How to Meet CSDDD Requirements: A Guide for Global Businesses

By Michela Mossali | 29 July 2026

minutes to read.

csddd guide blog header

The era of plausible deniability in global supply chains is at an end. With the EU’s Corporate Sustainability Due Diligence Directive (CSDDD), the corporate landscape is shifting from voluntary sustainability commitments to strict accountability.

It means companies can no longer state they are unaware of human rights or environmental issues within their supply networks. Now they are required to actively identify and prevent these issues across their entire operations – or risk non-compliance penalties.

This article provides a comprehensive breakdown of the CSDDD, covering its scope, implementation timeline, and the financial and reputational stakes of non-compliance.

We will explore practical strategies for supply chain risk management, highlighting how cutting-edge forensic science is emerging as a vital tool for verifying origin and ensuring CSDDD compliance.

 

Contents:

  1. Understanding the Corporate Sustainability Due Diligence Directive: Scope & applicability
  2. Consequences of failure: Penalties, liability, and reputation
  3. Identifying and mitigating supply chain risks: Enhancing due diligence with verification
  4. Beyond the audit: Achieving CSDDD compliance with forensic science

 

1. Understanding the Corporate Sustainability Due Diligence Directive: Scope & applicability

The Corporate Sustainability Due Diligence Directive was introduced by the European Union to compel large companies to identify, prevent, and mitigate human rights abuses and environmental harms across their global supply chains.

This extends beyond their own immediate operations to also encompass those of upstream and downstream partners. The EU Omnibus Directive, which came into effect in March 2026, specifies that businesses must undertake “risk-based due diligence across the chain of activities”, focusing on those areas where adverse risks are most likely.

In contrast to sustainability policies of the past, the CSDDD is not a voluntary ESG initiative but a legal mandate.

 

Determining your employee threshold and turnover

The CSDDD applies to both EU and non-EU companies that meet specific size and revenue thresholds. It covers:

  • EU-based companies with 5,000+ employees and worldwide turnover exceeding €1.5 billion.
  • Non-EU companies with more than €1.5 billion in turnover within the EU market.

 

Extraterritoriality and the impact on non-EU businesses

The CSDDD extends its reach far beyond Europe by targeting non-EU companies based on their economic footprint within the EU rather than their physical location. This places significant extraterritorial legal exposure on any company conducting business within the EU.

Globally, corporations generating over €1.5 billion in net turnover within the EU face direct mandatory compliance and severe regulatory penalties based on their worldwide revenue.

The regulation obliges both in-scope EU and non-EU businesses to clean up their supply networks and meet strict environmental and labor standards in order to maintain effective commercial relationships.

 

The timeline for compliance: CSDDD effective date

The CSDDD comes into effect from July 2029. The original timeline of a staggered rollout across 2027–2029 was overhauled when the EU Omnibus Directive was adopted in early 2026.

EU Member States are now required to transpose the CSDDD into their national legislation by the end of July 2028. Compliance obligations for all in-scope companies take effect from July 2029.

 

Key regulatory distinctions: CSDDD vs CSRD

While both the CSDDD and Corporate Sustainability Reporting Directive (CSRD) are pillars of the EU’s green transition, they serve fundamentally different functions: the CSRD mandates transparency, while the CSDDD enforces action.

The table below contrasts how these two directives operate.

Feature

Corporate Sustainability Due Diligence Directive

Corporate Sustainability Reporting Directive

Core focus

Companies must identify, prevent, and mitigate adverse human rights and environmental impacts.

Companies must report on their environmental, social, and governance (ESG) impacts, risks, and opportunities.

Scope of responsibility

Direct legal liability for harms occurring within the operations of the company and its supply chain partners.

Accurate disclosure of the company's operations and upstream/downstream supply chain.

Enforcement

Fines of up to 3% of global net turnover and civil liability.

Statutory audit requirements and compliance penalties managed at the member-state level.

Effective date

From July 2029

Since 2025

2. Consequences of failure: Penalties, liability, and reputation

The stakes of non-compliance are high under the Corporate Sustainability Due Diligence Directive, with businesses facing the prospect of immediate financial hits, civil liability suits, and long-term brand damage.

 

Financial penalties and turnover-based fines

National supervisory authorities are empowered to set financial penalties of at least 3% of global net turnover on businesses that fail to meet the regulation’s requirements.

These fines are calculated based on a company's total worldwide turnover – meaning their entire global revenue is at risk, not just earnings from the European market.

 

The rise of civil liability and the threat of litigation

The CSDDD also provides a private enforcement mechanism, allowing individuals, communities or NGOs (non-governmental organizations) to sue companies for damages caused by due diligence failures.

Such civil lawsuits may be brought against companies if victims believe that a failure to conduct proper due diligence directly causes or contributes to human rights or environmental harm.

 

Protecting brand integrity against greenwashing and regulatory breaches

Beyond avoiding financial and legal penalties, proactive CSDDD compliance acts as a powerful shield for maintaining critical market access. As the EU rolls out broader anti-greenwashing frameworks, such as the Green Claims Directive, companies can no longer rely on superficial sustainability marketing.

By embedding rigorous, legally binding due diligence and verifiable supply chain tracing into their operations, businesses can validate sustainability claims, neutralize greenwashing risks and maintain access to lucrative EU markets.

 

 

Preparing for CSDDD implementation

There are several practical first steps that legal and ESG teams can take to align their internal governance structures ahead of CSDDD implementation.

1. Establish a joint, cross-functional oversight committee that bridges the gap between legal compliance and ESG strategy. This group should conduct a gap analysis to map existing sustainability policies against the directive’s strict legal mandates. This will help ensure that public ESG commitments are supported by enforceable corporate policies.

2. Review and update third-party risk management and procurement frameworks. Because the CSDDD mandates due diligence across the entire supply chain, legal and ESG departments cannot operate in silos when vetting suppliers. Legal teams must draft robust sustainability clauses into vendor contracts, while ESG teams provide the specific risk metrics and environmental benchmarks used to evaluate suppliers.

3. Establish remediation mechanisms and reporting frameworks to formalize company response to issues identified and to deliver verified ESG data and legal risk assessments to senior leadership and other stakeholders.

 

 

3. Identifying and mitigating supply chain risks: Enhancing due diligence with verification

While the core obligation of the CSDDD is identifying and mitigating supply chain risks related to adverse human rights and environmental impacts, traditional corporate risk mapping often fails to capture these issues accurately because it relies on incomplete, flawed or self-reported data.

 

Defining the scope of CSDDD human rights obligations

Under the CSDDD, human rights obligations require companies to actively identify, prevent, and mitigate severe abuses across their supply chain.

The directive focuses on forced labor and modern slavery, including child labor, unlawful recruitment, and hazardous working conditions.

Its scope also extends to broader community impacts, protecting local populations and indigenous groups from unlawful land clearing, toxic environmental exposure, or resource degradation caused by a company's operations or suppliers.

 

Why traditional audits create compliance blind spots

Supplier paperwork and digital platforms can fail to detect origin fraud because they rely on unverified, self-reported data that can be easily manipulated. Because these systems don’t physically verify the source of materials, they are susceptible to creating a false sense of security while hiding the reality of illicit sourcing deep in the supply chain.

This gap leaves companies vulnerable to CSDDD litigation, as authorities demand rigorous standard of care rather than simple box-ticking. If environmental or human rights abuses are uncovered later, businesses cannot use unverified digital certificates as a legal shield.

This compliance blind spot then exposes the company to significant penalties and reputational damage.

  

 

4. Beyond the audit: Achieving CSDDD compliance with forensic science

Forensic science offers a more reliable solution for meeting the CSDDD’s strict due diligence demands by replacing corporate reliance on unverified supplier declarations with robust scientific assurance. This pivot from trusting paperwork to proving origin is essential for driving ESG compliance and transparency.

 

The limitations of supplier questionnaires and social audits

Traditional compliance strategies rely heavily on digital platforms, blockchain tracking, or paperwork like bills of lading – all of which can record fraudulent or unverified data that hides illicit sourcing practices, providing a false veneer of legitimacy.

Digital-only traceability is merely a proxy for the truth, but the CSDDD requires actual mitigation of real-world risks. Under the directive, companies can face stiff fines and lawsuits if human rights or environmental abuses are uncovered.

Because enforcement authorities demand a rigorous, legally defensible standard of care, relying on unverified supplier declarations is no longer a viable protection.

 

Scientific product origin verification as a risk mitigation tool

Oritain analyzes physical products and raw materials to measure the specific stable isotopes and trace elements incorporated  from the local soil and water, with isotopic signatures shaped by regional climate conditions. This product origin verification creates an Origin Fingerprint  that is highly resistant to being faked or replicated.

This allows legal and ESG teams to confidently verify the ground truth of where a material used in their products was grown or harvested.

By providing independent forensic evidence accepted by regulatory enforcement authorities including US Customs and Border Protection, Oritain enables businesses to build a fraud-resistant, science-backed compliance framework.

 

Building a defensible evidence base for regulatory scrutiny

Oritain’s forensic science provides a robust audit trail for the CSDDD and other EU legislation, such as the EU Deforestation Regulation (EUDR) and the EU Forced Labor Regulation, by replacing unverified paper trails with trusted, empirical data.

While standard supplier self-declarations can easily collapse under regulatory scrutiny, Oritain delivers independent forensic evidence of a standard suitable for regulatory scrutiny and enforcement proceedings.

By backing compliance assertions with established physical science, businesses can prove compliance to EU regulators and insulate themselves against costly ESG-related litigation.

The Corporate Sustainability Due Diligence Directive requires companies trading in the European market to have greater oversight of their global supply networks.

Oritain’s forensic science plays an integral role in compliance frameworks to minimize supply chain risk and maintain market access.

Contact us

Disclaimer: The information provided in this document does not and is not intended to constitute legal advice. Instead, all information presented here is for general informational purposes only. Counsel should be consulted with respect to any particular legal situation.

michela mossali

Michela Mossali

Michela Mossali is Government Relations Manager at Oritain. Based in Milan, Italy, Michela supports the company’s communication, advocacy, and governance activities concerning governmental policy, with a focus on EU regulations.