The big CSRD wave arrived in 2026 exactly where most advisory pieces said it never would: in mid-market and small businesses. Not because a 40-employee workshop suddenly has to file an ESRS-conforming sustainability report — but because large customers, banks and insurers push their reporting duty down the supply chain via questionnaires. And nearly every one of those questionnaires contains a block that classic bookkeeping cannot answer: IT, electricity consumption, server room, hardware lifecycle.
This article clears out the marketing haze from cloud vendors and hardware makers and describes soberly what an IT partner in the SMB space actually has to deliver in 2026 to make ESG numbers stand up to scrutiny.
The CSRD cascade: why ESG IT hits the SMB even without a reporting duty of its own
The Corporate Sustainability Reporting Directive (CSRD) obliges large companies and listed SMBs to file standardised sustainability reports under ESRS. The direct addressee is a small group — a few tens of thousands of firms across Europe. The practical addressee is huge: everyone who supplies these firms or gets supplied by them.
The mechanism is simple. A reporting corporation has to disclose its Scope 3 emissions — everything that arises along the value chain. It can no longer defend those numbers with generic industry averages if it wants its auditors to sign off. So it asks its suppliers. For the SMB, that means a customer questionnaire with 20 to 60 IT and energy fields, once a year, non-optional.
Cheating or leaving fields blank does not usually cause an immediate ejection. But the questionnaire feeds into the ESG rating, the rating into the next tender, and eventually into the next line of credit. That is the actual cascade — and the reason ESG IT is a board-level topic in the SMB even when CSRD does not apply in the narrow sense. If you want a similar-shape overview of the compliance landscape, our piece on NIS2 duties for SMBs in 2026 reads well next to this one.
IT share in Scope 1, 2 and 3: where your systems really feed in
The default reflex is to book IT entirely under Scope 2 — electricity, done. That is too short. IT shows up in all three scopes, with different leverage and different proof logic.
Scope 1 — direct emissions
For most SMBs, IT contributes little here, but not nothing. Counted are: diesel for the UPS, refrigerant leaks from the server-room aircon, occasionally the admin’s company car. Sounds marginal, but has to be documented as soon as auditors look at it. If you run a large UPS with a combustion-engine backup, keep operating hours and tank fills clean in the maintenance log once a year.
Scope 2 — electricity — the big IT lever
This is where most of the IT footprint sits: electricity for servers, storage, network, cooling. Two numbers are decisive: the real kWh figure (measured, not estimated) and the emission factor of the electricity tariff. A certified green-power contract will show a much lower Scope 2 number — but only if the certificate character is properly documented. That is not an IT job, but IT must supply the kWh figure that the finance team multiplies by the factor.
In practice that means: every PDU in the rack should be a metered one, or at minimum a meter per rack. If you only have a building meter and estimate server consumption, you are not producing an ESG-grade number. Cheap metered PDUs are enough to get started; if you want to do it properly, log monthly and archive the series in internal reporting. Our article on energy costs in the server room and the levers that actually matter goes deeper on the room side.
Scope 3 — hardware production and cloud services
The hardest part. Scope 3 collects: the embedded carbon of servers and notebooks, transport, end-of-life recycling, and — often overlooked — the pro-rata emissions of the cloud services in use. If you consume 200 Microsoft 365 licences, you effectively co-operate a hyperscaler data centre, and your share belongs in your Scope 3 book. Large cloud vendors now provide consumption dashboards for this; smaller SaaS vendors deliver nothing, and that has to be flagged honestly as a data gap.
The most powerful lever in Scope 3 is hardware lifetime. A server that runs for ten years spreads its production footprint over ten years. A server rotated out after three carries the same footprint into a third of the time.
PUE, server-room efficiency and the honest numbers
PUE (Power Usage Effectiveness) is the best-known efficiency indicator for data centres: total energy divided by IT-only energy. A perfect PUE would be 1.0 — everything above is cooling, lighting, losses. Hyperscalers like to communicate figures around 1.1 to 1.2. A typical SMB server room is worse, often in the 1.6 to 2.2 range, sometimes above in older buildings. That is not a scandal, but it has to be honestly measured and reported for what it is.
Three measures give the most in the SMB context:
- Separate warm and cold aisles, even if it is just half a curtain between two racks
- Raise the setpoint — modern servers tolerate 24 to 27 degrees Celsius intake air without issue; many rooms run needlessly cold
- Replace old aircon with inverter-based units whenever renewal is due anyway
If you handle those three points honestly and re-measure PUE once a year, you have a number that survives a customer questionnaire and a sustainability report.
Server refresh vs continued operation: what the ESG maths really say
The sales-side classic: “The new server is 40 percent more efficient, that pays for the CO2 balance too.” Sometimes true. Often not. The honest calculation has three rows:
- Operating emissions across the planned remaining lifetime (kWh times emission factor)
- Embedded carbon of the new device — typically a few thousand kg of CO2eq for a standard 2U server, depending on model and region
- End-of-life of the old device (recycling path, residual value)
As long as the old server still does a relevant job and its consumption is not dramatically out of line, continued operation is very often the better ESG answer. A refresh really pays when the old platform is off firmware support (a security problem that ESG bookkeeping does not heal) or when there is a real consolidation — four old boxes replaced by one new node. We ran that comparison in Server refresh: new purchase or upgrade, also without the marketing foam.
For the retired hardware, the rule is: do not throw it out, hand it over in a structured way. Working servers have a secondary market, truly exhausted units have proper recycling paths. We wrote it up as scrappage bonus for old servers.
TERRA and Wortmann as a German sustainability partner
If you want to describe your hardware origin in an ESG-suitable way, Wortmann AG and its brand TERRA make a grateful building block for SMB IT: production in Germany, short service paths, transparent recycling partners and a data centre in Huellhorst with a documented modernisation history. This does not replace your own sustainability report, but it closes Scope 3 data gaps because the vendor can answer follow-up questions with real numbers. The context is in our piece on Wortmann AG — sustainable IT maker from Germany.
Honesty matters here too: “Made in Germany” is one criterion among many. It does not replace measurement in your own rack. But it helps in the customer questionnaire when the questions cover supplier risk, transport distance and take-back logistics.
What the IT partner concretely has to deliver — a practical checklist
When an SMB has an ESG questionnaire on the desk, IT typically has to produce these items within a few weeks:
- IT kWh consumption (split by server, storage, network, cooling), measured at least at rack level
- PUE for the server room, or an honest “not measured, estimated X, action for 2026: install meters”
- Number of active servers, purchase year, planned lifetime — that carries the embedded-carbon allocation
- Cloud usage with provider, region and provider-supplied emission figures where available
- Take-back and recycling process for retired hardware
- UPS diesel in litres per year with a maintenance log
- Process documentation for procurement — are sustainability criteria present in the selection grid?
That looks like a lot but is manageable when the IT function approaches it in a structured way. A good IT service partner builds this data collection in and delivers reproducible reporting instead of yearly fire drills. And if you are thinking about a new storage or server landscape anyway, you can plan efficiency straight into it with the TrueNAS configurator — modern ZFS scales capacity linearly without spinning up a fresh box for every growth step.
Takeaway
ESG IT in the SMB space is no longer a fashion topic in 2026 — it is a concrete piece of customer questionnaires, credit checks and tender documents. Whoever can respond today with clean consumption data, an honest PUE, a realistic lifetime and a transparent supply chain has a very tangible edge over competitors who still get by with “we are sustainable too”. And it is all achievable with classic SMB IT — no cloud migration required, no million-euro programme, but a bit of discipline in measuring, documenting and letting things keep running.
FAQ on ESG IT and the CSRD reporting duty in the SMB
Does our SMB actually have to file a CSRD report?
Directly CSRD-obliged are large firms and listed SMBs. Most classic mid-market companies do not fall under it directly — but they are pulled in indirectly via customer questionnaires, bank requests and tender documents. It is therefore realistic to build the ESG numbers as if you were obliged, even if formally you are not.
How do we get a reliable kWh figure per server?
Simplest path: metered PDUs in the rack that report per socket. Entry-level models that speak SNMP or HTTP JSON are enough. If you do not want to swap PDUs, an interim meter per rack read monthly by hand is better than any vendor data-sheet estimate.
Is the cloud automatically more sustainable than on-prem servers?
No. A well-utilised on-prem server can produce lower operating emissions than the pro-rata cloud share of the same workload at a hyperscaler, especially if your electricity comes from a certified green tariff. Conversely, poorly utilised on-prem hardware is regularly worse than cloud operation. The honest answer is a calculation for the specific workload, not a matter of principle.
How often should we replace servers when ESG is part of the calculation?
Purely from an ESG angle, running servers for at least six to eight years makes sense, as long as firmware, spare parts and OS support are available. The classic three-year refresh is rarely compatible with sustainability. Exceptions: a real efficiency step through consolidation, end of security firmware, a genuine capacity problem.
What about e-waste and retired devices?
For retired IT hardware, a documented path matters: either take-back through the vendor or distributor, resale via a refurbisher, or proper recycling via a certified partner with a written record. Throwing hardware into a skip has to be declared as such in the questionnaire — it is much easier to set up a clean process ahead of time.
Do refurbished servers count for ESG?
Yes. Refurbished hardware extends effective lifetime and distributes embedded carbon over more operating years. For less critical workloads — backup targets, test environments, dev clusters — it is a very solid ESG answer. For production core systems, check first that firmware maintenance and spare-parts supply still line up with the intended runtime.
More articles
TrueNAS on Old Hardware: Recycle or Buy New?
TrueNAS on decommissioned server hardware: when recycling for backup and secondary storage makes sense, when ECC RAM, HBA and PSU need to be new.
ISO 9001 for IT Service Providers: Realistic Preparation
ISO 9001 without theatrics: document processes, schedule internal audits sensibly, budget honestly -- a pragmatic guide for IT service providers with 10 to 20 staff.
TrueNAS Made in USA: Honestly Assessing the Data Privacy Debate for EU Customers
TrueNAS is developed in the US -- is that a GDPR problem? An honest look at CLOUD Act, telemetry, source-available code and support contracts for EU customers.