CSDDDBoundary mapEU

CSDDD Chain of activities boundaries

Draw the CSDDD boundary between own operations, subsidiaries, upstream business partners, and limited downstream product activities.

Use the boundary record to decide which entities, activities, partners, and evidence records belong in the due diligence file.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Under the Corporate Sustainability Due Diligence Directive, the is narrower than the whole value chain. The due diligence duties cover a company's own operations and subsidiaries, while the definition sets the upstream business-partner boundary and limits downstream coverage to specified product activities carried out for or on behalf of the company.

Recommended next step

Turn the boundary map into evidence

Use Sorena to keep CSDDD chain-of-activities classifications tied to the source rule, partner record, contract evidence, and monitoring review.

Section 2

Separate upstream from downstream

Upstream coverage is broad. It includes activities of upstream business partners related to production of goods or provision of services by the company, including design, extraction, sourcing, manufacture, transport, storage, supply of raw materials, products or product parts, and development of the product or service.

Downstream coverage is narrower. It covers activities of downstream business partners related to distribution, transport, and storage of the company's product only where those partners carry out those activities for the company or on behalf of the company. The directive does not make ordinary customer use, product disposal, or unrelated downstream services part of this definition.

  • Include upstream design, extraction, sourcing, manufacture, transport, storage, raw-material supply, product-part supply, and product or service development.
  • Example: an indirect raw-material processor can be upstream even when the company buys only from a tier-one component supplier.
  • Include downstream distribution, transport, and storage only for company products and only when performed for or on behalf of the company.
  • Example: a contracted fulfilment centre storing the company's finished product can be downstream; a customer's warehouse storing purchased goods for its own operations is not included on that fact alone.
  • Exclude product disposal from the CSDDD chain-of-activities definition unless another law or internal commitment creates a separate obligation.
  • Exclude downstream services of the company from the chain-of-activities definition; for regulated financial undertakings, downstream partners receiving services and products are not included.
  • Exclude distribution, transport, and storage after export authorisation for products subject to Regulation (EU) 2021/821 export controls or national controls on weapons, munitions, or war material.
Section 3

Record subsidiaries and group-level support separately

A parent company may fulfil certain CSDDD obligations on behalf of in-scope subsidiaries where the conditions in Article 6 are met, but that does not erase the subsidiary from the boundary map. The subsidiary and parent must provide each other necessary information, the subsidiary must integrate due diligence into its policies and risk management systems, and the subsidiary remains subject to supervisory powers and civil liability.

For boundary evidence, keep one record for the group-level allocation and another record for each subsidiary's operational perimeter. This avoids the common mistake of treating a group policy as proof that subsidiary-specific operations, partners, and impacts have been mapped.

  • Name each in-scope subsidiary and its operational perimeter, including products, services, sites, and business-partner categories.
  • Identify which obligations the parent performs and which obligations the subsidiary continues to perform directly.
  • Keep the information-sharing record that shows how the parent and subsidiary exchange documents needed for due diligence.
  • Track subsidiary-specific direct and indirect business partners when they relate to that subsidiary's .
Section 4

Use direct and indirect partner labels for controls

The direct or indirect label matters because CSDDD uses it in the control design. Prevention and corrective measures can include contractual assurances from direct business partners, cascading assurances to partners where their activities are part of the , and, where impacts cannot otherwise be addressed, assurances from indirect business partners.

Do not classify every lower-tier supplier as out of reach. Amended Article 8 scopes all relevant partner levels using reasonably available information. Necessary information may be requested from a partner with fewer than 5,000 employees only when it cannot reasonably be obtained by other means.

  • For each direct partner, store the agreement, covered activities, product or service link, assurance clause, verification route, and SME support decision where relevant.
  • For each indirect partner that is material to a likely or severe impact, store the activity performed, how it was identified, the information source, and any assurance or engagement route.
  • When information can come from different chain levels, document why the request went to the partner level where the adverse impact is most likely to occur.
  • If an activity is outside the , record the exclusion reason rather than leaving the partner unclassified.
Section 5

Keep evidence that proves the boundary

A defensible boundary file should let a reviewer reproduce the classification. It should show the product or service, the entity, the partner relationship, the activity performed, the upstream or downstream side, the inclusion or exclusion rule, the source citation, and the owner who approved the decision.

The record should also connect to due diligence monitoring. Article 15 requires periodic assessments of the company's own operations and measures, those of subsidiaries, and, where related to the , those of business partners. Review the boundary without undue delay after a significant change, whenever new risks or ineffective measures give reasonable grounds for reassessment, and at least every five years.

  • Boundary register: entity, subsidiary, product or service, activity, upstream or downstream side, direct or indirect partner status, and inclusion outcome.
  • Downstream limit evidence: distribution, transport, or storage contract showing whether the partner acts for or on behalf of the company.
  • Exclusion log: product disposal, customer use, export-controlled downstream activity after authorisation, downstream services, or regulated-financial downstream recipient exclusions, with the cited rule.
  • Information record: data requested, partner level contacted, reason for that level, response received, and gaps still being pursued.
  • Review record: significant-change or new-risk trigger, at-least-five-year regular monitoring result, owner approval, and changes made to the due diligence policy or controls.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Amended Article 8 sets the scoping method, information-request safeguards, and the rule for prioritising requests to the partner where the impact is most likely to occur.
Related guides

Explore more topics

CSDDD adverse impact prioritisation workflow
A CSDDD workflow for identifying actual and potential adverse human rights and environmental impacts, ranking severity and likelihood, and documenting prevention, mitigation, remediation, and stakeholder evidence.
CSDDD Applicability Test After 2026 Changes
Test CSDDD scope after Directive (EU) 2026/470 using the current EU and third-country thresholds, parent-company rules, exclusions, dates, and evidence.
CSDDD chain of activities and supplier due diligence
Explain CSDDD chain-of-activities scope, upstream and downstream boundaries, subsidiaries, direct and indirect business partners, supplier risk segmentation, and evidence.
CSDDD chain of activities boundaries: upstream and downstream FAQ
FAQ on how the CSDDD defines chain of activities boundaries for subsidiaries, direct and indirect business partners, upstream activities, downstream logistics, and evidence.
CSDDD complaints and notifications FAQ
FAQ on Article 14 CSDDD complaint and notification mechanisms, who may complain, follow-up rights, confidentiality, retaliation, and evidence.
CSDDD compliance duties and evidence guide
A source-backed CSDDD compliance guide covering due diligence policy, impact scoping, prevention, corrective action, complaints, monitoring, reporting, climate-plan status, and supervisory evidence.
CSDDD contractual assurances FAQ for Articles 10 and 11
How CSDDD Articles 10 and 11 use contractual assurances with business partners, verification, SME support, action plans, and possible suspension escalation.
CSDDD Deadlines After Directive 2026/470
Current CSDDD calendar: 2027-2028 guidance, 2028 transposition, 2029 application, 2030 reporting, 2031 ESAP submission and review.
CSDDD due diligence checklist
A source-backed CSDDD checklist for scope, risk scoping, impact prioritisation, action plans, complaints, monitoring, communication, evidence, and the removed climate-plan duty.
CSDDD Due Diligence Steps Playbook for Articles 5 and 7-16
A playbook using current CSDDD provisions for policy integration, impact assessment, prioritisation, prevention, correction, remediation, stakeholder engagement, complaints, monitoring, communication, and evidence.
CSDDD FAQ: scope, dates, duties, liability, and evidence
Practical answers on CSDDD scope, current application dates, chain of activities, due diligence duties, complaints, remediation, civil liability, climate plans, and evidence.
CSDDD grievance and remediation workflow guide
Build a CSDDD grievance, notification, stakeholder engagement, and remediation workflow under Directive (EU) 2024/1760 as amended by Directive (EU) 2026/470.
CSDDD Liability and Enforcement After 2026
Understand CSDDD supervision, national penalties, substantiated concerns, remedial orders, and civil-liability analysis after Directive (EU) 2026/470.
CSDDD Non-EU Scope and 2029 Start
Test third-country CSDDD scope using the amended EUR 1.5 billion EU-turnover route and one 26 July 2029 application date.
CSDDD Penalties After Directive 2026/470
Current CSDDD penalty guidance after the EU 5% rule was replaced by a uniform 3% maximum limit: national sanctions, authority decisions, evidence, and country-by-country monitoring.
CSDDD prevention vs mitigation: potential and actual adverse impacts
CSDDD FAQ on when to prevent or mitigate potential adverse impacts, when to end or minimise actual adverse impacts, and what evidence records to keep.
CSDDD remediation FAQ: when companies must remedy adverse impacts
FAQ on CSDDD remediation: when Article 12 requires remedy, how complaints and stakeholder engagement affect the response, and what evidence to keep.
CSDDD Remediation Plan Template: Article 12, 13 and 14 evidence
A CSDDD remediation plan template for actual adverse impacts, complaint inputs, stakeholder engagement, action records, and monitoring under the Directive as amended in 2026.
CSDDD requirements: scope, due diligence, climate plan, and evidence
A source-backed map of current CSDDD requirements across scope, due diligence policy, impact assessment, complaints, remediation, monitoring, communication, and the removed climate-plan duty.
CSDDD risk prioritisation FAQ: severity, likelihood, and evidence
How to prioritise CSDDD adverse impacts when teams cannot address everything at once, using severity, likelihood, stakeholder evidence, and a reviewable rationale.
CSDDD Scope Thresholds After 2026
Understand amended CSDDD thresholds for EU and non-EU companies, group scope, exclusions, two-year evidence, and the 2029 application date.
CSDDD Supplier Contract Clause Review Workflow
Review supplier contract clauses against CSDDD Articles 10 and 11: contractual assurances, verification, SME fairness, support, action plans, and escalation evidence.
CSDDD Supplier Contract Clauses: Articles 10 and 11 Evidence
How to use CSDDD supplier contract clauses without treating clauses as a substitute for due diligence: contractual assurances, verification, SME support, action plans, limits, and evidence.
CSDDD supplier human rights impact scoring template
A CSDDD supplier impact scoring template for Article 8 identification, Article 9 prioritisation, severity, likelihood, stakeholder input, chain-of-activities boundaries, and evidence records.
CSDDD vs CSRD: Due Diligence and Reporting Compared
Compare CSDDD due diligence duties with CSRD sustainability reporting, including scope, timing, Article 16 reporting, evidence overlap, assurance, and enforcement.
CSDDD vs German LkSG Comparison
Compare the EU CSDDD with Germany's LkSG without mixing directive duties, national-law duties, chain boundaries, complaints, reporting, and enforcement routes.
CSDDD vs OECD Guidelines
Compare the binding EU CSDDD with the OECD Guidelines for responsible business conduct across scope, due diligence duties, business relationships, remediation, and evidence.
Did CSDDD Keep Its Climate Plan Duty?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty. Understand what changed and which separate obligations may remain.
Does CSDDD Still Have Scope Waves?
No separate company scope waves remain after Directive (EU) 2026/470: transposition is due in 2028 and all companies remaining in scope apply from 2029.
Does Franchising Trigger CSDDD Scope?
Directive (EU) 2026/470 retained the CSDDD franchise and licensing scope route but raised its royalty and turnover thresholds. Learn the current test.
How CSDDD overlaps with OECD, UNGP, and ILO standards
FAQ on how OECD responsible business conduct guidance, the UN Guiding Principles, and ILO labour standards inform CSDDD due diligence without being the same legal instrument.
How Does CSDDD Civil Liability Work Now?
Directive (EU) 2026/470 removed the uniform EU liability test but retained compensation and procedural safeguards. Claims still depend on Member State law.
Is a Climate Plan Still Required by CSDDD?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty; separate CSRD and national obligations need their own review.
What Did Omnibus Change in CSDDD?
CSDDD Omnibus status as of July 2026: what Directives (EU) 2025/794 and 2026/470 adopted, which dates apply, and which old duties were removed.
What EU Turnover Triggers CSDDD Scope?
A third-country company generally needs more than EUR 1.5 billion net turnover in the EU under Directive (EU) 2026/470; learn the evidence and timing.