Skip to main content
ExplainerSupply Chain ComplianceExplainer· 5 min read· in Guides

The New EU Supply Chain Reality: A Guide to the CSDDD, Mandatory Due Diligence, and Corporate Liability

The EU's Corporate Sustainability Due Diligence Directive (CSDDD) shifts ESG from reporting to mandatory action, requiring large companies to police their global supply chains for human rights and environmental risks. Following the 2026 Omnibus I amendments, the directive sets a hard 2029 compliance deadline and introduces penalties of up to 3% of global turnover.

By Kavya Nair

Corporate Compliance Teams 40%Human Rights & Environmental NGOs 30%Non-EU Suppliers 30%
Corporate Compliance Teams
Focused on the immense administrative and operational burden of deep-tier supply chain mapping.
Human Rights & Environmental NGOs
Viewing the Omnibus I scope reduction as a missed opportunity, while acknowledging the historic precedent.
Non-EU Suppliers
Facing the 'trickle-down' reality of European regulation being forced into commercial contracts.

Perspectives this story doesn't cover

  • Small and Medium Enterprises (SMEs) struggling with the cost of trickle-down compliance audits.
  • Consumers who may face higher prices as compliance costs are passed down the value chain.

For decades, corporate sustainability was largely a voluntary exercise—a mix of public relations, voluntary codes of conduct, and selective reporting. If a supplier three tiers down a company's value chain was found polluting a river or using forced labor, the reputational damage to the parent brand was real, but the legal liability was often minimal. The European Union’s Corporate Sustainability Due Diligence Directive (CSDDD) permanently ends that era. For procurement leaders, legal teams, and corporate boards, supply chain oversight is no longer just an ethical preference; it is a strict legal mandate backed by severe financial penalties.[1]

The CSDDD, which officially entered into force in 2024 and was significantly amended by the "Omnibus I" legislative package in early 2026, fundamentally rewrites the rules of global commerce. It requires large companies operating in the EU market to actively identify, prevent, mitigate, and account for negative human rights and environmental impacts. Crucially, this obligation extends beyond a company’s own operations and subsidiaries to encompass its entire "chain of activities"—meaning both upstream suppliers and certain downstream distribution channels.[2][4]

To understand the CSDDD, it is essential to distinguish it from its sister legislation, the Corporate Sustainability Reporting Directive (CSRD). While the CSRD forces companies to disclose extensive data about their environmental and social impacts, it is fundamentally a transparency law. The CSDDD is an action law. It demands that companies actually intervene in their supply chains to stop harm, provide remediation to affected parties, and align their business strategies with sustainable practices.[4]

The path to the current CSDDD framework was highly contested, culminating in the Omnibus I Amending Directive, which entered into force on March 18, 2026. Designed to reduce administrative burdens and prevent regulatory fragmentation, Omnibus I significantly narrowed the scope of the original directive. The law now targets only the largest economic actors, shifting the immediate compliance burden away from mid-sized enterprises while still capturing the massive multinational corporations that sit at the top of global supply chains.[3]

The 2026 Omnibus I amendments significantly narrowed the scope of companies directly regulated by the CSDDD.

Under the revised 2026 thresholds, the CSDDD applies to EU-based companies with more than 5,000 employees and a global net turnover exceeding €1.5 billion. For non-EU companies, the employee headcount is irrelevant; they are captured if they generate more than €1.5 billion in net turnover within the European Union. While this drastically reduces the number of directly regulated entities compared to earlier drafts, the "trickle-down" effect means thousands of smaller suppliers globally will still be forced to comply via strict contractual requirements imposed by their massive European buyers.[3][4]

The Omnibus I package also simplified the implementation timeline. Originally, the CSDDD was designed with a staggered, multi-year phase-in based on company size. The 2026 amendments scrapped this tiered approach in favor of a single, unified application date. EU Member States now have until July 26, 2028, to transpose the directive into their national laws, and all in-scope companies must fully comply by July 26, 2029.[3]

The Omnibus I package also simplified the implementation timeline.

Compliance with the CSDDD requires companies to implement a rigorous, six-step due diligence cycle. First, organizations must integrate due diligence into their corporate policies and risk management systems. Second, they must map their value chains to identify and assess actual or potential adverse impacts. This is often the most resource-intensive step, requiring deep visibility into opaque supplier networks across multiple continents and jurisdictions.[2][4]

Companies must implement a continuous six-step cycle to identify and address supply chain risks.

Once risks are identified, the third and fourth steps require companies to take concrete action to prevent potential impacts and mitigate or end actual harms. This can involve investing in supplier upgrades, redesigning products, or, as a last resort, terminating business relationships with non-compliant partners. Fifth, companies must establish accessible grievance mechanisms for affected stakeholders. Finally, they must publicly communicate their due diligence efforts and monitor the effectiveness of their interventions.[2]

The enforcement mechanisms backing the CSDDD are designed to be punitive enough to command board-level attention. The directive relies on a dual system of administrative supervision and civil liability. On the administrative side, Member States are required to designate supervisory authorities equipped with the power to launch investigations, order remedial actions, and impose substantial fines.[2]

Under the Omnibus I amendments, the maximum administrative penalty is capped at 3% of a company’s net worldwide turnover. For a multinational corporation generating €50 billion annually, a maximum fine could reach €1.5 billion. Furthermore, non-compliant companies risk being excluded from lucrative public procurement contracts across the European Union, adding a severe commercial penalty to the regulatory fines.[3]

Enforcement mechanisms include massive financial penalties and the risk of civil litigation.

The civil liability provisions of the CSDDD represent another major shift, though the 2026 amendments altered their application. Originally, the EU sought to establish a fully harmonized, EU-wide civil liability regime. Omnibus I removed this harmonization, leaving it up to individual Member States to define the specific conditions under which a company can be sued in national courts.

However, the core principle remains intact: victims of corporate negligence—whether they are factory workers in Asia or communities affected by pollution in South America—have the right to seek full compensation for damages resulting from a company's failure to meet its CSDDD obligations. National judges are also empowered to compel companies to disclose internal evidence during these proceedings, significantly lowering the barrier for plaintiffs to bring successful claims.

The Omnibus I package aligned all in-scope companies onto a single July 2029 compliance deadline.

Preparing for the 2029 deadline requires immediate action, as supply chain mapping and contract renegotiation are multi-year endeavors. Companies must begin updating their supplier codes of conduct and embedding CSDDD-compliant clauses into all new procurement contracts. The European Commission is mandated to publish detailed guidelines and voluntary model contractual clauses by July 2027, which will serve as the baseline for these legal updates.[2][3]

Ultimately, the CSDDD forces a paradigm shift in global procurement. Price and quality can no longer be the sole metrics for supplier selection; verifiable sustainability and human rights compliance are now equally critical. As the 2029 deadline approaches, the companies that treat due diligence as a strategic operational upgrade—rather than a mere compliance checklist—will be best positioned to navigate the new European market reality.[1]

What to know

  1. The CSDDD mandates large companies to identify, prevent, and mitigate human rights and environmental risks in their value chains.
  2. The 2026 Omnibus I amendments narrowed the scope to companies with over 5,000 employees and €1.5 billion in turnover.
  3. All in-scope companies face a unified compliance deadline of July 26, 2029.
  4. Penalties for non-compliance can reach up to 3% of a company's global net turnover.
  5. The directive establishes civil liability, allowing victims of supply chain abuses to sue companies for damages.
  6. Smaller suppliers globally will be affected as large buyers force compliance requirements into their contracts.

Key terms

Value Chain
The full range of activities required to bring a product or service to market, including upstream suppliers and downstream distribution.
Omnibus I
A 2026 EU legislative package that simplified and narrowed the scope of both the CSDDD and the CSRD to reduce administrative burdens.
Transposition
The process by which EU Member States incorporate an EU directive into their own national legal frameworks.
Civil Liability
Legal responsibility for damages, allowing affected individuals or communities to sue a company for failing to prevent harm.

Reader questions

What is the difference between the CSRD and the CSDDD?

The CSRD is a reporting directive that requires companies to disclose sustainability data. The CSDDD is an action directive that requires companies to actively prevent and mitigate harms in their supply chains.

Does the CSDDD apply to companies outside the EU?

Yes. Non-EU companies are subject to the directive if they generate more than €1.5 billion in net turnover within the European Union.

What are the penalties for violating the CSDDD?

Companies can face administrative fines of up to 3% of their global net turnover, exclusion from public contracts, and civil lawsuits for damages.

When do companies have to comply?

Following the 2026 Omnibus I amendments, all in-scope companies share a single, unified compliance deadline of July 26, 2029.

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Corporate Compliance Teams 40%Human Rights & Environmental NGOs 30%Non-EU Suppliers 30%
  1. [1]Factlen Editorial TeamNon-EU Suppliers

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team →
  2. [2]European Commission

    Corporate sustainability due diligence

    Read on European Commission →
  3. [3]DLA PiperCorporate Compliance Teams

    Omnibus I CSRD and CSDDD Simplification Directive

    Read on DLA Piper →
  4. [4]NormativeNon-EU Suppliers

    What is the CSDDD? A guide to the EU directive

    Read on Normative →

Comments

Stay informed

Every angle. Every day.

Get Guides stories with full source coverage and perspective breakdowns delivered to your inbox.