Global supply chains are facing a historic turning point: With the adoption of the Corporate Sustainability Due Diligence Directive (CSDDD)—better known as the EU Supply Chain Act—the European Union is establishing a uniform, binding legal framework for corporate due diligence obligations. While the German Supply Chain Due Diligence Act (LkSG) has been in effect since 2023, the European directive goes significantly further in many respects.
For companies, this means not only new bureaucratic challenges, but also the need to fundamentally digitize their procurement processes and make them more transparent. In this article, we take a detailed look at what the CSDDD entails, who it applies to, and how you can best prepare for the new requirements.

What is the EU Supply Chain Act (CSDDD)?
The Corporate Sustainability Due Diligence Directive (CSDDD) is an EU directive that requires large companies to identify, prevent, and address the negative impacts of their business activities on human rights and the environment.
Unlike pure reporting (as is the case with the CSRD), the CSDDD requires active action. Companies must monitor not only their own operations but also those of their subsidiaries and business partners along the entire “chain of activities.” This includes both direct and indirect suppliers (upstream) as well as certain downstream activities such as distribution and recycling (downstream).
The Difference Between LkSG and CSDDD
Although the German LkSG was considered a pioneer, the European CSDDD differs from it in key respects. Here is an overview of the most important differences:
| Criterion | German LkSG | EU CSDDD |
| Scope of Application (Employees) | 1,000 or more employees | For companies with 1,000 or more employees (EU-wide) |
| Scope of Application (Revenue) | No revenue threshold | Starting at 450 million euros in global net revenue |
| Supply Chain Under Review | Focus on direct suppliers (Tier 1); indirect suppliers only if there is “substantial evidence” | Entire “activity chain” (upstream and parts of downstream) |
| Civil Liability | Expressly excluded | Yes, companies can be sued for damages |
| Climate Protection | No explicit requirement for climate plans | Requirement to Develop and Implement a Climate Transition Plan (1.5-Degree Target) |
| Sanctions | Fines of up to 2% of annual revenue | Fines of up to 5% of global net revenue |
Table 1: Comparison of Key Requirements Between the LkSG and the CSDDD.
To whom does the CSDDD apply? (Scope of Application)
The CSDDD will be phased in to give companies sufficient time to adapt. The directive applies to both EU companies and companies from third countries that generate significant revenue in the EU.
The timeline for implementation:
- Starting in 2027: Companies with more than 5,000 employees and global net revenue exceeding 1,500 million euros.
- Starting in 2028: Companies with more than 3,000 employees and global net revenue exceeding 900 million euros.
- Starting in 2029: Companies with more than 1,000 employees and global net revenue exceeding 450 million euros.
The Trickle-Down Effect for SMEs
Even though small and medium-sized enterprises (SMEs) do not fall directly under the scope of the CSDDD, they are significantly affected indirectly. Large corporations must ensure compliance with due diligence obligations throughout their entire supply chain. Consequently, they will pass these requirements on to their suppliers—including SMEs—through contractual commitments (codes of conduct), questionnaires, and audits. Those unable to meet these requirements risk losing important major customers.

The 6 Core Obligations of the CSDDD
To comply with the directive, companies must establish a systematic risk management system. The CSDDD defines six key due diligence obligations for this purpose:
- Integration into corporate policy: Due diligence obligations must be firmly embedded in corporate guidelines and management processes.
- Risk Assessment: Companies must identify and assess actual and potential adverse impacts on human rights and the environment.
- Prevention and Remediation: Potential risks must be prevented or minimized through appropriate preventive measures. Injuries that have already occurred must be stopped or mitigated.
- Grievance Procedure: An effective and accessible grievance procedure must be established for affected parties and stakeholders (e.g., labor unions, NGOs).
- Effectiveness Review: The measures taken must be reviewed regularly (at least once a year) to assess their effectiveness.
- Public Reporting: Companies must report annually on their compliance with due diligence obligations (often in conjunction with CSRD reporting).
In addition, the CSDDD calls for the development of a climate transition plan that ensures the company’s business model is compatible with the transition to a sustainable economy and with limiting global warming to 1.5 °C (Paris Agreement).
How Companies Need to Prepare Now
Implementing the CSDDD requires more than just filling out Excel spreadsheets. It calls for a comprehensive digital transformation of supplier management.
1. Create transparency (supply chain mapping)
The first step is to fully map out your own supply chain. Who are your direct suppliers? Where do they source their raw materials? Without a central supplier portal, it is impossible to manage this volume of data.
2. Risk-Based Approach
Since it is impossible to audit thousands of suppliers at the same time, the CSDDD calls for a risk-based approach. Companies must classify their suppliers according to country and industry risks. Automated risk and compliance dashboards help with this by cross-referencing data from external sources (e.g., sanctions lists, NGO reports) with internal supplier data.
3. Use AI-powered automation
The sheer volume of unstructured data (certificates, messages, audit reports) makes it nearly impossible to analyze manually. Modern software solutions therefore rely on artificial intelligence. For example, an integrated SC agent can automatically search the internet for negative media reports about suppliers, verify the validity of certificates, and immediately trigger a red alert on the dashboard in the event of critical incidents.

Criticism and Challenges
The adoption of the CSDDD was accompanied by intense political debates. While supporters praise its protection of human rights and the environment, business associations such as the BME and the DIHK have voiced strong criticism.
The main points of criticism:
- Bureaucratic Overload: The burden of documentation ties up enormous resources that are particularly lacking in small and medium-sized businesses.
- Competitive Disadvantage: European companies fear they will be at a disadvantage compared to competitors from third countries that are less strictly regulated.
- Withdrawal from high-risk markets: There is a risk that companies will withdraw from developing and emerging markets (de-risking) rather than improving conditions on the ground, which ultimately harms workers in those countries.
- Civil Liability: The possibility of being sued for damages in European courts carries incalculable financial risks.
Despite this criticism, the CSDDD is now a done deal. Companies would be wise not to view the requirements as a mere compliance exercise, but rather as an opportunity to make their supply chains more resilient and future-proof.

Conclusion: From Obligation to Strategic Opportunity
The EU Supply Chain Due Diligence Directive (CSDDD) marks a paradigm shift in global trade. It compels companies to assume responsibility far beyond their own factory gates. While implementation undoubtedly requires a significant effort, it also offers an opportunity to elevate supplier relationship management to a new, strategic level.
Companies that invest now in digital tools, automated risk analyses, and transparent processes will not only comply with legal requirements but also protect their businesses from reputational damage and supply disruptions.
FAQ: Frequently Asked Questions About the CSDDD
1. What does the abbreviation CSDDD stand for?
CSDDD stands for “Corporate Sustainability Due Diligence Directive.” In German, it is usually referred to as the EU Supply Chain Act or the EU Due Diligence Directive.
2. When does the CSDDD take effect?
The directive was finally adopted in May 2024. Member states now have two years to transpose it into national law. It will apply to the largest companies starting in 2027.
3. What will happen to the German LkSG?
The German Supply Chain Due Diligence Act (LkSG) will remain in effect for the time being, but must be adapted to the stricter requirements of the European CSDDD. The Federal Ministry of Labor and Social Affairs (BMAS) is preparing the necessary legislative amendments.
4. Are SMEs affected by the CSDDD?
Not directly, since the thresholds are set at 1,000 employees and 450 million euros in revenue. Indirectly, however, they are massively affected (trickle-down effect), as large customers will require their suppliers to comply with the standards as a contractual condition.
5. What is the difference between CSRD and CSDDD?
The CSRD (Corporate Sustainability Reporting Directive) governs reporting on sustainability issues. The CSDDD, on the other hand, requires active measures (due diligence)—that is, the actual prevention and remediation of human rights and environmental violations.
6. What does civil liability mean?
Unlike Germany’s LkSG, the CSDDD allows victims of human rights or environmental violations (e.g., factory workers in Asia) to sue European companies in European courts for damages if those companies have failed to meet their due diligence obligations.
7. What is a climate transition plan?
The CSDDD requires companies to develop and implement a plan that ensures their business model is compatible with the 1.5-degree target of the Paris Agreement. This includes specific emissions reduction targets.
8. How far back into the supply chain do I need to check?
The CSDDD covers the entire “chain of activities.” This includes all direct and indirect suppliers (upstream) as well as certain downstream business partners, such as transportation, warehousing, and distribution.
9. What penalties apply for violations?
The relevant national supervisory authorities (in Germany, this will likely continue to be the BAFA) may impose fines of up to 5% of global net revenue for violations of the CSDDD.
10. How can software help with implementation?
Specialized software solutions such as SC-Manager automate data collection via supplier portals, perform AI-powered risk analyses, monitor certifications, and document all measures in an audit-proof manner for reporting purposes.