Resources
Regulations

Corporate Sustainability Due Diligence Directive (CSDDD)

Guide to the EU's Corporate Sustainability Due Diligence Directive — scope, requirements, civil liability, and how it differs from national due diligence laws.

Last updated: · 5 min read

Status, September 2026: The EU's Omnibus I directive (in force March 2026) narrows the CSDDD to companies with more than 5,000 employees and more than €1.5 billion in net turnover (and non-EU companies with more than €1.5 billion in EU turnover), and delays it: member states transpose it by July 26, 2028, and companies apply it from July 26, 2029. Source: PwC.

What Is CSDDD?

The Corporate Sustainability Due Diligence Directive (CSDDD, also known as CS3D), adopted by the EU in 2024, requires large companies to identify, prevent, mitigate, and account for adverse human rights and environmental impacts in their operations and value chains. It builds on existing national legislation (Germany's LkSG, France's Duty of Vigilance) and extends due diligence duties across the EU. The Omnibus I amendments (Directive (EU) 2026/470), in force since March 18, 2026, narrowed it to the largest companies and removed its EU-wide civil liability regime and its climate transition plan requirement.

CSDDD represents a fundamental shift in corporate accountability — companies must carry out due diligence not just on their own operations but across their chains of activities.

Who It Applies To

Scope after Omnibus I:

CompaniesApplies fromEmployeesTurnover
EU companiesJuly 26, 2029More than 5,000More than €1.5B net worldwide
Non-EU companiesJuly 26, 2029No employee testMore than €1.5B net in the EU

Omnibus I replaced the original three-phase rollout, which would have reached companies with more than 1,000 employees and €450 million in turnover. Law firm A&O Shearman estimated in December 2025 that the change cuts the number of companies in scope by around 70%.

Key Requirements

Due diligence obligations (six-step process):

  1. Integrate due diligence into policies: Adopt and implement a due diligence policy describing the company's approach, code of conduct, and processes

  2. Identify and assess impacts: Run a scoping exercise, based on reasonably available information, to find where in own operations, subsidiaries, and the chain of activities (business partners) adverse human rights and environmental impacts are most likely, then assess those areas in depth

  3. Prevent, mitigate, and end impacts: Take appropriate measures to prevent potential impacts and end or minimize actual impacts. This includes developing corrective action plans, seeking contractual assurances, making investments, and providing targeted support to business partners

  4. Monitor effectiveness: Track due diligence implementation and effectiveness through qualitative and quantitative indicators

  5. Communicate: Publicly report on due diligence through annual statements

  6. Provide remediation: Provide remediation where the company has caused or contributed to adverse impacts, including financial compensation, rehabilitation, and engagement with affected stakeholders

Climate transition plan: The directive as adopted in 2024 required companies in scope to adopt and implement a transition plan for climate change mitigation aligned with the Paris Agreement's 1.5°C target. Omnibus I deleted that requirement.

Covered impacts:

  • Human rights impacts as defined by the international instruments listed in the directive's annex, such as the UN human rights covenants and core ILO conventions
  • Environmental impacts listed in the annex, including biodiversity loss, pollution, excessive water use, deforestation, and hazardous chemicals and waste (climate change was addressed only through the deleted transition plan duty)

Timeline

  • 2024: CSDDD adopted
  • April 2025: "Stop-the-clock" directive delays transposition and the first phase by one year
  • March 18, 2026: Omnibus I enters into force, narrowing scope and removing the transition plan duty and the EU-wide civil liability regime
  • July 26, 2027: Deadline for the Commission's general due diligence guidelines
  • July 26, 2028: Member states must transpose into national law
  • July 26, 2029: All companies in scope, EU and non-EU, must comply
  • 2030: Annual due diligence statements required for financial years starting on or after January 1, 2030
  • July 26, 2031: First Commission review, including whether to widen scope

Civil Liability

Omnibus I removed the EU-wide civil liability regime from the 2024 text, so whether a company is liable now depends on national law:

  • Where a company is held liable under national law for damage caused by failing its due diligence duties, member states must ensure affected persons can obtain full compensation, without punitive damages
  • The EU-level requirement to let trade unions and NGOs bring actions on behalf of affected persons was deleted, though national law may still allow it
  • Limitation periods for damages claims must be at least five years and cannot start running before the infringement has ended and the claimant knows of it
  • Claimants must be able to seek injunctive measures to stop an infringement

Because liability now rests on national law, legal exposure will vary by member state.

Compliance Steps

  1. Scope assessment: Determine which entities and business relationships are covered
  2. Policy development: Adopt a comprehensive due diligence policy
  3. Scoping exercise: Using reasonably available information, identify the areas of your operations and chain of activities where adverse impacts are most likely and most severe
  4. Impact assessment: Assess the areas flagged by the scoping exercise in depth
  5. Prevention and mitigation: Implement measures to prevent and mitigate identified impacts
  6. Grievance mechanism: Establish or strengthen complaints procedures
  7. Monitoring and reporting: Track effectiveness and publish annual due diligence statements

Penalties

  • Administrative penalties: Up to 3% of the company's net worldwide turnover, a uniform cap set by Omnibus I
  • Civil liability: Compensation claims from affected persons where national law holds the company liable
  • Public procurement: Contracting authorities may treat compliance as an award criterion or contract condition in public tenders
  • Supervisory authority enforcement: National authorities can investigate, impose fines, and require corrective measures

How Council Fire Can Help

Council Fire helps companies prepare for CSDDD compliance — from value chain mapping and impact assessment through policy development, transition planning, and remediation frameworks. Contact us for CSDDD compliance support.

Corporate Sustainability Due Diligence Directive (CSDDD) — sustainability in practice

CSRD Readiness Checklist

Assess your organization's readiness for EU sustainability reporting.

Get Free Resource

Frequently Asked Questions

CSDDD reaches further along the value chain than LkSG, which centers on own operations and direct suppliers, and covers a wider range of environmental harms. After Omnibus I its company scope is narrower: more than 5,000 employees and €1.5 billion turnover, versus 1,000 employees for LkSG. LkSG stays in force until the revised CSDDD replaces it.
Adopted in 2024, CSDDD was delayed and narrowed by the 2025 stop-the-clock directive and Omnibus I. Member states must transpose it by July 26, 2028, and companies apply it from July 26, 2029. Its scope: EU companies with over 5,000 employees and €1.5 billion net turnover, and non-EU companies with over €1.5 billion in EU turnover.
Not at EU level since Omnibus I, which deleted the directive's EU-wide civil liability regime. Where a company is held liable under national law for failing its due diligence duties, member states must ensure victims receive full compensation. The EU rule requiring member states to let unions and NGOs bring claims on victims' behalf was also dropped.
Get Compliance Help

Need compliance support?

Navigating Corporate Sustainability Due Diligence Directive (CSDDD) requirements is complex. Council Fire’s regulatory experts can guide your compliance strategy.