Double materiality is the CSRD method for deciding what a company must disclose by looking at two angles at once. One side measures how the business affects people and the environment, while the other measures how sustainability issues affect enterprise value. Companies disclose topics material under either test.
Expanded Definition
Double materiality is a disclosure lens used in sustainability reporting to evaluate two distinct questions at once: what matters to the enterprise financially, and what matters because the enterprise affects people or the environment. In practice, it broadens reporting beyond investor-focused financial impact alone.
The key boundary is that the two tests are not interchangeable. A topic can be material because it creates enterprise value risk, or because the organisation has meaningful outward impact, even if that impact does not yet show up in near-term financial statements. That is why the term is often discussed as a reporting threshold, not as a general sustainability slogan.
Definitions and implementation details continue to vary across jurisdictions and vendors, especially in how companies operationalise impact materiality, value materiality, and topic-level scoring. For formal reporting rules, the CSRD and related European guidance are the most relevant starting points, while the concept itself is broader than any one template.
Examples and Use Cases
Double materiality appears in reporting workflows where organisations map sustainability topics to disclosure decisions rather than treating every ESG issue the same way.
- A manufacturer may treat carbon emissions as impact material because of environmental effects, even before those emissions create a direct earnings shock.
- A software company may treat cloud energy use as financially material if it creates cost pressure, procurement risk, or client scrutiny.
- A bank may assess data privacy and model governance through both lenses when customer harm and revenue exposure can both be relevant.
- An enterprise may decide a supplier issue is material because it affects its own operations and because it creates downstream social or environmental harm.
The practical tradeoff is that the method usually increases scoping effort. Teams must compare impacts across business units and time horizons, which makes documentation more demanding than single-lens materiality. That extra effort is the point: it reduces the chance that important external harms are omitted simply because they are not yet fully priced into the business.
Security Implications
For security and resilience topics, double materiality matters because disclosure decisions can change what a company measures, escalates, and audits. A topic such as identity compromise, data exposure, or supply-chain weakness may be financially material because it threatens uptime, costs, and liability, while also being impact material because it affects customers, partners, or critical services.
Misapplying the test can create blind spots. If an organisation only prioritises near-term enterprise value, it may under-report or under-govern issues whose damage is externalised to users or third parties until the problem becomes a regulatory or reputational event. If it only tracks outward impact, it may miss risks that are not obviously public-facing but still undermine enterprise continuity.
NHIMG’s research shows that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, underscoring how disclosure scoping can intersect with operational control gaps when machine identities are part of the risk surface.
Domain and Governance Relevance
In NHI and agentic AI governance, double materiality changes how organisations decide whether identity, access, and automation topics belong on the reporting register. A service account problem is not only a technical control issue; it can also be a governance issue when weak lifecycle control creates both enterprise loss exposure and external harm through data misuse, service disruption, or partner compromise.
That matters because NHIs often sit between operational security and broader accountability. A company that treats them only as infrastructure artefacts may miss their disclosure significance, while a company that treats them only as compliance items may miss the control reality that machine identities often scale faster than human oversight.
For NHI programs, the useful interpretation is simple: double materiality helps decide when identity lifecycle, privilege, and third-party access belong in board-level reporting, not just in technical hygiene. The term is therefore relevant wherever security governance must account for both business value and the wider impact of digital operations.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while NIS2, EU Cyber Resilience Act and DORA define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIS2 | Article 21 — Cybersecurity risk management measures | Requires risk governance that can surface material operational and societal impacts. |
| Recommendation — Map material sustainability and security topics into enterprise risk controls and oversight. | ||
| EU Cyber Resilience Act | Article 13 — Vulnerability handling and reporting | Connects product security obligations to outward impact and lifecycle disclosure concerns. |
| Recommendation — Track product-impact issues alongside financial exposure when classifying disclosure topics. | ||
| DORA | Article 5 — ICT risk management framework | Frames governance around resilience impacts that can affect both the firm and its stakeholders. |
| Recommendation — Use resilience governance to assess whether issues are material on both impact and enterprise-value axes. | ||
| NIST CSF 2.0 | GV.RM-03 — Risk Management Strategy | Supports enterprise-level decisions on which risks warrant governance attention and reporting. |
| Recommendation — Align reporting thresholds to a risk strategy that covers internal and external consequences. | ||
| CIS Controls v8 | 8.1 — Audit Log Management | Operational evidence and monitoring help substantiate materiality judgments with observed exposure. |
| Recommendation — Use logging and monitoring evidence to support materiality assessments for disclosed risks. | ||