ESG Regulations & Compliance

ESG Regulations & Compliance

CSDDD: what it is, what it requires and which companies it applies to

CSDDD: what it is, what it requires and which companies it applies to

Updated July 2026

Headshot Alessandro Nora
Alessandro Nora
CSDDD illustration showing global supply chain due diligence, human rights, environmental protection, corporate accountability and supplier monitoring.

CSDDD: what it is and what the European directive requires

The CSDDD is the European directive on corporate sustainability due diligence. Its objective is to integrate the management of environmental and social impacts into the decision-making processes of the largest companies.

Due diligence is an ongoing process through which a company assesses actual and potential adverse impacts connected with its own operations, its subsidiaries and the business relationships covered by its chain of activities. This assessment must be followed by measures proportionate to the severity and likelihood of the risks identified.

The Directive covers impacts relating to workers’ rights, health and safety, forced labour, child labour, pollution, biodiversity and the use of natural resources. The specific scope of the assessment depends on the company’s activities, sourcing markets and supply chain structure.

To understand what the CSDDD requires, it is useful to view it as a management system based on data, responsibilities and controls. Companies must be able to demonstrate how they identify material risks, which information they use, how they set priorities and which measures they implement. Having a corporate policy or supplier code of conduct does not, by itself, demonstrate that due diligence is being applied effectively.

Following the changes introduced by the Omnibus package, companies may focus their analysis on areas where adverse impacts are considered most likely and most severe, based on reasonably available information. This approach helps direct resources and controls towards suppliers, facilities, geographical areas or product categories with a higher risk profile.

The CSDDD differs from the Corporate Sustainability Reporting Directive, or CSRD. The CSRD primarily governs the disclosure of sustainability information, while the CSDDD regulates the process through which a company must identify and address specific impacts.

Information collected for sustainability reporting can support due diligence, but the two requirements serve different purposes. Reporting describes data, policies and results; the CSDDD also requires companies to document the decisions and actions taken to manage risks across their chain of activities.

CSDDD: entry into force, transposition and key deadlines

The original CSDDD entered into force on 25 July 2024, twenty days after its publication in the Official Journal of the European Union. This date marked the formal entry into force of the Directive, but did not trigger the immediate application of operational obligations for companies.

Timeline of the main CSDDD deadlines from 2024 to 2030, including entry into force, transposition, application, and communication requirements.

The official text of the CSDDD provides access to the original legislation and its subsequent amendments.

In 2025, the European Union approved an initial postponement of the deadlines through Directive (EU) 2025/794. In February 2026, Directive (EU) 2026/470 was adopted, substantially amending both the CSDDD and the CSRD. The revised due diligence provisions entered into force on 18 March 2026 and now represent the applicable European framework.

EU Member States must adopt and publish their national transposition measures by 26 July 2028. These national provisions must apply from 26 July 2029, while the communication requirements under Article 16 will apply to financial years beginning on or after 1 January 2030.

The European Commission provides an overview of the revised scope, deadlines and changes introduced through Omnibus I.

Each Member State will need to define the national rules required to implement the Directive, including the competent supervisory authorities, enforcement procedures and sanctions framework. Some application details may therefore vary across jurisdictions, although the core due diligence requirements will remain based on the common European framework.

Companies operating across several EU countries should monitor the transposition process in each relevant jurisdiction. Differences in supervisory structures, procedures and enforcement practices may affect how responsibilities are assigned and how compliance is documented at group level.

The period before 2029 can be used to assess data availability, update supplier qualification procedures and assign clear responsibilities to the functions involved. For groups with complex supply chains, waiting until all national measures have been finalised could leave limited time to implement a documented and consistent system across subsidiaries, business units and countries.

By July 2027, the European Commission is also expected to publish a significant part of the guidance supporting the application of the Directive. Further guidance is expected by July 2028. These documents may clarify operational aspects, including the use of contractual clauses, risk prioritisation and the involvement of companies within the chain of activities.

Which companies does the CSDDD apply to?

Following the 2026 amendments, the CSDDD applies directly to a narrower group of large companies.

For companies established in the European Union, the scope includes businesses with:

  • an average of more than 5,000 employees;

  • worldwide net turnover exceeding €1.5 billion.

Both requirements must be met. The thresholds introduced through Omnibus I are significantly higher than those included in the original version of the Directive.

Infographic explaining which companies fall under the CSDDD, including EU thresholds, non-EU criteria, and the role of SMEs and suppliers.

The Council of the European Union has summarised the changes to the CSDDD scope, including the revised thresholds and measures intended to reduce administrative burdens.

The CSDDD may also apply to companies established outside the European Union when their net turnover generated in the EU exceeds the relevant threshold. In these cases, the legislation uses turnover generated within the Union to determine whether the company has sufficient economic relevance in the European market.

For corporate groups, the scope assessment must take account of the rules governing parent companies and consolidated figures. It is therefore not sufficient to assess the number of employees or turnover of an individual operating company in isolation. The analysis should be conducted at group level, with input from legal, finance and sustainability teams.

Small and medium-sized enterprises generally fall outside the direct scope of the Directive. However, they may still be involved as suppliers or business partners of companies subject to the CSDDD. They may receive requests concerning working conditions, environmental management, material origins, control procedures or corrective actions.

Answering the question “Who does the CSDDD apply to?” therefore requires two checks: whether the company directly exceeds the applicable thresholds and whether it operates within the supply chain of clients that fall within the Directive’s scope.

The 2026 amendments seek to limit the indiscriminate transfer of requirements to smaller companies. This does not remove supply chain information requests, but it requires companies subject to the CSDDD to apply a proportionate, risk-based approach, avoiding extensive data collection where it is not justified by the nature of the business relationship or the potential impacts.

Suppliers should therefore assess how many of their clients fall within the scope, which information those clients already request and how much of their revenue depends on commercial relationships with large European groups.

In some sectors, CSDDD requirements may overlap with more specific rules on raw material traceability. One example is the EU Deforestation Regulation, or EUDR, which requires companies within its scope to collect detailed information on the origin of certain commodities and products.

What obligations does the CSDDD introduce for companies?

The first requirement is to integrate due diligence into corporate policies and management systems. Companies need to define responsibilities, assessment criteria, information sources and review procedures. The process should involve procurement, legal, sustainability, risk management and internal control teams, with consistent coordination across the group.

The company must then map its own operations, those of its subsidiaries and the relevant areas of its chain of activities. The objective is to identify where the most severe or likely impacts may occur. An effective mapping exercise combines internal data, supplier information, sector risk, geographical location, product characteristics and records of previous issues.

Under the Omnibus I amendments, the process may begin with a general assessment of the main risk areas. More detailed reviews should then focus on the segments presenting the greatest concerns. For a manufacturing company, for example, the analysis may reveal different risk levels across raw material suppliers, professional service providers and logistics operations.

When a potential adverse impact is identified, the company must take measures to prevent or mitigate it. If the impact has already occurred, the company must act to bring it to an end, minimise its extent and, where required, contribute to remediation. Actions may include changes to procurement processes, corrective action plans agreed with suppliers, training, additional controls or revised contractual terms.

Terminating a business relationship is not automatically the most appropriate solution. In some cases, it could worsen the impact on the people affected or transfer the problem to less closely monitored operators. The decision should therefore consider the severity of the impact, the company’s ability to influence the business partner and the results that could be achieved through an improvement plan.

The system must also include notification and complaints procedures. These channels can provide information that may not emerge through document reviews, particularly in long supply chains or activities located in high-risk areas.

The measures implemented must then be monitored. Companies should assess whether the actions have achieved the expected result, whether the risk level has changed and whether further intervention is required.

Information collected through due diligence can also contribute to the overall assessment of supplier ESG performance. ESG ratings can support risk classification, provided that they are based on verifiable data, transparent criteria and up-to-date information.

How to prepare for the CSDDD and supply chain due diligence

The first step is to determine the company’s position in relation to the legislation. The business should calculate the applicable thresholds, identify the group companies involved and assess indirect exposure through relationships with clients subject to the Directive.

The next step is to review the systems already in place. Many companies already use supplier qualification procedures, ESG questionnaires, codes of conduct, audits, notification channels and certified management systems. The initial assessment should establish which tools produce usable information, which areas remain uncovered and where data are difficult to verify.

ESG certifications and management systems can provide useful evidence, but they must be assessed in relation to the specific risk, the scope covered and the certification’s validity. A certification does not replace supply chain analysis, although it may reduce the need to request information that has already been independently verified.

Supply chain mapping should make it possible to associate each supplier with specific risk factors. These may include the country of operation, sector, purchasing value, importance of the supplied component, position within the supply chain and results of previous assessments. This segmentation prevents companies from applying the same level of control to suppliers with very different risk profiles.

The indicators selected should be verifiable and linked to a decision. The number of suppliers assessed, for example, provides limited insight unless it is considered alongside the percentage of high-risk suppliers, time required to close corrective actions and proportion of purchasing expenditure covered by the assessments.

The quality of supporting evidence should also be defined in advance. A self-declaration, certification, independent audit and document issued by a public authority provide different levels of assurance. Establishing a hierarchy of evidence helps companies assign consistent scores and request additional checks in the most material cases.

The process must also be capable of being updated. Suppliers, countries, purchasing volumes and operating conditions change over time. A static system can quickly become outdated. Companies should therefore define review frequencies, events that trigger a reassessment and responsibility for approving corrective measures.

CSDDD readiness can be measured through a limited number of concrete results: percentage of purchasing expenditure mapped, suppliers classified by risk level, average quality of evidence collected, open corrective actions and resolution times. These data allow management to assess whether due diligence is operating effectively and to document the decisions taken.

For companies managing a large number of third parties, supplier assessment software can support data collection, risk classification and corrective action monitoring. A centralised platform makes it possible to associate data and evidence with each supplier, update assessments over time and measure the effective coverage of the supply chain.

The Corporate Sustainability Due Diligence Directive, known as the CSDDD or CS3D, regulates corporate due diligence regarding adverse human rights and environmental impacts. It requires companies within its scope to establish a structured process to identify risks, prioritise action, implement corrective measures and monitor results across their chain of activities.

The Directive was adopted in 2024 and subsequently amended through the Omnibus I simplification package. These changes reduced the number of companies directly in scope, postponed key deadlines and revised several requirements. Companies assessing the impact of the CSDDD should therefore refer to the consolidated version in force since 18 March 2026.


Infographic showing the four-step CSDDD process: identifying impacts, setting priorities, taking action, and monitoring results.

CSDDD: what it is and what the European directive requires

The CSDDD is the European directive on corporate sustainability due diligence. Its objective is to integrate the management of environmental and social impacts into the decision-making processes of the largest companies.

Due diligence is an ongoing process through which a company assesses actual and potential adverse impacts connected with its own operations, its subsidiaries and the business relationships covered by its chain of activities. This assessment must be followed by measures proportionate to the severity and likelihood of the risks identified.

The Directive covers impacts relating to workers’ rights, health and safety, forced labour, child labour, pollution, biodiversity and the use of natural resources. The specific scope of the assessment depends on the company’s activities, sourcing markets and supply chain structure.

To understand what the CSDDD requires, it is useful to view it as a management system based on data, responsibilities and controls. Companies must be able to demonstrate how they identify material risks, which information they use, how they set priorities and which measures they implement. Having a corporate policy or supplier code of conduct does not, by itself, demonstrate that due diligence is being applied effectively.

Following the changes introduced by the Omnibus package, companies may focus their analysis on areas where adverse impacts are considered most likely and most severe, based on reasonably available information. This approach helps direct resources and controls towards suppliers, facilities, geographical areas or product categories with a higher risk profile.

The CSDDD differs from the Corporate Sustainability Reporting Directive, or CSRD. The CSRD primarily governs the disclosure of sustainability information, while the CSDDD regulates the process through which a company must identify and address specific impacts.

Information collected for sustainability reporting can support due diligence, but the two requirements serve different purposes. Reporting describes data, policies and results; the CSDDD also requires companies to document the decisions and actions taken to manage risks across their chain of activities.

CSDDD: entry into force, transposition and key deadlines

The original CSDDD entered into force on 25 July 2024, twenty days after its publication in the Official Journal of the European Union. This date marked the formal entry into force of the Directive, but did not trigger the immediate application of operational obligations for companies.

Timeline of the main CSDDD deadlines from 2024 to 2030, including entry into force, transposition, application, and communication requirements.

The official text of the CSDDD provides access to the original legislation and its subsequent amendments.

In 2025, the European Union approved an initial postponement of the deadlines through Directive (EU) 2025/794. In February 2026, Directive (EU) 2026/470 was adopted, substantially amending both the CSDDD and the CSRD. The revised due diligence provisions entered into force on 18 March 2026 and now represent the applicable European framework.

EU Member States must adopt and publish their national transposition measures by 26 July 2028. These national provisions must apply from 26 July 2029, while the communication requirements under Article 16 will apply to financial years beginning on or after 1 January 2030.

The European Commission provides an overview of the revised scope, deadlines and changes introduced through Omnibus I.

Each Member State will need to define the national rules required to implement the Directive, including the competent supervisory authorities, enforcement procedures and sanctions framework. Some application details may therefore vary across jurisdictions, although the core due diligence requirements will remain based on the common European framework.

Companies operating across several EU countries should monitor the transposition process in each relevant jurisdiction. Differences in supervisory structures, procedures and enforcement practices may affect how responsibilities are assigned and how compliance is documented at group level.

The period before 2029 can be used to assess data availability, update supplier qualification procedures and assign clear responsibilities to the functions involved. For groups with complex supply chains, waiting until all national measures have been finalised could leave limited time to implement a documented and consistent system across subsidiaries, business units and countries.

By July 2027, the European Commission is also expected to publish a significant part of the guidance supporting the application of the Directive. Further guidance is expected by July 2028. These documents may clarify operational aspects, including the use of contractual clauses, risk prioritisation and the involvement of companies within the chain of activities.

Which companies does the CSDDD apply to?

Following the 2026 amendments, the CSDDD applies directly to a narrower group of large companies.

For companies established in the European Union, the scope includes businesses with:

  • an average of more than 5,000 employees;

  • worldwide net turnover exceeding €1.5 billion.

Both requirements must be met. The thresholds introduced through Omnibus I are significantly higher than those included in the original version of the Directive.

Infographic explaining which companies fall under the CSDDD, including EU thresholds, non-EU criteria, and the role of SMEs and suppliers.

The Council of the European Union has summarised the changes to the CSDDD scope, including the revised thresholds and measures intended to reduce administrative burdens.

The CSDDD may also apply to companies established outside the European Union when their net turnover generated in the EU exceeds the relevant threshold. In these cases, the legislation uses turnover generated within the Union to determine whether the company has sufficient economic relevance in the European market.

For corporate groups, the scope assessment must take account of the rules governing parent companies and consolidated figures. It is therefore not sufficient to assess the number of employees or turnover of an individual operating company in isolation. The analysis should be conducted at group level, with input from legal, finance and sustainability teams.

Small and medium-sized enterprises generally fall outside the direct scope of the Directive. However, they may still be involved as suppliers or business partners of companies subject to the CSDDD. They may receive requests concerning working conditions, environmental management, material origins, control procedures or corrective actions.

Answering the question “Who does the CSDDD apply to?” therefore requires two checks: whether the company directly exceeds the applicable thresholds and whether it operates within the supply chain of clients that fall within the Directive’s scope.

The 2026 amendments seek to limit the indiscriminate transfer of requirements to smaller companies. This does not remove supply chain information requests, but it requires companies subject to the CSDDD to apply a proportionate, risk-based approach, avoiding extensive data collection where it is not justified by the nature of the business relationship or the potential impacts.

Suppliers should therefore assess how many of their clients fall within the scope, which information those clients already request and how much of their revenue depends on commercial relationships with large European groups.

In some sectors, CSDDD requirements may overlap with more specific rules on raw material traceability. One example is the EU Deforestation Regulation, or EUDR, which requires companies within its scope to collect detailed information on the origin of certain commodities and products.

What obligations does the CSDDD introduce for companies?

The first requirement is to integrate due diligence into corporate policies and management systems. Companies need to define responsibilities, assessment criteria, information sources and review procedures. The process should involve procurement, legal, sustainability, risk management and internal control teams, with consistent coordination across the group.

The company must then map its own operations, those of its subsidiaries and the relevant areas of its chain of activities. The objective is to identify where the most severe or likely impacts may occur. An effective mapping exercise combines internal data, supplier information, sector risk, geographical location, product characteristics and records of previous issues.

Under the Omnibus I amendments, the process may begin with a general assessment of the main risk areas. More detailed reviews should then focus on the segments presenting the greatest concerns. For a manufacturing company, for example, the analysis may reveal different risk levels across raw material suppliers, professional service providers and logistics operations.

When a potential adverse impact is identified, the company must take measures to prevent or mitigate it. If the impact has already occurred, the company must act to bring it to an end, minimise its extent and, where required, contribute to remediation. Actions may include changes to procurement processes, corrective action plans agreed with suppliers, training, additional controls or revised contractual terms.

Terminating a business relationship is not automatically the most appropriate solution. In some cases, it could worsen the impact on the people affected or transfer the problem to less closely monitored operators. The decision should therefore consider the severity of the impact, the company’s ability to influence the business partner and the results that could be achieved through an improvement plan.

The system must also include notification and complaints procedures. These channels can provide information that may not emerge through document reviews, particularly in long supply chains or activities located in high-risk areas.

The measures implemented must then be monitored. Companies should assess whether the actions have achieved the expected result, whether the risk level has changed and whether further intervention is required.

Information collected through due diligence can also contribute to the overall assessment of supplier ESG performance. ESG ratings can support risk classification, provided that they are based on verifiable data, transparent criteria and up-to-date information.

How to prepare for the CSDDD and supply chain due diligence

The first step is to determine the company’s position in relation to the legislation. The business should calculate the applicable thresholds, identify the group companies involved and assess indirect exposure through relationships with clients subject to the Directive.

The next step is to review the systems already in place. Many companies already use supplier qualification procedures, ESG questionnaires, codes of conduct, audits, notification channels and certified management systems. The initial assessment should establish which tools produce usable information, which areas remain uncovered and where data are difficult to verify.

ESG certifications and management systems can provide useful evidence, but they must be assessed in relation to the specific risk, the scope covered and the certification’s validity. A certification does not replace supply chain analysis, although it may reduce the need to request information that has already been independently verified.

Supply chain mapping should make it possible to associate each supplier with specific risk factors. These may include the country of operation, sector, purchasing value, importance of the supplied component, position within the supply chain and results of previous assessments. This segmentation prevents companies from applying the same level of control to suppliers with very different risk profiles.

The indicators selected should be verifiable and linked to a decision. The number of suppliers assessed, for example, provides limited insight unless it is considered alongside the percentage of high-risk suppliers, time required to close corrective actions and proportion of purchasing expenditure covered by the assessments.

The quality of supporting evidence should also be defined in advance. A self-declaration, certification, independent audit and document issued by a public authority provide different levels of assurance. Establishing a hierarchy of evidence helps companies assign consistent scores and request additional checks in the most material cases.

The process must also be capable of being updated. Suppliers, countries, purchasing volumes and operating conditions change over time. A static system can quickly become outdated. Companies should therefore define review frequencies, events that trigger a reassessment and responsibility for approving corrective measures.

CSDDD readiness can be measured through a limited number of concrete results: percentage of purchasing expenditure mapped, suppliers classified by risk level, average quality of evidence collected, open corrective actions and resolution times. These data allow management to assess whether due diligence is operating effectively and to document the decisions taken.

For companies managing a large number of third parties, supplier assessment software can support data collection, risk classification and corrective action monitoring. A centralised platform makes it possible to associate data and evidence with each supplier, update assessments over time and measure the effective coverage of the supply chain.

CONTRIBUTOR

Headshot Alessandro Nora

Alessandro Nora

CEO & Co-founder

Alessandro's goal is to make a real impact on sustainability. After founding a sustainable fashion marketplace, he decided to focus on ESG digitalisation with the aim of making sustainability more concrete, measurable and accessible for companies. A careful and methodical founder, with experience in Genoa, Berlin and Lisbon, Alessandro combines international vision and operational rigour in the development of digital solutions that simplify ESG regulations and compliance, supporting companies in adapting to ESG regulations, certifications and ratings through structured and audit-ready tools. Topics covered: CSRD, CSDDD, EUDR, CBAM ESG ratings, ESG certifications, Ecovadis, sustainability governance, regulatory compliance.

No headings found on page

Stay up to date with Metrikflow Insights!

We deliver expert insights, product updates, industry trends, and actionable strategies straight to your inbox. Stay ahead in ESG, GHG, and LCA — one edition at a time.

By submitting this form, you consent to receive the requested resource. For more information on how we process and protect your data, view our Privacy Policy.

The go-to software solution for
Sustainability Managers.

Customer-Oriented

Data Accurate

Built on Smart Tech

ESG radar: The Metrikflow Newsletter

Everything you need to know about sustainability,
all-in-one email. Weekly insights. Zero spam.

By submitting this form, you consent to receive the requested resource. For more information on how we process and protect your data, view our Privacy Policy.

Ask AI for a summary of Metrikflow

chatgptclaudeperplexity

Contact Us

The only platform you ever need to manage ESG and Compliance.

Data Security

Measurable Impact

AI + ESG Experts

Measurable Impact

AI + ESG Experts

Data Security

ESG radar: The Metrikflow Newsletter

Everything you need to know about sustainability,
all-in-one email. Weekly insights. Zero spam.

By submitting this form, you consent to receive the requested resource. For more information on how we process and protect your data, view our Privacy Policy.

Ask AI for a summary of Metrikflow

chatgptclaudeperplexity