Flying Image Flying Image

navigating the

EU Corporate Sustainability Due Diligence Directive

The Corporate Sustainability Due Diligence Directive (CSDDD) requires companies to embed human rights and environmental due diligence into their core operations.

Since 2016, the CORE team members have advised 90+ multinational companies on building practical, long-term human rights and environmental due diligence systems tailored to their business model and value chain.

the core team is your CSDDD implementation partner.

On this page, we offer a concise overview of the CSDDD along with practical guidance for businesses preparing to implement it. Scroll down to find everything you need to know about the directive and its implications for your business.

WHAT DO YOU NEED TO KNOW ABOUT THE EU CORPORATE SUSTAINABILITY DUE DILIGENCE DIRECTIVE?

What is the CSDDD?

What is the CSDDD?

The CSDDD is a landmark piece of EU legislation that establishes binding obligations for large companies to conduct risk-based human rights and environmental due diligence.

Companies must identify and address actual and potential adverse human rights and environmental impacts in their own operation as well as through business relationships in their chain of activities; including the set-up of a notification and complaint mechanism, monitoring and public communication. 

Who does the CSDDD apply to?

Who does the CSDDD apply to?

Following the Omnibus I amendment, the CSDDD applies to:

  • EU companies with more than 5,000 employees and a net annual turnover of over €1.5 billion.
  • Non-EU companies generating more than €1.5 billion net annual turnover in the EU
  • EU and non-EU companies that have entered into franchising or licensing agreements in the EU and receiving royalties over €75 million in the EU and having an annual turnover of more than €275 million.
  •  

When does the CSDDD apply?

When does the CSDDD apply?

The Directive entered into force in July 2024 and was substantially amended by the Omnibus I package in March 2026.

The CSDDD will apply from 26 July 2029, and each EU Member State must transpose the Directive into national law by 26 July, 2028.

Which activities does it apply to?

Which activities does it apply to?

The CSDDD covers a company’s own operations and those of its subsidiaries, as well as its chain of activities, which includes both upstream and downstream business partners.

Upstream covers business partners involved in the production of goods or provision of services for the company, including the design, extraction, sourcing, manufacture, transport, storage and supply of raw materials through to the supply of the final product or service.

Downstream is more limited: it covers business partners involved in the distribution, transport, and storage of the company’s products, but only where those activities are carried out for or on behalf of the company.

What is the risk-based approach?

What is the risk-based approach?

According to the CSDDD, companies are required to take a risk-based approach to due diligence. This means they should prioritize the most significant risks by considering both the severity and likelihood of each adverse impact.

The goal is to identify the groups most likely to be affected and the rights that are most at risk (known as salient risks), and to focus on addressing these. The CSDDD puts this into practice through a two-step process set out in Article 8:
  • a high-level scoping exercise to identify and prioritize where adverse impacts are most likely and most severe,
  • followed by an in-depth assessment of those priority areas.

This approach is also recommended by international standards such as the OECD Guidelines for Multinational Enterprises on Responsible Business Conduct and the UN Guiding Principles on Business and Human Rights, which many companies have been voluntarily following for years.  

What is stakeholder engagement in CSDDD?

What is stakeholder engagement in CSDDD?

Meaningful stakeholder engagement is required throughout the due diligence cycle, namely, when gathering information on actual and potential adverse impacts to identify, assess and prioritize adverse impacts, when developing prevention and corrective action plans and when adopting remediation measures.

While the CSDDD does not explicitly define what “meaningful” means, it provides clear expectations on how such engagement should be, emphasizing that effective engagement should allow for “genuine interaction and dialogue at the appropriate level, such as project or site level, and with appropriate periodicity”.

It should also include providing “the relevant and comprehensive information” to those consulted for the sake of transparency.

What happens if an adverse impact is identified?

What happens if an adverse impact is identified?

The CSDDD requires companies to respond differently depending on whether an impact is potential (it could happen) or actual (it has already happened).

The required response also depends on the company’s role whether it caused the impact, contributed to it with a business partner, or is linked to it through a business partner’s activities.

For potential impacts, companies must prevent them or, if that is not possible, adequately mitigate them. This may include developing a prevention action plan, obtaining contractual assurances from business partners, or changing their operations, strategy, or purchasing practices.

For actual impacts, companies must bring them to an end or, where that isn’t immediately possible, minimize their extent. This can be done through similar measures as those to address potential impacts. They must also take a corrective action plan with clear deadlines and, where the company caused or contributed to the impact, provide remediation to those affected.

What are the rules on complaints and remediation?

What are the rules on complaints and remediation?

Meaningful stakeholder engagement is required throughout the due diligence cycle, namely, when gathering information on actual and potential adverse impacts to identify, assess and prioritize adverse impacts, when developing prevention and corrective action plans and when adopting remediation measures.

While the CSDDD does not explicitly define what “meaningful” means, it provides clear expectations on how such engagement should be, emphasizing that effective engagement should allow for “genuine interaction and dialogue at the appropriate level, such as project or site level, and with appropriate periodicity”.

It should also include providing “the relevant and comprehensive information” to those consulted for the sake of transparency.

How will the CSDDD be enforced?

How will the CSDDD be enforced?

The CSDDD will be enforced through two main mechanisms:

Administrative enforcement: Each Member State will designate one or more supervisory authorities responsible for monitoring compliance.

For the most serious infringements, financial penalties can reach at least 3% of the company’s net worldwide turnover, with the level determined by factors such as the gravity, nature, duration, and extent of the infringement, as well as the severity of its impacts, among other relevant circumstances.

Penalties must be effective, proportionate, and dissuasive.

The European Commission will also establish a European Network of Supervisory Authorities to promote a coordinated approach to enforcement across the EU.

Civil liability: Under the Omnibus I proposal, the harmonized EU rules on civil liability have been removed, leaving each Member State to establish its own regime.

Where a company is found liable under national law for failing to meet its due diligence obligations, affected persons are entitled to full compensation for the harm suffered.

the core team is your CSDDD implementation partner.

We meet you where you are.

Our services support you at every stage of your CSDDD implementation: from identifying risks across your value chain to taking targeted action and engaging the right people to address those risks effectively.

human rights due diligence is our expertise.

Since 2016, we have advised 90+ multinational companies operating across complex international value chains on developing practical human rights management systems.

THIS IS HOW WE WILL SUPPORT YOU

risk assessment

 WHAT:

You receive a risk-based approach to identifying and assessing human rights and environmental risks across your value chain, practical and designed to generate the insights you actually need. 

HOW:

We design a holistic approach tailored to your company’s context, where every element connects and works together, from scoping to in-depth assessment, while identifying where existing tools and digital solutions can add the most value.

At the scoping level, we support you in conducting a prioritization exercise across your own operations and business relationships to identify where adverse impacts are most likely to occur and most severe, ensuring the scoping generates the right insights for the right functions to act on and go deeper where needed.

Where priority areas have been identified, we support you in conducting in-depth assessments, including triangulation across multiple data sources, engagement with rightsholders and stakeholders and identification of root causes, to inform targeted measures.

action plan and measures

WHAT:

You receive a practical action plan and implementation roadmap with clear timelines for effectively addressing potential and actual human rights and environmental impacts in your value chain.

HOW:

We start from where you are, taking stock of existing practices and governance structures, and develop a prioritized set of targeted measures to address risks along the value chain in line with the CSDDD.

We cover your company’s own operations ensuring that actions fit the operational context, are specific for each risk area and region and consider the affected rightsholder groups, so that impacts are effectively addressed. We work collaboratively with key internal stakeholders to ensure organizational ownership as a basis for successful implementation.

Supporting you to address risks along your supply chain, we help you design a pragmatic and targeted supplier engagement strategy and process focusing on the highest risks in your sourcing activities. This includes ensuring that tools and systems used are properly embedded into one coherent process.

stakeholder engagement

WHAT:
You receive a structured, context-specific approach to engaging stakeholders, including directly affected people and their representatives, civil society organizations, as well as subject matter experts, to strengthen your risk management and help you develop more effective responses.

HOW:

With stakeholder engagement being a core element of due diligence outlined in the CSDDD, we help you identify the right stakeholders for your context, shape the questions and objectives that will guide the engagement and design a process that surfaces issues that desk research alone rarely reveals.

We design stakeholder engagement to be inclusive and culturally sensitive, ensuring that participants are informed, able to engage on equal footing, and that those most at risk of being adversely affected are especially considered.

Acting as a neutral intermediary, we facilitate engagement directly and help you translate insights from the engagement into concrete action.

You can find more information about our engagement services here.

ARE YOU OPERaTING in OR SOURCING FROM A high-risk or conflict-affected area?

Operating in conflict-affected or high-risk regions comes with heightened human rights risks that require a different approach.

We conduct in-depth assessments and direct stakeholder engagement on the ground, and where that’s not possible or safe, we involve local experts, diaspora organizations and community representatives.

The aim is to understand the dynamics of the conflict, the specific risks as well as how your business may be linked to the impacts and translate that into concrete recommendations you can act on

Stephanie

Not sure where to start?

Reach out.
We’ll build the right path forward.

Stephanie Borowiec 
stephanie@peopleatcore.com

Read more on the csddd from the core team

Share