Corporate Sustainability Due Diligence Directive (CSDDD)
The Corporate Sustainability Due Diligence Directive (CSDDD), Directive (EU) 2024/1760, is an EU Directive requiring large companies to undertake due diligence on their own activities and those of their business partners. The core elements of this duty include identifying, ending, preventing, mitigating, and accounting for negative human rights and environmental impacts in the company’s operations, value chains and subsidiaries.
Specifically, the Directive provides a harmonised legal framework to address environmental and human rights adverse impacts by setting clear expectations and legal obligations for businesses to follow, ultimately contributing to a more sustainable and responsible economy.
As per the Annex to Directive (EU) 2024/1760 (Part I, human rights; Part II, environment), and drawing on internationally recognised frameworks and conventions such as the ILO conventions and the Montreal Protocol, examples of human rights and environmental adverse impacts that companies must assess and manage include, but are not limited to:
- Human rights: child labour, forced or compulsory labour, and discrimination; and
- Environmental: biodiversity loss, marine pollution, and environmental degradation.
By identifying, preventing, mitigating, and accounting for these adverse impacts, and by implementing robust governance and management systems, companies can drive meaningful change, fostering transparency and accountability.
From a due diligence perspective, the CS3D does not invent a new standard of corporate conduct, it takes the long-standing voluntary framework set out in the UN Guiding Principles on Business and Human Rights (2011) and the OECD Guidelines for Multinational Enterprises on Responsible Business Conduct (and the accompanying OECD Due Diligence Guidance) and converts it into binding EU law for large companies. Therefore, CS3D’s real innovation is not the substance of the standard but its legal status, turning a widely-adopted but voluntary corporate responsibility framework into an enforceable obligation, backed by supervisory authority powers.
Under Article 5 of Directive (EU) 2024/1760, the CS3D’s core due diligence duty is set out as a defined sequence of actions that maps directly onto the OECD’s well-known six-step due diligence framework:
- Embed responsible business conduct into policies and management systems (Article 7)
- Identify and assess adverse impacts in operations, supply chains and business relationships (Article 8,9)
- Cease, prevent or mitigate adverse impacts (Articles 10,11)
- Track implementation and results (Article 15)
- Communicate how impacts are addressed (Article 16)
- Provide for or cooperate in remediation when appropriate (Article 12, 13, 14)
Please note, the Omnibus I Directive (EU) 2026/470, published in the Official Journal on 26 February 2026 and effective from 18 March 2026, significantly narrowed the scope and softened several of the CS3D’s key requirements. In summary, it raised the scope thresholds, confined systematic due diligence to direct business partners, removed the climate transition plan obligation, replaced the previous uncapped 5% penalty floor with a 3% cap, and unified the compliance dates onto a single date, one year later than the original transposition deadline.
The CSDDD proposal aims to foster sustainable and responsible corporate behavior across global value chains, providing legal certainty and a level playing field for companies.
This objective, however, has been significantly recalibrated by the Omnibus I Directive (EU) 2026/470. Omnibus I was introduced under the Commission’s broader “simplification and competitiveness” agenda, following feedback that the original CSDDD imposed disproportionate administrative burden, particularly on companies sitting just above the original thresholds and on SMEs indirectly caught through the value chains of larger in-scope companies.
The Omnibus narrows who it applies to and how far certain obligations reach.
Who it applies to: Scope changes in detail
The most significant change is to the scope thresholds, which determine which companies must comply at all:
- EU companies: The threshold has risen from > 1,000 employees and €450 million net worldwide turnover, to > 5,000 employees and €1.5 billion net worldwide turnover,
- Non-EU companies: The threshold has risen from €450 million net turnover generated in the EU, to €1.5 billion net turnover generated in the EU,
- Franchising/licensing groups: The royalty and turnover thresholds have risen from €22.5 million royalties / €80 million worldwide turnover, to €75 million royalties / €275 million worldwide turnover.
Other key changes and what they mean:
| Change | What it means |
| Due diligence narrowed to direct business partners | Systematic due diligence is now required only in relation to direct business partners; indirect business partners are assessed only where credible information indicates an adverse impact has occurred or could occur. Companies no longer need to map and assess their entire multi-tier supply chain by default. |
| Climate transition plan obligation repealed | The standalone duty to adopt and implement a climate transition plan for climate-change mitigation has been removed entirely. Transition planning is no longer a CSDDD compliance item (though it may still arise under CSRD reporting obligations for companies in scope of that Directive). |
| EU-harmonised civil liability regime removed | The Union-wide civil liability regime has been deleted; liability is now governed by national law. The specific route to compensation, evidentiary rules, and procedural mechanics will vary by Member State, though victims retain a right to full compensation where liability is established. |
| Penalty cap replaced the previous floor | The uncapped minimum of 5% of global turnover has been replaced with a harmonised maximum cap of 3% of net worldwide turnover. Penalties are now bounded, and supervisory authorities must weigh a broader set of factors (gravity, duration, mitigating action) rather than anchoring fines to turnover alone. |
| Compliance dates unified | Transposition and application deadlines have been consolidated onto single dates for all in-scope companies. No more staggered “Group 1 / Group 2” wave dates, everyone complies from the same date |
What remains: Core requirements still in force
| Key requirement | What it means |
| Due diligence policy & risk management integration (Art. 7) | Companies must adopt a due diligence policy, developed in consultation with employees, and integrate it into corporate policies and risk-management systems, including a code of conduct extended to business partners. |
| Identification and assessment of adverse impacts (Art. 8, 9) | Companies must map operations and direct business partners to identify where impacts are most likely and severe, conduct an in-depth assessment in those areas, and prioritise the most severe/likely impacts where not all can be addressed at once. |
| Prevention of potential impacts (Art. 10) | Companies must take appropriate measures to prevent identified potential adverse impacts before they occur, including adapting purchasing practices and seeking contractual assurances. |
| Ending or minimising actual impacts (Art. 11) | Where an adverse impact has occurred, companies must take appropriate measures to bring it to an end or minimise its extent, with disengagement retained only as a last resort. |
| Remediation (Art. 12) | Companies must provide remediation where they have caused or contributed to an adverse impact. |
| Stakeholder engagement (Art. 13) | Companies must engage meaningfully with affected stakeholders at defined stages of the due diligence process (identification, action planning, remediation design). |
| Complaints and notification mechanism (Art. 14) | Companies must establish and maintain a channel for stakeholders to raise concerns about actual or potential adverse impacts. |
| Monitoring effectiveness (Art. 15) | Companies must monitor whether their due diligence policy and measures are actually working, and update them where necessary. |
| Public reporting (Art. 16) | Companies must publish an annual statement on due diligence; detailed content requirements are pending via a delegated act due by 31 March 2029. |
| Supervisory oversight (Art. 24, 25) | Member States must designate one or more national supervisory authorities with powers to investigate and require information from companies. |
| Penalties (Art. 27) | Non-compliance can trigger penalties (capped at 3% of net worldwide turnover) and a public statement naming the company. |
| Civil liability (Art. 29) | Companies can still be held liable for damage under national law where due diligence failures cause harm, with victims retaining a right to full compensation. |
The Directive targets both EU and non-EU companies generating turnover in or from the EU. Under Article 2, as amended by Omnibus I, a company falls into scope if it meets one of two alternative tests: a size-based test, or a franchising/licensing-based test.
EU companies (Article 2(1)): in scope if:
- the company itself has more than 5,000 employees on average and a net worldwide turnover of more than €1.5 billion in the last financial year; or
- the company does not meet that threshold itself, but is the ultimate parent company of a group that meets it on a consolidated basis; or
- the company (or its ultimate parent) has entered into EU franchising or licensing agreements generating more than €75 million in royalties, provided the group’s worldwide net turnover exceeds €275 million.
Non-EU companies (Article 2(2)): in scope if:
- the company generated a net turnover of more than €1.5 billion in the EU in the financial year preceding the last financial year; or
- the company does not meet that threshold itself, but is the ultimate parent company of a group that meets it on a consolidated basis in the EU; or
- the company (or its ultimate parent) has entered into EU franchising or licensing agreements generating more than €75 million in EU royalties, provided the group’s EU net turnover exceeds €275 million.
A company only falls into (or out of) scope once these conditions are met, or cease to be met for two consecutive financial years (Article 2(5)), and holding companies that are purely passive investment vehicles may apply to their supervisory authority for an exemption if a designated EU subsidiary takes on the obligations instead (Article 2(3)).
SMEs are not directly in scope, but may be indirectly affected as business partners of larger in-scope companies. This is otherwise known as the trickle down effect.
Next steps: The CS3D entered into force on 25 July 2024. Under Article 37, as amended by Omnibus I, Member States must transpose the amended Directive into national law by 26 July 2028, with in-scope companies required to comply from a single, unified application date of 26 July 2029, except for the Article 16 annual reporting obligation, which applies only from financial years starting on or after 1 January 2030.
The CS3D introduces corporate human rights and environmental due diligence duties across companies’ value chains and subsidiaries and, once applicable, it covers companies across all sectors, including financial services. Under Article 2(1)(a)(iii), a “regulated financial undertaking” (e.g. credit institutions and other categories defined by reference to EU financial services legislation) is itself a type of “company” that can fall within scope, regardless of its legal form.
For regulated financial undertakings, the Directive’s general definition of “chain of activities” (Article 3(1)(g)) applies without its downstream limb. Recital 27 confirms that, for regulated financial undertakings, “the definition of the term ‘chain of activities’ should not include downstream business partners that receive their services and products,” so that “only the upstream but not the downstream part of their chains of activities” is covered by the Directive. In practice, this means clients receiving loans, credit, insurance or other financial services and products sit outside the regulated financial undertaking’s due diligence obligations for downstream activities altogether, while the undertaking’s own operations and its own upstream suppliers remain fully in scope, as for any other company.
Whether to extend due diligence obligations further into financial services, for example to investment activities more broadly, was originally intended to be addressed through a dedicated Commission report under Article 36(1), due by 26 July 2026. Omnibus I has deleted that obligation entirely (rather than merely postponing it), on the basis that a specific financial-sector review was premature ahead of experience with the newly established general due diligence framework. There is no “high-impact sectors” list in the final Directive, an earlier sectoral risk-based scoping mechanism from the Commission’s original 2022 proposal was dropped before adoption and does not feature in the current, Omnibus-amended text. As things stand, whether financial services due diligence is extended further is likely to depend on the Commission’s broader five-yearly implementation review under the amended Article 36(2), the first of which is due by 26 July 2031.
The CS3D is linked to several other European sustainable finance legislative pieces:
- Taxonomy Regulation: The CS3D complements the Taxonomy Regulation by helping collect information on companies and their value chains that can be used in EU Taxonomy-alignment assessments. Article 18 of the Taxonomy Regulation sets out “minimum safeguards”, due diligence and remedy procedures a company must have in place to ensure alignment with the OECD Guidelines for Multinational Enterprises and the UN Guiding Principles on Business and Human Rights, as one of the four criteria an economic activity must meet to qualify as environmentally sustainable. The CS3D sets the regulatory framework that allows the collection of information used to assess this alignment.
- Sustainable Finance Disclosure Regulation (SFDR): The CS3D complements the SFDR. Financial Market Participants (FMPs) with more than 500 employees are required by the SFDR to publish a statement on their due diligence policies concerning Principal Adverse Impacts (PAIs) of their investment decisions on sustainability factors, on a comply-or-explain basis. The CS3D sets the regulatory framework that allows the collection of information used to publish this statement.
- Corporate Sustainability Reporting Directive (CSRD): The CS3D is also linked to the CSRD, which has itself been amended by Omnibus I in parallel with the CS3D (raising its own scope thresholds and narrowing its reporting requirements). The CSRD requires companies to set up processes to collect information for reporting purposes that is closely related to identifying adverse impacts under the CS3D’s due diligence duty. The two Directives are complementary rather than strictly sequential: the CS3D imposes its own standalone annual due diligence reporting obligation (Article 16), separate from the CSRD’s broader sustainability reporting regime.
No draft law has been published regarding the transposition of the CS3D as at August 2026. However, a motion no. 4778 was approved by the Luxembourg parliament (Chambre des Députés) for the purpose of inviting the government to ensure, in the context of the transposition of the CS3D, that (i) the supervising authority enjoys organisational, administrative and financial independence from the government and (ii) the designated supervisory authority shall develop sufficient expertise in the fields of human rights and environmental protection.
2024:
- 15 March 2024: Member States voted on a new text in COREPER.
- 24 April 2024: The European Parliament plenary approved the CS3D political agreement.
- 24 May 2024: The Council formally adopted the CS3D.
- 5 July 2024: The CS3D was published in the Official Journal of the EU as Directive (EU) 2024/1760.
- 25 July 2024: The CS3D entered into force.
2025: “Stop-the-Clock”
- 17 April 2025: Directive (EU) 2025/794 (the “Stop-the-Clock” Directive) entered into force, procedurally postponing the original transposition/application timeline by one year while the substantive Omnibus I negotiations continued. This was a delay-only mechanism: it did not change scope, thresholds, or substantive obligations.
2025–2026: Omnibus I (substantive amendments)
- 26 February 2025: European Commission publishes the Omnibus I package, proposing to raise thresholds, narrow due diligence to direct business partners, remove the mandatory transition-plan obligation, cap fines, and remove the EU-harmonised civil liability regime.
- 16 December 2025: European Parliament approves the final negotiated Omnibus I text.
- 24 February 2026: Council formally adopts Omnibus I.
- 26 February 2026: Published in the Official Journal as Directive (EU) 2026/470.
- 18 March 2026: Omnibus I enters into force
- 23 February 2022: The European Commission issued its proposal for the CS3D.
- November 2022: The EU Council released a ‘general approach’ to the proposal.
- 1 June 2023: The European Parliament adopted its negotiating position on the CS3D proposal
- 5 July 2024: The CS3D was published in the Official Journal of the EU; under the original text, the Directive entered into force 20 days after publication, and Member States originally had until 26 July 2026 (two years from entry into force) to transpose the rules into national law.
- 25 July 2024: The CS3D entered into force.
- 26 February 2025: The European Commission published its Omnibus I proposal to reduce sustainability disclosure requirements and administrative burdens as part of its competitiveness and growth agenda, proposing amendments to both the CS3D and CSRD, including raised scope thresholds, postponed application dates, and narrower due diligence requirements.
- 17 April 2025: Directive (EU) 2025/794 (the “Stop-the-Clock” Directive) entered into force, procedurally postponing the original CS3D transposition and application dates by one year, pending the outcome of the substantive Omnibus I negotiations.
- 16 December 2025: The European Parliament approved the final negotiated Omnibus I text.
- 24 February 2026: The Council formally adopted the Omnibus I Directive, simplifying the CS3D by raising thresholds to >5,000 employees and >€1.5 billion turnover, narrowing scope to only the largest EU and non-EU companies operating in the Union.
- 26 February 2026: Omnibus I published in the Official Journal as Directive (EU) 2026/470.
- 18 March 2026: Omnibus I entered into force. This is now the operative, amended version of the CS3D.
- 12 June – 24 July 2026: The European Commission ran a public consultation on guidelines for the implementation of the CS3D (now closed).
Where we stand today: the amended CS3D is in force but not yet applicable. National transposition is due by 26 July 2028, and the unified compliance deadline for all in-scope companies is 26 July 2029.
On 12 June 2026, the European Commission launched a public consultation on guidelines for the implementation of the Corporate Sustainability Due Diligence Directive, covering the practical application of due diligence obligations, such as the identification and prioritisation of risks, and stakeholder engagement. The consultation closed on 24 July 2026, and the Commission is now processing the responses received.
The Commission has indicated it is targeting adoption of the first tranche of guidelines in Q1 2027, ahead of the 26 July 2027 statutory deadline for that tranche. No draft guidelines text has been published yet.

