CSDDDRequirementsEU

EU Corporate Sustainability Due Diligence Directive Requirements

This page helps map the CSDDD requirements to concrete controls, owners, and evidence.

The focus is the Directive's current operating duties: scope, risk-based due diligence, stakeholder engagement, complaints, remediation, monitoring, communication, and accurate treatment of the removed Article 22 duty.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 26, 2026
Sections
8

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 26, 2026
Overview

The is Directive (EU) 2024/1760 as amended by Directive (EU) 2026/470. Member States must transpose it by 26 July 2028 and apply national measures from 26 July 2029; communication starts for financial years beginning on or after 1 January 2030. Covered EU and non-EU companies will need risk-based human rights and environmental due diligence across their own operations, subsidiaries, and the relevant . Start implementation with an article-by-article control map showing who is in scope, what process must exist, when impacts are escalated, what remedy is available, and which records show that the system operates.

Section 1

Who must test CSDDD scope before building controls?

Article 2 sets the company scope. EU companies are in scope where they meet the employee and net worldwide turnover route, where they are an ultimate parent of a group meeting that route, or where the franchising or licensing route is met. Third-country companies use Union net turnover rather than EU employee headcount for the main route, with parallel group and franchising or licensing routes.

Directive (EU) 2026/470 narrowed the general scope. EU companies generally require more than 5,000 employees and more than EUR 1.5 billion net worldwide turnover; third-country companies generally require more than EUR 1.5 billion net turnover in the Union. Relevant ultimate-parent routes remain. The separate franchise and licensing route also remains, but its thresholds rose to more than EUR 75 million in qualifying Union royalties and more than EUR 275 million turnover. Scope is tested over two consecutive financial years and ends only after two relevant years below the conditions.

Article 2 excludes alternative investment funds (AIFs) and undertakings for collective investment in transferable securities (UCITS). That exclusion does not automatically cover an external fund manager or every regulated financial undertaking, so test the legal person performing the management or financial activity separately.

A positive Article 2 scope result does not make the operating duties immediately applicable. Record the 26 July 2028 national transposition deadline, the 26 July 2029 application date, the separate financial-year trigger, and the national laws that will govern procedure and enforcement.

  • Keep a scope workbook showing employee counts, net worldwide turnover, Union net turnover, franchise or licensing royalties, group status, and the two-consecutive-financial-years test.
  • For third-country companies, identify the branch Member State. If there is no branch or there are branches in different Member States, identify the Member State where the company generated most Union turnover for the Article 24 supervisory-authority test.
  • Keep timing notes separate from the Article 2 scope test so phase-in planning does not change the underlying coverage analysis.
Section 2

What is the CSDDD due diligence system required to cover?

Article 5 is the control map for . It requires risk-based human rights and environmental due diligence covering policy and risk management, identification and assessment of actual or potential adverse impacts, prioritisation where not all impacts can be addressed at once, prevention and mitigation, ending actual impacts and minimising their extent, remediation, stakeholder engagement, complaints and notifications, monitoring, and public communication.

Article 7 turns that map into internal governance. The company must integrate into relevant policies and risk management systems and maintain a due diligence policy developed after prior consultation with employees and their representatives. The policy must describe the company's due diligence approach, include a code of conduct for the company, subsidiaries, and business partners, and describe the processes used to integrate and implement due diligence.

The Directive requires that can address the impact, match its severity and likelihood, and are reasonably available in the specific circumstances. It does not prescribe one identical control for every operation, partner, or impact.

  • Policy evidence: policy, employee consultation record, code of conduct, business-partner extension approach, and policy review history.
  • Risk-management evidence: risk taxonomy, escalation rules, links to procurement and operational controls, and management reporting for severe or likely adverse impacts.
  • Review trigger: Article 7 requires policy review and updates without undue delay after significant change and at least every 24 months.
Section 3

How must companies identify, assess, and prioritise impacts?

Amended Article 8 requires a scoping exercise based solely on reasonably available information across own operations, subsidiaries, and relevant business partners. The company then performs an in-depth assessment in areas where adverse impacts are most likely and most severe.

Article 9 applies when the company cannot prevent, mitigate, end, or minimise all identified impacts at the same time and to their full extent. Prioritisation must be based on severity and likelihood. Once the most severe and most likely impacts are addressed within a reasonable time, less severe and less likely impacts must be addressed.

Human-rights examples include child labour, forced labour, unsafe work, interference with freedom of association, and unlawful displacement when the Annex conditions are met. Environmental impacts are not any sustainability concern: they arise from breaches of the prohibitions and obligations listed in the Annex, including specified rules on hazardous substances, pollution, waste, biodiversity, and natural resources.

  • Mapping fields: activity, subsidiary or business-partner link, geography, sector, product or service, affected right or environmental obligation, severity, likelihood, information source, and assessment owner.
  • Assessment inputs: quantitative and qualitative information, independent reports, notifications, complaints, and necessary business-partner data. For a partner with fewer than 5,000 employees, request information only when it cannot reasonably be obtained by other means.
  • Prioritisation evidence: scoring rationale for severity and likelihood, record of impacts deferred, reason they were deferred, and date or condition for reassessment.
Section 4

What actions are required for potential and actual adverse impacts?

Article 10 covers potential adverse impacts through prevention or adequate mitigation, using action plans, contractual assurance with verification, investment or operational change, purchasing-practice change, SME support, collaboration, and the amended last-resort measures. Directive (EU) 2026/470 removed termination but retained restrictions on new or extended relationships, enhanced action plans, and suspension where legally available and not expected to cause manifestly more severe impacts.

Article 11 covers actual adverse impacts through action to end them or minimise their extent, corrective plans, verification, investment, operational change, SME support, collaboration, remediation, and the same last-resort structure. A suspension decision requires notice, measures addressing the impacts of suspension, and continuing review.

  • Prevention action plan: impact description, responsible owner, affected operations or partners, timelines, qualitative and quantitative improvement indicators, support measures, and verification method.
  • Corrective action plan: actual impact, immediate containment, steps to end or minimise the impact, remediation link, affected stakeholder input, timeline, and status.
  • Suspension evidence: why other measures were insufficient, whether suspension could create manifestly more severe impacts, reasonable notice, mitigation steps, and periodic review.
Section 5

When is remediation required?

Article 12 requires remediation where the company has caused or jointly caused an actual adverse impact. The definition in Article 3 frames remediation as restoring affected people, communities, or the environment to an equivalent or as-close-as-possible situation, in proportion to the company's implication in the impact. That can include financial or non-financial compensation and, where applicable, reimbursement of public-authority remedial costs.

Where the actual adverse impact is caused only by a business partner, the Directive allows voluntary remediation and allows the company to use its influence to encourage the business partner causing the impact to provide remediation.

  • Remediation file: impact description, affected person, community, or environmental interest, causation or contribution analysis, remedy offered, stakeholder engagement record, acceptance or dispute status, and follow-up monitoring.
  • Avoid treating remediation as only a payment workflow; the Directive's definition includes restoration and non-financial measures where appropriate.
  • Keep the remediation decision linked to Articles 10 and 11, because corrective measures for actual impacts may include remediation.
Section 6

What stakeholder, complaint, monitoring, and communication controls are required?

Article 13 retains meaningful engagement but Directive (EU) 2026/470 narrowed the stakeholder definition and mandatory consultation stages. Identify the affected stakeholders or legitimate representatives relevant to the decision, provide usable information, address access barriers, and protect confidentiality and non-retaliation.

Article 14 requires a notification mechanism and complaints procedure. People affected or with reasonable grounds to believe they might be affected, legitimate representatives, trade unions and workers' representatives, and experienced civil society organisations for environmental complaints must be able to submit complaints. The procedure must be fair, publicly available, accessible, predictable, and transparent, with follow-up rights and protection against retaliation.

Article 15 requires effectiveness assessments. Under Directive (EU) 2026/470, the regular cycle is at least every five years, plus reassessment after significant change or when reasonable grounds indicate new risks or ineffective measures. requires public communication under the amended reporting rules.

  • Stakeholder engagement evidence: stakeholder group, affected right or interest, information provided, additional requests, company responses, barriers addressed, confidentiality safeguards, and how input changed the decision.
  • Complaints evidence: channel publication, eligibility basis, founded or unfounded decision, reasons, meeting record for severe impacts where requested, follow-up actions, and anti-retaliation safeguards.
  • Monitoring and communication evidence: five-year assessment schedule, event-driven triggers, indicators, findings, policy or measure updates, exemption analysis, required languages, website publication no later than 12 months after the balance-sheet date, third-country authorised-representative details, and CSRD interaction where relevant.
Section 7

What happened to the CSDDD climate transition plan requirement?

Directive (EU) 2026/470 removed the standalone Article 22 climate-transition-plan requirement. A company may still have transition-plan, reporting, national-law, sector, contractual, financing, or public-commitment duties, but those must be mapped to their own current sources rather than presented as CSDDD requirements.

Where a climate plan is retained, label its actual basis and keep it connected to environmental adverse-impact analysis only where that connection is supported. Do not carry forward the former 12-month update, target, funding, or governance requirements as current law without a separate binding source.

  • If another current source requires a plan, retain the target baseline, scientific evidence, scope coverage, decarbonisation levers, investment and funding assumptions, governance role, and progress evidence that source requires.
  • Do not attribute former Article 22 best-efforts, design, implementation, or update language to current law.
  • Map any group or subsidiary climate-plan governance to the separate source that still requires or supports it.
Section 8

What evidence makes the requirements operational?

A defensible requirements file should show that the company has translated amended Article 2 and Articles 5 and 7 to 16 into owned processes. The evidence should connect the legal requirement to business systems: procurement, supplier management, operations, enterprise risk, sustainability reporting, complaints handling, remediation, legal governance, and board or management-body oversight.

The evidence should separate current law from legislative history: Directive (EU) 2026/470 is the adopted amendment, while the original Article 22 and proposal-stage Omnibus alternatives belong in the history record.

Article 5 requires the company to retain documentation of its actions, including supporting evidence, for at least five years from when the material was produced or obtained. If related judicial or administrative proceedings are still open when that period ends, retention continues until the matter concludes.

  • Scope and phase-in register with source citation, thresholds tested, responsible legal owner, and next review trigger.
  • policy pack with employee consultation, code of conduct, risk-management integration, and update history.
  • Impact register with mapping, in-depth assessments, severity and likelihood prioritisation, prevention plans, corrective plans, remediation records, and monitoring indicators.
  • Stakeholder and complaints records with channel evidence, confidentiality controls, anti-retaliation safeguards, follow-up decisions, and founded or unfounded complaint reasons.
  • Communication pack with annual-statement analysis and CSRD-reporting interaction; keep any transition-plan evidence in a separately sourced climate file.
  • Retention control with production or receipt date, five-year minimum disposal date, legal-hold status, evidence owner, and final release after any proceeding concludes.
Recommended next step

Turn CSDDD requirements into an evidence system

This CSDDD requirements map helps connect legal scope, due diligence controls, complaints, remediation, transition-plan governance, and cited evidence.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Current Article 5(4) requires due diligence documentation and supporting evidence to be retained for at least five years and extends retention for ongoing judicial or administrative proceedings.
eur-lex.europa.eu
Referenced sections
  • Binding source for current restrictions on new or extended relationships, enhanced action plans, suspension conditions, notice, review, and removal of mandatory termination.
commission.europa.eu
Referenced sections
  • Commission overview used for plain-language confirmation that the CSDDD targets adverse human rights and environmental impacts in operations, subsidiaries, and chains of activities.
"identify and address adverse human rights and environmental impacts"
Related guides

Explore more topics

CSDDD adverse impact prioritisation workflow
A CSDDD workflow for identifying actual and potential adverse human rights and environmental impacts, ranking severity and likelihood, and documenting prevention, mitigation, remediation, and stakeholder evidence.
CSDDD Applicability Test After 2026 Changes
Test CSDDD scope after Directive (EU) 2026/470 using the current EU and third-country thresholds, parent-company rules, exclusions, dates, and evidence.
CSDDD chain of activities and supplier due diligence
Explain CSDDD chain-of-activities scope, upstream and downstream boundaries, subsidiaries, direct and indirect business partners, supplier risk segmentation, and evidence.
CSDDD Chain of Activities Boundaries
Define CSDDD upstream and downstream chain of activities boundaries for subsidiaries, direct and indirect business partners, distribution, transport, storage, and records.
CSDDD chain of activities boundaries: upstream and downstream FAQ
FAQ on how the CSDDD defines chain of activities boundaries for subsidiaries, direct and indirect business partners, upstream activities, downstream logistics, and evidence.
CSDDD complaints and notifications FAQ
FAQ on Article 14 CSDDD complaint and notification mechanisms, who may complain, follow-up rights, confidentiality, retaliation, and evidence.
CSDDD compliance duties and evidence guide
A source-backed CSDDD compliance guide covering due diligence policy, impact scoping, prevention, corrective action, complaints, monitoring, reporting, climate-plan status, and supervisory evidence.
CSDDD contractual assurances FAQ for Articles 10 and 11
How CSDDD Articles 10 and 11 use contractual assurances with business partners, verification, SME support, action plans, and possible suspension escalation.
CSDDD Deadlines After Directive 2026/470
Current CSDDD calendar: 2027-2028 guidance, 2028 transposition, 2029 application, 2030 reporting, 2031 ESAP submission and review.
CSDDD due diligence checklist
A source-backed CSDDD checklist for scope, risk scoping, impact prioritisation, action plans, complaints, monitoring, communication, evidence, and the removed climate-plan duty.
CSDDD Due Diligence Steps Playbook for Articles 5 and 7-16
A playbook using current CSDDD provisions for policy integration, impact assessment, prioritisation, prevention, correction, remediation, stakeholder engagement, complaints, monitoring, communication, and evidence.
CSDDD FAQ: scope, dates, duties, liability, and evidence
Practical answers on CSDDD scope, current application dates, chain of activities, due diligence duties, complaints, remediation, civil liability, climate plans, and evidence.
CSDDD grievance and remediation workflow guide
Build a CSDDD grievance, notification, stakeholder engagement, and remediation workflow under Directive (EU) 2024/1760 as amended by Directive (EU) 2026/470.
CSDDD Liability and Enforcement After 2026
Understand CSDDD supervision, national penalties, substantiated concerns, remedial orders, and civil-liability analysis after Directive (EU) 2026/470.
CSDDD Non-EU Scope and 2029 Start
Test third-country CSDDD scope using the amended EUR 1.5 billion EU-turnover route and one 26 July 2029 application date.
CSDDD Penalties After Directive 2026/470
Current CSDDD penalty guidance after the EU 5% rule was replaced by a uniform 3% maximum limit: national sanctions, authority decisions, evidence, and country-by-country monitoring.
CSDDD prevention vs mitigation: potential and actual adverse impacts
CSDDD FAQ on when to prevent or mitigate potential adverse impacts, when to end or minimise actual adverse impacts, and what evidence records to keep.
CSDDD remediation FAQ: when companies must remedy adverse impacts
FAQ on CSDDD remediation: when Article 12 requires remedy, how complaints and stakeholder engagement affect the response, and what evidence to keep.
CSDDD Remediation Plan Template: Article 12, 13 and 14 evidence
A CSDDD remediation plan template for actual adverse impacts, complaint inputs, stakeholder engagement, action records, and monitoring under the Directive as amended in 2026.
CSDDD risk prioritisation FAQ: severity, likelihood, and evidence
How to prioritise CSDDD adverse impacts when teams cannot address everything at once, using severity, likelihood, stakeholder evidence, and a reviewable rationale.
CSDDD Scope Thresholds After 2026
Understand amended CSDDD thresholds for EU and non-EU companies, group scope, exclusions, two-year evidence, and the 2029 application date.
CSDDD Supplier Contract Clause Review Workflow
Review supplier contract clauses against CSDDD Articles 10 and 11: contractual assurances, verification, SME fairness, support, action plans, and escalation evidence.
CSDDD Supplier Contract Clauses: Articles 10 and 11 Evidence
How to use CSDDD supplier contract clauses without treating clauses as a substitute for due diligence: contractual assurances, verification, SME support, action plans, limits, and evidence.
CSDDD supplier human rights impact scoring template
A CSDDD supplier impact scoring template for Article 8 identification, Article 9 prioritisation, severity, likelihood, stakeholder input, chain-of-activities boundaries, and evidence records.
CSDDD vs CSRD: Due Diligence and Reporting Compared
Compare CSDDD due diligence duties with CSRD sustainability reporting, including scope, timing, Article 16 reporting, evidence overlap, assurance, and enforcement.
CSDDD vs German LkSG Comparison
Compare the EU CSDDD with Germany's LkSG without mixing directive duties, national-law duties, chain boundaries, complaints, reporting, and enforcement routes.
CSDDD vs OECD Guidelines
Compare the binding EU CSDDD with the OECD Guidelines for responsible business conduct across scope, due diligence duties, business relationships, remediation, and evidence.
Did CSDDD Keep Its Climate Plan Duty?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty. Understand what changed and which separate obligations may remain.
Does CSDDD Still Have Scope Waves?
No separate company scope waves remain after Directive (EU) 2026/470: transposition is due in 2028 and all companies remaining in scope apply from 2029.
Does Franchising Trigger CSDDD Scope?
Directive (EU) 2026/470 retained the CSDDD franchise and licensing scope route but raised its royalty and turnover thresholds. Learn the current test.
How CSDDD overlaps with OECD, UNGP, and ILO standards
FAQ on how OECD responsible business conduct guidance, the UN Guiding Principles, and ILO labour standards inform CSDDD due diligence without being the same legal instrument.
How Does CSDDD Civil Liability Work Now?
Directive (EU) 2026/470 removed the uniform EU liability test but retained compensation and procedural safeguards. Claims still depend on Member State law.
Is a Climate Plan Still Required by CSDDD?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty; separate CSRD and national obligations need their own review.
What Did Omnibus Change in CSDDD?
CSDDD Omnibus status as of July 2026: what Directives (EU) 2025/794 and 2026/470 adopted, which dates apply, and which old duties were removed.
What EU Turnover Triggers CSDDD Scope?
A third-country company generally needs more than EUR 1.5 billion net turnover in the EU under Directive (EU) 2026/470; learn the evidence and timing.