these tiers. Relying on Tier-1 estimates for Tier-2 and Tier-3 activities is not a compliant approach under the directive’s requirements for accurate and verifiable data.
Why Tier-1-only data collection won't be enough
The disconnect between where data is collected and where data is generated is the primary risk. Tier-1 suppliers are often intermediaries in the data flow. They may not have direct access to the raw material production data required for ESPR material composition claims or the detailed activity data needed for accurate CSRD Scope 3 calculations. When you request this data from Tier-1, you are often receiving aggregated estimates or secondary information that has not been verified at the source. This lack of direct visibility means your compliance data is only as strong as the weakest link in your supplier’s own reporting chain.
Where the verification burden lands when Tier-2 data is missing
Both ESPR material-composition claims and CSRD Scope 3 disclosures require verifiable data, not brand-level estimates, once assurance and audit requirements apply. If you cannot provide direct data from Tier-2 and Tier-3 suppliers, the verification burden shifts to your brand. Auditors and assurance providers will look for evidence that your data is accurate and complete. If your data relies on unverified Tier-1 estimates, you face the risk of qualified opinions or non-compliance findings. The cost of remediating these issues after an audit is significantly higher than the cost of establishing direct data collection channels now.
Starting the Tier-2 data conversation now
Addressing this gap requires a shift in how you manage supplier relationships. You need to move from a model of passive data collection to active data verification that includes upstream tiers. This involves mapping your supply chain beyond Tier-1, identifying the specific data points required for ESPR and CSRD, and establishing direct or verified indirect channels to collect this data. It is a complex process that requires specialized tools and expertise to manage the volume and variety of data involved.
Do not wait for the delegated acts to be finalized or for the first assurance audit to begin. The infrastructure for upstream data collection takes time to build. Start by assessing your current data gaps and the specific requirements for your product categories. See KadmilOS pricing to understand how to implement this, or Check ESPR scope to determine your immediate obligations.
Ready to handle compliance via API?
KadmilOS covers DPP data, eco scoring, CSRD documentation, and ECGT 2024/825 claim-support.