Comply with confidence under the EU’s due diligence directive.
CSDDD at a glance
The Corporate Sustainability Due Diligence Directive, Directive (EU) 2024/1760 (also known as CS3D), requires large companies to carry out risk-based human rights and environmental due diligence across their own operations, subsidiaries, and business relationships.
Why CSDDD exists and how it compares
Why was CSDDD created?
Companies identify and address human rights and environmental risks, replacing a patchwork of voluntary commitments with one clear set of rules. It sits alongside related EU legislation, including:
- The Corporate Sustainability Reporting Directive (CSRD).
- The EU Forced Labour Regulation.
Together, these mark a move from voluntary sustainability commitments to enforceable legal obligations for large companies.

CSDDD vs CSRD: What’s the difference?
CSDDD puts a heavy focus on supply chain diligence because many risks happen outside a company’s direct control.
- CSDDD focuses on due diligence and risk management, identifying, preventing, and addressing harm
- CSRD focuses on sustainability reporting and disclosure, communicating what a company has done
Strong CSDDD due diligence makes CSRD reporting more manageable.

Which companies are in scope?
CSDDD applies to large companies, whether they’re based in the EU or not. The table below shows exactly which businesses are covered and when the rules start applying to them.
| Company Type | Does the Law Apply? | When |
| Large EU company | Yes, if it has more than 5,000 employees AND more than €1.5 billion in worldwide revenue | From 26 July 2029 |
| Large non-EU company (incl. US) | Yes, if it earns more than €1.5 billion in revenue from the EU specifically | From 26 July 2029 |
| Franchise or licensing business | Yes, if it earns more than €75 million in EU royalties AND has more than €275 million in total revenue | From 26 July 2029 |
| Small or medium business (SME) | Not directly, unless it independently meets one of the tests above. May still be asked by a larger customer for due-diligence info | Not applicable |
What are the main requirements under CSDDD?
Companies subject to CSDDD must establish and maintain a comprehensive due diligence framework. Key requirements include:
Identify and assess adverse impacts
Companies must identify and prioritise actual and potential human rights and environmental impacts across their own operations, subsidiaries, and supply chain
Prevent and mitigate risks
Where risks are identified, companies must take steps to prevent or mitigate them, including working with suppliers and business partners
Remediate harm
Where harm occurs, companies must provide remediation and maintain a notification and complaints process so concerns can be raised and addressed
Monitor effectiveness
Due diligence processes must be reviewed regularly to check they’re working, and updated as risks change
Public communication
Companies must publicly report on their due diligence policies and actions, ensuring transparency and accountability
Integrate in policies
Companies must embed due diligence into their policies, risk management, and decision-making, with input from those affected
What parts of the value chain are covered?
CSDDD doesn’t treat every supplier and customer the same way. The table below shows which parts of a company’s own business and supply chain are covered. Map these relationships first, then focus effort where the risk of harm is greatest.
| Stage Part of the Business | What’s Included |
| The company itself | Its own day-to-day operations |
| Its subsidiaries | Other companies it owns or controls |
| Its direct business partners | Suppliers and customers it works with directly |
| Its wider supply chain | Everyone else involved in making, moving, storing, or delivering its products |
Not sure if CSDDD applies to you?
Check your company against CSDDD and seven other global supply chain laws, and get a shareable summary in under a minute. See which regulations apply.
Timeline, penalties, and enforcement
CSDDD timeline
CSDDD became law in 2024. EU countries had to write it into their own national law by 2028, and companies must start complying from 2029, with public reporting following from 2030. The table below breaks down each milestone.
| Phase | What It Means | Date |
| Law takes effect | The law officially becomes EU law | 25 July 2024 |
| Countries adopt it | Each EU country turns it into national law | By 26 July 2028 |
| Companies must comply | In-scope companies must follow the rules | From 26 July 2029 |
| Companies must report | Public annual due-diligence statements begin | For financial years from 1 January 2030 |
How CSDDD affects your team
For procurement teams
Procurement teams help meet CSDDD by factoring sustainability risk into buying decisions, communicating standards to suppliers, and keeping records that prove due diligence has been done.
Procurement best practices for CSDDD compliance

For procurement teams
Sustainability teams typically coordinate due diligence efforts across the business, align CSDDD work with other reporting like CSRD, and monitor performance over time.
See how sustainability teams can excel under CSDDD


Get ready for CSDDD: Preparation checklist
A few first steps to start with: map your supply chain tiers, identify high-risk geographies and sectors, and establish a due-diligence policy.
How Sedex supports CSDDD due diligence workflows
CSDDD calls for risk-based due diligence. Sedex gives you the tools to build it, spot the risks that matter most, act on them, and show the evidence when it counts.
Frequently asked questions about CSDDD
Related Sedex CSDDD resources
References
- Directive (EU) 2024/1760 — https://eur-lex.europa.eu/eli/dir/2024/1760.
- Amending instruments: Directive (EU) 2025/794; Directive (EU) 2026/470


