CSDDDCompliance guideEU

CSDDD compliance guide

This page helps translate Directive (EU) 2024/1760 into operating controls, evidence records, and supervisory-ready documentation.

The focus is the core due diligence cycle: policy integration, impact identification and prioritisation, prevention, corrective action, remediation, complaints, stakeholder engagement, monitoring, communication, and accurate treatment of the removed climate-plan duty.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 31, 2026
Sections
7

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 31, 2026
Overview

CSDDD compliance requires a risk-based due diligence system, not only a supplier questionnaire. After Directive (EU) 2026/470, EU companies generally need more than 5,000 employees and EUR 1.5 billion worldwide turnover, while third-country companies use a EUR 1.5 billion Union-turnover route. National measures apply from 26 July 2029. In-scope companies need policies, assessment and prioritisation, appropriate action, stakeholder engagement, complaints, remediation, monitoring, and public communication. The former standalone Article 22 climate-plan duty is no longer current CSDDD law.

Section 1

Build the compliance baseline around the amended Articles 7 to 16

A defensible CSDDD programme starts by mapping each obligation to an internal control owner and an evidence record. Article 7 is the anchor: due diligence must be integrated into relevant policies and risk management systems, and the company must have a due diligence policy that supports risk-based due diligence.

The policy record should include the company's long-term due diligence approach, a code of conduct for the company, subsidiaries, and relevant business partners, and the processes used to implement due diligence and verify code-of-conduct compliance. Keep phase-in dates and national transposition status in a separate legal tracker, because timing can change through EU amendments and Member State implementation.

  • Board or executive governance record: confirms who owns CSDDD implementation, escalation, and resourcing.
  • Due diligence policy: states the long-term approach, code of conduct, and procedures for integrating due diligence into business processes.
  • Risk management link: shows how CSDDD impact work connects to enterprise risk, procurement, legal, sustainability, HR, and site-level controls.
  • Employee consultation record: documents consultation with employees and their representatives before adopting or updating the due diligence policy.
  • Policy update trigger: captures significant changes and the scheduled review of the policy at least every 24 months.
Section 2

Identify, assess, and prioritise adverse impacts

Amended Article 8 starts with a scoping exercise based solely on reasonably available information across own operations, subsidiaries, and relevant business partners. The company then performs an in-depth assessment in the areas where impacts are most likely and most severe. A generic supplier score does not meet that sequence.

Article 9 allows prioritisation when all identified impacts cannot be handled at the same time and to their full extent. Prioritisation must be based on severity and likelihood, and the record should show why the most severe and most likely impacts were handled first.

  • Map operations, subsidiaries, and chain-of-activities business partners where adverse impacts are most likely and most severe.
  • Use quantitative and qualitative inputs, including independent reports, site data, complaints, and notification-channel evidence. Request partner information only where necessary; for partners with fewer than 5,000 employees, request it only when the information cannot reasonably be obtained elsewhere.
  • Record each identified impact as actual or potential, human rights or environmental, affected stakeholder group, location, business relationship, severity, likelihood, and information source.
  • Prioritise only when simultaneous full treatment is not feasible, and document the severity and likelihood criteria used.
  • After the most severe and likely impacts are addressed, keep a backlog for less severe or less likely impacts with owners and next review triggers.
  • Examples of human-rights impacts include child labour, forced labour, unsafe working conditions, interference with freedom of association, and unlawful displacement where the Annex conditions are met. Environmental impacts are tied to the specific prohibitions and obligations in the Annex, including listed duties on pollution, waste, biodiversity, and hazardous substances; do not substitute a generic ESG issue list.
Section 3

Prevent potential impacts and correct actual impacts

CSDDD separates potential and actual impacts. For potential impacts, Article 10 requires to prevent them or, where prevention is not possible or not immediately possible, adequately mitigate them. For actual impacts, Article 11 requires appropriate measures to bring the impact to an end or, where that is not immediately possible, minimise its extent.

A useful compliance file should show whether the impact is caused by the company, jointly caused, or linked through a business partner. That analysis drives prevention, corrective action, contractual assurance, verification, operational change, SME support, collaboration, suspension, or remediation. Directive (EU) 2026/470 removed termination but retained last-resort restrictions on new or extended relationships, enhanced action plans, and suspension where legally available and not expected to cause manifestly more severe impacts.

  • Prevention action plan: use for potential impacts that require structured measures, timelines, and qualitative or quantitative improvement indicators.
  • Corrective action plan: use for actual impacts that cannot immediately be brought to an end and need staged action.
  • Business partner controls: document contractual assurances, code-of-conduct flow-down, verification method, and any independent third-party verification.
  • Operational changes: record changes to purchasing practices, design, distribution, facilities, production, infrastructure, business plans, or overall strategies.
  • SME support: where relevant, show targeted and proportionate support such as capacity-building, training, management-system upgrades, financing support, or continued sourcing guarantees.
  • Relationship action: document the legal basis, proportionality, ability to influence the partner, and expected consequences of suspension, disengagement, or continued engagement; termination is no longer a mandatory CSDDD last resort.
Section 4

Handle remediation, complaints, and stakeholder engagement as operating controls

Article 12 remediation remains tied to the company's involvement in an actual . For Article 13 engagement, use the stakeholder definition and consultation stages as amended by Directive (EU) 2026/470 rather than the broader original list.

Article 14 requires a notification mechanism and complaints procedure. The procedure should be fair, publicly available, accessible, predictable, and transparent. It should allow affected or potentially affected persons and their legitimate representatives, trade unions and worker representatives for workers in the chain concerned, and civil society organisations active and experienced in the relevant area for environmental complaints to raise concerns. Complaints require confidentiality and anti-retaliation safeguards; the notification mechanism must permit anonymous or confidential submissions under national law.

  • Remediation record: impact, affected person or community, company implication, chosen remedy, proportionality rationale, owner, status, and close-out evidence.
  • Stakeholder engagement file: consulted stakeholder group, information shared, additional information requests, barriers to engagement, confidentiality measures, and how input changed the decision.
  • Complaints procedure: public channel, eligibility categories, acknowledgement, assessment, founded or unfounded decision, reasons, follow-up, meeting option, and remediation discussion record.
  • Notification mechanism: anonymous or confidential intake route for information about actual or potential adverse impacts.
  • Retaliation control: records measures taken to protect complainant or notifier identity and safety where information must be shared.
Section 5

Reopen due diligence for acquisitions, restructuring, and new markets

Run a change-event review before an acquisition, merger, restructuring, new country entry, major product or service launch, material input change, or new form of business relationship. The review should identify impacts that the current policy, partner map, complaint channel, and action plans do not cover.

After closing an acquisition or restructuring, integrate the acquired entity or changed operation into the CSDDD system without waiting for the five-year cycle. Current Article 15 requires assessment without undue delay after a significant change and when there are reasonable grounds to believe new risks have arisen or existing measures are no longer adequate or effective.

  • Pre-transaction file: target or project entities, operations, products and services, countries, workforce, subsidiaries, business partners, known complaints, investigations, environmental liabilities, action plans, remedy commitments, and evidence gaps.
  • Decision record: salient actual and potential impacts, affected rightsholders, chain-of-activities boundary, proposed prevention or corrective measures, deal or launch condition, owner, budget, timeline, and unresolved risk accepted by the approving body.
  • Integration plan: policy and training rollout, partner and impact-register migration, complaint-channel access, worker and community communication, contract and purchasing-practice review, supplier support, remediation continuity, monitoring indicators, and Article 16 reporting boundary.
  • Change triggers after integration: facility closure, workforce transfer, supplier replacement, production relocation, new raw material, changed logistics route, product redesign, new customer or market, serious complaint, failed corrective action, or loss of access to affected stakeholders.
  • Evidence control: preserve the pre-change baseline and the reasons for each boundary, priority, action, and remedy decision so later reviewers can distinguish inherited impacts from impacts caused or jointly caused after the change.
Section 6

Monitor, communicate, and separate any retained climate-plan evidence

Article 15 requires assessment of implementation, adequacy, and effectiveness. Directive (EU) 2026/470 moved the regular cycle from at least every 12 months to at least every five years, while retaining event-driven reassessment after significant change or when reasonable grounds indicate new risks or ineffective measures.

Article 16 requires public communication through an annual website statement unless the company is subject to the listed sustainability-reporting requirements, including the relevant exemptions. Publish in the required Union language and, where different, a language customary in international business, no later than 12 months after the balance-sheet date; a third-country company's statement also identifies its authorised representative. The delegated acts specifying content and criteria are due by 31 March 2029, and the reporting measures apply for financial years starting on or after 1 January 2030. Directive (EU) 2026/470 removed the separate CSDDD Article 22 climate-transition-plan duty.

  • Monitoring pack: assessment date, significant-change trigger, indicators used, findings, stakeholder information considered, and updates to policy, impact register, or measures.
  • Annual due diligence statement: exemption analysis, publication language, website location, reporting boundary, covered matters, approval record, and ESAP submission readiness from 1 January 2031 where applicable.
  • If a climate transition plan remains required elsewhere: record the target, milestones, emissions coverage, decarbonisation levers, and product or service portfolio changes required by that separate source.
  • Climate status evidence: record removal of the standalone CSDDD duty and map any retained plan to its separate current legal, contractual, risk-management, or voluntary basis.
  • Document retention: keep identified impacts, assessments, action plans, contracts, verifications, remediation measures, monitoring records, notifications, and complaints together for at least five years.
Recommended next step

Turn CSDDD obligations into an evidence workflow

This CSDDD guide helps connect due diligence duties, impact records, complaint channels, climate-plan evidence, and supervisory response files before teams publish or report compliance claims.

Section 7

Prepare for supervisory and enforcement review

CSDDD compliance evidence should be built for supervisory review, not only internal assurance. Member States must designate supervisory authorities to supervise compliance with national provisions adopted under the amended Directive. Track the final transposition law for information powers, investigations, orders, remediation, penalties, interim measures, and appeal procedures.

Directive (EU) 2026/470 requires Member States to set the maximum limit for pecuniary penalties at 3% of the company's net worldwide turnover in the preceding financial year, or 3% of consolidated worldwide turnover for the specified ultimate-parent routes. National law still determines the penalty process and the amount imposed in a case. Track administrative supervision, substantiated concerns, investigation records, remedial-action periods, effective, proportionate, and dissuasive penalties, and possible public statements for unpaid pecuniary penalties.

  • Authority-response file: designated supervisory authority, contact point, information requests, submissions, response dates, and legal review notes.
  • Substantiated-concern register: concerns received from authorities or stakeholders, objective basis, competence routing, assessment outcome, and protective measures for identity information.
  • Investigation record: nature and result of investigation, remedial-action period, enforcement action, and evidence supplied to the authority.
  • Penalty factors file: gravity, duration, severity of impacts, prevention or corrective investments, collaboration, prioritisation rationale, previous infringements, remedial action, and financial benefit or loss avoided.
  • Non-EU company file: authorised representative designation, accepted appointment, contact details, powers and resources, and supervisory authority notification.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding source for the amended 3% maximum limit for pecuniary penalties and the current national-law civil-liability framework.
commission.europa.eu
Referenced sections
  • The Commission page describes administrative supervision through Member State authorities and coordinated EU-level supervision.
"Member States will designate one or more authorities to supervise and enforce the rules"
eur-lex.europa.eu
Referenced sections
  • The EUR-Lex summary confirms annual public due diligence communication, five-year documentation retention, and climate transition-plan content.
"keeping all documentation on their due diligence compliance for at least five years"
Related guides

Explore more topics

CSDDD adverse impact prioritisation workflow
A CSDDD workflow for identifying actual and potential adverse human rights and environmental impacts, ranking severity and likelihood, and documenting prevention, mitigation, remediation, and stakeholder evidence.
CSDDD Applicability Test After 2026 Changes
Test CSDDD scope after Directive (EU) 2026/470 using the current EU and third-country thresholds, parent-company rules, exclusions, dates, and evidence.
CSDDD chain of activities and supplier due diligence
Explain CSDDD chain-of-activities scope, upstream and downstream boundaries, subsidiaries, direct and indirect business partners, supplier risk segmentation, and evidence.
CSDDD Chain of Activities Boundaries
Define CSDDD upstream and downstream chain of activities boundaries for subsidiaries, direct and indirect business partners, distribution, transport, storage, and records.
CSDDD chain of activities boundaries: upstream and downstream FAQ
FAQ on how the CSDDD defines chain of activities boundaries for subsidiaries, direct and indirect business partners, upstream activities, downstream logistics, and evidence.
CSDDD complaints and notifications FAQ
FAQ on Article 14 CSDDD complaint and notification mechanisms, who may complain, follow-up rights, confidentiality, retaliation, and evidence.
CSDDD contractual assurances FAQ for Articles 10 and 11
How CSDDD Articles 10 and 11 use contractual assurances with business partners, verification, SME support, action plans, and possible suspension escalation.
CSDDD Deadlines After Directive 2026/470
Current CSDDD calendar: 2027-2028 guidance, 2028 transposition, 2029 application, 2030 reporting, 2031 ESAP submission and review.
CSDDD due diligence checklist
A source-backed CSDDD checklist for scope, risk scoping, impact prioritisation, action plans, complaints, monitoring, communication, evidence, and the removed climate-plan duty.
CSDDD Due Diligence Steps Playbook for Articles 5 and 7-16
A playbook using current CSDDD provisions for policy integration, impact assessment, prioritisation, prevention, correction, remediation, stakeholder engagement, complaints, monitoring, communication, and evidence.
CSDDD FAQ: scope, dates, duties, liability, and evidence
Practical answers on CSDDD scope, current application dates, chain of activities, due diligence duties, complaints, remediation, civil liability, climate plans, and evidence.
CSDDD grievance and remediation workflow guide
Build a CSDDD grievance, notification, stakeholder engagement, and remediation workflow under Directive (EU) 2024/1760 as amended by Directive (EU) 2026/470.
CSDDD Liability and Enforcement After 2026
Understand CSDDD supervision, national penalties, substantiated concerns, remedial orders, and civil-liability analysis after Directive (EU) 2026/470.
CSDDD Non-EU Scope and 2029 Start
Test third-country CSDDD scope using the amended EUR 1.5 billion EU-turnover route and one 26 July 2029 application date.
CSDDD Penalties After Directive 2026/470
Current CSDDD penalty guidance after the EU 5% rule was replaced by a uniform 3% maximum limit: national sanctions, authority decisions, evidence, and country-by-country monitoring.
CSDDD prevention vs mitigation: potential and actual adverse impacts
CSDDD FAQ on when to prevent or mitigate potential adverse impacts, when to end or minimise actual adverse impacts, and what evidence records to keep.
CSDDD remediation FAQ: when companies must remedy adverse impacts
FAQ on CSDDD remediation: when Article 12 requires remedy, how complaints and stakeholder engagement affect the response, and what evidence to keep.
CSDDD Remediation Plan Template: Article 12, 13 and 14 evidence
A CSDDD remediation plan template for actual adverse impacts, complaint inputs, stakeholder engagement, action records, and monitoring under the Directive as amended in 2026.
CSDDD requirements: scope, due diligence, climate plan, and evidence
A source-backed map of current CSDDD requirements across scope, due diligence policy, impact assessment, complaints, remediation, monitoring, communication, and the removed climate-plan duty.
CSDDD risk prioritisation FAQ: severity, likelihood, and evidence
How to prioritise CSDDD adverse impacts when teams cannot address everything at once, using severity, likelihood, stakeholder evidence, and a reviewable rationale.
CSDDD Scope Thresholds After 2026
Understand amended CSDDD thresholds for EU and non-EU companies, group scope, exclusions, two-year evidence, and the 2029 application date.
CSDDD Supplier Contract Clause Review Workflow
Review supplier contract clauses against CSDDD Articles 10 and 11: contractual assurances, verification, SME fairness, support, action plans, and escalation evidence.
CSDDD Supplier Contract Clauses: Articles 10 and 11 Evidence
How to use CSDDD supplier contract clauses without treating clauses as a substitute for due diligence: contractual assurances, verification, SME support, action plans, limits, and evidence.
CSDDD supplier human rights impact scoring template
A CSDDD supplier impact scoring template for Article 8 identification, Article 9 prioritisation, severity, likelihood, stakeholder input, chain-of-activities boundaries, and evidence records.
CSDDD vs CSRD: Due Diligence and Reporting Compared
Compare CSDDD due diligence duties with CSRD sustainability reporting, including scope, timing, Article 16 reporting, evidence overlap, assurance, and enforcement.
CSDDD vs German LkSG Comparison
Compare the EU CSDDD with Germany's LkSG without mixing directive duties, national-law duties, chain boundaries, complaints, reporting, and enforcement routes.
CSDDD vs OECD Guidelines
Compare the binding EU CSDDD with the OECD Guidelines for responsible business conduct across scope, due diligence duties, business relationships, remediation, and evidence.
Did CSDDD Keep Its Climate Plan Duty?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty. Understand what changed and which separate obligations may remain.
Does CSDDD Still Have Scope Waves?
No separate company scope waves remain after Directive (EU) 2026/470: transposition is due in 2028 and all companies remaining in scope apply from 2029.
Does Franchising Trigger CSDDD Scope?
Directive (EU) 2026/470 retained the CSDDD franchise and licensing scope route but raised its royalty and turnover thresholds. Learn the current test.
How CSDDD overlaps with OECD, UNGP, and ILO standards
FAQ on how OECD responsible business conduct guidance, the UN Guiding Principles, and ILO labour standards inform CSDDD due diligence without being the same legal instrument.
How Does CSDDD Civil Liability Work Now?
Directive (EU) 2026/470 removed the uniform EU liability test but retained compensation and procedural safeguards. Claims still depend on Member State law.
Is a Climate Plan Still Required by CSDDD?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty; separate CSRD and national obligations need their own review.
What Did Omnibus Change in CSDDD?
CSDDD Omnibus status as of July 2026: what Directives (EU) 2025/794 and 2026/470 adopted, which dates apply, and which old duties were removed.
What EU Turnover Triggers CSDDD Scope?
A third-country company generally needs more than EUR 1.5 billion net turnover in the EU under Directive (EU) 2026/470; learn the evidence and timing.