Forscope

How secondary software helps companies meet ESG goals and extend IT lifespan

Secondary software offers companies a sustainable alternative to vendor-driven upgrade cycles. By preventing premature hardware replacement and reducing supply-chain emissions (Scope 3 under CSRD), pre-owned licenses act as a practical circular IT solution that balances cost savings, security, and ESG goals.

The debate over the carbon footprint of digital technologies often focuses on electricity consumption in data centers. In reality, however, a seemingly routine decision about how a company approaches software procurement and the related hardware investments can also have a profound impact. At a time when businesses proudly declare their commitment to sustainability and corporate social responsibility through ESG initiatives, a well-thought-out IT strategy holds untapped potential to reduce carbon emissions and conserve material resources.

Increasingly sophisticated applications, operating systems, and cloud services raise demands on computing power, memory, storage, and network infrastructure. When functional computers or servers no longer meet these requirements simply due to a new software version, the cost of upgrading is not the only consequence. The company also accelerates hardware turnover, which carries a significant portion of IT's total environmental footprint.

This is precisely where three areas that were long addressed in isolation converge: ESG (Environmental, Social, and Governance a set of criteria used to assess a company's impact and sustainability), security, and software license management. Secondary software enters this discussion as a tool that gives companies more freedom to make rational upgrade decisions based on actual needs, rather than manufacturer-driven product or sales cycles.

IT has a carbon footprint beyond the wall socket

Digital technologies may seem intangible, but every application, database, cloud service, or mailbox runs on physical infrastructure – computers, servers, disk arrays, and data centers. Operating them consumes energy, but even before that, each device had to be manufactured. The processes involved raw material extraction, component manufacturing, and transportation generate what are known as embodied emissions.

This principle is reflected in the Software Carbon Intensity (SCI) methodology. SCI evaluates the carbon intensity of software as a combination of:

This is not merely an academic exercise. Standardized as ISO/IEC 21031:2024, the SCI methodology serves as a practical framework for organizations to measure and reduce the emissions of digital services.

Software can shorten hardware lifespan

A common phenomenon in the hardware-software relationship is psychological or software-induced obsolescence. This occurs when a device is retired not because it has physically stopped working, but because it can no longer support the demands of new software, loses manufacturer support, lacks security updates, or loses compatibility with newer services.

European ICT frameworks cover the full lifecycle of digital technologies, and expert studies confirm that software significantly influences energy consumption and the pace of hardware replacement. For example, a peer-reviewed study (Sustainable software products – Towards assessment criteria for resource and energy efficiency) demonstrates that the environmental impacts of software can be tracked through two interconnected streams:

  1. Energy consumption: The power drawn by the hardware while running the software.

  2. Hardware supply chain: The physical hardware that organizations must acquire, maintain, and eventually discard to run that software.

Software is therefore not just a digital layer sitting on top of hardware; to a large extent, it determines how long hardware remains usable and how quickly a company will replace it.

European policymakers share concerns over software-induced obsolescence. A study prepared for the European Commission as part of ecodesign preparations highlights software-related factors that shorten the lifespan of electronics. Key reasons include the termination of technical support, missing security updates, or the sunsetting of cloud services required to operate a product.

This does not mean that every new software version poses an environmental hazard; updates are often essential. The problem lies in the automatic habit of replacing hardware or licenses simply because a vendor's business or product cycle has changed, without evaluating actual operational needs or assessing the remaining lifespan of existing infrastructure.

ESG reporting: voluntary and mandatory

In recent years, European companies have increasingly embraced responsible and sustainable business practices, incorporating them into their ESG strategies. At the EU level, ESG reporting is framed by the Corporate Sustainability Reporting Directive (CSRD). CSRD requires designated companies (following regulatory adjustments, the scope primarily targets companies with over 1,000 employees and an annual net turnover exceeding €450 million) to report on the environmental and social impacts of their operations, sustainability risks and opportunities, and their management practices. Central to this is the principle of double materiality, where companies evaluate not only how climate and social issues affect their business, but also how their business affects society and the environment.

Even though ESG reporting remains voluntary for small and medium-sized enterprises (SMEs), pressure to deliver reliable carbon footprint and environmental management data affects them as well. Large enterprises reporting emissions across their supply chains require detailed data from their suppliers. Furthermore, similar information requests are increasingly coming from banks, investors, insurance companies, and public procurement authorities.

From an enterprise IT perspective, the ESRS E1 standard (focused on climate change) is particularly relevant, addressing Scope 1, Scope 2, and Scope 3 emissions:

Enterprise leaders are already measuring IT emissions

The debate around sustainable IT is expanding. Beyond renewable energy, data center cooling, and efficient servers, it increasingly touches on software its quality, system requirements, licensing models, vendor support, and its power to either extend or shorten hardware lifespans.

Both examples offer a takeaway for organizations of any size: you cannot manage what you do not measure. To take the first step, companies do not need to calculate the precise footprint of every component right away; simply auditing how many devices are deployed, how long they stay in service, which servers are active, how many licenses sit idle, and which IT purchases are strictly necessary provides a solid starting point.

Secondary software as part of circular IT

This is where secondary (used) software licenses play a role. While secondary software is not a universal solution for IT's environmental footprint, and purchasing a used license does not automatically reduce emissions by a fixed amount of CO₂, it forms a legitimate component of circular digital asset management.

By reusing existing perpetual licenses instead of letting them sit idle with original owners, secondary software enables organizations to:

For manufacturing firms, hospitals, schools, public institutions, and companies operating industrial technologies, compatibility with legacy software versions is often vital. Replacing an application frequently requires upgrading associated computers, servers, peripherals, and production machinery. Secondary perpetual licenses allow organizations to transition gradually, spreading upgrades over a timeline dictated by technical, economic, and security requirements rather than vendor schedules. Conversely, selling off unused perpetual licenses aligns with circular economy principles by returning digital assets to productive use.

Balancing longevity and security

Security remains an absolute requirement. Running outdated, unsupported software without vendor updates introduces severe cybersecurity and compliance risks. A sound IT strategy is neither about blindly extending the life of obsolete systems nor about automatically buying every new release. Instead, it relies on structured evaluations based on key criteria:

An evaluation may reveal that upgrading is the correct path because a new system significantly reduces energy consumption, enhances security, or improves resource utilization. However, that decision stems from data rather than the assumption that newer is automatically better.

Equally, the optimal path may involve leveraging secondary software to extract maximum value from existing digital assets, avoid unnecessary procurement, and pace infrastructure modernization sustainably. Its true value lies not in a broad "green" promise, but in giving organizations greater control to manage IT thoughtfully, aligning budget, security, legal obligations, and environmental impact.