California SB 253: what software companies with $1B+ revenue must do now
Anand Srinivasan
20 Jul 2026 · 7 min read
SB 253 — the California Climate Corporate Data Accountability Act — is the first US state law requiring full Scope 1, 2, and 3 GHG disclosure for large companies. It passed in October 2023. The first filing deadline has already passed for Scope 1 and 2. The Scope 3 deadline is January 2027.
Who it applies to
If your company has annual revenue above $1 billion and does business in California — meaning employees, customers, or a registered entity in the state — you are in scope. The threshold is gross revenue, not California revenue. A $3B company with one engineer in San Francisco qualifies.
Revenue threshold: >$1B annual gross revenue
Nexus requirement: Doing business in California
(employees / customers / registered entity)
Filing entity: Ultimate parent company
Designated ERO: CDP (Carbon Disclosure Project)
Enforcement body: CARB (California Air Resources Board)
Penalty: Up to $500,000 per reporting year for wilful non-complianceWhat you have to disclose
Scope 1 → Direct emissions
Office gas boilers, company vehicles, diesel generators, refrigerants
DUE: FY2025 filing — past due
Scope 2 → Purchased electricity
Office power, owned or leased data centres
DUE: FY2025 filing — past due
Scope 3 → Value chain emissions
Cloud compute, CI/CD runners, hardware, SaaS, business travel,
employee commuting, purchased goods and services
DUE: FY2026 filing — January 2027 (six months away)
Third-party assurance (Scope 1 + 2):
Limited assurance required from FY2026 onward
Must engage an accredited GHG assurance providerThe three gaps most software companies have
The first is Scope 3 completeness. SB 253 requires disclosure of all material Scope 3 categories, not just the ones you already have data for. Every category you do not cover must include an explicit exclusion statement with a stated reason. Auditors check completeness before they check the numbers. A filing that covers cloud compute but ignores SaaS tools or hardware without an exclusion row will not pass review.
The second is the base year trap. SB 253 requires year-over-year comparison against a locked base year. If FY2024 or FY2025 data has been deleted by your data retention policy, you cannot reconstruct it. No base year means no compliant YoY comparison. Lock historical periods in your systems before the retention sweep runs — once data is gone it is gone.
The third is assurance readiness. Limited assurance on Scope 1 and 2 is required from FY2026. Assurance providers need your methodology document, emission factor sources, raw data with calculation trail, and data governance records. Preparing these takes four to six weeks minimum. Start now, not in December.
How SB 253 and CSRD relate
SB 253 CSRD
────── ────
Jurisdiction: California (US) European Union
Revenue/size: >$1B revenue in CA >250 employees + €40M revenue
What: Scope 1, 2, 3 GHG Scope 1, 2, 3 + ESRS narrative
Filing: Via CDP portal In annual management report
Assurance: Limited S1+2 from FY2026 Limited FY2025, Reasonable FY2028
Format: CDP C6 questionnaire ESRS E1-6 structureCSRD and SB 253 require the same underlying data: Scope 1, 2, and 3 totals, base year comparison, methodology documentation, and assurance records. If you prepare for one you are most of the way to the other. The difference is format — CSRD uses ESRS E1-6, SB 253 files via CDP's C6 climate questionnaire.
What a compliant SB 253 filing looks like
FILING PACKAGE — CDP CLIMATE QUESTIONNAIRE
──────────────────────────────────────────────────────────────
C6.1 Scope 1 total (tCO₂e) + methodology + sources
C6.3 Scope 2 total — location-based and market-based
C6.5 Scope 3 by category (MTCO₂e)
Covered: values + data source + methodology
Excluded: category name + reason for exclusion
C6.1c Third-party assurance for Scope 1
Provider, level (limited/reasonable), date, reference
C6.3e Third-party assurance for Scope 2
Methodology PDF
Boundary method (operational control / financial / equity)
Data sources per category
Emission factor table + sources + vintage
Uncertainty bounds per source
Recalculation policyEmitCI produces all of this. The CDP Excel workbook auto-fills C6.5 from your connected cloud accounts, CI/CD runs, hardware declarations, and SaaS tool spend. C6.1c and C6.3e Verification columns populate automatically from the assurance details you declare per year in the Scope 1 and 2 cards. The Methodology PDF is generated from your installation's actual data sources, emission factors, and boundary settings.
The timeline you are working against
Jan 2025 Jan 2026 Jul 2026 Jan 2027
│ │ │ │
▼ ▼ ▼ ▼
FY2024 FY2025 S1+2 TODAY FY2026 S3
base year FILING DUE FILING DUE
window opens (past due) ← 6 months
─────────────────────────────────────────────────────────────
If FY2024/FY2025 data has been deleted by retention policy:
→ No base year for FY2026 Scope 3 comparison
→ No YoY data = filing is non-compliant
→ Up to $500k penalty exposure per year
─────────────────────────────────────────────────────────────
Action required NOW:
1. Lock FY2024 and FY2025 as closed periods (prevents deletion)
2. Declare Scope 1 + Scope 2 for FY2025 (past due)
3. Start assurance provider engagement for S1+2
4. Build Scope 3 inventory before January 2027The SB 253 readiness checklist in EmitCI's Company Profile card tracks your seven required disclosure components with colour-coded filing deadline urgency. Connect cloud accounts, declare Scope 1 and 2 on the Emissions page cards, add SaaS tools and hardware headcount, set your base year, then download the CDP workbook and Methodology PDF from the compliance section. That covers the Scope 3 inventory. The only thing EmitCI cannot do for you is the assurance engagement — that requires a human provider.