Aug 24, 2026
10 min read

Before you wait for Brussels' CSDDD guidance, start designing your due-diligence system now

Governance
Regulation
Strategy

You have read the news. The Omnibus package cut the scope. The dates moved. Washington is publicly pressing Brussels to soften the rules further. So the temptation is obvious: sit tight, wait for the Commission's official guidance and the national laws, and let the picture settle before you spend a euro on due diligence.

Here is the problem with that plan.

The guidance will arrive before you have to comply. But if you wait for the complete guidance package and final national transposition before you start building, you could leave yourself only about twelve months to operationalise a due-diligence system across a complex group and chain of activities.

And while the Commission's guidelines will be important, they will not replace the national laws that supervisors actually enforce.

There is a better move, and it is available today. Enough of the architecture is already fixed in law to start designing the system now. The guidance and national transpositions should refine that system — not force you to build it from scratch in 2028.

Below is what is already settled, what remains open, and the due-diligence infrastructure you can start building this quarter.

The gap that should worry you

The Corporate Sustainability Due Diligence Directive (CSDDD), as amended by the Omnibus I Directive (EU) 2026/470, now creates a much clearer sequence than the original legislation.

When and what happens

  • 12 June–14 August 2026: Commission consultation on the CSDDD implementation guidelines. The consultation has now closed.
  • Q1 2027, planned: Commission adoption of the first package of implementation guidelines. The legal deadline is later.
  • 26 July 2027: Legal deadline for the main guidance tranche and the Commission's voluntary model contractual clauses.
  • 26 July 2028: Member States must have transposed the amended CSDDD into national law. The second guidance tranche — including guidance relating to protected sharing of compliance resources and stakeholder engagement — is also due by this date.
  • 26 July 2029: In-scope companies must start applying the national measures implementing the CSDDD.
  • Financial years starting on or after 1 January 2030: The CSDDD's Article 16 communication requirement begins to apply. Where a separate CSDDD statement is required, it is generally due no later than 12 months after the balance-sheet date. Companies already subject to the relevant CSRD sustainability-reporting requirements are exempt from that separate Article 16 statement.

That chronology changes the question.

The issue is not that Brussels will give you the instructions after compliance starts. It will not.

The issue is that a company waiting for all the instructions — the complete guidance package plus its final national legislation — may have only about one year left to turn legal requirements into operating processes, supplier workflows, governance, contracts, controls, evidence trails, complaints procedures and trained teams.

For a large multinational group, twelve months is not much runway.

Why waiting is still the riskiest option

Waiting can feel prudent because the legislation has already changed once. But four things make a full "wait and see" strategy more dangerous than it appears.

The guidance is not the law that ultimately binds you

The Commission's guidelines will matter. They should clarify how the Directive is expected to work in practice, help companies apply the requirements consistently and support national authorities in implementation and supervision.

But they remain guidance. They do not replace the Directive, national transposing legislation or ultimately the interpretation of EU law by the courts.

Your enforceable obligations will sit in the national measures implementing the CSDDD, overseen by national supervisory authorities.

That means the right design target is not "whatever the Commission guidance says." It is a system capable of accommodating the Directive, the guidance and the national rules together.

There will still be national differences — but not 27 completely different CSDDDs

The amended Directive contains important harmonisation rules that restrict Member States from imposing divergent general due-diligence obligations across much of the CSDDD's core architecture. That significantly reduces the risk of 27 fundamentally different substantive regimes.

But harmonisation does not eliminate national implementation.

Differences can still matter around supervision, enforcement practice, remedies, procedural rules, interaction with existing national laws and areas outside the harmonised core. Companies operating across several Member States therefore still need a system that can accommodate jurisdiction-specific overlays without rebuilding the underlying due-diligence process.

That is an architecture problem — and it is better solved before 2028 than during it.

Do not build your compliance plan around another political rescue

Washington is continuing to press the EU over the CSDDD and CSRD. On 14 August 2026, the United States publicly renewed calls for the EU to ease the impact of the legislation on US companies, building on commitments made in the 2025 EU-US trade framework.

So further political pressure is real.

Further legislative change is possible too.

But possible is not the same as adopted.

Any additional change to the Directive would require another legislative process. Until that happens, the rational planning baseline is the law that exists today — not the version somebody may negotiate tomorrow.

A well-designed due-diligence system is also not wasted if the legal scope narrows again. Risk mapping, supplier intelligence, grievance channels, contract governance and evidence management have operational value far beyond formal CSDDD compliance.

The dates that matter are already law

Directive (EU) 2026/470 was adopted on 24 February 2026 and entered into force on 18 March 2026. It fixes the revised scope, the 26 July 2028 transposition deadline, the 26 July 2029 application date and the reporting timetable.

You can plan against those dates today.

The remaining uncertainty concerns implementation detail — not whether a due-diligence operating system will be needed.

What is actually fixed today

Here is the good news that the "wait and see" instinct hides from you: the fundamental architecture of the obligation is already settled.

You do not need the final guidelines to know what a defensible due-diligence system needs to do.

Who is in scope

For EU companies, the amended CSDDD generally applies where the company has:

  • more than 5,000 employees on average; and
  • more than €1.5 billion in net worldwide turnover.

Ultimate parent companies can also fall within scope where the group reaches the relevant thresholds.

For qualifying franchising and licensing structures, the alternative threshold is more than €75 million in royaltiestogether with more than €275 million in net worldwide turnover.

For non-EU companies, there is no employee threshold. The general threshold is more than €1.5 billion in net turnover generated in the EU. For qualifying franchise and licensing arrangements, the corresponding EU thresholds are more than €75 million in royalties and more than €275 million in EU turnover.

The relevant scope conditions generally need to be met for two consecutive financial years.

Below the line? You are not automatically brought into the CSDDD's legal scope merely because you supply an in-scope company.

But you may still feel its effects.

Large customers can require information, contractual assurances, corrective actions and other forms of cooperation from business partners as part of their own due diligence. For many suppliers, CSDDD readiness will therefore become a commercial capability even where it is not a direct statutory obligation.

What the amended Directive already requires

The system is risk-based.

Companies must first carry out a scoping exercise based solely on reasonably available information across their own operations, their subsidiaries and, where connected to their chains of activities, their business partners. The purpose is to identify the general areas where adverse human-rights and environmental impacts are most likely to occur and most severe.

They must then carry out an in-depth assessment in the areas identified as presenting the greatest likelihood and severity.

That already tells you something important about system design:

CSDDD compliance is not supposed to be a giant questionnaire sent indiscriminately to every supplier. It is supposed to be a prioritised intelligence process.

The Directive also requires companies to:

  • integrate risk-based due diligence into their policies and risk-management systems;
  • maintain a due-diligence policy and review it at least every 24 months, updating it without undue delay after a significant change;
  • prevent or adequately mitigate potential adverse impacts;
  • bring actual adverse impacts to an end or minimise their extent;
  • provide remediation where the company has caused or jointly caused an actual adverse impact;
  • use appropriate measures such as action plans, investments, purchasing-practice changes, contractual assurances and support for business partners where relevant;
  • maintain notification and complaints procedures;
  • engage meaningfully with relevant stakeholders at the stages required by the Directive; and
  • assess the adequacy and effectiveness of due-diligence measures at least every five years, as well as when specified trigger events justify reassessment.

For regulated financial undertakings, the chain-of-activities concept does not extend in the same way to downstream financial services, leaving their CSDDD due diligence focused on the upstream side of the chain.

And where preventive or corrective measures ultimately fail, suspension of relevant business relationships can become a last-resort measure, alongside an enhanced action plan and a prohibition on entering into or extending affected relationships. The Directive also requires companies to consider whether suspension itself would cause even more severe adverse impacts.

That is not a supplier-checking exercise.

It is an operating model.

What the Omnibus took off your plate

Omnibus I materially reduced the burden compared with the original CSDDD.

The standalone CSDDD climate-transition-plan obligation is gone

Article 22 has been deleted.

CSDDD therefore no longer imposes its own standalone obligation to adopt and put into effect a climate-transition plan. Climate-related disclosure requirements may still arise under the CSRD and ESRS where applicable, but they are no longer a CSDDD due-diligence obligation.

The harmonised EU substantive civil-liability test is gone

Omnibus removed the specific EU-wide substantive liability regime originally created by the CSDDD.

Liability for damage is now determined under applicable national law. Where a company is held liable under national law for damage caused by failure to comply with CSDDD due-diligence requirements, Article 29 still requires access to full compensation and retains certain protections around access to justice.

Administrative penalties now have a 3% ceiling

Member States must set the maximum limit for pecuniary penalties at 3% of net worldwide turnover, or the corresponding consolidated worldwide turnover for relevant ultimate parent companies.

Information requests to smaller business partners are constrained

For the purposes of an in-depth assessment, information requests to business partners must be necessary.

Where the business partner has fewer than 5,000 employees, the company should request the information only when it cannot reasonably be obtained by other means. Requests should therefore become more targeted, proportional and evidence-driven rather than defaulting to blanket supplier questionnaires.

That provision alone should influence how companies design supplier-data systems today.

The system to start designing this quarter

You are not waiting for permission to begin.

You are waiting for implementation detail that does not prevent you from making the foundational decisions.

Here is a six-step programme you can start now, built on the adopted Directive and the risk-based due-diligence logic it shares with international frameworks such as the OECD Guidelines.

1. Confirm scope and map the group

Test each relevant EU and non-EU entity against the thresholds and the two-consecutive-financial-years rule.

Identify which ultimate parent companies may be in scope, which subsidiaries may independently qualify and whether group-level fulfilment of obligations makes sense.

This is not just a legal-scoping exercise. It determines ownership, governance, system boundaries and supervisory exposure.

2. Map the chain of activities

Build a usable view of the upstream activities connected to production and services, together with the limited downstream activities covered by the Directive, such as distribution, transport and storage carried out for or on behalf of the company.

Do not confuse mapping with collecting every datapoint from every supplier.

The purpose of the map is to create enough visibility to support the CSDDD scoping exercise: where could the most likely and most severe human-rights and environmental impacts sit?

That map becomes the spine of everything that follows.

3. Build a risk-based prioritisation engine

The Directive expressly expects prioritisation.

Start defining how you will rank sectors, countries, commodities, activities, facilities and business relationships according to the likelihood and severity of adverse impacts.

Document the reasoning.

A defensible system should be able to show not just what the company investigated, but why it investigated that first.

That reasoning becomes part of your evidence.

4. Rework contracts and purchasing practices

Contractual assurances are one tool in the CSDDD framework — not a substitute for due diligence.

Start identifying where clauses will be required, how compliance will be verified, what corrective-action mechanisms should exist and how contractual leverage can be increased without simply transferring responsibility to suppliers.

The Commission's voluntary model contractual clauses are due by 26 July 2027. When they arrive, you should be able to benchmark and adjust your clauses rather than begin drafting from zero.

At the same time, look inward.

Purchasing practices, pricing pressure, unrealistic lead times and contractual structures can themselves contribute to adverse impacts. A sophisticated due-diligence programme therefore examines not only supplier behaviour but also the incentives created by the buyer.

5. Stand up the mechanisms

Build the operating infrastructure:

  • stakeholder-engagement processes;
  • notification and complaints channels;
  • escalation rules;
  • corrective and preventive action workflows;
  • remediation governance;
  • decision records;
  • suspension and enhanced-action-plan procedures;
  • policy-review triggers; and
  • effectiveness-monitoring processes.

The statutory five-year monitoring interval should be treated as a minimum backstop, not as an argument for ignoring new risk signals between formal reviews.

A system that cannot react to a credible new risk until its next scheduled assessment is not much of a due-diligence system.

6. Build the evidence file from day one

This is the step companies most often leave until too late.

The CSDDD requires documentation demonstrating compliance to be retained for at least five years, with longer retention where relevant proceedings are ongoing.

So design evidence into the workflow.

Every risk assessment, source, supplier request, prioritisation decision, stakeholder interaction, corrective action, contractual assurance, approval, reassessment and remediation decision should create an attributable record.

Do not build a due-diligence process first and an audit trail later.

Build one system that produces both.

What to watch next

There are four developments worth following closely.

Your national transposition

Member States have until 26 July 2028 to adopt and publish the laws necessary to implement the amended CSDDD.

Track the jurisdictions where your group is established and supervised.

Do not assume every national implementation decision will be identical simply because the Directive contains a substantial harmonised core.

The first guidance package and model contractual clauses

The Commission currently plans its first guidance package for Q1 2027, with the statutory deadline falling on 26 July 2027. The voluntary model contractual clauses are due by the same date.

Treat these as inputs for calibration.

They should help you improve your risk methodology, stakeholder approach, data sources, contracts and controls.

They should not be the starting gun.

The 2031 review

By 26 July 2031, the Commission must review the Directive's implementation and assess, among other things, whether the turnover and employee thresholds should be revised and whether a sector-specific approach should be introduced for high-risk sectors.

The current scope is therefore not necessarily the final shape of the regime.

Companies below today's threshold should keep that in mind when deciding whether due-diligence capability has strategic value.

The transatlantic negotiations

The US pressure is worth monitoring because it could influence future EU policy.

But political negotiation is not a compliance strategy.

Until the legislation changes, build against the legislation that exists.

Start now, refine later

The companies that will find 2029 comfortable are unlikely to be the ones that guessed every detail of the final guidance correctly in 2026.

They will be the ones that built adaptable infrastructure early.

The fundamental design is already knowable: map the chain, identify where impacts are most likely and severe, prioritise intelligently, act proportionately, engage the right stakeholders, manage complaints and remediation, monitor whether measures work and preserve the evidence showing why decisions were made.

The Commission's guidance will make that system better.

National transposition will make parts of it more specific.

Future political negotiations may change its perimeter again.

None of those are good reasons to postpone building the underlying capability.

Because if you wait until July 2028 for the complete rulebook, the question is no longer whether you understand the CSDDD.

It is whether twelve months is enough time to make it operational.

Made by Riffmax & Powered by Webflow