The New EU Supply Chain Reality: A Guide to the CSDDD, Mandatory Due Diligence, and Corporate Liability
The EU's Corporate Sustainability Due Diligence Directive (CSDDD) shifts ESG from reporting to mandatory action, requiring large companies to police their global supply chains for human rights and environmental risks. Following the 2026 Omnibus I amendments, the directive sets a hard 2029 compliance deadline and introduces penalties of up to 3% of global turnover.
By Kavya Nair
- Corporate Compliance Teams
- Focused on the immense administrative and operational burden of deep-tier supply chain mapping.
- Human Rights & Environmental NGOs
- Viewing the Omnibus I scope reduction as a missed opportunity, while acknowledging the historic precedent.
- Non-EU Suppliers
- Facing the 'trickle-down' reality of European regulation being forced into commercial contracts.
How we got here
May 2024
The original Corporate Sustainability Due Diligence Directive (CSDDD) is officially adopted by the EU.
March 2026
The Omnibus I Amending Directive enters into force, narrowing the scope and simplifying the timeline.
July 2028
Deadline for all EU Member States to transpose the amended CSDDD into their national laws.
July 2029
The unified application date when all in-scope companies must fully comply with the directive.
Why it matters
The CSDDD transforms supply chain oversight from a voluntary ethical exercise into a strict legal mandate. Companies that fail to actively prevent human rights and environmental abuses in their value chains now face massive financial penalties and direct civil liability in European courts.
For decades, corporate sustainability was largely a voluntary exercise—a mix of public relations, voluntary codes of conduct, and selective reporting. If a supplier three tiers down a company's value chain was found polluting a river or using forced labor, the reputational damage to the parent brand was real, but the legal liability was often minimal. The European Union’s Corporate Sustainability Due Diligence Directive (CSDDD) permanently ends that era. For procurement leaders, legal teams, and corporate boards, supply chain oversight is no longer just an ethical preference; it is a strict legal mandate backed by severe financial penalties.[1]
The CSDDD, which officially entered into force in 2024 and was significantly amended by the "Omnibus I" legislative package in early 2026, fundamentally rewrites the rules of global commerce. It requires large companies operating in the EU market to actively identify, prevent, mitigate, and account for negative human rights and environmental impacts. Crucially, this obligation extends beyond a company’s own operations and subsidiaries to encompass its entire "chain of activities"—meaning both upstream suppliers and certain downstream distribution channels.[2][4]
To understand the CSDDD, it is essential to distinguish it from its sister legislation, the Corporate Sustainability Reporting Directive (CSRD). While the CSRD forces companies to disclose extensive data about their environmental and social impacts, it is fundamentally a transparency law. The CSDDD is an action law. It demands that companies actually intervene in their supply chains to stop harm, provide remediation to affected parties, and align their business strategies with sustainable practices.[4]
The path to the current CSDDD framework was highly contested, culminating in the Omnibus I Amending Directive, which entered into force on March 18, 2026. Designed to reduce administrative burdens and prevent regulatory fragmentation, Omnibus I significantly narrowed the scope of the original directive. The law now targets only the largest economic actors, shifting the immediate compliance burden away from mid-sized enterprises while still capturing the massive multinational corporations that sit at the top of global supply chains.[3]

Under the revised 2026 thresholds, the CSDDD applies to EU-based companies with more than 5,000 employees and a global net turnover exceeding €1.5 billion. For non-EU companies, the employee headcount is irrelevant; they are captured if they generate more than €1.5 billion in net turnover within the European Union. While this drastically reduces the number of directly regulated entities compared to earlier drafts, the "trickle-down" effect means thousands of smaller suppliers globally will still be forced to comply via strict contractual requirements imposed by their massive European buyers.[3][4]
The Omnibus I package also simplified the implementation timeline. Originally, the CSDDD was designed with a staggered, multi-year phase-in based on company size. The 2026 amendments scrapped this tiered approach in favor of a single, unified application date. EU Member States now have until July 26, 2028, to transpose the directive into their national laws, and all in-scope companies must fully comply by July 26, 2029.[3]
The Omnibus I package also simplified the implementation timeline.
Compliance with the CSDDD requires companies to implement a rigorous, six-step due diligence cycle. First, organizations must integrate due diligence into their corporate policies and risk management systems. Second, they must map their value chains to identify and assess actual or potential adverse impacts. This is often the most resource-intensive step, requiring deep visibility into opaque supplier networks across multiple continents and jurisdictions.[2][4]

Once risks are identified, the third and fourth steps require companies to take concrete action to prevent potential impacts and mitigate or end actual harms. This can involve investing in supplier upgrades, redesigning products, or, as a last resort, terminating business relationships with non-compliant partners. Fifth, companies must establish accessible grievance mechanisms for affected stakeholders. Finally, they must publicly communicate their due diligence efforts and monitor the effectiveness of their interventions.[2]
The enforcement mechanisms backing the CSDDD are designed to be punitive enough to command board-level attention. The directive relies on a dual system of administrative supervision and civil liability. On the administrative side, Member States are required to designate supervisory authorities equipped with the power to launch investigations, order remedial actions, and impose substantial fines.[2]
Under the Omnibus I amendments, the maximum administrative penalty is capped at 3% of a company’s net worldwide turnover. For a multinational corporation generating €50 billion annually, a maximum fine could reach €1.5 billion. Furthermore, non-compliant companies risk being excluded from lucrative public procurement contracts across the European Union, adding a severe commercial penalty to the regulatory fines.[3]

The civil liability provisions of the CSDDD represent another major shift, though the 2026 amendments altered their application. Originally, the EU sought to establish a fully harmonized, EU-wide civil liability regime. Omnibus I removed this harmonization, leaving it up to individual Member States to define the specific conditions under which a company can be sued in national courts.
However, the core principle remains intact: victims of corporate negligence—whether they are factory workers in Asia or communities affected by pollution in South America—have the right to seek full compensation for damages resulting from a company's failure to meet its CSDDD obligations. National judges are also empowered to compel companies to disclose internal evidence during these proceedings, significantly lowering the barrier for plaintiffs to bring successful claims.

Preparing for the 2029 deadline requires immediate action, as supply chain mapping and contract renegotiation are multi-year endeavors. Companies must begin updating their supplier codes of conduct and embedding CSDDD-compliant clauses into all new procurement contracts. The European Commission is mandated to publish detailed guidelines and voluntary model contractual clauses by July 2027, which will serve as the baseline for these legal updates.[2][3]
Ultimately, the CSDDD forces a paradigm shift in global procurement. Price and quality can no longer be the sole metrics for supplier selection; verifiable sustainability and human rights compliance are now equally critical. As the 2029 deadline approaches, the companies that treat due diligence as a strategic operational upgrade—rather than a mere compliance checklist—will be best positioned to navigate the new European market reality.[1]
What to know
- The CSDDD mandates large companies to identify, prevent, and mitigate human rights and environmental risks in their value chains.
- The 2026 Omnibus I amendments narrowed the scope to companies with over 5,000 employees and €1.5 billion in turnover.
- All in-scope companies face a unified compliance deadline of July 26, 2029.
- Penalties for non-compliance can reach up to 3% of a company's global net turnover.
- The directive establishes civil liability, allowing victims of supply chain abuses to sue companies for damages.
- Smaller suppliers globally will be affected as large buyers force compliance requirements into their contracts.
Where opinion splits
Corporate Compliance Teams
Focused on the immense administrative and operational burden of deep-tier supply chain mapping.
For corporate legal and procurement departments, the CSDDD represents a monumental data-gathering challenge. Mapping a supply chain beyond Tier 1 (direct suppliers) to Tier 2, Tier 3, and raw material extractors is notoriously difficult due to opaque sub-contracting practices. Compliance officers warn that even with the narrowed scope under Omnibus I, the requirement to embed and enforce contractual assurances throughout the value chain will require massive investments in specialized software, third-party audits, and expanded procurement teams.
Human Rights & Environmental NGOs
Viewing the Omnibus I scope reduction as a missed opportunity, while acknowledging the historic precedent.
Advocacy groups broadly celebrate the CSDDD as a historic victory that finally pierces the corporate veil, allowing victims of supply chain abuses to seek redress in European courts. However, many NGOs strongly criticized the 2026 Omnibus I amendments, arguing that raising the threshold to 5,000 employees exempts thousands of mid-sized companies operating in high-risk sectors like textiles and agriculture. They also point to the removal of a harmonized EU-wide civil liability regime as a loophole that could lead to uneven justice depending on which Member State a claim is filed in.
Non-EU Suppliers
Facing the 'trickle-down' reality of European regulation being forced into commercial contracts.
Suppliers based in Asia, Africa, and the Americas—even those far below the €1.5 billion turnover threshold—are rapidly discovering that they cannot escape the CSDDD. Because massive European buyers must guarantee the compliance of their value chains, they are aggressively pushing CSDDD obligations down to their suppliers via strict contractual clauses. Non-EU manufacturers report that European clients are increasingly demanding comprehensive ESG audits, emissions data, and human rights certifications as a non-negotiable condition for doing business.
Key terms
- Value Chain
- The full range of activities required to bring a product or service to market, including upstream suppliers and downstream distribution.
- Omnibus I
- A 2026 EU legislative package that simplified and narrowed the scope of both the CSDDD and the CSRD to reduce administrative burdens.
- Transposition
- The process by which EU Member States incorporate an EU directive into their own national legal frameworks.
- Civil Liability
- Legal responsibility for damages, allowing affected individuals or communities to sue a company for failing to prevent harm.
Unanswered questions
- How aggressively individual EU Member States will enforce the civil liability provisions, given the removal of EU-wide harmonization.
- The exact contents of the European Commission's forthcoming guidelines and model contractual clauses, due in July 2027.
- How courts will define 'appropriate measures' when judging whether a company did enough to prevent a supply chain violation.
Reader questions
What is the difference between the CSRD and the CSDDD?
The CSRD is a reporting directive that requires companies to disclose sustainability data. The CSDDD is an action directive that requires companies to actively prevent and mitigate harms in their supply chains.
Does the CSDDD apply to companies outside the EU?
Yes. Non-EU companies are subject to the directive if they generate more than €1.5 billion in net turnover within the European Union.
What are the penalties for violating the CSDDD?
Companies can face administrative fines of up to 3% of their global net turnover, exclusion from public contracts, and civil lawsuits for damages.
When do companies have to comply?
Following the 2026 Omnibus I amendments, all in-scope companies share a single, unified compliance deadline of July 26, 2029.
Sources
[1]Factlen Editorial TeamNon-EU Suppliers
Synthesis by Factlen editorial team
Read on Factlen Editorial Team →[2]European Commission
Corporate sustainability due diligence
Read on European Commission →[3]DLA PiperCorporate Compliance Teams
Omnibus I CSRD and CSDDD Simplification Directive
Read on DLA Piper →[4]NormativeNon-EU Suppliers
What is the CSDDD? A guide to the EU directive
Read on Normative →
Comments
Every angle. Every day.
Get guides stories with full source coverage and perspective breakdowns delivered to your inbox.




