CM.com N.V.
Material Topics
Sustainability statement, in full
The complete text of CM.com N.V.’s FY2025 sustainability statement is held here – 157 pages, captured from the published report. Every disclosure below also links to its own passage.
ESRS 2 – General Disclosures
GOV-1The role of the administrative, management and supervisory bodiesReported
Reference: pages 61, 34-35.
CM.com has a two-tier board structure: a Management Board (CEO, COO and CFO) and a six-member Supervisory Board, both reporting to the General Meeting, supported by a five-member Executive Committee. "The Management Board has delegated its responsibility to identify and consequently manage sustainability matters to the CFO" (p.35, and confirmed p.61).
Oversight of sustainability reporting sits with the Audit Committee, which "monitors (i) the financial and sustainability reporting process and drawing up proposals to safeguard the integrity of the process (ii) the identification and management of sustainability matters and issuing advise to the Supervisory Board in that regard (iii) the effectiveness of the internal control systems... with regard to the company's financial and sustainability reporting" (p.61). "Several members of the Supervisory Board hold positions in Sustainability Committees at companies with years of experience in sustainability reporting and membership in the Dow Jones Sustainability Index" (p.61).
GOV-2Information provided to and sustainability matters addressed by the undertaking's administrative, management and supervisory bodiesReported
Reference: page 61.
CM.com installed a CSRD working group drawing on Legal, ESG, Risk and Compliance, and Reporting expertise, which "met regularly to discuss developments and progress related to the CSRD, and related sustainability topics" (p.61). Key process owners at Senior Management level are accountable for disclosure requirements in their domain and report into the working group, which helps them with "the identification of sustainability matters, reporting requirements, and further improving the provided information" (p.61).
The CFO, who holds delegated responsibility for sustainability matters, "together with the working group... provides periodic reports to the Management Board and the Audit Committee regarding sustainability, ensuring that the Management Board, Audit Committee, and Supervisory Board are informed and able to bring sustainability matters into their decision-making" (p.61). "The Management Board, Supervisory Board, and Audit Committee are sufficiently qualified to perform their duties for the identification and management of sustainability matters" (p.61); members with less direct experience "gained knowledge this year, particularly regarding the CSRD, through training such as webinars."
GOV-2(was GOV-3)Integration of sustainability-related performance in incentive schemesReported
Reference: pages 61, 51-52.
"CM.com has integrated sustainability-related performance into the incentive schemes of the Management Board and Senior Management. The set targets mostly regard the material social topics: Employee Engagement and Diversity & Inclusion" (p.61).
In the Management Board's Short-Term Incentive Plan, the COO's personal objectives include improving employee engagement, representing "one-third of the organizational development target, which accounts for 10% of the total target" (p.61); business-unit leadership STI plans weight employee engagement at 20%. In the 2025-2027 Long-Term Incentive Plan, "ESG - Gender diversity: female leadership" and "Employee engagement" each carry a 15% weight (30% combined) of the performance-share criteria, targeting "33% women in leadership roles" and an engagement score of 75 by 2027 (p.52, p.61). The 2023-2025 LTI outturn scored gender diversity at 108% of target and employee engagement at 40% of target, "slightly below the threshold" (p.52). Climate performance is not currently one of the incentive criteria.
GOV-3(was GOV-4)Statement on due diligenceReported
Reference: pages 61-62.
CM.com maps its due-diligence process against a table of "core elements of due diligence": embedding due diligence in governance sits under GOV-2/GOV-3/SBM-3; engaging with affected stakeholders under GOV-2, SBM-2, IRO-1, MDR-P, E1-1 and S1-2; identifying and assessing negative impacts under SBM-3/IRO-1; taking action under MDR-A, E1-1, E1-3 and S1-4; and tracking effectiveness under MDR-M/MDR-T and E1-4/E1-5/E1-6/S1-5/S1-6/S1-9/S1-13/S1-15 (p.62). "The results of our due diligence process are incorporated in our double materiality assessment" (p.62).
CM.com "engaged [its] independent external auditor, Deloitte Accountants B.V., to provide limited assurance on our sustainability statements" (p.62), and "the Annual Report of which these sustainability statements form an integrated part is published after approval by the Audit Committee" (p.62). The Management Board "has delegated this responsibility to the CFO" (p.61), who reports periodically to the Audit Committee and Supervisory Board.
GOV-4(was GOV-5)Risk management and internal controls over sustainability reportingReported
Reference: pages 61, 27-28.
CM.com "applies the principles of the three-lines model": the business (first line), Risk and Compliance (second line) and Internal Audit (third line) "operate independently while working in close collaboration" (p.27). DMA scores feed directly into "risk prioritization within the overarching ERM framework, as well as in developing mitigating strategies and controls" (p.61), and CM.com "leveraged our internal control framework for sustainability reporting related risks, relating to relevance, faithful representation, comparability, verifiability, and understandability of disclosed information, based on ESRS 1 (Appendix B)" (p.61).
In its In Control and Responsibility Statement, the Management Board states that "the risk management and control systems provide limited assurance that the 2025 sustainability reporting does not contain any material inaccuracies" (p.28) - a lower assurance level than the "reasonable assurance" the same statement gives for financial reporting. "The EFRAG IG 3 List of ESRS Data Points is used to verify and monitor that all disclosure requirements are addressed" (p.61).
SBM-1Strategy, business model and value chainReported
Reference: pages 63, 10, 1.
"Our business model focuses on creating value for our clients by integrating mobile technology into our Engagement Platform" (p.63). CM.com is "a global leader in AI-powered Customer Engagement solutions," combining a CPaaS messaging platform (SMS, WhatsApp Business, RCS, voice), a licensed Payment Service Provider stack, and a live-events/ticketing offering on "one complete platform" (p.1). It is listed on Euronext Amsterdam (CMCOM) and was founded in 1999.
The upstream value chain is defined as "tier 1 suppliers and contractors (including co-locations and data centers)"; downstream as "customers, consumers, and end-users" (p.60). A strategy-interaction table maps each material topic: "our strategy emphasizes leveraging renewable energy and optimizing energy consumption across our own operations and our clients," and "training and skills development are crucial for maintaining a competitive edge" in a changing market (p.63).
SBM-2Interests and views of stakeholdersReported
Reference: page 64.
CM.com engaged "in extensive dialogue with our internal stakeholders and reached out to external stakeholders via a survey, on which the response rate was limited" (p.64). In deep-dive sessions with key process owners, stakeholders were categorized as either "affected stakeholders" or "users of sustainability reporting," and CM.com assessed its influence on each group and vice versa to identify the relevant stakeholder groups it actively engages with.
Views and interests of affected stakeholders concerning sustainability-related impacts "are shared with the Management Board and Audit Committee as part of the regular updates" (p.64). Per the ESRS Content Index, "ESRS-2 45c is not applicable as our strategy and business model were not adjusted" (p.93) following this year's stakeholder engagement.
SBM-3Material impacts, risks and opportunities and their interaction with strategy and business modelReported
Reference: pages 64, 69, 80, 88-89, 92.
CM.com reassessed its 2024 DMA in 2025 through its CSRD working group, including a peer analysis of competitors' sustainability reports and emerging risks, and "management concludes that the 2024 materiality assessment remains valid as of December 31, 2025, except that Reliability of our Solutions is no longer considered a material topic in the DMA" (p.64). The six FY2025 material topics are: Climate change, Diversity & Inclusion, Employee engagement, Training and skills development, Privacy & Data security, and Business Ethics.
Material IROs are disclosed at the head of each topical section: one negative impact and one transitional (policy & legal) risk for Climate change (p.69); positive impacts, an opportunity and a negative-impact/risk pairing across Diversity & Inclusion, Employee engagement, Training and skills development and Privacy & Data security (p.80); and two positive impacts plus a negative-impact/risk pairing for Business Ethics (p.88-89). "Current financial effects for material risks and opportunities are deemed not material, we expect no adjustments on book values of assets or liabilities in the upcoming year" (Content Index, p.92); CM.com "applies the phase-in provision in accordance with Appendix C of ESRS 1" for this datapoint (SBM-3, paragraph 48e).
IRO-1Description of the processes to identify and assess material impacts, risks and opportunitiesReported
Reference: pages 64, 66-67, 27.
CM.com started "with the long list of sustainability matters covered in topical ESRS published by the EFRAG (ESRS 1 - AR 16)" and assessed each for potential material IROs across the value chain, using input from key process owners and "knowledge of the industry and engagement with our internal and external stakeholders," benchmarked via peer analysis (p.64).
Impact materiality is scored 1-4 (minor to severe) on scale, scope and irremediability (with likelihood added for potential impacts); financial materiality uses a 2% of Gross Profit threshold: "a risk or opportunity is assessed to be material if the expected financial impact exceeds 2% of the Gross profit realized over the previous reporting year" (p.67). Scores are "aligned with our enterprise risk framework (ERM)" (p.67) so IRO prioritization feeds into the same risk process described under Risk Management (p.27). Per the Content Index: "No external experts were introduced in this process" and there were "No changes compared to prior period" to the process itself (p.93).
IRO-2Disclosure requirements in ESRS covered by the undertaking's sustainability statementReported
Reference: pages 92-97.
IRO-2 is met by the ESRS Content Index itself (pages 92-96), a disclosure-requirement-by-disclosure-requirement table listing the report section and page where each General Disclosure and topical Disclosure Requirement is addressed, together with explanatory notes on non-applicable paragraphs and the phase-in provisions used. Per the index: "Our reporting meets the requirements of ESRS 1 section 3.2" (p.93).
A separate "List of data points that derive from other EU legislation" table (pages 96-97) cross-references GOV-1, GOV-4, E1-1, E1-4, E1-5, E1-6, S1-1, S1-3, S1-16, S4-1 and G1-1 to specific EU-legislation-derived datapoints (e.g. board gender diversity, percentage of independent board members, unadjusted gender pay gap, protection of whistleblowers).
E1 – Climate Change
E1-1Transition plan for climate change mitigationReported
Reference: pages 70-71, 93.
CM.com states plainly, via the ESRS Content Index, that it "has not yet adopted a transition plan and, therefore, actions are limited; no concrete timeline has been defined" (p.93). In place of a formal plan, the Climate Change section (p.70) sets out current policy (an overarching ESG Policy plus a 2025 Environmental Policy, pending Management Board approval at the signing date) and an ISO 14001-certified Environmental Management System adopted in 2024 "to effectively identify, manage, and mitigate environmental risks."
Actions already under way include renewable-electricity contracts at the headquarters and four other offices, the London office now "fully heated electrically, with no gas usage, and operates on renewable electricity," the Denmark office "now fully supplied with renewable energy," 66 rooftop solar panels installed in 2024, and no new fossil-fuel lease cars added in 2025 (p.70-71). Under Outlook, CM.com confirms it is "still in the process of further formalizing target setting for reducing GHG emissions, including proposed short-, medium-, and long-term targets" (p.71) - i.e. no milestone years or decarbonisation roadmap exist yet.
E1-2(was covered under ESRS 2 IRO-1)Identification of climate-related risks and scenario analysisReported
Reference: Back-filled from ESRS 2 SBM-3 / IRO-1, where this content is disclosed in the FY2025 report (pages 69-70). This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.
CM.com assessed physical and transition climate risk "using our established risk methodology and governance processes, supported by qualitative scenario analysis. At this stage, only qualitative information is disclosed; no estimated or anticipated financial effects of material physical or transition risks are reported" (p.70). For physical risk, a high-emission scenario was used: under it, "global temperatures could rise by approximately 4°C above pre-industrial levels by 2100," assessed with Copernicus and KNMI climate data over offices covering "90% of employees and significant co-locations, both with a lifespan of over 10 years" (p.69-70); heat, cold, flood and sea-level risks were "not deemed significant for CM.com up to 2050."
For transition risk, CM.com "considered the IPCC's RCP 1.9 scenario aiming to limit global warming below 1.5°C by 2050" (p.70), identifying a medium/long-term policy-and-legal transition risk tied to tightening CO2 regulation and shifting customer preferences. This analysis was carried out alongside the company's 2024 business resilience analysis and was not updated or re-run in 2025; no global-average-temperature rationale beyond the headline figures is given, which is itself a gap worth noting.
E1-3(was covered under ESRS 2 SBM-3)Resilience in relation to climate changeReported
Reference: Back-filled from ESRS 2 SBM-3, where this content is disclosed in the FY2025 report (page 70). This disclosure requirement did not exist under the 2023 ESRS the report was prepared against.
"As no significant changes occurred in our business model, risk profile, or external context during the reporting year, it was not necessary to repeat the resilience analysis in 2025" (p.70) - consistent with ESRS 1 AR 9, which does not require an annual refresh, so this is not treated as a gap. The 2024 resilience analysis "evaluated the company's ability to adapt to regulatory developments, market fluctuations, and emerging threats while maintaining customer trust and operational efficiency," considered TCFD recommendations, and covered "own operations and data center co-locations" (p.70).
No quantified capacity-to-adjust metrics (financial flexibility, ability to redeploy or decommission assets) are disclosed; the qualitative conclusion is that CM.com's physical-asset exposure is limited because it "operates with relatively low investment in physical assets" - headquarters, rented offices and data-centre co-locations (p.69-70).
E1-4(was E1-2)Policies related to climate change mitigation and adaptationReported
Reference: page 70.
CM.com "has implemented an overarching Environmental, Social, and Governance (ESG) Policy that addresses sustainability in a broad sense," and in 2025 "an additional Environmental Policy was initiated to specifically address climate change," noted as "pending Management Board approval as per the signing date of the sustainability statements" (p.70). Since 2024, CM.com has operated an ISO 14001-certified Environmental Management System (EMS) "to effectively identify, manage, and mitigate environmental risks."
An ESG Manager, reporting to the CFO, works with topic owners across "housing, fleet, travel, IT, procurement, and talent," and sustainability is a recurring item on Management Board, Supervisory Board and Audit Committee agendas (p.70). Per the Content Index: "ESRS-E1 14,16abcdhij: CM.com has not yet adopted a transition plan, and no concrete timeline has been defined" (p.93) - so the policy does not yet extend to transition-plan-level commitments, and "ESRS-E1 16e: At this stage, there are no concrete plans in place to increase alignment with the EU Taxonomy on climate change mitigation."
E1-5(was E1-3)Actions and resources in relation to climate change policiesReported
Reference: pages 70-71, 93.
Per the ESRS Content Index: "CM.com has not yet adopted a transition plan and, therefore, actions are limited; no concrete timeline has been defined" (p.93). The actions the company does report: renewable electricity at its headquarters and four other offices, 66 rooftop solar panels installed in 2024, the London office now "fully heated electrically, with no gas usage, and operates on renewable electricity," the Denmark office "now fully supplied with renewable energy," no new fossil-fuel lease cars added in 2025 (existing leases only renewed), and priority given to energy-efficient equipment whenever assets are replaced (p.70-71).
CM.com frames its AI workloads as emissions-favourable: it "does not perform large-scale pretraining of AI models," instead finetuning "Open Weights models" and using closed-source models on "state-of-the-art hardware (GPUs) selected for their energy efficiency," and its major cloud providers "operate on renewable electricity" (p.71).
E1-6(was E1-4)Targets related to climate change mitigation and adaptationReported
Reference: pages 70-71, 93.
CM.com's ESRS Content Index states plainly: "CM.com has not yet adopted a transition plan and, therefore, not yet adopted targets; no concrete timeline has been defined" (p.93), and that milestone/target years "are not yet set because transition plan is not adopted, therefore this part of the table is not disclosed" (ESRS-E1 AR48 note, p.93).
Under Outlook, CM.com confirms: "We are still in the process of further formalizing target setting for reducing GHG emissions, including proposed short-, medium-, and long-term targets" (p.71). No base year, percentage-reduction target or net-zero date is disclosed for Scope 1, 2 or 3 emissions for FY2025; the absence of an adopted target is itself the company's FY2025 position, reported rather than silently omitted.
E1-7(was E1-5)Energy consumption and mixReported
Reference: pages 71-72, 93.
Total energy consumption fell to 2,565 MWh in 2025 from 2,641 MWh in 2024 and 2,974 MWh in 2023 (a 14% three-year decline), which CM.com attributes to "the overall lower energy usage of our offices and fewer leased cars" (p.72). Renewable energy's share of consumption rose to 76% in 2025 (70% in 2024, 63% in 2023); fossil energy fell to 21% (28% in 2024, 35% in 2023) and nuclear-sourced energy stood at 3%.
Per the Content Index: "ESRS-E1 38, 40-43: Not applicable as we don't have activities in high climate impact sectors, based upon the designated NACE code from CM.com (J) and the NACE codes being classified as high climate impact sectors (A until H, plus L)" (p.93), and "ESRS-E1 39: No non-renewable energy generation, therefor not disclosed." CM.com "only considers these energy consumptions as deriving from renewable sources if the origin of the purchased energy is clearly defined in the contractual arrangements with its suppliers," per ESRS E1-5 AR32(j) (p.72).
E1-8(was E1-6)Gross Scopes 1, 2, 3 and Total GHG emissionsReported
Reference: pages 72-73, 60, 93.
Gross Scope 1 emissions were 78 tCO2e in 2025 (76 in 2024, 127 in 2023); gross Scope 2 emissions were 588 tCO2e location-based and 193 tCO2e market-based (662/212 in 2024). Total GHG emissions were 666 tCO2e location-based and 271 tCO2e market-based, down 22% and 27% respectively versus the 2023 base year (p.72-73). GHG intensity was 2.57 tCO2e per €m revenue (location-based) and 1.04 (market-based) (p.73).
CM.com explicitly "made use of" the ESRS 1 Appendix C phase-in for "E1-6 Disclosure requirement 51, 53 and 55 (gross Scope 3 GHG emissions, and GHG emissions intensity)" (p.60), so Scope 3 is not disclosed for FY2025; the report attributes this to anticipation of "potential changes in EU sustainability reporting requirements under the Omnibus package" (p.70). Per the index, "CM.com does not have any scope 1 emissions from regulated emission trading schemes" and "Scope 2 emissions include bought electricity (for offices and fleet) and heat... only... emissions that are the result of our own procurement" (p.93).
S1 – Own Workforce
S1-1Policies related to own workforceReported
Reference: pages 81, 93.
CM.com's workforce policies are formalized through "The Principles for Integrity and Responsibility (Code of Conduct), Employee Handbook, Working Conditions Policy for Dutch employees, and the Diversity and Inclusion Policy," which "clearly state that CM.com does not tolerate bullying, discrimination, or harassment," with accountability resting with the Head of HR (p.81-82). A Training Policy covers "all employees of CM.com, including contractors and agency workers" (p.85).
Per the ESRS Content Index: "ESRS-S1 20, 21 and 22: CM.com has no Human Rights policy. We don't see a material risk for incompliance based on CM.com's business activities in the Netherlands and foreign sales offices... Our whistleblower procedure is based on the UN Guiding Principles on Business and Human Rights" (p.93). "ESRS-S1 23: CM.com has no specific workplace accidents policy," and "ESRS-S1 24c: CM.com has not identified groups particularly vulnerable in own workforce" (p.93).
S1-2Processes for engaging with own workforce and workers' representatives about impactsReported
Reference: pages 84-85.
CM.com maintains "a robust communication framework that includes quarterly town hall meetings and regular CEO and CFO updates where employees have the opportunity to send in questions beforehand or ask them live" (p.84-85), plus a global employee engagement survey run annually and, since 2024, quarterly with topic-specific questions (p.84).
In the Netherlands, "Management Board members bi-monthly engage with the Works Council representing the interests of the Dutch CM.com employees, discussing, for example, topics like Diversity & Inclusion and outcomes of the employee survey" (p.85); CM.com "has no Works Councils outside the Netherlands." Per the Content Index: "ESRS-S1 27d and 27e, 28 and 29: Not applicable to CM.com" (p.93).
S1-2(was S1-3)Processes to remediate negative impacts and channels for own workforce to raise concernsReported
Reference: pages 85, 87, 90.
"Multiple reporting channels are offered, both internally and externally, through confidential advisers. Individuals are encouraged to first discuss matters directly with the individual(s) involved or escalate to a direct lead, HR business partner, or the Head of Risk & Compliance" (p.85). The "Speak-Up Policy (Whistle-blower Policy)... goes beyond things like bullying and harassment and includes, for example, criminal offenses or violation of the law, human rights violations, bribery and corruption, and threats to the environment" (p.85), with all reports channelled to the Speak-Up Committee (cross-referenced to Business Ethics, p.90).
The Working Conditions Policy "is very clear on our zero tolerance for bullying, harassment, and/or discrimination on any ground" and "includes clear steps that can be taken as well as possible consequences and disciplinary actions" (p.85).
S1-3(was S1-4)Taking action on material impacts on own workforceReported
Reference: pages 82, 84-85, 87.
Actions taken in 2025 span CM.com's four material S1 sub-topics. Diversity & Inclusion: a Diversity & Inclusion Task Force "composed of employees from all over the world," Leadership Training on microaggressions and bias, and gender-diversity consideration during the 2025 CFO search (p.82). Employee engagement: vitality workshops, a multidisciplinary "care team," and social and community-building events (p.84). Training and skills development: the new 2025 "CM.com Leadership Program," CM Academy/Udemy/LinkedIn Learning access, and AI-skills workshops (p.85). Privacy: mandatory annual training via CM Academy with tracked completion rates (p.87).
Effectiveness is tracked via the annual employee engagement survey ("CM.com scored 74" against an 80 target, p.84), performance-review participation (92% in 2025, p.85), and training-completion monitoring (p.87).
S1-4(was S1-5)Targets related to own workforceReported
Reference: pages 61, 82, 84, 87.
CM.com sets quantified targets across its material workforce topics. Diversity: "at least 33% of our Supervisory Board and 30% of our Senior Management are women," and "at least 30% female representation in our Management Board by 2032" (p.82); the LTIP 2025-2027 carries a matching 33% women-in-leadership target (p.61). Employee engagement: "we aimed for an employee engagement score of 80 over 2025 (on target score for LTIP 2023-2025). During 2025, CM.com scored 74 (2024: 73). The on target score for LTIP 2025-2027 is set on 75 over 2027" (p.84). Training: a participation target of "95% of our employees... participate in at least one learning or development activity annually" (p.85). Privacy: "Starting in 2025, we aim for a 95% completion rate for mandatory security and compliance training" (p.87).
Per the Content Index, "the process of target setting is described under Governance... CM.com's own workforce and the worker's representatives are not directly engaged in this process" (ESRS S1-47, p.93).
S1-5(was S1-6)Characteristics of the undertaking's employeesReported
Reference: page 81.
"As of December 31, 2025, CM.com employed 646 own employees (705 in 2024)" (p.81). Headcount by region, gender and contract type is given for the Netherlands (476 employees, 74% of headcount) and the rest of the world (170 employees); 86% of Dutch employees and 80% of rest-of-world employees hold permanent contracts. Employee turnover was 22% in both 2025 and 2024. Age distribution: 26% under 30, 65% aged 30-50, 8% over 50 (p.81-82).
"Apart from the Netherlands, there are no other countries where CM.com has more than 50 employees or represents at least 10% of its total number of employees" (p.81). Per the Content Index: "ESRS-S1 50e: Where applicable, contextual information is provided" (p.93).
S1-6(was S1-7)Characteristics of non-employee workersReported
Reference: page 81.
"As of December 31, 2025, CM.com... engaged 29 self-employed contractors (31 in 2024) as well as 1 agency worker (7 in 2024). Of the contractors, 8 were independent specialists contributing their knowledge and experience in our R&D and General departments (12 in 2024), while 21 were operational staff members supporting live events for our clients in the Netherlands (19 in 2024)" (p.81).
Per the Content Index: "ESRS-S1 55c: Where applicable, contextual information is provided" (p.93). No further breakdown of non-employee workers by region or gender is given.
S1-8(was S1-9)Diversity metricsReported
Reference: pages 82-83.
Gender distribution is disclosed at three leadership levels. Supervisory Board: 2 women (33%), 4 men (67%) in both 2025 and 2024. Management Board: 100% male in 2025 (3 members), versus 100% male in 2024 (2 members). Senior Management: 36% female in 2025 (12 of 33), versus 36% in 2024 (13 of 36) (p.82-83).
CM.com's Diversity & Inclusion Policy "outlines the company's commitment to diversity within the Management Board, Executive Committee, Senior Management, and the Supervisory Board, in line with the Dutch Corporate Governance Code," targeting "at least 33% of our Supervisory Board and 30% of our Senior Management" being women and "at least 30% female representation in our Management Board by 2032" (p.82).
S1-12(was S1-13)Training and skills development metricsReported
Reference: pages 85-86, 60.
CM.com runs an internal Training Policy covering "all employees of CM.com, including contractors and agency workers" (p.85), delivered through CM Academy, Udemy, LinkedIn Learning, the Young Professional program, the CMBA high-potential program, and (new in 2025) the CM.com Leadership Program for team leads (p.85). "Employees who participated in regular performance reviews and/or career dialogue" rose to 92% in 2025 (87% in 2024), with 90% participation for women and 93% for men (p.86).
CM.com partially phases in this disclosure: "In accordance with ESRS S1-13, training and skills development metrics require entities also to disclose the average number of training hours per employee, by gender. At this stage, we do not yet have detailed and robust information at this level and apply for the transition relief" (p.86), confirmed as a declared phase-in on page 60 ("S1-13 Disclosure requirement 81-85... the average number of training hours per employee, by gender").
S1-14(was S1-15)Work-life balance metricsReported
Reference: pages 84, 60.
"The percentage of Dutch employees that took family-related leave" is reported: 9% in 2025 (10% in 2024), split 8% of female and 9% of male Dutch employees in 2025 (p.84). "Everyone employed by CM.com entities in the Netherlands is entitled to take family-related leave, regardless of gender"; beyond statutory maternity leave, "Dutch law allows secondary caregivers to take five weeks of additional birth leave at 70% of the daily wage, covered by the Dutch employee insurance agency UWV. CM.com supplements this payment to 100% of the maximum daily wage" (p.84).
The disclosure is partially phased in for employees outside the Netherlands: "At this stage, we do not yet have detailed information at this level for employees who are employed outside the Netherlands and apply for the transition relief" (p.84), confirmed on page 60 ("S1-15 Disclosure requirement 93 (work-life balance, for non-NL employees)").
S1-15(was S1-16)Compensation metrics (pay gap and total compensation)Reported
Reference: page 83.
"Unadjusted gender-pay gap" was 25% in 2025 (26% in 2024); the "Total remuneration ratio" was 12.1 in 2025 (13.3 in 2024) (p.83). CM.com explains the pay-gap driver: "the pay gap is mainly caused by an underrepresentation of women in higher job grades... and significant differences in international salaries, making aggregated comparisons less representative for gender pay gaps based on same-level roles" (p.83).
Salary data is "largely retrieved from our payroll service provider's system," covering gross salaries, cash benefits and the value of long-term incentive bonuses granted in the year, extrapolated to full-time equivalents (p.83). Per the EU-legislation datapoint table, this disclosure also satisfies the "Unadjusted gender pay gap" and "Excessive CEO pay ratio" datapoints required by other EU legislation (p.96).
S4 – Consumers and End-users
S4-1Policies related to consumers and end-usersReported
Reference: pages 86-87, 93.
"In this section, we will address the (potential) impacts and risks related to the material topic of Privacy & Data Security... covered in topical ESRS S4 under the subtopic 'Information-related impacts for consumers and/or end-users,' specifically 'Privacy'" (p.86). CM.com's Privacy Program is "guided by our Privacy Policy and overseen by the Data Privacy Governance Board ('DPGB'), a multi-disciplinary team comprising members of the Legal, HR, Security, Revenue Operations, and Risk & Compliance departments," taking "a risk-based approach to data protection, ensuring compliance with... GDPR and other applicable regional privacy laws" (p.87).
CM.com's Risk & Control framework is aligned with "ISO 27001, ISO 27017, and ISO 27018," extended in 2025 with "ISO 27701 (Privacy Information Management System) and ISO 42001 (AI Management System)" (p.87). Per the Content Index: "ESRS-S4 15: In the context of protecting Privacy and PII data, no distinction is made between different groups of consumers and end-users" and "ERSRS-S4 16,17: CM.com has no human rights policy commitments relevant to consumers and/or end-users other than our whistleblower procedure" (p.93).
S4-2Processes for engaging with consumers and end-users about impactsReported
Reference: pages 86-87, 94.
Per the ESRS Content Index, CM.com states directly that "there are no general processes for engaging with consumers and end-users and their representatives about actual and potential impacts on them, as this is covered by legislation" (p.94). This nil position sits alongside CM.com's description of privacy-by-design development: "Privacy is a key focus in the development of all CM.com software and applications... Following the principle of 'privacy by design,' CM.com performs Privacy Impact Assessments (PIAs) for new projects or initiatives to identify and mitigate privacy risks early" (p.87).
No survey or consultation process specifically engaging consumers/end-users on privacy impacts is described; regulatory compliance (GDPR and related legislation) is treated as the substitute channel through which their interests are protected.
S4-2(was S4-3)Processes to remediate negative impacts and channels for consumers and end-users to raise concernsReported
Reference: pages 87, 90, 94.
"To promote transparency and accountability, we encourage stakeholders to report concerns or violations related to CM.com or its representatives, via our Speak-Up tool. Our publicly available Speak-Up Policy ensures concerns are addressed and whistle-blowers are protected. For more information, reference is made to the Business Ethics section" (p.87), which describes the Speak-Up Committee that "operates independently from management to ensure objectivity and thorough investigations" and reports quarterly to the Management Board (p.90).
Results for 2025: "no data breaches required notification to the Dutch Data Protection Authority under GDPR, and no complaints were received from the Dutch Data Protection Authority. There were no data breaches in other countries either" (p.87).
S4-3(was S4-4)Taking action on material impacts on consumers and end-users, and approaches to managing material risks and pursuing material opportunities related to consumers and end-users, and effectiveness of those actionsReported
Reference: pages 87-88.
Actions in 2025 include mandatory privacy and security training via CM Academy (87% completion for basic privacy training, 65% for advanced data-process-owner training, against a 95% completion target), a new internal "Privacy Knowledge Page," and full migration of the data processing register "to a new environment, enabling CM.com... to automate updates, review the accuracy and relevance of data processes, and actively monitor and report on the progress" (p.87-88), including incorporation of AI-related requirements ahead of the EU AI Act.
Per the Content Index: "ESRS-S4 31b,32c: Specific actions to provide or enable remedy to an actual material impact are only considered necessary in case of incidents, as described clients are informed immediately," "ESRS-S4 34: CM.com is not aware of contributing to material negative impacts on consumers and/or end-users through own practices," and "ESRS-S4 35: No severe human rights issues or incidents connected to consumers and/or end-users have been reported" (p.94).
S4-4(was S4-5)Targets related to managing material negative impacts, advancing positive impacts, and managing material risks and opportunitiesReported
Reference: page 87.
CM.com's privacy targets are expressed as training-completion rates rather than breach or risk-reduction targets: "Starting in 2025, we aim for a 95% completion rate for mandatory security and compliance training within set timeframes. For new employees, these trainings are part of the onboarding process. Privacy awareness training participation was 87%... Advanced training for data process owners was introduced in November 2025, with participation actively monitored by the DPGB. Participation measured at year-end was 65%" (p.87).
"Besides training participation, no other targets are adopted to manage private and data security-related material negative impacts and risks, as these are covered by our Risk & Control framework as described" (p.87).
G1 – Business Conduct
G1-1Business conduct policies and corporate cultureReported
Reference: pages 89-91.
"Our Code of Conduct, which is accessible on our website and intranet, serves as a cornerstone for our ethical framework. It outlines clear principles for all employees, contractors, and partners to act with integrity... encompass[ing] a wide range of policies, including anti-corruption and bribery, anti-harassment, gifts and hospitality, insider trading, security, and privacy" (p.89-90). The Management Board "oversees business conduct and ensures compliance with the Code of Conduct, which is aligned with the Dutch Corporate Governance Code" (p.90). CM.com built an AI agent, "Norma," on its HALO product so employees can search the Policy House for applicable policies (p.90).
Per the Content Index: "ESRS-G1-1-10b: alignment with UN Convention is not yet tested," "ESRS-G1-1-10d: not applicable considering we do have Speak Up policies," "ESRS-G1-1-10f: animal welfare is not a relevant topic for CM.com," and "ESRS-G1-1-10h: We believe all employees are at a certain degree of risk and therefore have a training programme that is cross-functional" (p.94).
G1-2(was G1-3)Prevention and detection of corruption and briberyReported
Reference: page 90.
CM.com's "Anti-Fraud and Corruption Policy emphasize[s] the importance of cultivating an ethical business environment that prioritizes safety and integrity. Employees are expected to act ethically and report any suspicions of fraud or bribery through our dedicated Speak-Up channels... any gift exceeding €250 requires prior approval to ensure it does not compromise CM.com reputation or interests" (p.90). As a licensed Payment Service Provider, CM.com "actively monitors and prevents illegal activities through Know Your Customer (KYC) and customer due diligence procedures... refusing to engage with those on national or international sanction lists," and in 2025 "started to expand the KYC procedures to other service offerings" (p.90).
Per the Content Index: "ESRS-G1-3-21b: We believe all employees are at a certain degree of risk and therefore have a training programme that is cross-functional" (p.94).
G1-3(part of MDR-T/GDR-T disclosures)Targets related to business conductReported
Reference: page 91.
CM.com tracks effectiveness of its business-conduct policies through training-completion targets rather than a numeric corruption-reduction target: "Since the start of 2025, we actively monitor training completion aiming at 95% completion rate for mandatory security and compliance training within designated timeframes. The Code of Conduct training reached 90% participation. This is an increase in comparison to previous years but can be increased still" (p.91). Follow-up actions are named to close the gap: "actively involving BU management teams and HR business partners," though "including participation of mandatory trainings in the yearly employee performance reviews, as part of the cultural fit axis, is postponed to 2026" (p.91).
CM.com also validates perceived safety via survey: employees scored the statement that "CM.com will take appropriate action when an employee experiences misconduct" at "8.0 (out of 10)" (p.91).
G1-4Incidents of corruption or briberyReported
Reference: pages 90-91.
"During 2025, no incidents of bribery or corruption have been reported, nor have there been any convictions or fines for violating anti-corruption and anti-bribery laws" (p.90). Separately, under the Speak-Up Policy: "In 2025, 2 cases of possible misconduct have been reported and processed in line with the Speak Up policy. The investigation by the Speak-Up committee showed that the 2 cases were one-off deviations from the desired ethical behavior. Follow-up actions to create more awareness about desired behavior have been taken, as well as improvement in operational procedures preventing more likewise cases to happen" (p.90-91).
Per the Content Index: "ESRS-2 5b: Not specifically disclosed. See general sections in Roles and responsibilities section and in Report of the Supervisory Board" (p.94).