FAQCSDDDEU

CSDDD chain of activities where upstream and downstream due diligence boundaries stop

The CSDDD chain of activities boundary covers a company's own operations, subsidiaries, and business partners where their activities fall inside the directive's upstream or downstream definitions.

This FAQ helps classify suppliers, logistics providers, service partners, subsidiaries, and downstream exclusions before assigning CSDDD due diligence evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
7

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Under the CSDDD as amended by Directive (EU) 2026/470, the is not an unlimited value-chain map. It retains defined upstream and narrower downstream product boundaries. Scoping covers relevant business partners using reasonably available information, and in-depth assessment targets areas where impacts are most likely and most severe; direct partners may be prioritised only where areas are equally likely or severe.

Search this module

Find a question or answer quickly

7 of 7 questions
Question 1

What does chain of activities mean under the CSDDD?

For CSDDD due diligence, start with three buckets: the company's own operations, the operations of its subsidiaries, and the operations of business partners where those partner activities are related to the company's .

The upstream side is broad. It covers business partner activities related to producing goods or providing services for the company, including design, extraction, sourcing, manufacture, transport, storage, raw material supply, product or part supply, and development of the product or service.

The downstream side is narrower. It covers distribution, transport, and storage of the company's product only where the downstream business partner performs those activities for the company or on the company's behalf.

Member States must transpose the amended CSDDD by 26 July 2028 and apply the due diligence measures from 26 July 2029. Use the current EU definition for readiness and data design, then confirm the enacted national provision before treating a boundary decision as an operative legal conclusion.

  • Map own operations and subsidiary operations separately from partner operations.
  • Classify each partner as upstream, downstream product logistics, or outside the CSDDD chain-of-activities definition.
  • Do not treat downstream customer use, general resale, product disposal, or downstream services as covered merely because they occur after sale.
Citations
Directive (EU) 2026/470

Binding current amendment for CSDDD scope, due diligence, monitoring, enforcement, and status changes discussed on this page.

Question 2

Are subsidiaries inside the chain of activities boundary?

Subsidiaries sit in a separate category from suppliers. The CSDDD treats due diligence as covering a company's own operations, the operations of its subsidiaries, and, where related to the , the operations of business partners.

That means a boundary file should identify subsidiaries directly, then identify which business partners sit in each subsidiary's . If a parent carries out due diligence obligations on behalf of in-scope subsidiaries, the subsidiary still needs enough local records to show how the parent policy, risk assessment, prevention measures, stakeholder engagement, remediation, and monitoring apply to that subsidiary.

Where a parent uses the CSDDD group-level support route, keep the parent-subsidiary information exchange, adapted policy, local risk-management integration, and any subsidiary-specific partner measures visible in the evidence file.

  • Record each covered subsidiary, legal entity, activity, site, product line, and service line.
  • Show which parent-level due diligence elements apply to the subsidiary and which are handled locally.
  • Keep subsidiary evidence separate enough to respond to supervisory authority questions and civil-liability analysis.
Citations
Recommended next step

Turn CSDDD boundary decisions into an evidence file

Map subsidiaries, upstream partners, downstream logistics providers, exclusions, and unresolved cases before assigning CSDDD assessment and prevention measures.

Question 3

How should direct and indirect business partners be classified?

A is an entity with a commercial agreement related to the company's operations, products, or services, or an entity to which the company provides services. An is not the direct contracting party, but performs business operations related to the company's operations, products, or services.

The distinction matters because CSDDD measures often start with direct partners, then extend to indirect partners when their activities are part of the and where risk assessment shows adverse impacts are likely or severe. For example, contractual assurances from a direct partner may need corresponding assurances from that partner's relevant partners; in some cases, the company may seek assurances directly from an indirect partner.

Do not stop classification at the procurement system's vendor record. The useful test is whether the partner's activity is related to the company's operations, products, or services and falls inside the upstream or downstream chain-of-activities definition.

  • Use contract records to identify direct business partners.
  • Use bills of material, logistics flows, service delivery maps, supplier disclosures, audit data, and complaints to identify indirect partners.
  • Flag indirect partners in high-risk geographies, sectors, product inputs, or logistics roles for deeper assessment rather than treating them as invisible tiers.
Citations
Question 4

Where do downstream distribution, transport, and storage stop?

Downstream coverage is limited to distribution, transport, and storage of the company's product where a business partner carries out those activities for the company or on the company's behalf. It is not a general downstream customer, reseller, user, or end-of-life obligation.

A contracted warehouse, fulfilment provider, carrier, distributor, or logistics provider can therefore sit inside the downstream boundary when it handles the company's product for the company. A customer that buys and uses the product for its own business normally needs a separate analysis and should not be included merely because it is downstream.

The directive also states that the does not include product disposal. It excludes distribution, transport, storage, and disposal of products subject to Member State export controls, including dual-use controls or weapons, munitions, and war material controls, once export is authorised.

  • Include downstream product logistics performed for the company or on its behalf.
  • Exclude downstream activities related to the company's services, and for regulated financial undertakings exclude downstream recipients of services and products.
  • Exclude product disposal from the CSDDD chain-of-activities boundary, while checking whether another product, waste, export-control, or sector law applies.
Citations
Question 5

How does amended Article 8 limit partner information requests?

The boundary map and the in-depth assessment are different steps. Article 8 first requires a scoping exercise based only on reasonably available information to identify general areas where adverse impacts are most likely and most severe. The company then performs an in-depth assessment in those areas.

For that in-depth assessment, a company may request partner information only where it is necessary. If the partner has fewer than 5,000 employees, the company may request the information only when it cannot reasonably obtain it by other means. Where several partners can provide the information, the company should request it, where reasonable, from the partner or partners where impacts are most likely to occur. Direct partners may be prioritised only where areas are equally likely or equally severe.

  • Use reasonably available information for the initial scoping exercise.
  • Record why a requested data item is necessary for the in-depth assessment.
  • For a partner with fewer than 5,000 employees, record why another reasonable source could not supply the information.
  • Do not turn direct-tier convenience into a blanket rule that excludes higher-risk indirect partners.
Citations
Question 6

What evidence should a CSDDD boundary decision retain?

Keep evidence that proves why each activity is in scope, out of scope, or unresolved. A useful boundary record links the legal definition to the company's actual product, service, subsidiary, supplier, logistics, and partner facts.

The record should also show how the boundary decision fed the Article 8 scoping exercise and in-depth assessment, and how it affected prevention or mitigation measures under Article 10 or actual-impact measures under Article 11.

Because business partners are not generally required to disclose trade secrets, preserve the minimum information needed to identify direct and indirect partners and adverse-impact risks without turning the evidence request into an unsupported data grab.

  • Boundary matrix with columns for entity, activity, product or service, upstream or downstream classification, direct or indirect partner status, inclusion decision, source citation, and reviewer.
  • Product and service flow evidence: bills of material, sourcing maps, logistics routes, warehouse contracts, distributor contracts, service delivery diagrams, and subsidiary activity descriptions.
  • Risk evidence: sector, geography, product, service, business-operation, and complaint data used for the reasonably available scoping exercise and the later in-depth assessment.
  • Information-request record: necessity, partner size, alternative sources checked, requested fields, response, and the reason for choosing that partner.
  • Action evidence: prevention action plans, contractual assurances, verification records, SME support decisions, enhanced-plan or suspension reviews, and monitoring updates where the boundary decision triggered CSDDD measures.
Citations
Question 7

What is the most common mistake with CSDDD chain-of-activities boundaries?

The most common mistake is using a broad value-chain diagram as if every actor in it is automatically inside the CSDDD . The directive's wording is more specific: upstream is tied to production of goods or provision of services, while downstream is limited to product distribution, transport, and storage performed for the company or on its behalf.

A second mistake is losing the distinction between subsidiaries, direct partners, and indirect partners. Those categories affect who holds information, who can influence the relevant activity, which assurances are realistic, and what evidence can be requested without overreaching.

A defensible answer is a maintained boundary file: it names the entity, activity, product or service, partner tier, inclusion decision, exclusion rationale, risk signals, and follow-up due diligence measure.

  • Do not include product disposal unless another legal regime separately requires disposal controls.
  • Do not include downstream service recipients as if they were downstream product logistics providers.
  • Do not rely only on first-tier supplier lists when indirect partners perform activities tied to high-risk production, sourcing, manufacture, transport, storage, or supply.
Citations
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Current Article 8(2) and 8(2a) distinguish reasonably available scoping from targeted in-depth assessment and set necessity, smaller-partner, and partner-prioritisation limits.
eur-lex.europa.eu
Referenced sections
  • Binding current amendment for CSDDD scope, due diligence, monitoring, enforcement, and status changes discussed on this page.
Related guides

Explore more topics

CSDDD adverse impact prioritisation workflow
A CSDDD workflow for identifying actual and potential adverse human rights and environmental impacts, ranking severity and likelihood, and documenting prevention, mitigation, remediation, and stakeholder evidence.
CSDDD Applicability Test After 2026 Changes
Test CSDDD scope after Directive (EU) 2026/470 using the current EU and third-country thresholds, parent-company rules, exclusions, dates, and evidence.
CSDDD chain of activities and supplier due diligence
Explain CSDDD chain-of-activities scope, upstream and downstream boundaries, subsidiaries, direct and indirect business partners, supplier risk segmentation, and evidence.
CSDDD Chain of Activities Boundaries
Define CSDDD upstream and downstream chain of activities boundaries for subsidiaries, direct and indirect business partners, distribution, transport, storage, and records.
CSDDD complaints and notifications FAQ
FAQ on Article 14 CSDDD complaint and notification mechanisms, who may complain, follow-up rights, confidentiality, retaliation, and evidence.
CSDDD compliance duties and evidence guide
A source-backed CSDDD compliance guide covering due diligence policy, impact scoping, prevention, corrective action, complaints, monitoring, reporting, climate-plan status, and supervisory evidence.
CSDDD contractual assurances FAQ for Articles 10 and 11
How CSDDD Articles 10 and 11 use contractual assurances with business partners, verification, SME support, action plans, and possible suspension escalation.
CSDDD Deadlines After Directive 2026/470
Current CSDDD calendar: 2027-2028 guidance, 2028 transposition, 2029 application, 2030 reporting, 2031 ESAP submission and review.
CSDDD due diligence checklist
A source-backed CSDDD checklist for scope, risk scoping, impact prioritisation, action plans, complaints, monitoring, communication, evidence, and the removed climate-plan duty.
CSDDD Due Diligence Steps Playbook for Articles 5 and 7-16
A playbook using current CSDDD provisions for policy integration, impact assessment, prioritisation, prevention, correction, remediation, stakeholder engagement, complaints, monitoring, communication, and evidence.
CSDDD FAQ: scope, dates, duties, liability, and evidence
Practical answers on CSDDD scope, current application dates, chain of activities, due diligence duties, complaints, remediation, civil liability, climate plans, and evidence.
CSDDD grievance and remediation workflow guide
Build a CSDDD grievance, notification, stakeholder engagement, and remediation workflow under Directive (EU) 2024/1760 as amended by Directive (EU) 2026/470.
CSDDD Liability and Enforcement After 2026
Understand CSDDD supervision, national penalties, substantiated concerns, remedial orders, and civil-liability analysis after Directive (EU) 2026/470.
CSDDD Non-EU Scope and 2029 Start
Test third-country CSDDD scope using the amended EUR 1.5 billion EU-turnover route and one 26 July 2029 application date.
CSDDD Penalties After Directive 2026/470
Current CSDDD penalty guidance after the EU 5% rule was replaced by a uniform 3% maximum limit: national sanctions, authority decisions, evidence, and country-by-country monitoring.
CSDDD prevention vs mitigation: potential and actual adverse impacts
CSDDD FAQ on when to prevent or mitigate potential adverse impacts, when to end or minimise actual adverse impacts, and what evidence records to keep.
CSDDD remediation FAQ: when companies must remedy adverse impacts
FAQ on CSDDD remediation: when Article 12 requires remedy, how complaints and stakeholder engagement affect the response, and what evidence to keep.
CSDDD Remediation Plan Template: Article 12, 13 and 14 evidence
A CSDDD remediation plan template for actual adverse impacts, complaint inputs, stakeholder engagement, action records, and monitoring under the Directive as amended in 2026.
CSDDD requirements: scope, due diligence, climate plan, and evidence
A source-backed map of current CSDDD requirements across scope, due diligence policy, impact assessment, complaints, remediation, monitoring, communication, and the removed climate-plan duty.
CSDDD risk prioritisation FAQ: severity, likelihood, and evidence
How to prioritise CSDDD adverse impacts when teams cannot address everything at once, using severity, likelihood, stakeholder evidence, and a reviewable rationale.
CSDDD Scope Thresholds After 2026
Understand amended CSDDD thresholds for EU and non-EU companies, group scope, exclusions, two-year evidence, and the 2029 application date.
CSDDD Supplier Contract Clause Review Workflow
Review supplier contract clauses against CSDDD Articles 10 and 11: contractual assurances, verification, SME fairness, support, action plans, and escalation evidence.
CSDDD Supplier Contract Clauses: Articles 10 and 11 Evidence
How to use CSDDD supplier contract clauses without treating clauses as a substitute for due diligence: contractual assurances, verification, SME support, action plans, limits, and evidence.
CSDDD supplier human rights impact scoring template
A CSDDD supplier impact scoring template for Article 8 identification, Article 9 prioritisation, severity, likelihood, stakeholder input, chain-of-activities boundaries, and evidence records.
CSDDD vs CSRD: Due Diligence and Reporting Compared
Compare CSDDD due diligence duties with CSRD sustainability reporting, including scope, timing, Article 16 reporting, evidence overlap, assurance, and enforcement.
CSDDD vs German LkSG Comparison
Compare the EU CSDDD with Germany's LkSG without mixing directive duties, national-law duties, chain boundaries, complaints, reporting, and enforcement routes.
CSDDD vs OECD Guidelines
Compare the binding EU CSDDD with the OECD Guidelines for responsible business conduct across scope, due diligence duties, business relationships, remediation, and evidence.
Did CSDDD Keep Its Climate Plan Duty?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty. Understand what changed and which separate obligations may remain.
Does CSDDD Still Have Scope Waves?
No separate company scope waves remain after Directive (EU) 2026/470: transposition is due in 2028 and all companies remaining in scope apply from 2029.
Does Franchising Trigger CSDDD Scope?
Directive (EU) 2026/470 retained the CSDDD franchise and licensing scope route but raised its royalty and turnover thresholds. Learn the current test.
How CSDDD overlaps with OECD, UNGP, and ILO standards
FAQ on how OECD responsible business conduct guidance, the UN Guiding Principles, and ILO labour standards inform CSDDD due diligence without being the same legal instrument.
How Does CSDDD Civil Liability Work Now?
Directive (EU) 2026/470 removed the uniform EU liability test but retained compensation and procedural safeguards. Claims still depend on Member State law.
Is a Climate Plan Still Required by CSDDD?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty; separate CSRD and national obligations need their own review.
What Did Omnibus Change in CSDDD?
CSDDD Omnibus status as of July 2026: what Directives (EU) 2025/794 and 2026/470 adopted, which dates apply, and which old duties were removed.
What EU Turnover Triggers CSDDD Scope?
A third-country company generally needs more than EUR 1.5 billion net turnover in the EU under Directive (EU) 2026/470; learn the evidence and timing.