Product carbon footprint (PCF) software calculates the cradle-to-gate or cradle-to-grave emissions of a single product, expressed as kg CO2e per unit. The good ones do it against a recognized method (ISO 14067, the GHG Protocol Product Standard, or a PEF category rule), pull activity data from your systems, apply emission factors, and give you a number per SKU.
That much is now table stakes. Most tools in the category will produce a number.
The harder question, and the one that separates a reporting tool from a compliance tool, is whether the number survives contact with a third-party assurer. "Audit-ready" gets printed on nearly every PCF product page. It usually means far less than it sounds. This article explains what the term should mean, what assurers actually look for, and how to tell the difference before you buy.
A dashboard number and a defensible number are not the same thing
Here is the distinction that matters. A dashboard tells you a SKU is 8.4 kg CO2e. A defensible number lets you show, on demand, exactly how you got to 8.4: which activity data went in, which emission factor was applied, which methodology version was in force, and which source document each input came from.
The first is an output. The second is an output plus its provenance. Under assurance, only the second is worth anything, because the assurer's entire job is to test whether the number is supported by evidence. If you can produce the figure but not the trail behind it, you have a finding waiting to happen.
This is not a theoretical concern. As limited assurance becomes mandatory under the EU's CSRD and similar regimes tighten globally, the cost of an unsupported number moves from awkward to qualified opinion. Software that optimizes for a clean-looking dashboard and skips the evidence layer is solving the wrong problem.
What a third-party assurer actually checks
Assurance is not a spot-check of your headline figure. An assurer works backward from the disclosed number toward its sources, sampling as they go. In practice they test for a recognizable set of things.
Traceability of inputs. For a sampled SKU, can you show the raw activity data, meaning kilograms of material, kilowatt-hours of energy, tonne-kilometers of freight, and where each figure came from? A bill of materials, a utility invoice, a carrier EDI record, a supplier-provided PCF. "We estimated it" is an acceptable answer only if the estimation method is documented and the secondary data is disclosed as secondary.
Primary versus secondary data split. This is now an explicit disclosure expectation. Assurers want to see which inputs came directly from value-chain partners (supplier PCFs, EPDs, metered data) and which are industry averages or proxies. Software that blends the two without flagging the difference makes this disclosure impossible to produce accurately.
Emission factor sourcing and versioning. Which factor database, which version, which vintage year? Factors change. If you recalculated last quarter's number with this quarter's factor set, the assurer needs to see that, not a silently updated figure.
Methodology consistency. Was the same boundary and allocation method applied across comparable SKUs and across reporting periods? Inconsistent boundaries are one of the most common sources of findings.
Reproducibility. The quiet killer. Can you reproduce a number you published twelve months ago, using the data and factors that were in force then? If your tool overwrites prior states, you cannot. The number stops being defensible the moment its inputs change underneath it.
Notice that none of these test whether your number is low. They test whether it is supported. That reframing is the whole game.
The four properties that make PCF software genuinely audit-ready
Strip away the marketing and "audit-ready" reduces to four concrete capabilities. Use them as a checklist when you evaluate any tool, including ours.
1. Every number is bound to its source documents
Each input should link to the actual artifact behind it: the manifest, purchase order, supplier PCF, utility bill, or certificate, ideally hashed so you can prove the document hasn't changed since it was used. A number floating free of its evidence is an assertion, not a measurement.
2. The calculation lineage is replayable
You should be able to walk any result backward, from activity data to emission factor to methodology to result, with each step recorded. If someone challenges a figure in next year's assurance cycle, you replay the lineage instead of reconstructing it from memory and spreadsheets.
3. Everything is versioned
Source documents, emission factors, methodology, and results all carry versions and timestamps. Recalculation creates a new version. It does not erase the old one. This is what lets you answer "what did you report in FY2025, and why" two years later.
4. Data quality is visible, not hidden
The primary and secondary split, confidence levels, and known gaps should be surfaced on the number itself, not buried in an appendix. Clear data-quality flags are an asset in assurance, not a liability. Assurers trust a tool that admits its proxies more than one that presents every number with false uniformity.
Where most PCF tools stop short
To be fair to the category, several established platforms, including Carbonfact, Vaayu, Plan A, Ecochain, and CarbonCloud, do real, methodologically sound calculation work, and some now market audit trails. The common gap is not the math. It is that the evidence layer is treated as an export feature rather than the foundation.
The tell is in how a tool handles change. Ask a vendor: "If I recalculate a SKU because a supplier sends a corrected PCF, can I still reproduce the original number exactly, with its original evidence, a year from now?" If the answer involves restoring a backup or digging through change logs, the audit-readiness is partial. The architecture has to treat the evidence chain as the system of record, not as a report you generate at the end.
A short worked example
Say an apparel brand reports 8.4 kg CO2e for a cotton T-shirt. Under assurance, the assurer samples that SKU and asks for support. An audit-ready setup answers in one pass:
- 0.22 kg cotton fabric, from the bill of materials (linked, hashed PO #4471).
- Emission factor for conventional cotton, ecoinvent v3.10, applied per ISO 14067 boundary.
- Dyeing energy from the supplier's metered data (primary; supplier PCF v2, received 2026-03), not an industry average.
- Inbound freight 0.9 tonne-km, from the carrier EDI record.
- Result computed under methodology v4, locked at time of reporting.
Every line points to a document. The 8.4 is not the claim. It is the conclusion of a chain the brand can show. That is the difference "audit-ready" should buy you.
How CarbonSKU approaches this
CarbonSKU is built around the evidence chain rather than the dashboard. Every number is bound to hashed, versioned source documents, calculation lineage is replayable step by step, and the primary and secondary data split is visible on each figure, so the system is designed to produce the support an assurer asks for rather than just the headline. The product tour walks through the evidence locker and the SKU ledger.
Bottom line
Choosing PCF software is no longer about who computes a number, because they all do. It is about who lets you defend the number a year later, under assurance, against an auditor working backward from the figure to its sources. Score every tool on the four properties above: evidence binding, replayable lineage, versioning, and visible data quality. If a tool can only show you the answer and not the chain behind it, it is reporting software wearing a compliance label.
If your brand falls under the EU's climate disclosure regime, the assurance stakes are concrete and dated. See our companion guide, CSRD and ESRS E1 for physical-product brands, for what the rules require and how to prepare an audit packet. For the audit itself, what assurers actually ask for goes item by item.