California passed two climate disclosure laws in the same legislative package, and it is common to see them referenced interchangeably. They are not interchangeable. SB 253 and SB 261 ask companies to produce fundamentally different documents, built on different logics, and a compliance program built for one will not satisfy the other.
Two different questions
SB 253, the Climate Corporate Data Accountability Act, asks a measurement question: how much greenhouse gas did your company and its value chain emit. It requires disclosure across Scope 1, Scope 2, and Scope 3, following the GHG Protocol's category structure — the fifteen categories spanning purchased goods, capital goods, transportation, business travel, use of sold products, and the rest. The deliverable is an emissions inventory, and over time that inventory has to be verified by an independent third party rather than simply self-reported.
SB 261, the Climate-Related Financial Risk Act, asks a different question: what climate-related risks does your company face, and how are you managing them. This is a risk narrative, not an emissions count. It follows the structure popularized by the Task Force on Climate-related Financial Disclosures — governance, strategy, risk management, and metrics — applied to physical risks (supply chain disruption, resource scarcity, extreme weather exposure) and transition risks (policy shifts, changing customer demand, stranded assets). A company can, in principle, satisfy SB 261 without ever calculating a Scope 3 footprint, because the law is about disclosing exposure and response, not about quantifying tonnes of CO2e.
This distinction matters operationally. Teams that treat SB 261 as "SB 253 lite" tend to under-invest in the risk assessment and governance narrative, while teams that treat SB 253 as a narrative exercise tend to under-invest in the actual measurement infrastructure — supplier data collection, activity-data mapping, category-by-category calculation — that regulators and assurance providers will expect to see.
Who has to comply
Both laws share a jurisdictional logic that surprises companies outside California: they apply based on doing business in California, not on where the company is headquartered. A company incorporated and run entirely outside the state can still fall in scope if it meets the size threshold and has sufficient business activity in California. This mirrors a pattern seen elsewhere in climate disclosure regulation — the EU's CSRD, for instance, can reach non-EU companies through a large enough EU subsidiary presence. Regulators are increasingly using market access, not corporate domicile, as the hook for disclosure obligations.
Both laws are also size-based, applying to large companies rather than the full population of California-connected businesses, though the two laws use different revenue thresholds to define "large" — a detail worth confirming directly against current statutory text and any implementing guidance, since threshold figures and effective dates have been subject to legislative and regulatory adjustment.
Why the assurance requirement changes the calculus for SB 253
SB 253's phased move toward third-party assurance is the detail that should reshape how companies build their Scope 3 programs. Under the GHG Protocol's data quality hierarchy — spend-based data at the weak end, then average-data, then hybrid approaches, then supplier-specific primary data at the strong end — a spend-based estimate for purchased goods and services is defensible as a starting inventory but becomes a liability under assurance scrutiny. Auditors verifying a Scope 3 disclosure will look for a credible methodology and a trajectory toward primary data in the categories that matter most to the business, not a single static estimate frozen at the spend-based level. Companies preparing for SB 253 should treat the assurance requirement as the design constraint from day one, not a problem to solve once reporting deadlines are close.
Practical sequencing
For companies that fall under both laws, the sensible order of operations is to build the emissions inventory first, because the SB 253 measurement work — mapping categories, engaging suppliers, establishing calculation methodology — generates much of the factual basis that SB 261's risk narrative needs to be credible. A climate risk disclosure that says supply chain disruption is a material risk carries more weight when it is backed by an actual Scope 3 breakdown showing where emissions, and by extension exposure, are concentrated. Building the two disclosures in isolation usually means redoing work, or worse, producing a risk narrative that doesn't match what the emissions data actually shows.
Companies should also expect these two laws to interact with obligations elsewhere — a company already assembling a CSRD-grade Scope 3 inventory for European reporting, or preparing BRSR Core disclosures in India, is not starting from zero on SB 253's data requirements, even though the reporting formats differ. The underlying measurement work, done properly once, tends to be reusable across regimes. The narrative and assurance wrapper around it is what changes jurisdiction by jurisdiction.
Companies working through which of these obligations apply to their specific structure, and how to sequence measurement against reporting deadlines, can reach us at carbon@digi.ai.in.