ISO 45003 & CSRD

ISO 45003 & CSRD

ISO 45003 and CSRD: must mid-sized employers now report on psychological health?

Note: this applies to German law. For most mid-sized employers: no. Since Directive (EU) 2026/470, only companies with at least 1,000 employees and over €450m revenue report. ISO 45003 is a guideline without certification. § 5 ArbSchG remains binding.

Reporting duty, standard and statute: what applies to whom (as of August 2026)

FrameworkApplies toBinding force
CSRD (after the Omnibus)At least 1,000 employees AND over €450m revenue — both criteria cumulativelyMandatory; national transposition by 19 March 2027, first application year from 1 January 2027
CSDDD (due diligence directive)At least 5,000 employees AND over €1.5bn revenueMandatory; transposition by 26 July 2028, application from 26 July 2029
ISO 45001Any organisation wishing to build an occupational health and safety management systemVoluntary — certifiable
ISO 45003Supplement to ISO 45001 for psychosocial risksVoluntary — a guideline without requirements, therefore NOT certifiable
§ 5 ArbSchGEvery employer from the first employee onwardsMandatory — subject to fines, regardless of size or reporting duty

What the Omnibus changed — and why it overtakes the trend narrative

International trend reports have for years named the anchoring of wellbeing in reporting as a driver: European sustainability reporting supposedly makes workforce topics a board matter. For Germany that narrative has not held since February 2026.

Amending Directive (EU) 2026/470 was published in the Official Journal on 26 February 2026 and entered into force on 18 March 2026. It raises the CSRD thresholds considerably: in future only companies with at least 1,000 employees and more than €450m in revenue are covered — both criteria must be met together, and capital market orientation no longer plays a role. Estimates suggest fewer than 500 reporting companies remain in Germany. Member States have until 19 March 2027 to transpose it; the first application year begins on 1 January 2027.

For mid-sized employers this is the practical all-clear: a company with 200, 500 or 900 employees is not obliged by the CSRD to report on psychological health. Anyone claiming otherwise — often just before making a consulting offer — is working from the legal position before the Omnibus.

The value chain: the channel through which it still arrives

The other half of the truth: not being subject to reporting does not mean never being asked. Companies that do report must include their value chain — and pass questionnaires on to suppliers. That is precisely why the legislator built a cap on value-chain requests into the Omnibus: smaller suppliers are no longer automatically obliged to provide comprehensive sustainability data.

That cap only protects against legally enforced requests, however, not contractual ones. A large customer may still make voluntary disclosure a condition of a tender, and a bank may ask during a credit review. Realistically, therefore, mid-sized employers meet this topic as a customer and financing requirement, not as a statutory duty.

The appropriate response is correspondingly sober: do not set up a CSRD project structure, but be able to answer. Anyone who has documented the psychological risk assessment properly and keeps a measures plan and a few robust indicators can answer such questionnaires from existing material — without a single reporting project.

ISO 45003: a guideline, not a certifiable standard

ISO 45003 was published in 2021 and was the first international standard with practical guidance on handling psychological health and safety at work. It supplements ISO 45001, which describes the occupational safety management system as a whole, and focuses on psychosocial risks: work overload, leadership behaviour, work organisation and social relationships at work.

The point where most misunderstandings arise: ISO 45003 is a guideline standard. It contains recommendations, not requirements — and is therefore not certifiable. ISO 45001 is certifiable; ISO 45003 can be applied within such a system and considered in an audit, but an 'ISO 45003 certificate' in the strict sense does not exist. Anyone offered one should ask precisely what is being attested.

This also clarifies what ISO 45003 can and cannot deliver in the German context: it replaces no duty and creates none — the duty to assess psychological strain has been in § 5 (3) no. 6 ArbSchG since the end of 2013 and applies from the first employee onwards. ISO 45003 provides structure, not the legal basis.

What mid-sized employers actually take from it

The real value of the standard lies in its systematics. The German psychological risk assessment is legally clear but substantively open — the ArbSchG says that an assessment must happen, not how granular it must be. ISO 45003 fills exactly that gap with a sorted map of psychosocial risk categories that can be laid over your own survey as a check: is work organisation covered? Leadership behaviour? Social relationships? The work environment?

A second practical benefit is anchoring in the management system. ISO 45003 treats psychological health not as a programme but as part of a plan–do–check–act cycle — the same logic the risk assessment requires anyway. Using the standard as a structural aid rather than a certification target saves inventing your own framework.

And third, connectivity: when a large customer asks how you handle psychosocial risks, 'we orient ourselves on ISO 45003 and document under § 5 ArbSchG' is an answer that is understood internationally. That is the realistic benefit — being able to speak the language of corporate customers, not compliance.

The honest list of duties

What is actually binding for a German mid-sized employer on psychological health can be stated briefly — and has nothing to do with reporting duties. First: the psychological risk assessment under § 5 ArbSchG, from the first employee onwards, with the documentation duty under § 6 ArbSchG. Second: deriving measures and reviewing their effectiveness under § 3 ArbSchG. Third: involving the works council where one exists.

Everything else — ISO 45001, ISO 45003, voluntary sustainability reports under simplified standards — is a business decision. It can pay off where corporate customers, tenders or financing partners ask for it. It does not pay off as anticipatory obedience towards a duty that, since the Omnibus, no longer exists for mid-sized employers.

The sober priority is therefore: first fulfil properly the duty that applies anyway and that inspections actually check. Anyone who documents the psychological risk assessment, derives measures and reviews their effect simultaneously has the substance from which any later voluntary reporting is fed.

Related measures & topics

Key takeaways

  • Omnibus Directive (EU) 2026/470: CSRD now applies only from 1,000 employees AND over €450m revenue — cumulative, without the capital market criterion.
  • Estimates suggest fewer than 500 reporting companies remain in Germany; transposition by 19 March 2027, application from 1 January 2027.
  • The Omnibus also caps value-chain requests towards smaller suppliers — contractual questions remain possible nonetheless.
  • ISO 45003 (2021) is a guideline without requirements and therefore NOT certifiable; ISO 45001 is.
  • Regardless of all this, § 5 (3) no. 6 ArbSchG remains binding — from the first employee, with the documentation duty under § 6 ArbSchG.
  • Practical benefit of the standard: a check framework for your own survey and the ability to speak the language of corporate customers — not compliance.

Frequently asked questions

Is my company still subject to CSRD reporting after the Omnibus?+

Only if both thresholds are met together: at least 1,000 employees and more than €450m in revenue. The earlier link to capital market orientation has been dropped. Estimates suggest fewer than 500 reporting companies remain in Germany. What ultimately counts is the national transposition, due by 19 March 2027.

Can you be certified to ISO 45003?+

No. ISO 45003 is a guideline standard: it contains recommendations but no requirements that could be audited against. ISO 45001 is certifiable as an occupational safety management system; ISO 45003 can be applied within it and considered in the audit. If someone offers an 'ISO 45003 certificate', ask them to explain exactly what it covers.

Does ISO 45003 replace the psychological risk assessment?+

No — and conversely it creates no additional duty either. The legal basis in Germany is § 5 (3) no. 6 ArbSchG, in force since the end of 2013 and applicable from the first employee. ISO 45003 supplies a systematics of psychosocial risk categories that can be laid over your own survey as a check — no more, but no less.

Our large customer sends a sustainability questionnaire — must we answer?+

As a rule you are not legally obliged to: the Omnibus explicitly capped value-chain requests towards smaller suppliers. Contractually, however, a customer may still make disclosure a condition. The workable approach is to answer from existing material — a documented risk assessment, a measures plan, a few robust indicators.

Is ISO 45001 worth it for a mid-sized company?+

That is a business decision, not a compliance question. It usually becomes worthwhile when customers or tenders require a certified management system, or when several sites are to be run consistently. It is not required to fulfil German occupational safety duties.

The duty documented properly — instead of a reporting project

EasyBGM keeps the psychological risk assessment, the measures plan and the effectiveness review in one place — the substance from which any later customer or bank enquiry can be answered.

Sources

Last updated: 2026-08-18. Not legal or tax advice — have your specific case reviewed by a professional.

Read more

BGM-Kompass covers German workplace health management (BGM): funding paths, figures and legal references (e.g. § 20b SGB V, § 3 No. 34 EStG, § 167 SGB IX, the statutory-health-insurer prevention guidelines) apply to Germany.