CSDDD vs German LkSG comparison Keep EU and German duties separate
This page helps compare the EU Corporate Sustainability Due Diligence Directive with Germany's national LkSG without copying scope, chain, complaints, reporting, or enforcement assumptions across regimes.
The LkSG has applied since 1 January 2023 and, since 2024, covers enterprises with at least 1,000 employees in Germany. CSDDD has a later application date and a much higher scope threshold.
CSDDD and the German both sit in the corporate due diligence family, but they are not interchangeable. CSDDD is an EU directive that Member States transpose into national law and that sets a chain-of-activities due diligence framework for large EU and non-EU companies with significant EU activity. The German LkSG is a national supply-chain due diligence law. Treat CSDDD work as a directive-to-national-implementation program, and treat LkSG work as a German-law program that may share supplier risk data but still needs its own legal scope check.
Comparison matrix
CSDDD vs German LkSG: what changes in practice
The rows below separate the EU directive requirements from the German-law workstream so teams do not merge scope, chain boundaries, complaints channels, reports, or enforcement records.
CSDDD is an EU directive for very large EU and non-EU companies. After Directive (EU) 2026/470, it retains amended risk-based due diligence but no longer contains a standalone climate-transition-plan duty.
Second framework
German LkSG
German is a German national supply-chain due diligence regime. Use it as a separate legal workstream: confirm coverage, supplier boundary, complaint process, reporting, and enforcement against current German official material before reusing CSDDD conclusions.
After Directive (EU) 2026/470, CSDDD generally applies to EU companies above 5,000 employees and EUR 1.5 billion worldwide turnover, and third-country companies above EUR 1.5 billion Union turnover, including relevant ultimate-parent routes. A separate franchise and licensing route remains at more than EUR 75 million in qualifying Union royalties and more than EUR 275 million turnover.
The applies to enterprises, regardless of legal form, that have their central administration, principal place of business, administrative headquarters, statutory seat, or a domestic branch in Germany and generally employ at least 1,000 employees in Germany. The statutory calculation includes employees posted abroad and, for a parent enterprise, employees of German group companies.
An enterprise can be subject to the now but fall outside the much narrower CSDDD scope. Prepare one entity and employee-count analysis for the LkSG and a separate employee-and-turnover analysis for CSDDD.
CSDDD is Directive (EU) 2024/1760. It must be transposed into national law and does not reduce existing national human, employment, social, environmental, or climate provisions.
The is already binding German federal law. BAFA supervises compliance. The current German government plans to replace it when implementing CSDDD, but that policy plan does not repeal or suspend the law.
CSDDD uses a chain-of-activities concept. It covers own operations, subsidiaries, and business partners where related to the company's chains of activities, with mapping and in-depth assessment focused on areas where adverse impacts are most likely and severe.
The supply chain covers all steps in Germany and abroad needed to produce goods or provide services, from raw-material extraction to delivery to the end customer. It includes the enterprise's own business area and direct suppliers. Indirect suppliers enter the specific duties in section 9 when the enterprise has suggesting that a human-rights or environment-related violation may be occurring.
Use one supplier map if practical, but label each node with the rule that brings it into review. CSDDD's chain of activities includes specified upstream and downstream activities; the uses its own direct-supplier and substantiated-knowledge rules.
CSDDD requires risk-based human rights and environmental due diligence: integrate due diligence into policies and risk management systems, identify and prioritise adverse impacts, prevent and mitigate potential impacts, bring actual impacts to an end or minimise them, provide remediation where required, engage stakeholders, monitor effectiveness, communicate publicly, and keep documentation.
section 3 requires an appropriate and effective risk-management system, internal responsibility, regular risk analyses, a policy statement, preventive measures, remedial action, a complaints procedure, and documentation and reporting. These are duties of effort: section 3 states that a breach does not itself create civil liability under the LkSG, while civil liability arising independently of the Act remains unaffected.
Build a crosswalk from control to source. Mark a control as reusable only when the same record satisfies both the CSDDD article-level need and the German requirement.
After Directive (EU) 2026/470, CSDDD uses a regular monitoring cycle of at least every five years plus event-driven reassessment, public communication under amended Article 16, and traceable due diligence records.
section 10 requires continuous documentation retained for at least seven years and still contains an annual-report and website-publication rule. The statute also contains a BAFA submission route, but BAFA stopped examining company reports and disabled report submission through its portal in 2025 while legislative reform remained pending. Keep the underlying due diligence documentation and check current BAFA instructions before treating the statutory reporting workflow as operational.
CSDDD requires accessible, publicly available notification and complaints procedures with appropriate follow-up. Complaints may come from affected persons, their legitimate representatives, trade unions and workers' representatives, and experienced civil-society organisations for environmental impacts.
section 8 requires an appropriate internal complaints procedure, or participation in an appropriate external procedure, through which people can report human-rights and environment-related risks and violations caused by the enterprise's own business area or by direct or indirect suppliers. The enterprise must publish rules of procedure, protect confidentiality, confirm receipt, discuss the facts with the reporting person, and review effectiveness at least annually and when material risk changes occur.
A shared intake tool can serve both regimes only if it reaches the relevant people, routes each report to the applicable procedure, protects confidentiality, records follow-up, and supports each law's review requirements.
CSDDD relies on Member State supervisory authorities with powers to require information, investigate, order cessation, impose penalties or interim measures, and publish penalty decisions. After Directive (EU) 2026/470, civil-liability conditions come from national law, with full compensation protected where national-law liability is established for damage caused by a covered due diligence failure.
BAFA monitors and enforces the . It may require corrective action, summon persons, order enterprises to provide information and documents, enter business premises during operating hours, and impose coercive payments. Section 24 creates offence-specific administrative fines, including turnover-based fines for certain breaches by enterprises with average annual turnover above EUR 400 million. Section 22 also permits exclusion from public procurement for specified final fines, subject to its thresholds and maximum periods.
Keep enforcement response playbooks separate. Shared evidence can support both, but authority powers, response deadlines, penalty logic, and litigation exposure need regime-specific review.
CSDDD evidence should show the article-level basis for scope, chain-of-activities mapping, due diligence measures, complaints, monitoring, public communication, and supervisory authority responses. Record the deleted Article 22 climate-plan duty only as legislative history.
evidence should show the German entity and employee-count analysis, risk-management responsibilities, annual and event-driven risk analyses, policy statement, preventive and remedial measures, complaint handling, effectiveness reviews, and section 10 documentation and reporting. Supplier questionnaires, audit results, complaints, and remediation logs may support both regimes when each legal mapping is recorded.
Use one evidence repository, but not one legal conclusion. Every reused record should identify the source, obligation, owner, date, affected entity, supplier boundary, and publication or authority-use status.
Directive (EU) 2026/470 removed the standalone CSDDD climate-transition-plan duty. Any remaining plan or disclosure requirement must be sourced to CSRD, national law, a sector rule, contract, financing term, or voluntary commitment.
Do not add a German climate-transition-plan obligation by analogy. If a German entity also reports under another sustainability regime, handle that under the relevant reporting source, not under LkSG by assumption.
After Directive (EU) 2026/470, CSDDD generally applies to EU companies above 5,000 employees and EUR 1.5 billion worldwide turnover, and third-country companies above EUR 1.5 billion Union turnover, including relevant ultimate-parent routes. A separate franchise and licensing route remains at more than EUR 75 million in qualifying Union royalties and more than EUR 275 million turnover.
The applies to enterprises, regardless of legal form, that have their central administration, principal place of business, administrative headquarters, statutory seat, or a domestic branch in Germany and generally employ at least 1,000 employees in Germany. The statutory calculation includes employees posted abroad and, for a parent enterprise, employees of German group companies.
An enterprise can be subject to the now but fall outside the much narrower CSDDD scope. Prepare one entity and employee-count analysis for the LkSG and a separate employee-and-turnover analysis for CSDDD.
CSDDD is Directive (EU) 2024/1760. It must be transposed into national law and does not reduce existing national human, employment, social, environmental, or climate provisions.
The is already binding German federal law. BAFA supervises compliance. The current German government plans to replace it when implementing CSDDD, but that policy plan does not repeal or suspend the law.
CSDDD uses a chain-of-activities concept. It covers own operations, subsidiaries, and business partners where related to the company's chains of activities, with mapping and in-depth assessment focused on areas where adverse impacts are most likely and severe.
The supply chain covers all steps in Germany and abroad needed to produce goods or provide services, from raw-material extraction to delivery to the end customer. It includes the enterprise's own business area and direct suppliers. Indirect suppliers enter the specific duties in section 9 when the enterprise has suggesting that a human-rights or environment-related violation may be occurring.
Use one supplier map if practical, but label each node with the rule that brings it into review. CSDDD's chain of activities includes specified upstream and downstream activities; the uses its own direct-supplier and substantiated-knowledge rules.
CSDDD requires risk-based human rights and environmental due diligence: integrate due diligence into policies and risk management systems, identify and prioritise adverse impacts, prevent and mitigate potential impacts, bring actual impacts to an end or minimise them, provide remediation where required, engage stakeholders, monitor effectiveness, communicate publicly, and keep documentation.
section 3 requires an appropriate and effective risk-management system, internal responsibility, regular risk analyses, a policy statement, preventive measures, remedial action, a complaints procedure, and documentation and reporting. These are duties of effort: section 3 states that a breach does not itself create civil liability under the LkSG, while civil liability arising independently of the Act remains unaffected.
Build a crosswalk from control to source. Mark a control as reusable only when the same record satisfies both the CSDDD article-level need and the German requirement.
After Directive (EU) 2026/470, CSDDD uses a regular monitoring cycle of at least every five years plus event-driven reassessment, public communication under amended Article 16, and traceable due diligence records.
section 10 requires continuous documentation retained for at least seven years and still contains an annual-report and website-publication rule. The statute also contains a BAFA submission route, but BAFA stopped examining company reports and disabled report submission through its portal in 2025 while legislative reform remained pending. Keep the underlying due diligence documentation and check current BAFA instructions before treating the statutory reporting workflow as operational.
CSDDD requires accessible, publicly available notification and complaints procedures with appropriate follow-up. Complaints may come from affected persons, their legitimate representatives, trade unions and workers' representatives, and experienced civil-society organisations for environmental impacts.
section 8 requires an appropriate internal complaints procedure, or participation in an appropriate external procedure, through which people can report human-rights and environment-related risks and violations caused by the enterprise's own business area or by direct or indirect suppliers. The enterprise must publish rules of procedure, protect confidentiality, confirm receipt, discuss the facts with the reporting person, and review effectiveness at least annually and when material risk changes occur.
A shared intake tool can serve both regimes only if it reaches the relevant people, routes each report to the applicable procedure, protects confidentiality, records follow-up, and supports each law's review requirements.
CSDDD relies on Member State supervisory authorities with powers to require information, investigate, order cessation, impose penalties or interim measures, and publish penalty decisions. After Directive (EU) 2026/470, civil-liability conditions come from national law, with full compensation protected where national-law liability is established for damage caused by a covered due diligence failure.
BAFA monitors and enforces the . It may require corrective action, summon persons, order enterprises to provide information and documents, enter business premises during operating hours, and impose coercive payments. Section 24 creates offence-specific administrative fines, including turnover-based fines for certain breaches by enterprises with average annual turnover above EUR 400 million. Section 22 also permits exclusion from public procurement for specified final fines, subject to its thresholds and maximum periods.
Keep enforcement response playbooks separate. Shared evidence can support both, but authority powers, response deadlines, penalty logic, and litigation exposure need regime-specific review.
CSDDD evidence should show the article-level basis for scope, chain-of-activities mapping, due diligence measures, complaints, monitoring, public communication, and supervisory authority responses. Record the deleted Article 22 climate-plan duty only as legislative history.
evidence should show the German entity and employee-count analysis, risk-management responsibilities, annual and event-driven risk analyses, policy statement, preventive and remedial measures, complaint handling, effectiveness reviews, and section 10 documentation and reporting. Supplier questionnaires, audit results, complaints, and remediation logs may support both regimes when each legal mapping is recorded.
Use one evidence repository, but not one legal conclusion. Every reused record should identify the source, obligation, owner, date, affected entity, supplier boundary, and publication or authority-use status.
Directive (EU) 2026/470 removed the standalone CSDDD climate-transition-plan duty. Any remaining plan or disclosure requirement must be sourced to CSRD, national law, a sector rule, contract, financing term, or voluntary commitment.
Do not add a German climate-transition-plan obligation by analogy. If a German entity also reports under another sustainability regime, handle that under the relevant reporting source, not under LkSG by assumption.
How should teams decide what belongs in CSDDD work versus German LkSG work?
Start with legal status: CSDDD requires national implementation and applies from 26 July 2029; the is current German law and has applied to enterprises with at least 1,000 employees in Germany since 2024.
Scope each entity twice when Germany is relevant: once against CSDDD criteria and once against current German source material.
Keep CSDDD chain-of-activities and Article 16 language separate from the supply-chain, substantiated-knowledge, section 10 reporting, and section 3 civil-liability rules.
Reuse supplier risk evidence only with obligation-level labels, not as a blanket statement that one regime satisfies the other.
What this comparison should and should not be used for
This page is relevant when a Germany-relevant supplier due diligence program also needs to prepare for CSDDD. It helps teams avoid three common errors: treating CSDDD as if it automatically replaces German work, importing German-law conclusions into CSDDD scope, or reusing supplier evidence without checking the obligation it supports.
The current statutory position matters because announced reforms do not change the until an amending law enters into force. Track proposals separately from the duties that BAFA can enforce today.
Use it for internal crosswalks, supplier-risk evidence maps, and compliance roadmap scoping.
Do not use it as a substitute for a German applicability assessment.
Do not copy CSDDD penalty, civil-liability, transition-plan, or reporting language into German materials without a German source.
Use a source-labeled crosswalk to separate CSDDD obligations from German LkSG obligations while reusing supplier evidence only where both legal bases support it.
The practical output should be a crosswalk, not a merged checklist. Each evidence item should show the entity in scope, the supplier or business-partner boundary, the adverse-impact category, the relevant source, the owner, the last review date, the complaint or remediation status, and whether the record is used in public reporting or authority correspondence.
For CSDDD, cover policies and risk management systems, impact identification and prioritisation, prevention and corrective action, remediation, stakeholder engagement, notification and complaints, monitoring, public communication, record retention, supervisory response, and a history entry showing Article 22 was removed. For the , add the section 1 employee calculation, annual and event-driven risk analysis, policy statement, direct- and indirect-supplier triggers, complaints-procedure effectiveness review, seven-year documentation, reporting status, and BAFA correspondence.
Label CSDDD records by article-level topic, such as chain mapping, complaints, monitoring, and communication; retain the former transition-plan duty only as superseded Article 22 history.
Label records by statutory topic and supplier tier, including whether section 9 triggered action for an indirect supplier.
Keep one owner for shared supplier evidence and separate legal owners for CSDDD and German conclusions.
BAFA states that it stopped examining reports under sections 12 and 13 and that submission through the BAFA access is no longer possible while the legislative amendment proceeds.