The creates a due diligence framework for very large EU and non-EU companies. Teams must decide whether the entity is in scope, when national rules apply, which operations and business partners sit inside the chain of activities, which adverse impacts need action, and which records show how the program works.
Browse sub-FAQs
Choose the question set you need
These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.
Use the binding Directive (EU) 2026/470 timetable: Member States transpose by 26 July 2028, and national measures apply from 26 July 2029 to every company remaining in amended Article 2 scope. Article 16 measures follow for financial years starting on or after 1 January 2030.
The broader simplification package is no longer merely proposal-stage. Label COM(2025)80 and COM(2025)81 as historical proposals, Directive (EU) 2025/794 as an adopted but superseded timing step, Directive (EU) 2026/470 as the current amendment, and each later Member State measure as national implementation.
26 July 2028: Member State transposition and supervisory-authority notification deadline.
26 July 2029: all companies remaining in amended scope begin applying national measures.
1 January 2030: Article 16 measures apply for financial years starting on or after this date.
Guidance, Article 16, ESAP, and review milestones remain separate calendar dependencies.
After Directive (EU) 2026/470, the main scope test generally covers EU companies with more than 5,000 employees on average and more than EUR 1.5 billion net worldwide turnover, and third-country companies with more than EUR 1.5 billion net turnover in the Union. Relevant ultimate-parent group routes remain, as does a separate franchise and licensing route above EUR 75 million in qualifying Union royalties and EUR 275 million turnover.
Each route must be met for two consecutive financial years and ceases only after the conditions are not met for each of the last two relevant years. Article 2 excludes alternative investment funds (AIFs) and undertakings for collective investment in transferable securities (UCITS), but their managers and other regulated financial undertakings require separate entity tests.
Micro companies and SMEs do not meet the direct size thresholds, but they can be indirectly affected when an in-scope customer asks for necessary sustainability or adverse-impact information. Treat those requests as evidence requests, not as proof that the smaller business is directly regulated. For an Article 8 in-depth assessment, an in-scope company may ask a partner with fewer than 5,000 employees only when it cannot reasonably obtain the information elsewhere.
Identify the exact legal entity and whether it is EU or non-EU.
Measure employee and turnover thresholds using the relevant financial year and group position.
Check whether the company is an ultimate parent or a third-country company with Union turnover, and separately test the amended franchise and licensing thresholds where relevant.
Record why each in-scope, out-of-scope, or indirectly affected conclusion was reached.
chain of activities is not a generic supply-chain label. It covers upstream business-partner activities linked to producing goods or providing services, including design, extraction, sourcing, manufacture, transport, storage, supply of raw materials, products or parts, and development of the product or service. It also covers downstream distribution, transport, and storage of products when those business partners act for or on behalf of the company.
The Directive excludes disposal of the product from the definition, and the original text does not include downstream service recipients for regulated financial undertakings. A chain map should therefore name the activity, partner role, product or service link, and whether the partner acts for or on behalf of the company.
Map own operations, subsidiaries, upstream partners, and covered downstream product activities.
Do not treat every customer, recycler, or end-of-life activity as covered without checking the definition.
Flag regulated financial undertakings separately because their downstream coverage is narrower.
Attach procurement, logistics, contract, and product-flow evidence to each included activity.
The operating model starts with integrating due diligence into policies and risk management systems, then identifying and assessing actual and potential adverse human-rights and environmental impacts. Companies must prioritise impacts when they cannot address everything at once, prevent or mitigate potential impacts, bring actual impacts to an end or minimise their extent, provide remediation when they caused or jointly caused an actual adverse impact, monitor effectiveness, and communicate as required.
The duty is risk-based. The evidence should show how the company mapped likely and severe impact areas, what quantitative and qualitative information it used, why it prioritised particular impacts, which prevention or corrective actions were selected, and how the company reviewed whether those actions worked.
Due diligence policy and code of conduct reviewed at least every 24 months or after significant change.
Impact map covering own operations, subsidiaries, and business partners where related to the chain of activities.
Prioritisation record based on severity and likelihood.
Prevention and corrective action plans with timelines, indicators, responsible owners, and support for affected SMEs where relevant.
Monitoring record without undue delay after significant change, whenever reasonable grounds indicate new risks or ineffective measures, and at least every five years.
requires a notification mechanism and complaints procedure for legitimate concerns about actual or potential adverse impacts in the company's own operations, subsidiaries, or business partners in the chain of activities. A well-founded complaint means the adverse impact is treated as identified and must be handled through the relevant prevention, corrective, or remediation duties.
The complaints procedure should be fair, publicly available, accessible, predictable, and transparent. It should allow affected persons, their legitimate representatives, trade unions, workers' representatives, and experienced civil-society organisations to raise concerns, and it should protect confidentiality and prevent retaliation.
Publish the complaint channel and explain who can use it.
Log the alleged impact, affected right or environmental obligation, business relationship, severity, and location.
Give founded or unfounded reasons and record follow-up actions.
When the company caused or jointly caused an actual adverse impact, document the remediation offered or delivered.
Do not make internal complaints a precondition for access to supervisory, civil-liability, or other non-judicial mechanisms.
Use the CSDDD FAQ to convert scope, chain-of-activities, impact, complaints, remediation, liability, and climate-duty status decisions into traceable records.
What should teams know about civil liability and penalties?
enforcement has two tracks. Supervisory authorities enforce national transposition rules through information requests, investigations, orders, remedial action, and penalties. Separately, civil liability concerns damage claims where the national liability rules implementing the Directive apply.
Directive (EU) 2026/470 requires Member States to set the maximum limit for pecuniary penalties at 3% of net worldwide turnover, or consolidated worldwide turnover for the specified ultimate-parent routes, in the financial year preceding the penalty decision. National law determines the procedure and the amount imposed in a case.
The same amendment deleted the original uniform EU liability test in Article 29(1), so national law now determines liability conditions. It retained EU safeguards: full compensation without overcompensation, a limitation period of at least five years, non-prohibitive costs, injunctive measures, and proportionate court-ordered disclosure where a claimant supports a plausible damages claim.
Keep supervisory correspondence, investigation responses, orders, and penalty decisions separate from civil-claim files.
Retain the impact record, action plan, stakeholder engagement, complaint handling, remediation decision, and monitoring evidence that explain what the company did.
Do not promise a fixed EU-level fine amount unless the applicable national transposition rule and supervisory authority guidance support it.
For litigation risk, identify the applicable national duty, fault and causation rules, damage, standing, and procedure, then apply the retained Article 29 limitation, cost, injunction, disclosure, and compensation safeguards.
Do not treat contractual clauses, third-party verification, or participation in an industry initiative as an automatic liability defence.
Is a climate transition plan still required by CSDDD?
No standalone climate-transition-plan duty remains after Directive (EU) 2026/470 removed the original Article 22 obligation.
That change does not remove separate CSRD, national, sector, contractual, financing, or public-commitment requirements. Map any retained plan to its actual current basis.
Record the 2026 amendment and retire the old Article 22 obligation entry.
Map retained climate controls to their separate current source.
Update training, board material, assurance scope, and public claims.
Do not describe the original targets or 12-month update as current law.
Recheck national transposition and other applicable frameworks before deleting useful evidence.
Good evidence connects a legal question to a business fact, a decision, an owner, and a review trigger. A visitor should be able to see whether the answer depends on scope, timing, chain-of-activities coverage, impact severity, stakeholder input, complaint status, remediation, national transposition, or a separate current source for retained climate work.
For a program, the evidence set should be usable by legal, sustainability, procurement, risk, product, and finance teams. Avoid generic evidence folders; keep named records that match the obligation being answered.
What is the first document to pull for a answer?
Start with a scope memo or legal-entity assessment, then use the chain-of-activities map and the relevant impact, complaint, remediation, or Article 16 records. Use climate-plan records only when a separate current source makes them relevant.
Should evidence be kept only by legal?
No. The records usually sit across legal, sustainability, procurement, risk, product, and finance. The answer should trace back to the document that supports it.
Scope memo: entity, group, employee count, turnover, EU/non-EU status, two-year threshold test, and 26 July 2029 application decision.
Chain-of-activities map: own operations, subsidiaries, upstream partners, covered downstream activities, exclusions, and evidence source.
Adverse-impact register: right or environmental obligation, severity, likelihood, affected stakeholders, data source, and prioritisation decision.
Action-plan evidence: prevention, mitigation, corrective action, SME support, contractual assurances, and responsible disengagement assessment.
Complaints and remediation log: complaint intake, founded or unfounded reasoning, follow-up, confidentiality, anti-retaliation safeguards, and remedy.
Current Article 29 shows the national-law liability basis and the compensation, limitation, costs, injunction, disclosure, and related-party provisions that remain after the 2026 amendment.
Original source for records implied by scope, due diligence, complaints, remediation, monitoring, communication, liability, and the former climate-plan duty; read with Directive (EU) 2026/470.
"identification, prevention, mitigation, bringing to an end and minimisation"