CSDDD vs LkSG: What Companies Need to Know

Two Due Diligence Laws, One Goal
If your company is German and already works under the Supply Chain Due Diligence Act, the LkSG, you might reasonably feel that human rights due diligence is handled. You have a risk management system. You run annual risk analyses. You train your buyers, you push contractual assurances down to suppliers, and you operate a complaints procedure. Then the EU Corporate Sustainability Due Diligence Directive, the CSDDD, lands on your desk, and it looks like a second version of the same homework.
It is not. The CSDDD is the LkSG's bigger, broader sibling, and for companies that already comply with the German law it is both good news and a serious amount of new work. The good news is that the foundations you built for the LkSG count for a lot. The work is that the CSDDD reaches further into your value chain, covers more environmental ground, and carries consequences the LkSG never did.
This post is for the people who have to make sense of both laws without becoming full-time lawyers. Here is what the LkSG already requires, where the CSDDD goes beyond it, and what that means for your monitoring, your evidence, and your reporting.
Start with the thing the two laws share, because it explains everything else. Both laws exist to make companies responsible for the human rights and environmental harm connected to their business, even when that harm happens far down the supply chain. Both are built on the same due diligence logic: identify risks, prevent them, track your efforts, and respond when things go wrong. If you understand one law, you understand the skeleton of the other. The differences are in the reach, the detail, and the enforcement, and each of those differences lands on your compliance team as a concrete task.
Germany got there first. The LkSG has been shaping how German companies buy responsibly since January 2023, and it has given them a genuine head start over peers who are only now opening the CSDDD for the first time. But a head start is not a finish line. The directive, which applies across the EU to companies with 5,000 or more employees and more than €1.5 billion in turnover from 26 July 2029, asks for more than the German law does, in ways that matter for both your risk exposure and your reputation.
The LkSG Baseline
The LkSG (Lieferkettensorgfaltspflichtengesetz, the German Supply Chain Due Diligence Act) has been in force since January 2023. It applies to companies based in Germany with more than 3,000 employees in the country, and the threshold was lowered in 2024 to bring more companies under the law. Oversight sits with the Federal Office for Economic Affairs and Export Control, better known as BAFA, which can order corrective measures and impose fines.
Under the LkSG, a company must:
- Establish a risk management system covering human rights and environmental risks.
- Conduct a risk analysis of its own operations and its suppliers at least once a year, and whenever circumstances change.
- Adopt preventive measures, including contractual assurances from direct suppliers, and train its own staff on due diligence duties.
- Take remedial action when a violation is found or imminent, and terminate or suspend a business relationship as a last resort.
- Run a complaints procedure that workers and communities can use, with a documented process for handling reports.
- Document everything and report annually on how the duties have been fulfilled.
Notice what the list does and does not cover. The LkSG's core duty is tied to your own operations and your direct suppliers. Indirect suppliers enter the picture only when you have substantiated knowledge that a violation is happening at their level. In practice, that has meant a lot of companies built strong Tier 1 programs and left the rest of the chain to chance, which was legal under the German law but is exactly the gap the CSDDD closes.
The environmental side of the LkSG is deliberately narrow. It covers a short list of international conventions: deforestation, the Minamata Convention on mercury, and the Stockholm Convention on persistent organic pollutants (POPs). That list matters because it defines what counts as an environmental risk in your LkSG risk analysis. If an issue is not on the list, it sits outside the law's environmental scope, even when the damage is plain to see.
Enforcement under the LkSG is administrative. BAFA can fine companies and order them to change their practices, and fines scale with company size. What the LkSG does not do is create a direct right for victims to sue a company for damages in German courts. That limitation, more than anything else, is where the two laws part ways.
Key Differences at a Glance
| Aspect | LkSG (Germany) | CSDDD (EU) |
|---|---|---|
| Who it applies to | German companies with more than 3,000 employees, and more than 1,000 since 2024 | From 26 July 2029: EU companies with 5,000+ employees and €1.5B+ worldwide turnover; non-EU companies with €1.5B+ EU turnover. A narrower, single threshold following the 2025-2026 Omnibus simplification (the original 2024 law would have phased in companies down to 1,000 employees by 2029) |
| Value chain coverage | Own operations and direct suppliers; indirect suppliers only with substantiated knowledge of a violation | The full value chain, upstream and downstream, including indirect suppliers and the use, transport, and disposal of products |
| Environmental coverage | Limited list: deforestation, mercury (Minamata), persistent organic pollutants (Stockholm) | Full environmental due diligence across a broad set of environmental standards and obligations |
| Remediation | Required mainly for own operations and direct suppliers | Required across the value chain where the company caused or contributed to harm |
| Complaints mechanism | Required for own operations and direct suppliers | Required across the value chain, with protection for complainants against retaliation |
| Civil liability | Limited; enforcement through administrative fines, with no direct liability under the act itself | Victims can still claim damages for due diligence failures, but the Omnibus process removed the directive's harmonized EU-wide liability standard (originally Article 29); claims are now governed by each member state's own national law |
| Climate transition plans | Not required | Originally required under Article 22; the Omnibus process removed the obligation to adopt and put into effect a climate transition plan in its entirety |
Read that table twice, because the differences are not cosmetic. The CSDDD is not the LkSG with a wider audience. It is the LkSG with a wider reach, a wider environmental mandate, and consequences that reach into the courtroom.
What Changes for LkSG-Compliant Companies
If you already run an LkSG program, you are not starting from zero. Your risk analysis, your supplier management, and your complaints channel are a real foundation, and the CSDDD explicitly allows companies to build on existing due diligence systems. But three changes in particular will ask more of you, and a fourth deserves attention even though it is easy to overlook.
Value Chain Breadth
The LkSG's core duty stops at your direct suppliers, with indirect suppliers pulled in only when you have reason to suspect a violation. The CSDDD does not work that way. It covers your full value chain: every tier of suppliers upstream, and the use and disposal of your products downstream. "We didn't know" stops being a defense, because the directive requires you to identify and map risks across the whole chain, not just the first tier.
For most companies, this is the single biggest shift. Your Tier 1 suppliers are the ones you already know: the ones with contracts, audits, and annual scorecards. Tier 3 and Tier 4, where raw materials are extracted and commodities are grown, are often unknown to you, and they have no direct relationship with your company at all. Under the CSDDD, the obligation reaches those levels anyway, which means your map of the chain has to go deeper than your purchase orders ever did.
Environmental Scope
Your LkSG risk analysis probably treats the environment through the narrow lens of deforestation, mercury, and POPs. The CSDDD replaces that short list with full environmental due diligence. Companies must identify and address environmental impacts across a much broader set of standards, covering pollution, biodiversity, land use, and emissions, among others. The practical effect is that your risk analysis needs new categories, new data, and new evidence about environmental conditions you were not tracking before.
Civil Liability
This is the change that keeps general counsels awake. The CSDDD, unlike the LkSG, exposes companies to civil damages claims for due diligence failures across the full value chain. That exposure looked different as originally enacted in 2024, when Article 29 created a single, harmonized EU-wide liability standard. The Omnibus process removed that harmonized standard, so today the exact rules for bringing a claim, and what a claimant has to prove, vary by member state. The LkSG, by contrast, is enforced through administrative fines, and it does not itself give victims a direct right to sue.
The consequence is not just legal exposure. It is evidentiary exposure. When a claim is brought, you will need to show the court that you took appropriate measures, that your monitoring was real, and that your records are honest. A fine is painful. A damages claim built on your own incomplete documentation is worse, because your own files become the plaintiff's best evidence.
Climate Transition Plans
There is a fourth item worth knowing, even though it is no longer a live obligation: the climate transition plan. As originally enacted in 2024, the CSDDD would have required companies to adopt and put into effect a plan making their business model compatible with the Paris Agreement's 1.5°C limit. The Omnibus process removed that requirement entirely. The LkSG never asked for this either, so on this one point the two laws have converged rather than diverged. Worth tracking, though: the EU's review clause means scope and obligations, including this one, could shift again.
The Practical Challenge
The gap between the two laws is easy to describe on paper and hard to close in practice. Three challenges dominate, and they all come back to the same theme: the CSDDD demands visibility and proof from parts of your supply chain you have never really seen.
Extending Monitoring Beyond Tier 1
To cover your full value chain, you first have to know what is in it. Most companies can name their direct suppliers. Far fewer can name the farms, mines, and processing sites where their raw materials actually originate, and fewer still have any live view of conditions there. The deeper you go, the less you know and the harder information becomes to get. That is exactly the zone the CSDDD now requires you to monitor.
Site audits are the traditional answer, but they do not scale to thousands of sites in dozens of countries, and they capture a few days a year at best. An audit is a point-in-time photograph of a facility that prepared for the visit. What happens between audits, in the fields and forests where the real risk lives, is precisely what due diligence is supposed to catch, and audits routinely miss it.
Evidence Requirements
The CSDDD does not ask for good intentions. It asks for appropriate measures, which means measures you can prove you took. That puts a premium on verifiable evidence: real observations from real places, with dates and locations, not self-reported declarations from suppliers with an interest in looking clean. Regulators and courts have seen enough spreadsheet declarations to know their limits, and a declaration is not evidence of anything.
The evidence that holds up is independent, timely, and grounded in what actually happened on the ground. It is the kind of evidence that survives scrutiny, whether that scrutiny comes from BAFA, from a supervisory authority in another member state, or from a plaintiff's lawyer reading your due diligence file for the first time.
Documentation
Both laws are, at bottom, documentation exercises. You must be able to show what you found, what you did about it, and why that was enough. Under the LkSG that means an annual report and files BAFA can inspect. Under the CSDDD, the same documentation becomes evidence in a possible liability claim, which changes the standard.
Documentation built for a regulator's file review is different from documentation built to survive a lawyer's cross-examination. The records need to be continuous, structured, and connected to the specific risks you identified, and they need to cover the parts of your chain you never audited before. Assembling that file by hand, once a year, is no longer enough.
How Earth PBC Bridges the Gap
Earth PBC is a public benefit corporation built for exactly this transition: from first-tier, audit-based compliance to value chain due diligence backed by evidence. We combine three capabilities that map directly onto the three challenges above, and we have built them to work in more than 100 countries, including the places where commodity supply chains actually start.
Community Monitoring Reaches the Commodity Source
Our community monitoring network puts smartphones in the hands of people who live and work at the source of your supply chain: farmworkers, forest communities, mine workers, and local observers. They report conditions in their own words, with photos, location data, and timestamps, and they are paid directly in stablecoins for verified reports. That direct payment matters. It turns monitoring into a relationship instead of a request, and it is why reporters keep reporting month after month.
This is how you get a live view of Tier 3 and Tier 4, the levels audits never reach, and how you hear about problems weeks before a regulator or a plaintiff does. When a community at the source of your cocoa or timber or cotton flags a problem, it arrives in your system as a dated, located, verifiable record, not as a rumor.
Satellite Verification for Environmental Evidence
For the environmental side, where the CSDDD stretches far beyond the LkSG's short list, we work with Planet Labs to verify conditions from space. Our satellite layer covers more than 3 million square kilometers daily, drawing on more than 200 satellite passes a day, and it independently verifies community reports with around 90% accuracy.
When a community reports land clearing, tree loss, or encroachment, the satellite record confirms it from above. When the satellite spots change first, we can task the community network to ground-truth it. That two-way loop produces the independent, timely evidence that an environmental due diligence file requires, and the kind that stands up in court.
AI Reporting for Documentation
None of that data is useful if it sits in a spreadsheet nobody reads. Our AI-powered reporting turns community reports, satellite verification, and your own records into the documentation the CSDDD demands: risk registers, trend analyses, escalation alerts, and audit-ready evidence files. Instead of assembling a compliance file in the weeks before a deadline, you have one that builds itself continuously, organized around the risks in your value chain.
The result is a due diligence system that covers the whole chain, not just Tier 1; that produces independent environmental evidence, not just declarations; and that documents its own work as it goes. That combination is what the gap between the LkSG and the CSDDD actually requires.
The LkSG gave German companies a serious head start. The CSDDD asks them to go further: further down the value chain, further into environmental risk, and further into a legal regime where documentation is evidence. Companies that treat this as a paperwork extension will feel the pain when the July 2029 compliance date arrives. Companies that treat it as a monitoring problem will find it manageable, because monitoring is a solvable problem when the right tools are in place.
If you are building your CSDDD program on an LkSG foundation, we would like to help. Talk to us about how community monitoring, satellite verification, and AI reporting can extend what you already have, without rebuilding it from scratch. Contact the Earth PBC team to set up a conversation about your value chain.
