Compliance

Your cloud bill is a carbon report you're not reading

A

Anand Srinivasan

19 Jul 2026 · 6 min read

Every cloud billing row contains enough information to produce a carbon number. Service, region, and usage quantity are all you need, your billing API already provides all three. Most engineering teams just are not reading it. EmitCI does — automatically, for every account you connect.

The compliance deadline

Jan 2025              Jan 2026              Jan 2027
   │                      │                     │
   ▼                      ▼                     ▼
Large EU              Mid-size EU           Small EU +
>500 staff            >250 staff            listed co's
FILING NOW            FILING NOW            FILING SOON
────────────────────────────────────────────────────────
Fines: up to 10% of global annual turnover
Non-compliant companies listed on public registry
Enterprise procurement now requires supplier Scope 3 data

CSRD fines run to 10% of global annual turnover. A €15M ARR company faces up to €1.5M exposure. But the harder constraint is the base year: it requires historical data, which requires a pipeline running last year. Start today and your earliest compliant first filing is FY2026 — unless you have prior years locked already.

Cost data is carbon data

BILLING ROW                       CARBON ROW
──────────────────────            ──────────────────────────────
Provider  │ AWS                   + Instance TDP  (mfr. spec)
Region    │ us-east-2        →    + Grid intensity (IEA 2023)
Service   │ EC2                   ───────────────────────────────
Usage     │ 720 hrs               Energy = hrs × (watts ÷ 1000)
Cost      │ $252/mo               CO₂   = energy × gCO₂/kWh
                                  Accuracy: ±30-50% (IEA averages)
                                  If provider-native API available:
                                  Accuracy: ±10% (measured)

EmitCI reads service, region, and usage from your billing API, enriches each row with IEA grid intensity and instance TDP, and merges provider-native carbon data where available. The same data FinOps already pulls, with one extra enrichment step.

Where cost and carbon align, and where they diverge

ALIGNMENT — cheaper AND cleaner
──────────────────────────────────────────────────────────────
Region             Grid intensity     vs dirty alternative
eu-north-1               7 gCO₂/kWh   98% less carbon, <3% cost
us-west-2              130 gCO₂/kWh   70% less carbon, same cost

DIVERGENCE — cheaper but dirtier (the compliance trap)
──────────────────────────────────────────────────────────────
ap-south-1 (Mumbai)    713 gCO₂/kWh   cheapest APAC, dirtiest grid
polandcentral (Azure)  640 gCO₂/kWh   cheapest EU compute
us-east-2 (Ohio)       440 gCO₂/kWh   same price as us-east-1, dirtier
──────────────────────────────────────────────────────────────
A FinOps migration to cheaper dirty compute can increase
Scope 3 Cat 1 by 80–120% — showing up as an unexplained
YoY spike in your CSRD filing. FinOps and sustainability
need to look at the same data.

SaaS and hardware: the two layers most teams miss

Cloud compute is ~60% of engineering Scope 3. The rest is SaaS and hardware, and most dashboards count neither. EmitCI tracks both.

SaaS: DEFRA's spend-based factor converts monthly spend to kgCO2/month. No vendor telemetry needed, just the invoice. Add a tool name and its monthly spend in EmitCI and it appears in the Scope 3 summary immediately. A busy observability platform at $5k/month emits ~700 kgCO2/month, more than most teams' storage layer.

Hardware: A MacBook Pro M3 carries ~147 kgCO2e of embodied carbon from manufacturing. At 50 engineers, 3-year refresh: 2,450 kgCO2/year before a single job runs. Cat 11 is required under GHG Protocol. Most tools ignore it. EmitCI's hardware declaration takes headcount and device type and computes the annual embodied carbon automatically.

Anomaly detection

Carbon spikes are cost spikes. Emissions doubling without a throughput increase means idle compute, runaway autoscaling, or a region migration to a dirtier grid — all three also inflate the invoice. EmitCI flags anomalies automatically by comparing current-period emissions against the rolling prior average, so the signal surfaces before it becomes a line item in your CSRD filing.

Confidence scoring

Data Source                        Accuracy     Confidence
───────────────────────────────────────────────────────────
Provider-native API (AWS, GCP)     ±10%         ████████  90%
IEA regional annual averages       ±30–50%      █████     55%
IEA global average fallback        ±50%+        ████      40%
DEFRA spend-based (SaaS tools)     ±40%         █████     60%
───────────────────────────────────────────────────────────
Blended score = CO₂-weighted average across all sources
Required in CSRD methodology statement — not optional

EmitCI tracks the data source for every carbon record and computes a blended confidence score across the installation. It shows in the Scope 3 summary and is included in the generated methodology statement. ≥70% is defensible for a first CSRD filing. A single CO2 number with no confidence metadata is an incomplete disclosure.

Base year: the decision that cannot wait

Lock your base year before data retention runs. If FY2024 is gone, it is gone, no reconstruction, no YoY comparison, no compliant filing. EmitCI's period locking permanently exempts closed years from the retention sweep — the data is preserved for audit regardless of plan limits. This is the only decision in the pipeline that cannot be undone in the wrong direction.

Getting started with EmitCI

┌────────────────────────────────────────────────────┐
│  WEEK 1 — CONNECT AND LOCK                         │
│  ① Connect cloud accounts  (AWS / GCP / Azure)    │
│  ② Connect GitHub  (CI/CD runner carbon)           │
│  ③ Lock base year  ← do this before anything else │
└──────────────────────────┬─────────────────────────┘
                           │
                           ▼
┌────────────────────────────────────────────────────┐
│  WEEK 2 — COMPLETE COVERAGE                        │
│  ① Add tag attribution  (Team, Env, Project)       │
│  ② Add SaaS tools + monthly spend                  │
│  ③ Declare headcount + device type  (Cat 11)       │
└──────────────────────────┬─────────────────────────┘
                           │
                           ▼
┌────────────────────────────────────────────────────┐
│  WEEK 3 — COMPLIANCE OUTPUTS  (Team+)              │
│  ① Download ESRS E1 CSV  (includes exclusion rows) │
│  ② Download CDP C6.5 workbook                      │
│  ③ Download Methodology PDF                        │
└──────────────────────────┬─────────────────────────┘
                           │
                           ▼
            ┌──────────────────────────────┐
            │  Defensible first disclosure │
            │  Complete  ·  Auditable      │
            │  Base year locked            │
            └──────────────────────────────┘

Three weeks with data you already have. Completeness is what CSRD auditors check first, not perfect confidence, not zero gaps, just a complete picture with every category accounted for.

Get started free

Start measuring your CI carbon today

Connect your GitHub account in 2 minutes. Per-workflow carbon and cost estimates appear within 24 hours. No code changes required.

Install GitHub App — free for 14 days