The New EU Supply Chain Reality: A Guide to the CSDDD, Mandatory Due Diligence, and Corporate Liability
The EU's Corporate Sustainability Due Diligence Directive (CSDDD) shifts ESG from reporting to mandatory action, requiring large companies to police their global supply chains for human rights and environmental risks. Following the 2026 Omnibus I amendments, the directive sets a hard 2029 compliance deadline and introduces penalties of up to 3% of global turnover.
By Kavya Nair
- Corporate Compliance Teams
- Focused on the immense administrative and operational burden of deep-tier supply chain mapping.
- Human Rights & Environmental NGOs
- Viewing the Omnibus I scope reduction as a missed opportunity, while acknowledging the historic precedent.
- Non-EU Suppliers
- Facing the 'trickle-down' reality of European regulation being forced into commercial contracts.
Perspectives this story doesn't cover
- Small and Medium Enterprises (SMEs) struggling with the cost of trickle-down compliance audits.
- Consumers who may face higher prices as compliance costs are passed down the value chain.
For decades, corporate sustainability was largely a voluntary exercise—a mix of public relations, voluntary codes of conduct, and selective reporting. If a supplier three tiers down a company's value chain was found polluting a river or using forced labor, the reputational damage to the parent brand was real, but the legal liability was often minimal. The European Union’s Corporate Sustainability Due Diligence Directive (CSDDD) permanently ends that era. For procurement leaders, legal teams, and corporate boards, supply chain oversight is no longer just an ethical preference; it is a strict legal mandate backed by severe financial penalties.[1]
The CSDDD, which officially entered into force in 2024 and was significantly amended by the "Omnibus I" legislative package in early 2026, fundamentally rewrites the rules of global commerce. It requires large companies operating in the EU market to actively identify, prevent, mitigate, and account for negative human rights and environmental impacts. Crucially, this obligation extends beyond a company’s own operations and subsidiaries to encompass its entire "chain of activities"—meaning both upstream suppliers and certain downstream distribution channels.[2][4]
To understand the CSDDD, it is essential to distinguish it from its sister legislation, the Corporate Sustainability Reporting Directive (CSRD). While the CSRD forces companies to disclose extensive data about their environmental and social impacts, it is fundamentally a transparency law. The CSDDD is an action law. It demands that companies actually intervene in their supply chains to stop harm, provide remediation to affected parties, and align their business strategies with sustainable practices.[4]
The path to the current CSDDD framework was highly contested, culminating in the Omnibus I Amending Directive, which entered into force on March 18, 2026. Designed to reduce administrative burdens and prevent regulatory fragmentation, Omnibus I significantly narrowed the scope of the original directive. The law now targets only the largest economic actors, shifting the immediate compliance burden away from mid-sized enterprises while still capturing the massive multinational corporations that sit at the top of global supply chains.[3]
Under the revised 2026 thresholds, the CSDDD applies to EU-based companies with more than 5,000 employees and a global net turnover exceeding €1.5 billion. For non-EU companies, the employee headcount is irrelevant; they are captured if they generate more than €1.5 billion in net turnover within the European Union. While this drastically reduces the number of directly regulated entities compared to earlier drafts, the "trickle-down" effect means thousands of smaller suppliers globally will still be forced to comply via strict contractual requirements imposed by their massive European buyers.[3][4]
The Omnibus I package also simplified the implementation timeline. Originally, the CSDDD was designed with a staggered, multi-year phase-in based on company size. The 2026 amendments scrapped this tiered approach in favor of a single, unified application date. EU Member States now have until July 26, 2028, to transpose the directive into their national laws, and all in-scope companies must fully comply by July 26, 2029.[3]
The Omnibus I package also simplified the implementation timeline.
Compliance with the CSDDD requires companies to implement a rigorous, six-step due diligence cycle. First, organizations must integrate due diligence into their corporate policies and risk management systems. Second, they must map their value chains to identify and assess actual or potential adverse impacts. This is often the most resource-intensive step, requiring deep visibility into opaque supplier networks across multiple continents and jurisdictions.[2][4]
Once risks are identified, the third and fourth steps require companies to take concrete action to prevent potential impacts and mitigate or end actual harms. This can involve investing in supplier upgrades, redesigning products, or, as a last resort, terminating business relationships with non-compliant partners. Fifth, companies must establish accessible grievance mechanisms for affected stakeholders. Finally, they must publicly communicate their due diligence efforts and monitor the effectiveness of their interventions.[2]
The enforcement mechanisms backing the CSDDD are designed to be punitive enough to command board-level attention. The directive relies on a dual system of administrative supervision and civil liability. On the administrative side, Member States are required to designate supervisory authorities equipped with the power to launch investigations, order remedial actions, and impose substantial fines.[2]
Under the Omnibus I amendments, the maximum administrative penalty is capped at 3% of a company’s net worldwide turnover. For a multinational corporation generating €50 billion annually, a maximum fine could reach €1.5 billion. Furthermore, non-compliant companies risk being excluded from lucrative public procurement contracts across the European Union, adding a severe commercial penalty to the regulatory fines.[3]
The civil liability provisions of the CSDDD represent another major shift, though the 2026 amendments altered their application. Originally, the EU sought to establish a fully harmonized, EU-wide civil liability regime. Omnibus I removed this harmonization, leaving it up to individual Member States to define the specific conditions under which a company can be sued in national courts.
However, the core principle remains intact: victims of corporate negligence—whether they are factory workers in Asia or communities affected by pollution in South America—have the right to seek full compensation for damages resulting from a company's failure to meet its CSDDD obligations. National judges are also empowered to compel companies to disclose internal evidence during these proceedings, significantly lowering the barrier for plaintiffs to bring successful claims.
Preparing for the 2029 deadline requires immediate action, as supply chain mapping and contract renegotiation are multi-year endeavors. Companies must begin updating their supplier codes of conduct and embedding CSDDD-compliant clauses into all new procurement contracts. The European Commission is mandated to publish detailed guidelines and voluntary model contractual clauses by July 2027, which will serve as the baseline for these legal updates.[2][3]
Ultimately, the CSDDD forces a paradigm shift in global procurement. Price and quality can no longer be the sole metrics for supplier selection; verifiable sustainability and human rights compliance are now equally critical. As the 2029 deadline approaches, the companies that treat due diligence as a strategic operational upgrade—rather than a mere compliance checklist—will be best positioned to navigate the new European market reality.[1]
What to know
- The CSDDD mandates large companies to identify, prevent, and mitigate human rights and environmental risks in their value chains.
- The 2026 Omnibus I amendments narrowed the scope to companies with over 5,000 employees and €1.5 billion in turnover.
- All in-scope companies face a unified compliance deadline of July 26, 2029.
- Penalties for non-compliance can reach up to 3% of a company's global net turnover.
- The directive establishes civil liability, allowing victims of supply chain abuses to sue companies for damages.
- Smaller suppliers globally will be affected as large buyers force compliance requirements into their contracts.
Key terms
- Value Chain
- The full range of activities required to bring a product or service to market, including upstream suppliers and downstream distribution.
- Omnibus I
- A 2026 EU legislative package that simplified and narrowed the scope of both the CSDDD and the CSRD to reduce administrative burdens.
- Transposition
- The process by which EU Member States incorporate an EU directive into their own national legal frameworks.
- Civil Liability
- Legal responsibility for damages, allowing affected individuals or communities to sue a company for failing to prevent harm.
Reader questions
What is the difference between the CSRD and the CSDDD?
The CSRD is a reporting directive that requires companies to disclose sustainability data. The CSDDD is an action directive that requires companies to actively prevent and mitigate harms in their supply chains.
Does the CSDDD apply to companies outside the EU?
Yes. Non-EU companies are subject to the directive if they generate more than €1.5 billion in net turnover within the European Union.
What are the penalties for violating the CSDDD?
Companies can face administrative fines of up to 3% of their global net turnover, exclusion from public contracts, and civil lawsuits for damages.
When do companies have to comply?
Following the 2026 Omnibus I amendments, all in-scope companies share a single, unified compliance deadline of July 26, 2029.
Sources
[1]Factlen Editorial TeamNon-EU SuppliersSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
[2]European CommissionCorporate sustainability due diligence
Read on European Commission →
[3]DLA PiperCorporate Compliance TeamsOmnibus I CSRD and CSDDD Simplification Directive
Read on DLA Piper →
[4]NormativeNon-EU SuppliersWhat is the CSDDD? A guide to the EU directive
Read on Normative →
Comments
More in Guides
See all →Inflation Metrics
The Basket of Goods, the Laspeyres Formula, and the Geometric Mean: How CPI, RPI, and HICP Measure International Inflation
7 sources
Patent Law
The Novelty, Non-Obviousness, and Utility Requirements: How US Law Defines a Patentable Invention
8 sources
Network Protocols
The TCP Three-Way Handshake: How the SYN, SYN-ACK, and ACK Sequence Establishes Reliable Network Connections
6 sources
Quantum Optics
How Population Inversion and Stimulated Emission Generate Coherent Laser Light
9 sources
Every angle. Every day.
Get Guides stories with full source coverage and perspective breakdowns delivered to your inbox.




