Blog

CSDDD: What the Supply Chain Directive Under Omnibus I Means for Businesses

Janina Schmieds
Product Manager, Compliance College, Haufe Akademie
Reading time: 5 min
CSDDD
On this page
table of contents

The EU has significantly scaled back its supply chain directive. The reform, enacted through Omnibus I, takes effect on March 18, 2026, and changes almost everything: thresholds, deadlines, penalties, and liability. The CSDDD (Corporate Sustainability Due Diligence Directive) will apply only to very large companies in the future, uniformly effective July 26, 2029. These companies will then be required to systematically assess their supply chains for risks. Read here to find out who is affected, which due diligence obligations remain, and how the CSDDD differs from Germany’s LkSG.

Share this article

CSDDD: Key Points at a Glance

  • The CSDDD is an EU directive that requires large companies to identify and address human rights and environmental risks in their supply chains.
  • Only companies with more than 5,000 employees and net revenue exceeding 1.5 billion euros are directly affected; suppliers are impacted indirectly by the directive.
  • Member States must implement the CSDDD by July 26, 2028, and affected companies must apply it uniformly starting July 26, 2029.
  • Companies assess risks through a continuous, risk-based process consisting of six steps, ranging from risk identification to effectiveness monitoring.
  • Omnibus I eliminated the Climate Transition Plan and the uniform EU liability regime and capped fines at a maximum of 3 percent of global net revenue.
  • In Germany, the LkSG remains in effect until it is implemented. Targeted training helps embed due diligence processes into everyday practice.

What is the CSDDD?

The CSDDD is an EU directive. It requires large companies to identify and address human rights and environmental risks in their value chain. Due diligence essentially means exercising due care and aims to ensure a thorough and comprehensive risk assessment of the corporate value chain. This refers to a structured process: Companies assess risks and negative impacts on people and the environment, take corrective measures, and give affected parties a voice.

Because the directive holds companies accountable for their supply chains, many also refer to it as the Supply Chain Directive. However, it takes a broader view and refers to the “activity chain.” This encompasses upstream stages such as suppliers and raw material extraction—in other words, the supply chain—as well as downstream stages such as distribution and transportation.

A directive does not apply directly to companies. Member states must first transpose it into national law. Unlike Corporate Social Responsibility (CSR)—which refers to companies’ voluntary social responsibility—the CSDDD imposes binding obligations.

Which companies are subject to the CSDDD?

The reform simplifies the scope of application; there is now only one threshold instead of three. EU companies with more than 5,000 employees and more than 1.5 billion euros in global net revenue are directly affected. For companies outside the EU, revenue within the EU is the determining factor: it must exceed 1.5 billion euros.

Smaller companies do not have any obligations under the CSDDD, but they should still expect to be asked about their risks and supporting documentation. The reason: Large customers that fall under the CSDDD must assess their supply chains for risks. To do so, they request information from their suppliers—for example, regarding working conditions and environmental standards. As a result, the CSDDD can also affect companies that are not themselves subject to it. The table shows which of the three categories your company falls into. 

Case Group Who is part of it? What does that mean?
Directly affected EU companies with more than 5,000 employees and more than 1.5 billion euros in net revenue worldwide; non-EU companies with more than 1.5 billion euros in revenue within the EU You must comply with the due diligence requirements starting July 26, 2029.
Indirectly affected Suppliers and business partners of large companies You have no obligation of your own, but you should expect to be asked questions about risks and proof of your customers .
Not affected Other companies with no business relationship with the companies directly affected You have no obligations under the CSDDD, but please review the Supply Chain Due Diligence Act (LkSG).

When does the CSDDD take effect?

The old implementation phases with staggered deadlines are a thing of the past. Under Omnibus I, a uniform start date applies: All directly affected companies will apply the CSDDD starting July 26, 2029. Member states have until July 26, 2028, to transpose the directive into national law. The European Commission is also developing guidelines to show companies how to implement due diligence obligations in practice. These are expected to be available by 2027/2028.

Date Milestone
February 26, 2026 Publication of Directive (EU) 2026/470 in the Official Journal
March 18, 2026 Effective Date of the Omnibus I Reform
July 26, 2028 Deadline for Member States to transpose the directive into national law
July 26, 2029 Uniform Effective Date for All Affected Companies

Human Rights and the Environment: What Areas Does the CSDDD Cover?

The CSDDD requires companies to assess adverse impacts in two areas: human rights and the environment. The directive specifies which violations companies must prevent or remedy in their supply chains. These include, for example:

  • Prohibit child labor and forced labor
  • create safe and healthy working conditions
  • ensure a fair wage
  • Prevent discrimination based on gender, age, or sexual orientation
  • Prevent environmental damage and protect natural resources

Companies should not only identify these risks but also actively address them. The six-step process described in the next section shows how this works in practice. Since Omnibus I, the group of stakeholders has been narrowed: companies primarily engage with groups directly affected and their representatives; consumers and NGOs are no longer included.

What due diligence obligations apply to companies?

The CSDDD does not require a one-time test, but rather a process that runs continuously within the company. At its core is the risk-based approach: Companies focus on the points in their value chain where the greatest risks lie. They must embed their due diligence obligations in their strategy and policies. The process consists of six steps:

  1. Mitigating Risks: You gain an overview of your own business operations, subsidiaries, and business partners , and identify where risks are most likely to arise.
  2. Conduct a more in-depth risk assessment: In high-risk areas, analyze the nature and severity of potential impacts in greater detail.
  3. Preventing harm: You establish measures to prevent or reduce violations and harm, such as codes of conduct for suppliers, contractual representations, and training. 
  4. Resolving Violations: If violations occur, put an end to them, compensate for any resulting damages, and provide support to those affected. 
  5. Offer a complaint process: Those affected can submit reports and receive a response.
  6. Check effectiveness: You regularly check whether your measures are effective and adjust them as needed.

The directive does not require that every supplier be vetted to the same extent. It emphasizes prioritization, even for indirect suppliers. The current version does not provide for a blanket restriction to direct business partners (Tier 1). However, large companies may only request a limited amount of information from smaller business partners. This eases the burden on suppliers and reduces the workload for all parties.

Compliance College: Implementing Mandatory Training Digitally

The Compliance College , part of Haufe Akademie , offers mandatory digital training courses on compliance and awareness that you can select and document as needed.

Get to know Compliance College

What changes did Omnibus I make to the CSDDD?

Omnibus I consolidates amendments to the Corporate Sustainability Reporting Directive (CSRD) and the CSDDD. The European Commission presented the package in February 2025, and the Council adopted it in February 2026. Amending Directive (EU) 2026/470 has been in force since March 18, 2026. It is therefore now applicable law and no longer a proposal. 

This does not apply:

  • The Requirement for a Climate Transition Plan
  • the uniform EU liability regime
  • the phased rollout with lower thresholds
  • NGOs and consumers among the participating stakeholders

A clear upper limit now applies to sanctions: National supervisory authorities may impose fines of no more than 3 percent of global net revenue. With regard to liability, the directive no longer prescribes a uniform EU regime. National law determines when affected parties can claim damages. The impact of the reform is thus most evident in the thresholds, deadlines, and sanctions. At the same time, it significantly reduces the number of entities subject to these obligations, though the core logic of the due diligence obligations remains in place.

CSDDD and CSRD: What's the difference?

The two guidelines complement each other because they promote transparent and sustainable corporate governance, but they address different issues. 

  • The CSDDD specifies what companies must do to prevent risks in the chain of activities. In addition, they must publicly report on their due diligence obligations. The due diligence obligations take effect on July 26, 2029; the reporting requirement does not begin until after that date.
  • The Corporate Sustainability Reporting Directive (CSRD) specifies what companies must report on in general regarding sustainability. The CSRD has also been amended by Omnibus I: It will apply in the future to companies with more than 1,000 employees and more than 450 million euros in net revenue. 

CSDDD and LkSG: What Are the Rules in Germany?

Germany already has its own set of regulations in the form of the Supply Chain Due Diligence Act (LkSG). It is already in effect today, whereas the CSDDD will not take effect until 2029. When it comes to damages, the two sets of regulations differ only slightly: In the future, affected parties will be able to seek damages only under national law; there is no longer a uniform EU rule. Companies may be required to fully compensate those who have suffered harm. The table shows where the remaining differences lie.

Feature CSDDD (under Omnibus I) LkSG (current)
Status Effective July 26, 2029 Already in effect
Scope of Application More than 5,000 employees and more than 1.5 billion euros in net revenue Companies with at least 1,000 employees in Germany
Range Risk-Based Activity Chain, Including Indirect Partners Our own business unit and direct suppliers; indirect suppliers as needed
Climate Plan No longer mandatory Not required
Sanctions A maximum of 3% of global net sales Fines of up to 8 million euros; for companies with revenue exceeding 400 million euros, fines of up to 2 percent of annual revenue
Liability No uniform EU regime; national law No separate basis for civil liability

The CSDDD applies to significantly fewer companies than the LkSG, but takes a closer look at the chain of activities. For companies with 1,000 to 5,000 employees in Germany, the LkSG therefore continues to apply for the time being.

Until Germany transposes the CSDDD into national law, the LkSG will continue to apply. Although lawmakers plan to amend the LkSG, the Bundestag has not yet passed the amendment. You should therefore base your planning on the current law and keep an eye on the status of the amendment.

What measures and training do companies need right now?

By July 26, 2029, directly affected companies must establish a functioning due diligence process. To do so, they need clear lines of responsibility, documented procedures, and trained employees. The directive does not list training as a separate mandatory component. In practice, however, training plays a crucial role in ensuring that risk assessments, supplier codes, and complaint procedures function effectively in day-to-day operations. The appropriate measures depend on how your company is affected:

  • Directly affected: You begin by taking stock of your supply chain, define responsibilities and the budget, add due diligence clauses to supplier contracts, and establish a complaint procedure.
  • Indirectly affected: You work with your major customers to determine what documentation they require, develop your own code of conduct, and establish a process for providing information.
  • Not affected: You should check whether the LkSG applies to you and monitor the national implementation of the CSDDD.

Training is most effective when it is tailored to the role. The table shows who you should target with which content.

Target group Training Content Goal
Executive Management and Senior Executives CSDDD's Duties, Responsibilities, and Risk Strategy They manage the due diligence process and provide resources.
Purchasing and supplier management Risk Analysis, Supplier Code of Conduct, Contract Clauses, Audits They identify risks in the supply chain and take early action.
Compliance and law Directive, national implementation, LkSG, documentation They keep records up to date and advise the departments.
Departments that interact with suppliers Recognize warning signs, use reporting channels They promptly report suspected cases to the appropriate authority.
Suppliers and Business Partners Expectations, Documentation, Code of Conduct You'll meet the requirements of your customers without delay.

HR developers They play a key role in this process. They assess the needs of each target group, select appropriate formats, and make learning outcomes measurable. The procurement department, in particular, needs to know how to identify risks in the supply chain.

Provide clear training on due diligence requirements with the " Haufe Akademie " and embed compliance 

CSDDD may sound like bureaucracy, but it offers much more: By embedding due diligence requirements early on, companies can identify vulnerabilities in the value chain in a timely manner, reduce risks, and strengthen the trust of customers as well as investors. The Haufe Akademie has been supporting HR developers in this process for decades as an equal partner. The Compliance College supplements your learning environment with mandatory digital training courses. You choose the topics, and we provide certification and learning outcome assessments tailored to your company.

Discover Compliance College now

FAQ

What is the CSDDD?

The CSDDD (Corporate Sustainability Due Diligence Directive) is the EU Supply Chain Directive. It requires very large companies to identify, prevent, and address human rights and environmental risks in their supply chains. Since Omnibus I, it has been in effect in a significantly abbreviated version.

Which companies are affected by the CSDDD?

EU companies with more than 5,000 employees and global net revenue exceeding 1.5 billion euros are directly affected. Non-EU companies are covered if they generate more than 1.5 billion euros in revenue within the EU. Suppliers to large companies are indirectly affected by the directive.

When does the CSDDD take effect?

Member States must transpose the CSDDD into national law by July 26, 2028. Companies directly affected by the directive will apply it uniformly starting July 26, 2029. The earlier phases of implementation have been eliminated.

What penalties apply for violations?

National supervisory authorities may impose fines. The directive caps these fines at a maximum of 3 percent of global net revenue. Whether and how affected parties can seek damages is governed by national law.

Janina Schmieds
Product Manager, Compliance College, Haufe Akademie
With a clear focus on innovative learning solutions, Janina, as Product Manager for Compliance College Haufe Akademie , is driving Haufe Akademie expansion of the portfolio and the further development of modern features and services. Her goal: to design learning programs that provide companies with efficient and practical support for training.
Key topics:
Compliance & sustainability
-
Adaptive learning
-
Mandatory Training & Processes
-
All articles by
Janina Schmieds