CSDDD

September 15, 2026

CSDDD Compliance Timeline: What to Do Before 2029

The Clock Is Running

If your company has 5,000 or more employees and annual worldwide turnover above €1.5 billion (or, for non-EU companies, EU turnover above that figure), the European Union's Corporate Sustainability Due Diligence Directive applies to you from 26 July 2029. That sounds like a long way off. It is closer than it looks.

Here is what the intervening months actually contain. The directive entered into force in July 2024. It was then substantially reworked through the EU's "Omnibus" simplification process, concluding with final adoption in February 2026: member states now have until 26 July 2028 to transpose it into national law, a year ahead of the July 2029 compliance date. That means the rules only recently stopped moving, which makes it easy to tell yourself there is still plenty of time. But the compliance work itself, the part that cannot be rushed, does not wait for the last details to land. Mapping a value chain, building monitoring, standing up grievance channels: this is work measured in years, not quarters.

Think of it the way you would think of preparing for a product launch or a major factory audit. The deadline is not the day you start. It is the day everything has to be finished and working. If July 2029 is your launch date, the engineering needs to start now, not in 2028.

And here is the uncomfortable part: most companies in scope have not started. They are still waiting for guidance, still assigning owners, still treating this as a legal exercise when it is really an operational one. The companies that begin now will be ready with time to spare. The companies that begin in 2028 will be scrambling, and scrambling is exactly when mistakes happen.

The Compliance Timeline

The directive was originally designed to switch on in three waves between 2027 and 2029. That is not how it ended up. The EU's Omnibus simplification process, finalized in February 2026, replaced the tiered rollout with a single threshold and a single date. Knowing exactly where that leaves your company is the first piece of due diligence you can do today.

  • From 26 July 2029. EU companies with 5,000 or more employees and more than €1.5 billion in worldwide net turnover. Non-EU companies with more than €1.5 billion in EU turnover. Transposition into national law is due by 26 July 2028, a year earlier.

Non-EU companies are in scope too, as long as they generate EU turnover above that threshold. The directive reaches across borders by design, and companies headquartered anywhere in the world need to take the deadline seriously if their EU sales are large enough.

Two things are worth noticing. First, the narrowed threshold means fewer companies are formally in scope than under the original 2024 law, which would eventually have reached companies with as few as 1,000 employees and €450 million in turnover. A review clause allows the EU to revisit that scope later, so a company that sits just below today's threshold should not assume it is permanently outside the law's reach.

Second, the directive cascades regardless of the formal threshold. Even if your company sits below it, the companies above you will need answers from you. They will ask about your suppliers, your sites, your sourcing. Contractual cascading means the compliance burden travels down the chain whether or not the law formally reaches you. The threshold chart is the public version of the story. The private version is that everyone in a supply chain is on someone's timeline.

What Compliance Will Look Like

The directive is long, but the practical shape of compliance comes down to six things. If you can demonstrate all six with evidence, you are in a strong position. If you cannot, no amount of policy documents will save you.

  1. Map your value chain. This means knowing your suppliers beyond tier one: the indirect suppliers, the commodity sources, the raw materials that end up in your products. For most companies this is the single biggest piece of work, and we will come back to it.
  2. Identify actual and potential impacts, with evidence. You have to say where human rights and environmental harms are occurring, or could occur, anywhere in your chain. And you have to back it up. An assertion is not evidence. The directive expects you to know, not to guess.
  3. Prevent and mitigate, with verifiable outcomes. Where you find risks, you have to act, and you have to show the action changed something. Plans are cheap. Outcomes are what count.
  4. Establish grievance and complaints mechanisms. Workers and communities in your value chain need a way to raise concerns, and it has to be genuinely accessible to them: in their language, through channels they can actually use, without fear of retaliation.
  5. Track remediation, including financial remediation. When harm happens, you have to repair it. That can mean compensation, and it can mean financial remediation paid directly to affected people. You need to track it and show it.
  6. Publish an annual due diligence statement. Every year you report what you found, what you did, and what your monitoring data shows. The statement is public, and it becomes the permanent record that your stakeholders, your investors, and your lawyers will read.

Read that list again and notice what it is really asking for. It is not asking for a policy. It is asking for a system: a way of seeing what happens deep in your supply chain, continuously, and a way of acting on it. That distinction is the heart of this directive, and it is where most companies will struggle.

Why Companies Underestimate the Work

The gap between "we have a sustainability team" and "we are compliant" is larger than almost anyone expects. Here is why.

Value chain mapping takes 12 to 24 months. This is the number that should worry you the most. A full map of your value chain, including indirect suppliers and commodity sources, is not a spreadsheet exercise you finish in a quarter. It means finding out who actually supplies your suppliers, where commodities are grown or extracted, which tiers are opaque, and which countries and regions carry risk. Most companies discover along the way that their own procurement data is incomplete, that suppliers are reluctant to share, and that a commodity changes hands several times before it reaches them. Doing this properly takes a year at minimum, and two years is realistic for complex chains.

Monitoring infrastructure does not exist yet. Compliance under this directive is continuous. You need to know what is happening at sites and in sourcing regions on an ongoing basis, not once a year when an audit rolls around. Very few companies have anything like this in place. They have audits, surveys, and incident reports, and all of those are episodic. The directive wants a standing capability, and a standing capability cannot be rented at the last minute.

Data collection is genuinely hard, especially beyond tier one. Your tier one suppliers will answer your emails. The subcontractor three tiers down, or the smallholder farmer who sells into a trading hub, will not. The further you get from headquarters, the less data exists, and the data that does exist arrives in different languages, different formats, and different levels of quality. This is not a small problem. It is the core problem, and it is the reason the directive is harder in practice than it looks in the text.

Audits are not enough. Many companies assume that existing social audits cover this directive. They do not. Audits are snapshots, they are scheduled, and they are announced, which means they systematically miss the conditions that matter most: forced labor, unsafe working conditions, environmental damage at remote sites. If the directive teaches one lesson, it is that scheduled self-reporting from the audited party is not a substitute for independent, continuous visibility.

The Cost of Waiting

It is worth being clear about what is actually at stake, because the stakes change the math on when to start.

Civil liability, now via national law. The directive as originally enacted created a single, EU-wide right for victims to claim damages from companies for harm caused by failures in due diligence. The Omnibus process removed that harmonized standard, so liability is now governed by each member state's own law rather than one uniform EU rule. That is a meaningful change, but it is not an exit: victims can still bring claims, in national courts, for harm connected to failures in due diligence, and the exact rules simply now vary somewhat by country. That is not a fine paid to a regulator. That is a lawsuit, brought by people who were actually harmed, against your company, reaching the full chain, including indirect suppliers.

Enforcement by national authorities. Member states are required to set up supervisory authorities with real powers: investigations, inspections, and fines. Companies will be asked to show their work, and the showing will be on the record.

Reputational risk. The annual due diligence statement is public. So are enforcement actions and lawsuits. In an age when supply chain stories travel fast, a finding against you, or a documented failure to act on a known risk, is the kind of news that shows up in boardrooms, in the press, and in the procurement decisions of your own customers.

Shareholder and investor pressure. Investors increasingly treat due diligence capability as a risk factor, and the ones who have not yet are going to start. A company that is visibly unprepared heading into 2029 is a company carrying unquantified liability. That is exactly what investors discount.

None of this is meant to scare you into a panic. It is meant to correct the record. Waiting has a price, and the price is paid in the worst possible currency: legal exposure, reputation, and trust, all at once, at a moment when time cannot be bought back.

A Realistic 12-Month Roadmap

If you are starting now, here is a roadmap that respects how long the work actually takes. It is deliberately unglamorous. Compliance is built in unglamorous months.

Months 1 to 3: scope and govern. Decide who owns this. Assign a senior accountable lead, not a coordinator. Identify your in-scope entities, your countries, and your highest-risk commodities. Run a gap analysis against the six requirements so you know what exists and what does not. Then start the value chain map at tier one: collect supplier lists, contracts, and country data, and begin the conversations with suppliers that you will need anyway.

Months 4 to 6: map and assess. Push the map beyond tier one. Identify indirect suppliers and trace commodity sources back toward origin. Run the risk assessment: where are the actual and potential impacts, and what evidence do you have for each one? Where you have no evidence, that gap is itself a finding. This is also the moment to decide how you will monitor, because the monitoring decision shapes everything that comes after it.

Months 7 to 9: build the infrastructure. Stand up your monitoring. That means continuous channels for frontline workers and communities to report, verification of what they report, and a way to aggregate it into something decision-makers can actually use. Build the grievance mechanism so it is accessible in the languages and regions that matter, with clear escalation and no retaliation. Then start piloting: pick one commodity or one region and run the whole loop end to end, because the first full run always exposes problems that paper exercises never do.

Months 10 to 12: remediate and report. Turn your findings into prevention and mitigation plans with named owners and dates. Establish how remediation, including financial remediation, will be tracked. Set the reporting cadence and draft the first annual due diligence statement, even if it is imperfect. The first statement is a milestone, not a monument, and the systems behind it get better with every cycle.

Twelve months is the honest minimum for this work. If you compress it, you compress the mapping, and the mapping is the foundation everything else stands on.

How Earth PBC Helps You Get Ready

Here is where we come in, and we will be straight about what we do and do not do. We are not a law firm. We do not draft your policies or run your legal analysis. What we build is the layer most companies are missing: the monitoring infrastructure that turns this directive from a paperwork exercise into something you can actually demonstrate.

Earth PBC is a public benefit corporation, and our platform is built around three sources of evidence that work together, plus one principle that keeps the whole thing honest.

Community monitoring. Workers and communities at the front line of your value chain report directly through smartphones, in their own languages, from more than 100 countries. The people who see a problem first are the people closest to it, and this is the channel that lets their reports reach you without being filtered, delayed, or lost.

Satellite verification. In partnership with Planet Labs, we verify what is happening on the ground from space, with more than 200 satellite passes every day and more than 3 million square kilometers of daily coverage. Imagery does not negotiate, does not get tired, and does not get told what to say. It is the independent check that community reports, and your own data, both need.

AI-powered reporting. All of that information, from the ground and from orbit, is analyzed and assembled into reporting you can use, with verification accuracy around 90 percent. The point is not more data. It is data that has been turned into answers, on the cadence the directive demands.

Direct payments to communities. And because monitoring should not be extractive, verified contributions from frontline reporters are compensated directly in stablecoin, reaching people in more than 100 countries. The people who protect your supply chain are part of the system, not inputs to it.

Put those pieces together and you have what the directive is really asking for: continuous visibility into your value chain, evidence you can show to a supervisor, a court, or a customer, and a grievance channel that is genuinely accessible to the people who need it. That is the monitoring layer, and it is the hardest layer to build from scratch.

You still have to do the mapping. You still have to do the remediation. But you do not have to invent the infrastructure.

Start Before the Deadline Does

July 2029 is coming whether anyone is ready or not, and the transposition deadline a year earlier means the national rules you will actually operate under start crystallizing well before that. The companies that treat this as an operational challenge, not a legal formality, will walk into it with evidence and systems in place. The companies that wait will meet it with a scramble, and the scramble is where liability, bad headlines, and hard shareholder questions come from.

The work is not mysterious and it is not optional. It is mapping, monitoring, and reporting, and it takes years, not months, to do honestly. The only real decision left is when you start.

If you want to talk through where your company stands, and whether our monitoring infrastructure fits what you are building, we would genuinely like to hear from you. Get in touch with the Earth PBC team, and we will show you how the pieces work together.