# CSDDD (Corporate Sustainability Due Diligence Directive) Compliance

Climate Disclosure & Sustainability Laws

###### CSDDD

## Your Largest Customers Will Demand Human Rights and Environmental Due Diligence Evidence From Your Entire Value Chain. Can You Deliver It?

CSDDD compliance requires risk-based due diligence across your own operations, subsidiaries, and business partners—covering human rights, labour rights, and environmental impacts. The Omnibus I amendments are final. Member States must transpose by July 2028. All in-scope companies must comply by July 2029. Penalties reach 3% of global net turnover. Certivo automates supplier due diligence evidence collection from risk assessment to audit-ready documentation.

### Key Data Points

- **5,000+** Employee threshold for EU companies in scope (post-Omnibus I)
- **€1.5B** Net turnover threshold triggering CSDDD obligations
- **3%** Maximum penalty as percentage of global net turnover

## Regulation Overview

- **Jurisdiction:** European Union / European Economic Area (national transposition required)
- **Regulatory Body:** European Commission; enforcement by national supervisory authorities
- **Regulation Number:** Directive (EU) 2024/1760, amended by Directive (EU) 2026/470 (Omnibus I)
- **Effective Date:** Entered into force July 25, 2024; compliance required from July 26, 2029
- **Official Source:** [EU Source](https://commission.europa.eu/business-economy-euro/doing-business-eu/sustainability-due-diligence-responsible-business/corporate-sustainability-due-diligence_en)
- **Key Threshold:** >5,000 employees AND >€1.5B net worldwide turnover (EU companies)

# What is the CSDDD?

The CSDDD is the EU's mandatory human rights and environmental due diligence directive. It requires large companies to identify, prevent, mitigate, and remediate adverse impacts across their own operations, subsidiaries, and business partners' chains of activities—following the six-step OECD Due Diligence Guidance framework. Following the Omnibus I amendments published February 26, 2026, the CSDDD scope is narrowed to EU companies with more than 5,000 employees and €1.5 billion net worldwide turnover. Non-EU companies generating more than €1.5 billion in EU turnover are also in scope. Member States must transpose by July 26, 2028. Companies must comply from July 26, 2029. CSDDD compliance requires supplier-level due diligence evidence—risk assessments, contractual assurances, corrective action plans, and grievance mechanism records—from direct business partners and, where risk indicators exist, from indirect partners. When supervisory authorities investigate, your evidence chain must be complete.

## Key Components / Sub-Frameworks

**Obligations**  
1. **Due Diligence Policy**: Adopt, publish, and periodically update formal policy integrating HREDD into management systems
2. **Impact Assessment**: Scoping exercise followed by in-depth assessment of most severe and likely impacts
3. **Prevention & Mitigation**: Prevention action plans; contractual assurances from business partners
4. **Remediation**: Financial or non-financial remediation proportionate to implication
5. **Grievance Mechanism**: Operational mechanism for affected stakeholders and their representatives
6. **Monitoring & Reporting**: At least every 5 years; annual due diligence statement from FY 2030

## Key Compliance Requirements

# Who Must Comply

- EU companies with 5,000 employees AND €1.5 billion net worldwide turnover
- Non-EU companies generating €1.5 billion net turnover in the EU
- EU/non-EU franchisors and licensors with €75M royalties AND €275M net turnover
- Subsidiaries of in-scope parent companies (obligations may be fulfilled at group level)
- Companies in the value chain of in-scope entities (indirect compliance pressure)
- Companies already subject to national due diligence laws (e.g., German LkSG, French Loi de Vigilance)

# Key Thresholds

#### 5,000 employees + €1.5B turnover  
EU company in scope of CSDDD obligations

#### €1.5B EU turnover  
Non-EU company in scope (no employee threshold)

#### 3% of net worldwide turnover  
Maximum administrative penalty for non-compliance

#### 5 years  
Minimum frequency for effectiveness monitoring assessments

## Core Obligations

1. `Due Diligence Policy`: Adopt and embed HREDD policy into governance and risk management systems  
   **DEADLINE:** From July 26, 2029
2. `Impact Identification & Assessment`: Scoping exercise to identify adverse impacts  
   **DEADLINE:** Ongoing; at least every 5 years
3. `Prevention & Mitigation`: Implement prevention action plans  
   **DEADLINE:** Ongoing once impacts identified
4. `Grievance Mechanism`: Operate accessible complaints procedure  
   **DEADLINE:** From July 26, 2029
5. `Annual Due Diligence Statement`: Publish statement on sustainability due diligence matters  
   **DEADLINE:** For financial years starting on or after January 1, 2030

## CSDDD-Specific Pain Points

### The Value Chain Visibility Gap

Your company has 800 direct suppliers and thousands of indirect partners. CSDDD requires a scoping exercise across your entire chain of activities.

### The Contractual Assurance Scramble

CSDDD requires contractual assurances from direct business partners to prevent adverse impacts.

### The Risk-Based Prioritization Challenge

The Omnibus I amendments require companies to prioritize the most severe and most likely adverse impacts.

### The Cascading Compliance Demand

Even if your company falls below CSDDD thresholds, your largest customers are in scope. They will cascade due diligence requirements down to you.

## Certivo in Action—CSDDD Workflow

### GET EVIDENCE IN

Collect Human Rights and Environmental Due Diligence Evidence From Every Supplier—Without the Chasing.

### MAKE SENSE OF IT

Know Instantly Which Suppliers and Value Chain Segments Carry the Highest Risk.

### PROVE COMPLIANCE OUT

Demonstrate Due Diligence to Supervisory Authorities and Customers in Hours, Not Months.

## Features Tabs

### Due Diligence Collection

Certivo's automated campaigns achieve 95% response rates vs. 20-30% with manual outreach.

### Risk Extraction & Scoring

Every supplier submission parsed to risk-indicator level automatically—no manual data entry.

### Impact Prioritization

Always validated against current risk data—not your last annual assessment.

### Customer Response

Generate CSDDD compliance evidence packages in hours instead of 4-6 weeks.

### Annual Reporting

Pre-validated due diligence data turns annual reporting from burden to streamlined workflow.

## Key Statistics

- **6** OECD due diligence steps operationalized per supplier
- **99.2%** Risk indicator extraction accuracy from supplier submissions
- **95%** Supplier response rate with CORA-powered campaigns

## Frequently Asked Questions

### What companies are in scope of the CSDDD after the Omnibus I amendments?

Following Directive (EU) 2026/470, the CSDDD applies to:
- EU companies with more than 5,000 employees and net worldwide turnover exceeding €1.5 billion.
- Non-EU companies generating more than €1.5 billion in EU turnover.

### What are the penalties for CSDDD non-compliance?

Under the Omnibus I amendments, administrative fines are capped at a maximum of 3% of global net worldwide turnover.

### What does the CSDDD due diligence process require in practice?

Companies must follow the six-step OECD framework.

### How does Certivo support CSDDD supplier due diligence at scale?

CORA launches targeted due diligence campaigns, collects supplier risk self-assessments, extracts risk indicators automatically, and generates customer-ready compliance packages.

### How does the CSDDD relate to the CSRD, LkSG, and other EU sustainability regulations?

CSDDD covers due diligence obligations, while CSRD covers sustainability reporting. Certivo validates supplier evidence against all applicable frameworks from a single submission.
