New Rules on Greenhouse Gas Emissions and Cybersecurity Shake Up Corporate Responsibilities
Corporate regulations on greenhouse gas reporting and cybersecurity are evolving, requiring firms to adapt sustainability and security practices.
- • Revised Greenhouse Gas Protocol will include SAF investments in Scope-3 emissions accounting.
- • The Book-and-Claim model allows companies to claim emission reductions from SAF certificates without physical fuel delivery.
- • Cyber Resilience Act mandates continuous cybersecurity risk management for connected products.
- • CRA encourages integration of data protection and cybersecurity risk assessments under GDPR synergy.
Key details
Two significant regulatory steps are reshaping corporate accountability in environmental impact and cybersecurity. The Greenhouse Gas Protocol is undergoing reforms to enhance sustainability reporting, especially by allowing companies to include sustainable aviation fuel (SAF) investments in their Scope-3 emissions. Currently, only renewable energy certificates are recognized, leaving aviation emissions unaccounted for. According to Vincent Santamaria, the upcoming "Actions and Market Instruments" initiative will introduce a market-based CO₂ inventory incorporating SAF certificates. This Book-and-Claim approach lets companies claim emission reductions by purchasing SAF certificates without physically receiving the fuel, potentially shifting the financial burden of costly SAFs from airlines to companies aiming to offset emissions. The final protocol draft is expected for public discussion by 2027, with full publication targeted for late 2028. Companies are advised to begin assessing carbon footprints and developing tracking systems for SAF certificates.
Alongside environmental reforms, the EU's Cyber Resilience Act (CRA) imposes stringent cybersecurity requirements on businesses responsible for connected products such as software, IoT devices, and cloud applications. The CRA mandates continuous risk management throughout product lifecycles, ensuring security is embedded by design and persists beyond product deployment. Companies must adapt operational and supply chain processes accordingly and assign dedicated internal responsibilities for ongoing security assessments. The CRA works synergistically with GDPR by enabling combined risk-based approaches for data protection and cybersecurity.
These regulatory advances compel German companies to integrate more robust environmental and cybersecurity measures, reflecting evolving standards in corporate sustainability and digital resilience.
This article was translated and synthesized from German sources, providing English-speaking readers with local perspectives.
Source articles (2)
Kostenloser E-Guide: CRA: Was Unternehmen wissen sollten
Source comparison
Latest news
SC Freiburg's Youth-Driven Success Propels Them to Bundesliga Third Place in 2026 Season
Jürgen Klopp Debuts as Germany Coach with Strict Rules and Tactical Overhaul Ahead of Nations League Clash
Germany Ratifies UN High Seas Agreement to Boost Marine Biodiversity Protection
AI-Driven Cybersecurity Risks Surge in German SMEs Amid Accelerated Threats and New Regulations
New Rules on Greenhouse Gas Emissions and Cybersecurity Shake Up Corporate Responsibilities
2026 German State Elections Shake Federal Politics and EU Relations
The top news stories in Germany
Delivered straight to your inbox each morning.