What is the CSDDD? A Plain-English Guide for Compliance Teams

If your compliance team has a folder labeled CSDDD and you are not entirely sure what belongs in it, you are in good company. The EU Corporate Sustainability Due Diligence Directive is one of the most consequential pieces of business regulation to come out of Europe in a decade, and it is also one of the most misunderstood. Some teams treat it as a reporting exercise. Others assume it only applies to European giants. Both readings are wrong, and the difference matters, because in-scope companies must comply from 26 July 2029, and the work needed to get there takes years, not months. This guide explains what the CSDDD actually is, who it covers, what it demands, and what real compliance will look like in practice.
What is the CSDDD?
The Corporate Sustainability Due Diligence Directive is an EU law that requires large companies to identify, prevent, mitigate, and account for the harm their business can cause to people and the environment. It entered into force in July 2024. Following the 2025-2026 Omnibus simplification process, member states now have until 26 July 2028 to transpose it into national law, and in-scope companies must comply from 26 July 2029. From then on, it is enforced like any other law: national authorities will supervise companies, investigate complaints, and impose penalties for non-compliance.
The core idea is simple, even if the details are not. If your business reaches into the European market, you are responsible for adverse impacts on human rights and the environment anywhere in your value chain, including in countries you have never visited. The directive takes expectations that were once voluntary, the UN Guiding Principles on Business and Human Rights and the OECD Due Diligence Guidance, and turns them into binding law with enforcement behind them.
Two features make this law different from earlier sustainability rules. First, it is mandatory, not voluntary. There is no opt-out and no good-faith statement that substitutes for action. Second, it carries real consequences: national supervisory authorities can investigate and fine companies up to 3% of net worldwide turnover, and victims of harm can still bring civil claims against companies that fail their due diligence obligations. That line of liability, from a person harmed at a mine or farm at the far end of your supply chain, to your company's balance sheet, is real, even though (as we explain below) it now runs through national courts rather than a single EU-wide standard.
One more thing worth knowing before we go further: the directive was substantially revised through the EU's "Omnibus" simplification process, which ran from a Commission proposal in February 2025 through a Council-Parliament agreement in December 2025 to final adoption in February 2026. The changes narrowed the company-size threshold, pushed back the application date, and removed the EU-wide harmonized civil liability regime, which is why the numbers and mechanics below look different from the directive as originally enacted in 2024. What did not change is the basic substance for the companies still in scope: they have to actually do due diligence, and they have to be able to prove it.
Who Is In Scope?
Two groups of companies are covered. The first is large EU companies, including EU parent companies of groups that meet the thresholds. The second is non-EU companies with significant turnover generated in the EU. A US manufacturer, a Brazilian meat processor, or an Asian electronics maker can all be in scope without a single office in Europe, as long as their EU sales are large enough. In our own research, hundreds of companies headquartered outside the EU now mention the CSDDD in their US securities filings, which tells you how widely the net is cast.
As originally enacted in 2024, the CSDDD was going to phase in across three size-based waves between 2027 and 2029. The Omnibus process eliminated that tiered rollout. There is now a single threshold, applying from a single date:
- From 26 July 2029. EU companies with 5,000 or more employees and more than €1.5 billion in net turnover worldwide. Non-EU companies with more than €1.5 billion in turnover generated in the EU. Member states must transpose the directive into national law by 26 July 2028, a year ahead of that compliance date.
That single threshold is considerably narrower than the original law, which would have eventually reached companies with as few as 1,000 employees and €450 million in turnover. The Commission's own estimate for that earlier, broader scope was roughly 6,000 large EU companies and 900 non-EU companies; the narrower, post-Omnibus scope covers substantially fewer.
Three practical points about scope. First, the employee and turnover thresholds count the whole group, not a single legal entity, so a parent company can pull its subsidiaries into scope with it. Second, a review clause allows the EU to revisit the scope in future, including whether to bring smaller companies back in, so this is worth watching rather than treating as permanently settled. Third, and this is the one that surprises most people: even if your company sits below the threshold, you can still feel the law. Large in-scope buyers will pass their due diligence requirements down the chain through contracts, and they will expect the same evidence from their suppliers that regulators expect from them. In practice, the directive reaches beyond the roughly 5,000-6,000 companies formally in scope.
What Are the Core Obligations?
The directive sets out seven core obligations. They apply to the whole company, not just the sustainability team, and together they form a complete due diligence cycle:
- Integrate due diligence into policies. The company must adopt a due diligence policy and build it into the management systems that actually run the business: procurement, sourcing, human resources, and risk management.
- Identify and assess actual and potential adverse impacts. This means mapping human rights and environmental risks across the full value chain, upstream and downstream, and prioritizing the impacts that are most severe and most likely.
- Prevent and mitigate potential impacts. Where risks exist, the company must act on them: contractual assurances from business partners, support and capacity building for suppliers, changes to its own purchasing practices, and other measures appropriate to the risk.
- Bring actual impacts to an end. Where harm is happening, the company must stop it. If ending it immediately is not possible, it must minimize the extent of the harm and track progress toward ending it.
- Establish a complaints procedure. Workers, communities, and others affected by the company's operations must have a way to raise concerns. The mechanism must be accessible, operate in languages people understand, and lead to genuine follow-up.
- Monitor the effectiveness of due diligence measures. Due diligence is not a one-time project. The company must assess, periodically, whether its measures are actually working, and adjust them when they are not.
- Communicate publicly. The company must publish an annual statement on its due diligence: its approach, the impacts it identified, and the measures it took.
These seven obligations map closely to the steps of the OECD Due Diligence Guidance, which is deliberate. What the CSDDD adds is enforcement: supervision by national authorities, administrative fines of up to 3% of net worldwide turnover, and a scope that reaches the full value chain. Civil liability toward victims remains possible, but Omnibus I removed the harmonized EU-wide liability standard, so claims are now governed by each member state's own national law rather than a single uniform rule. An earlier requirement for in-scope companies to adopt and put into effect a climate transition plan was removed from the directive entirely during the Omnibus process. If your compliance program can demonstrate the seven due diligence obligations in action, you are most of the way there. The hard part is doing them where the risks actually live.
The Full Value Chain Problem
The hardest part of the CSDDD is not the paperwork. It is the geography. The directive's obligations apply across the full value chain: upstream suppliers, from raw materials to components and processing, and downstream, through distribution, use, and disposal. Critically, that includes the communities where commodities originate.
Most companies know their direct suppliers well. Very few know who supplies their suppliers, and fewer still know who grows, mines, or harvests the raw material at the very start of the chain. That is exactly where the worst risks live: child labor on farms, unsafe conditions in artisanal mines, land grabs, deforestation, and pollution of water that communities depend on. A focus on Tier 1 suppliers cannot see any of it, because none of it happens at Tier 1.
Commodity sourcing makes the problem worse. Cocoa, coffee, cotton, cattle, palm oil, timber, and minerals are usually bought through traders and aggregators who source from vast networks of smallholders, often hundreds of thousands of them. Your contracts sit with the trader. Your responsibility under the CSDDD extends to the source. When a regulator asks where your raw material actually came from and what you know about the people who produced it, "we audited our Tier 1 supplier" is not an answer.
There is also a cascading effect to consider. Buyers further up the chain will demand proof of due diligence from everyone below them, and regulators will follow the same chain when they investigate. The company that cannot show what it knows about its sourcing geography is not just missing documentation. It is carrying risk it cannot see, priced into every contract it signs.
What Compliance Will Actually Require
Translate the seven obligations into operating terms, and a clear picture emerges. Real CSDDD compliance requires:
- Value chain mapping. A credible map of where your materials and products come from, reaching beyond Tier 1 and prioritized by risk, so you know which parts of the chain deserve the most attention.
- Evidence, not assertions. Regulators and courts will look at what you actually did: risk assessments, decisions, actions, and follow-ups. You need records that show your reasoning, not just your intentions.
- Ongoing monitoring. Continuous visibility into the high-risk parts of your chain, with the ability to detect change when it happens, not at the next annual review.
- A working grievance mechanism. A channel that is genuinely accessible to affected people, including workers and communities in remote areas with limited internet, in local languages, and that feeds directly into action.
- Remediation. When harm is found, you must work to stop it and repair the damage, in cooperation with your business partners, and in severe cases end the relationship.
- Public statements. An annual, public account of your due diligence that stands up to scrutiny from authorities, customers, and civil society.
The through-line is simple: the CSDDD rewards companies that can show continuous, real engagement with risk, and it punishes companies that cannot. That means compliance is not a folder of certificates. It is a set of operating capabilities: seeing your chain, hearing the people in it, and acting on what you learn.
Why Traditional Audits Fall Short
Most companies plan to meet the CSDDD with their existing audit program. That plan deserves a hard look, because audits and due diligence are not the same thing. Here is why:
- Periodic versus continuous. An audit is a point-in-time snapshot. It tells you how a facility looked on the day the auditor visited. The directive expects monitoring on an ongoing basis, with measures adapted as risks change. Harm rarely schedules itself around your audit calendar.
- Self-reported data. Audits rely on documents and interviews arranged by the party being audited. In the deepest parts of the chain there are no documents at all, and where documents exist, they say what the supplier wants them to say. A spreadsheet cannot tell you what is happening on a farm that has never seen an auditor.
- No stakeholder engagement. Audit teams rarely speak with the people who actually experience harm: workers on night shifts, smallholder farmers, communities downstream of a discharge point. The CSDDD's complaints procedure demands exactly that kind of direct channel, and audits do not build it.
- Wrong geography. Audits cover the facilities you know about and can schedule. The deepest risks live in places you have never seen, at the end of chains you have not mapped.
- No forward signal. An audit reports the past. Due diligence needs early warning: signals from the field that a risk is emerging before it becomes a violation.
None of this means audits are useless. They are a valuable tool for the facilities they cover. But they are not due diligence, and building your CSDDD program around them leaves the deepest risks invisible and leaves you with little to show an investigator. The directive asks a different question than any audit: what do you know, right now, about the people and places at the far end of your value chain?
How Earth PBC Helps
Earth PBC is a public benefit corporation that helps multinationals see and act on the parts of their value chains that audits cannot reach. Our platform combines four capabilities, and each one maps directly to the obligations in the directive.
Community monitoring
We put smartphone-based reporting tools in the hands of frontline workers and local communities in more than 100 countries. People at the source report what they see, in their own languages, on phones they already own: working conditions, wages, safety, environmental damage, and the issues that matter most to them. For your compliance team, this is a working, direct channel to affected people. It is the practical engine of the CSDDD's complaints procedure, and it feeds the identify-and-assess obligation with ground truth from the places where risk is real.
Satellite verification
Through our partnership with Planet Labs, we analyze satellite imagery over monitored areas with 200 or more satellite passes daily and more than 3 million square kilometers of coverage every day, with 90% verification accuracy. The imagery is independent and continuous, and it is evidence-grade: when an investigator asks whether deforestation or encroachment happened at a source site, satellite records cannot be edited by a supplier. This maps directly to the obligation to monitor the effectiveness of your measures, and to identifying environmental impacts across the chain.
AI-powered reporting
Field reports and imagery are organized into clear, actionable intelligence: risk signals, trends, and audit-ready documentation your team can act on and publish. This turns scattered signals from the field into the structured record that the public communication obligation demands, and it keeps the cost of continuous monitoring realistic for teams that are already stretched.
Direct payments
We pay communities directly for verified monitoring work, using stablecoin payments that reach people in more than 100 countries, including places where banking is not available. Money lands with the people doing the monitoring, and when remediation is needed, it lands with the people who were harmed. That is the remediation obligation working in practice, in a way no audit report has ever achieved.
None of this replaces your existing program. It extends it to the parts of the chain that have been invisible: the farms, mines, and communities where your products begin, and the people who know the truth about them.
Where to Start
If the CSDDD is on your roadmap, the practical questions start now. Where does your raw material come from? What do you actually know about the people who produce it? And how will you prove it when the authorities ask? Those are exactly the questions Earth PBC was built to answer. Talk to our team at earthpbc.com/contact, and we will show you how community monitoring, satellite verification, and direct payments fit into your compliance program, starting with the parts of your value chain you cannot see today.
