For years, organizations have evaluated their suppliers primarily from an economic perspective: price, quality, delivery times, and technical capabilities.
The Corporate Sustainability Due Diligence Directive (CSDDD) significantly changes this approach. Once it takes effect, large European companies will be required to demonstrate that they identify, prevent, mitigate, and monitor risks related to human rights and the environment throughout their value chain.
Due diligence is no longer just a best practice; it has become an ongoing, documented process.
What is the CSDDD?
The CSDDD (Corporate Sustainability Due Diligence Directive), also known as CS3D, is a European directive whose goal is to ensure that companies integrate sustainability risk management into their day-to-day operations.
It is not just a matter of publishing a sustainability report, but of demonstrating that there is a system in place capable of identifying risks, taking action when they arise, and maintaining records of all actions taken.
Among the main obligations are:
- Have a due diligence policy in place.
- Identify and assess risks in operations and throughout the value chain.
- Take measures to prevent or mitigate negative impacts.
- Implement corrective actions when noncompliance is detected.
- Have mechanisms in place to receive complaints and reports.
- Periodically monitor the system’s effectiveness.
- Publicly report on the measures taken.
In short, the CSDDD requires the implementation of a continuous management model, not a one-time review.
Which companies does this apply to?
Following the amendments introduced by the Omnibus Package, the directive will initially apply to large companies.
European Union companies that simultaneously exceed the following thresholds will be subject to the rules:
- 5,000 employees.
- 1.5 billion euros in global revenue.
Certain companies outside the EU that generate more than 1.5 billion euros in annual revenue within the European market will also be included.
Member States must transpose the directive into their national legislation by July 2028, and the obligations will take effect as of July 2029.
The big question: What about companies that aren’t required to do so?
This is where the greatest impact will likely be felt.
Although thousands of companies do not fall directly within the scope of the directive, many will be part of the supply chain of organizations that are subject to it.
A large company must demonstrate that it is aware of the risks associated with its suppliers. To do so, it will need to request information, evaluate evidence, and conduct periodic follow-ups.
This means that many small and medium-sized businesses will receive requests such as:
- Do you have a reporting channel?
- How do you evaluate your own suppliers?
- What human rights policies have you implemented?
- How do they manage environmental risks?
- What controls are in place?
- How do you train your employees?
- What evidence can they provide?
In other words, even if a company is not legally bound by the CSDDD, its customers may still require it to demonstrate a certain level of maturity in order to remain part of its supply chain.
Due diligence requires a system, not isolated documents
Responding to each questionnaire manually may be feasible once.
Dealing with dozens of different customers, each with their own requirements, is a whole different story.
Organizations will need to centralize compliance-related information to avoid duplication and keep documentation up to date at all times.
Some of the elements that are likely to become commonplace include:
- List of suppliers and third parties.
- Risk Assessments.
- Certification questionnaires.
- Mitigation plans.
- Regular inspections.
- Policy Management.
- Incident Log.
- Channel for reporting issues and filing complaints.
- Records and traceability of all actions.
The key will not be simply having this information, but being able to demonstrate when it was obtained, who reviewed it, what decisions were made, and how the risk evolved.
A single repository for multiple regulations
The CSDDD should not be viewed as an isolated obligation.
It shares many elements with regulatory frameworks such as NIS2, DORA, ISO 27001, ENS, ISO 37301, the AI Act, and whistleblower protection obligations.
For this reason, it makes more and more sense to build a unified compliance model in which risks, controls, suppliers, policies, incidents, and evidence are managed from a single platform and then mapped against the various regulatory requirements.
This approach reduces duplicate work, improves traceability, and makes it easier to respond to audits as well as requests from customers or regulators.

Opportunity comes before obligation
It’s easy to think that the CSDDD affects only a few thousand large companies.
However, its true scope will be much greater.
Every regulated company works with hundreds or thousands of suppliers. All of them will have to account for, demonstrate, and document how they manage their risks.
The question will no longer be solely whether an organization is bound by the directive.
The question will be whether it is prepared to demonstrate to its customers that it properly manages the risks associated with its operations and supply chain.
And that capability will likely end up becoming a competitive advantage for any organization that wants to remain part of the most demanding supply chains.