Update LkSG und CSDDD - die wichtigsten Änderungen
26.08.2026

CSDDD and LkSG Implementation: Why Companies Need Resilient Supplier Processes Now

What’s changing with LkSG and CSDDD, what the timeline for CSDDD implementation in Germany means, and why companies should integrate due diligence obligations into resilient supplier processes.

In brief

  • CSDDD implementation refers to transposing the European due diligence directive into national law
  • Affected companies must systematically identify, prioritize, and address human rights and environmental risks in their supply chains
  • In Germany, the CSDDD will replace the LkSG; it applies from July 26, 2029, for companies with 5,000 or more employees and €1.5 billion or more in revenue.

The rules around corporate due diligence obligations are in flux. CSDDD implementation was adjusted through the Omnibus package. As a result, the scope, individual requirements, and timeline have changed.

For many companies, one thought seems obvious: wait until it’s finally clear who has to meet which requirements and when.

But that reduces the European supply chain directive, the CSDDD, too much to thresholds and deadlines. The underlying task remains the same: companies must identify, prioritize, and appropriately address human rights and environmental risks in their supply chains. Directly affected companies need their own due diligence processes, and smaller companies and suppliers will continue to be drawn in through their customers’ data requests, evidence, and measures.

Waiting to build resilient structures doesn’t automatically buy time. Supplier data can’t be completed on short notice, responsibilities can’t be clarified overnight, and supplier relationships can’t be developed through a one-time questionnaire.

For efficient LkSG and CSDDD implementation, companies shouldn’t treat due diligence as an isolated compliance task. It makes more sense to embed it firmly into existing supplier and risk management.

What does CSDDD implementation mean?

CSDDD stands for Corporate Sustainability Due Diligence Directive. In German, it’s often referred to as the EU supply chain law or European supply chain directive.

The directive obligates the companies it covers to embed human rights and environmental due diligence into their own operations, subsidiaries, and relevant business relationships. The goal is to identify negative impacts on people and the environment and, where possible, prevent, mitigate, or end them.

Core due diligence obligations include, in particular:

  • integrating due diligence into policies and risk management systems,
  • identifying and prioritizing actual and potential negative impacts,
  • implementing prevention and remediation measures,
  • enabling complaint and grievance mechanisms,
  • monitoring the effectiveness of measures,
  • and documenting implementation in a traceable way.

The CSDDD therefore doesn’t describe a one-time review process. Due diligence forms a cycle: risks are identified, measures are decided, progress is reviewed, and processes are adjusted as needed.

A completed supplier questionnaire can provide information for a risk analysis. However, it replaces neither the prioritization of risks nor the tracking of measures nor continuous supply chain monitoring.

What are the differences and similarities between CSDDD and LkSG?

Germany’s Supply Chain Due Diligence Act, known as LkSG, has been in effect since 2023. It currently forms the German legal framework for human rights and certain environmental due diligence obligations in supply chains.

The CSDDD applies a similar underlying logic at the European level. It, too, requires systematic risk management, prevention and remediation measures, complaint mechanisms, and monitoring of effectiveness.

Criterion LkSG CSDDD
Legal level German law EU directive, to be transposed nationally
Applicable from Since 2023 July 26, 2029 (first wave)
Threshold Currently 1,000 employees (restructuring planned) 5,000 employees / €1.5 billion revenue
Core obligations Risk analysis, prevention/remediation, complaints, documentation Largely equivalent, risk-based approach

What do LkSG and CSDDD implementation have in common?

For companies in Germany, LkSG and CSDDD aren’t two entirely separate tasks. Existing structures from LkSG implementation can form an important foundation for CSDDD implementation. These include, for example:

  • defined responsibilites,
  • structured supplier and risk analyses,
  • prevention and remediation measures,
  • complaint procedures,
  • as well as documentation and effectiveness monitoring.

What changes with the CSDDD?

While the LkSG is a German law, the CSDDD creates a common European framework. It must be transposed into national law by member states, which will further develop Germany’s existing regulations.

Until national transposition takes place, the LkSG formally remains in effect, though enforcement has already become more restrained. Details on implementation status can be found in the timeline section.

What matters for you in procurement: don’t build a separate process for every new law — build one resilient system for corporate due diligence obligations.

When does the CSDDD apply? Germany’s implementation timeline

The CSDDD is already in force and was adjusted as part of the Omnibus package. The changes affect, among other things, the scope, individual due diligence obligations, and the timeline.

The following requirements remain particularly relevant for companies:

  • systematically identifying and prioritizing human rights and environmental risks,
  • implementing appropriate prevention and remediation measures,
  • providing a complaint mechanism,
  • monitoring the effectiveness of measures,
  • and documenting implementation in a traceable way.

In Germany, the amended CSDDD still needs to be transposed into national law. Until a corresponding new regulation is in place, the LkSG remains the existing legal framework. It’s expected, however, that Germany will implement the CSDDD largely in close alignment with the European requirements.

The direction in Germany is now clear: the federal government has decided to transpose the CSDDD into German law on a one-to-one basis. The LkSG will be restructured accordingly; its scope is set to be limited to companies with 5,000 or more employees and revenue exceeding €1.5 billion. The external LkSG reporting obligation is effectively already obsolete: BAFA has not reviewed it since fall 2025, and its formal repeal is underway.

For preparation purposes, waiting for every regulatory detail makes little sense. The operational fundamentals are already clear: companies need resilient supplier data, a risk-based approach, documented measures, and clear responsibilities.

Companies that wait to build these structures until after the legislative process concludes will then be starting with the most time-intensive tasks.

Which companies are affected by the EU supply chain law?

Following the adjustments made through the Omnibus package, the so-called EU supply chain law, the CSDDD, applies from July 2029 to companies with more than 5,000 employees and worldwide net revenue exceeding €1.5 billion. This covers both companies headquartered in the EU and certain companies from non-EU countries, provided they meet the relevant revenue criteria in the European single market.

In practice, however, direct legal applicability isn’t the only factor that matters. Smaller companies and suppliers can also have requirements passed on to them through their business relationships. This makes it worth distinguishing between direct and indirect applicability.

Which companies are directly affected by the CSDDD?

Directly affected companies must integrate the statutory due diligence obligations into their organization and risk management. These include, among others:

  • identifying risks and negative impacts,
  • prioritizing them,
  • implementing prevention and remediation measures,
  • providing complaint mechanisms,
  • monitoring the effectiveness of measures,
  • and documenting implementation.

These tasks can’t be handled by legal, compliance, or sustainability teams alone. They directly affect procurement, supplier, and risk processes.

Are mid-market companies affected by the CSDDD?

Mid-market companies generally don’t fall directly within the CSDDD’s scope. Even so, they can be affected through their business relationships.

Large customers need information to assess their own risks and meet their due diligence obligations. As a result, they may request from suppliers, for example:

  • information on production sites and supply chains,
  • evidence of human rights or environmental standards,
  • self-disclosures and risk information,
  • contractual assurances,
  • and participation in prevention or improvement measures.

This doesn’t create automatic legal equivalence with directly affected companies. In practice, however, requirements are passed down through the supply chain. Not being directly affected doesn’t automatically mean there’s no need to act.

Want a quick overview of the CSDDD?

Our CSDDD factsheet, including a comparison with the LkSG, gives you all the key information on the supply chain law in one compact summary.

What does CSDDD implementation mean for procurement and supplier management?

Responsibility for the CSDDD sits at the company level. For operational implementation, though, procurement plays a central role: this is where suppliers are selected and assessed, requirements are communicated, and measures are carried out within the business relationship.

A resilient data foundation comes first. Companies need to know which suppliers and production sites they work with, and which countries, industries, or activities may carry elevated risks. Often, however, this information is scattered across ERP systems, spreadsheets, emails, and various departments.

The task, therefore, isn’t just about collecting more data. Information needs to be current, plausible, and clearly assigned to a supplier or site. Only then can companies meaningfully assess and prioritize risks.

Why supplier questionnaires aren’t enough for CSDDD implementation

One-time supplier questionnaires only capture a snapshot. Production conditions, sites, and risk situations can change, evidence can become outdated, and new information can emerge. Completeness and quality of responses also often vary considerably.

Above all, the due diligence process doesn’t end with data collection. When risks are identified, companies must initiate appropriate prevention or remediation measures, assign responsibilities, and review effectiveness.

For procurement, this means in particular:

  • bringing supplier and risk data together in a usable way,
  • continuously assessing and prioritizing risks,
  • clearly communicating requirements and evidence needed,
  • tracking measures and deadlines,
  • and documenting decisions and supplier communication in a traceable way.

Supplier management shouldn’t be reduced to control, though. Smaller suppliers in particular may not yet have the systems or resources to meet every requirement immediately. Effective due diligence therefore pairs clear expectations with targeted supplier development.

How are companies preparing for CSDDD implementation?

The CSDDD’s core requirements are set. Companies should now align their existing supplier and risk processes to systematically capture risks, track measures, and document implementation in a traceable way.

Five areas are especially important here:

1. Clarify responsibilities

Procurement, sustainability, compliance, legal, and management need to be clearly aligned. Companies should define who assesses risks, requests information, decides on measures, escalates critical cases, and documents effectiveness.

2. Bring supplier and risk data together

Much of the relevant information already exists — supplier master data, audit reports, certificates, or quality assessments, for example. What’s often missing is a shared view. Companies should therefore check what data exists, how current it is, and where gaps remain.

3. Establish continuous risk management

Risk assessments should be updated regularly and whenever specific triggers arise. New suppliers, changed production sites, incidents, or complaints can all call for a renewed assessment. A risk-based approach helps focus limited resources on the most important cases.

4. Document measures and evidence centrally

Risk analyses, supplier communication, evidence, measures, deadlines, and effectiveness checks should be documented in one shared process. This keeps companies audit-ready and avoids time-consuming reconstruction from emails and spreadsheets.

5. Automate recurring processes

Requests, reminders, deadlines, and monitoring are difficult to manage manually on an ongoing basis for large supplier bases. Automation reduces the burden of recurring tasks and creates a consistent documentation history.

Companies shouldn’t build a separate structure just for the CSDDD. A more sustainable approach is supplier management that can accommodate different due diligence obligations, customer requirements, and other regulatory requirements (EUDR, PPWR, CBAM, etc.).

Go deeper on due diligence obligations

Find out how to ensure due diligence, such as under the CSDDD, efficiently and in compliance with the law in our whitepaper on supply chain due diligence obligations.

Software for LkSG and CSDDD implementation

Efficient implementation requires connecting supplier data, risk analyses, requests, measures, and evidence.

VERSO Supply Chain Hub helps companies map these tasks into one central process. You can:

  • bring supplier and risk data together in a structured way,
  • assess and prioritize suppliers based on relevant risks,
  • automate requests and reminders,
  • continuously monitor risks,
  • manage prevention and remediation measures,
  • track responsibilities and deadlines,
  • and centrally document evidence and supplier communication.

This doesn’t create an additional standalone solution for the CSDDD. Requirements are embedded where supplier relationships are already managed.

Assess CSDDD requirements and implement them efficiently with us

Want to know which requirements are relevant for your company and how to integrate them into existing supplier processes?

In a no-obligation conversation, we’ll show you how VERSO Supply Chain Hub supports you with LkSG and CSDDD implementation.

Frequently asked questions about LkSG and CSDDD

What does CSDDD stand for?

CSDDD stands for Corporate Sustainability Due Diligence Directive. The EU directive is often referred to as the EU supply chain law and governs human rights and environmental due diligence obligations for large companies.

What is the CSDDD, simply explained?

The CSDDD requires affected companies to systematically identify and prioritize risks to people and the environment across their operations and business relationships. This must be followed by appropriate prevention or remediation measures and regular effectiveness checks.

What’s the difference between CSDDD and LkSG?

The LkSG is an already applicable German law. The CSDDD creates a common European framework that member states transpose into national law. Both regimes require, among other things, risk management, prevention and remediation measures, complaint procedures, and documentation.

Is the CSDDD already in force?

Yes. The CSDDD entered into force on July 25, 2024, and its scope was significantly reduced through the Omnibus package (Directive (EU) 2026/470, finalized March 18, 2026). Member states must transpose it into national law by July 26, 2028; the obligations apply uniformly to affected companies from July 26, 2029.

When do I need to implement the CSDDD?

Application starts July 26, 2029, for the largest companies. Germany has also decided on a one-to-one transposition of the CSDDD, combined with a restructuring of the LkSG. That doesn’t mean you should wait until then, though: since you’ll need a lot of information from your supply chain, you should start preparing your data foundation and processes well before that.

What changes for mid-market suppliers?

Mid-market companies generally aren’t directly covered by the CSDDD. They can, however, be indirectly affected when larger customers request information, evidence, contractual assurances, or improvement measures to meet their own due diligence obligations.

How do mid-market suppliers meet the requirements?

As a supplier, you demonstrate due diligence through self-disclosures on human rights and environmental risks within your own operations. This is supplemented by concrete evidence such as certificates, audit reports, or questionnaires that your customers may request. When risks are identified, this often leads to involvement in the customer’s prevention or remediation measures. Ideally, your customers set clear expectations and support you with targeted supplier development.

Which industries does the CSDDD affect?

The CSDDD applies across industries in principle. The specific need for action, however, depends heavily on supply chain structure, production countries, raw materials used, and the human rights and environmental risk profile.

What data do I need for CSDDD implementation?

You fundamentally need resilient supplier and site data. You’ll also need risk indicators by country or industry, evidence, and the status of measures on hand.

What does due diligence mean in the context of the CSDDD?

Due diligence means systematically identifying, prioritizing, and appropriately addressing risks and negative impacts on people and the environment. Companies must also enable complaints, monitor measures, and document implementation in a traceable way.

What does the CSDDD require for risk management?

Companies must systematically identify actual and potential negative impacts and prioritize them by severity and likelihood. Based on this, suitable measures must be defined, reviewed regularly, and adjusted as needed.

What complaint mechanisms does the CSDDD require?

Companies must establish appropriate procedures through which affected individuals, employee representatives, or relevant organizations can submit reports and complaints. These reports must be reviewed, handled, and factored into risk management in a structured way.

What happens in the event of CSDDD violations?

Violations can result in regulatory action and financial penalties. Companies also face liability, reputational, and business risks — for example, if customer requirements aren’t met or supply chain risks aren’t adequately addressed.

What changes does the CSDDD Omnibus bring?

The Omnibus package adjusted the CSDDD’s scope, individual requirements, and timeline. The core obligation remains, though: affected companies must establish a risk-based process for identifying, addressing, and monitoring human rights and environmental impacts.

What criticism has the CSDDD faced?

Critics point mainly to added administrative burden, high implementation costs, and indirect strain on smaller suppliers. Supporters, on the other hand, expect more consistent European standards, greater transparency, better protection for people and the environment, and more systematic risk management.

Which tools support CSDDD implementation?

Suitable CSDDD software connects supplier data, risk analysis, continuous monitoring, and measure management. Automated requests and reminders are also important, along with central documentation of evidence, deadlines, and supplier communication.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up to receive regular updates on:

Current ESG topics and regulatory changes
Best practices in ESG and sustainable supply chains
VERSO news
Sustainability events, and more

Worker welding a steel pipe – illustrating CBAM's impact on steel imports into the EU
30.01.2026

Fit for CBAM: Key Facts and Requirements

As part of the EU’s climate strategy, the Carbon Border Adjustment Mechanism (CBAM) puts a price on CO2 emissions from goods imported into the EU from non-EU countries. The goal is to promote emission reductions and protect the competitiveness of EU industry. This article outlines what companies need to know to ensure CBAM compliance.

What is CBAM? A brief overview

CBAM (Carbon Border Adjustment Mechanism) is the official name of EU Regulation 2023/956. It entered into force on 1 October 2023 and complements the EU Emissions Trading System (EU ETS). Together, they aim to reduce emissions from both goods produced within and imported into the EU.

Objectives of CBAM:

  • Strengthen existing emission reduction measures
  • Encourage companies to reduce emissions rather than relocate production
  • Protect EU-based companies from cost-related competitive disadvantages

Annex I of the CBAM regulation lists the relevant CN codes in detail.

The EU plans to expand the scope of CBAM. By 2030, all products covered under the EU ETS are expected to be included.

Overview of goods covered by CBAM: steel, aluminium, cement, fertilisers, electricity and hydrogen

CBAM reporting and certificates: deadlines and to-dos

Transitional phase 2023–2025: quarterly reports (“reporting obligation”)

Reports must be submitted within one month after the end of each quarter and include:

  • Company master data
  • CBAM account number
  • Quantity and type of imported goods
  • CBAM-relevant greenhouse gas emissions
    • Specific emissions, not default values
    • Direct and indirect emissions (in line with the CBAM scope during the transitional phase)
  • CO2 price paid in the country of origin

From 2026: annual CBAM declaration – certificates from 2027

Starting 1 January 2026:

From January 1, 2026, emissions from imported CBAM goods will be recorded for the first time for later financial settlement. The actual compensation through CBAM certificates, however, will only take place from 2027 as part of the annual CBAM declaration. A prerequisite is registration as an authorized CBAM declarant, as only authorized declarants are permitted to import CBAM goods from 2026 onward.

From 2027, CBAM certificates can be purchased via a central platform. The price of CBAM certificates is based on the weekly average price of EU ETS certificates.

From the start of the certificate obligation in 2027, a sufficient number of CBAM certificates must be held at all times to cover at least 80 percent of imported CBAM goods. Companies are responsible for calculating the required compensation and corresponding number of certificates themselves. The CBAM module in the VERSO Supply Chain Hub supports this process.

Important: From 2026, only authorized declarants are allowed to import CBAM goods and purchase certificates.

From 2027: first annual CBAM declaration:

From 2027, the CBAM quarterly report will be replaced by the annual CBAM declaration.

    • To be submitted by September 30 of the following year
      (example: the CBAM declaration for 2026 is due on September 30, 2027)
    • Total quantity of imported goods
    • Total amount of embedded emissions for each product group
    • Total number of CBAM certificates allocated to embedded emissions, minus any CO₂ price paid in the country of origin
CBAM timeline 2023–2027: key milestones from regulation entry into force to certificate trading obligation

CBAM FAQ

Answers to the most common questions about CBAM: what it means for your business and how to stay compliant.

Where do I submit CBAM reports?

Reports were submitted via the CBAM transitional registry until end of 2025, which you should be able to access via your national customs portal. From 2026 onward, the annual CBAM declaration will be submitted via the central CBAM Registry by authorized declarants.

Are there penalties for non-compliance with CBAM?

Yes. The regulation allows for proportionate and dissuasive penalties. Even during the transition phase, fines between 10 and 50 euros per tonne of unreported CO2 emissions may apply. From the start of the regular CBAM phase, sanctions may also apply in cases of missing registration, incorrect declarations, or failure to surrender CBAM certificates.

Are there thresholds for CBAM reporting?

Yes. If a company exceeds the threshold of 50 tonnes per year, the full CBAM obligations apply.

Can I still use default values in the report?

From 31 July 2024, default values may no longer be used. If you do not yet have real emissions data (e.g. from suppliers), Germany’s Emissions Trading Authority may still allow temporary use of default values if:
– You document your approach to obtaining real data
– You demonstrate that you made reasonable efforts to collect the data
– You provide your explanation in the “Comments” field of the transitional registry
– Your submitted report must be internally consistent – review it carefully.

Will the Omnibus proposal change anything?

Adjustments to the CBAM implementation timeline and design were introduced as part of the Omnibus package:
Deferred payment obligation: 2026 is the first emissions year, but CBAM certificates must only be purchased and surrendered from 2027 onward.
New reporting logic: Quarterly reporting ends in 2025 and is replaced by an annual CBAM declaration from 2026 onward (deadline: September 30).
New threshold: The €150 threshold is removed; instead, a quantity threshold of 50 tonnes per year applies.
Central registration: From 2026 onward, only authorized CBAM declarants may import CBAM goods.

Tips for CBAM implementation

CBAM compliance adds administrative effort – particularly around data collection. Close collaboration with suppliers is crucial.

Solutions like the our CBAM Tool can support companies by automating data capture, monitoring emissions, managing certificates, and ensuring documentation.

Background knowledge on CBAM

In 2005, the EU ETS was introduced as the EU’s instrument to meet Kyoto Protocol targets. It has undergone multiple reforms – most recently in 2021 as part of the Fit-for-55 package.

The ETS operates as a cap-and-trade system: companies receive an emissions allowance and must buy more if they exceed it.

This created a challenge: to avoid EU regulations and costs, some companies moved their CO2-intensive production to countries with lower or no carbon pricing – a practice known as “carbon leakage”.

*This information is summarized editorial content and should not be considered legal advice. VERSO assumes no liability. 

Baumstamm mit Efeublättern als Symbolbild für die EUDR
04.04.2025

EUDR: Key Questions and Answers

With the EUDR Regulation, the EU aims to strictly regulate trade in products that contribute to deforestation. But what does this mean in practice for affected companies, and how can they prepare for it? In this article, you’ll find answers to the most important questions about the new deforestation regulation, as well as practical tips for implementation.

What is the EUDR? A brief overview to the EU Deforestation Regulation

The EUDR introduces extensive due diligence obligations. Companies must ensure their products are deforestation-free. The focus is on transparency and traceability throughout the supply chain — businesses must be able to track a product’s journey from origin to market without gaps.

The EUDR requires companies to collect detailed data. As Klaus Wiesen, our supply chain expert, explains: “Given the complexity, it’s clear that software is a must for implementation. That already applies to the LkSG, but even more so for the EUDR — a pragmatic approach is nearly impossible without digital tools.”

When will the EUDR come into force?

Starting December 30, 2026, the EUDR enters its application phase for large and medium-sized companies. Small companies have until June 30, 2027 to implement the regulation.

Starting December 30, 2026 Starting June 30, 2027
Large and medium-sized companies meeting at least two of these criteria:

– More than 50 employees

– More than €10 million revenue

– More than €5 million balance sheet total

Small and micro-enterprises meeting at least two of these criteria:

– Fewer than 50 employees

– Less than €10 million revenue

– Less than €5 million balance sheet total

 

Overview on EUDR Deadlines

Who is affected by the EUDR (EU Deforestation Regulation)?

The EUDR is product-based and applies to all companies trading EUDR-relevant commodities and products derived from them.

The regulation differentiates between roles within the market, which determines specific obligations — see Determine your EUDR market role below.

First placer on the market Downstream operator
Companies placing EUDR-relevant products on or exporting from the EU market for the first time. Companies that further process or resell EUDR-relevant products for which the due diligence obligation has already been fulfilled in the upstream supply chain.

Which products are covered by the EUDR regulation?

The regulation applies to the following commodities and their derived products:

  • Wood
  • Palm oil
  • Coffee
  • Cocoa
  • Cattle
  • Soy
  • Rubber

There are no thresholds or volume limits. The list of covered commodities is expected to expand over time.

The EUDR Regulation provides for exceptions in the following cases:

  • 100% recycled materials
  • Packaging materials solely used for support, protection, or transportation
  • User manuals
  • Bamboo products
  • Products manufactured before the EUDR’s reference date (June 29, 2023), except for wood products
Overview on products covered by the EUDR

What conditions must products fulfill under the EU Deforestation Regulation?

Starting with the implementation phase: Import, trade and export of the above-mentioned raw materials and their derived products on the EU internal market are only permitted, if these three conditions are met:

  • Deforestation-free: The products were manufactured without converting natural forest into agricultural land or tree plantations after 31.12.2020. This also applies if deforestation was considered legal in the country of origin!
  • Production in accordance with the relevant rights of the country of origin: This concerns both environmental protection and human rights. Species protection measures, anti-corruption measures, labor rights, the UN Declaration on the Rights of Indigenous Peoples, trade law, etc. have been complied with.
  • Due diligence declaration available: A risk assessment has been carried out for the product, the due diligence obligations have been complied with and there is no or only a negligible risk of deforestation.

What requirements apply to the different EUDR market roles?

The EU Deforestation Regulation categorizes affected companies as Traders and Operators, and as SMEs and non-SMEs (note: the EUDR uses its own criteria for this).

This leads to different requirements – for example:

  • First placers on the market (importers) are required under the EUDR to conduct a risk assessment, mitigate risks, and submit a due diligence statement via the EU’s “Traces” system. In addition, non-SMEs are subject to reporting obligations.
  • First downstream operators must store and retain this due diligence statement (DDS) and only validate it in the case of substantiated concerns. They are not required to pass the DDS on to further downstream operators and traders (their customers).
  • Small and micro primary operators in low-risk countries (e.g., small forest owners in the EU): this is also a new category with simplified rules. A one-time, simplified declaration is possible — without geolocation data, requiring only the postal address. The aim is to relieve the burden on small farmers within the EU.

As a first step, use our free check to easily find out which category your company falls into and which obligations apply to you.

How can importers prepare? Practical steps for EUDR implementation

Step 1: Collect EUDR data

Gather detailed information about your products and raw materials — including descriptions, volumes, suppliers, and countries of origin.

The EUDR requires geo-location data for every plot where relevant commodities are produced, including production dates — retroactively from December 31, 2020.

Ensure proof that all legal rights are respected in the country of origin.

Step 2: Conduct risk assessment

Evaluate the deforestation risk for any new product or commodity.

Factors include:

  • Country of origin
  • Deforestation trends
  • Political and social conditions
  • Supply chain complexity

The EU will provide a benchmarking system categorizing countries by risk level. Only products with no or negligible risk may enter the EU market.

Step 3: Mitigate risks

If risks are identified, work with suppliers to reduce them. Develop new codes of conduct, strategies, and control measures. Verify compliance via supplier audits or documentation

Step 4: Document and report

Companies must maintain detailed records and submit reports.

For every batch, a due diligence statement or EUDR compliance confirmation must be included — customs will verify compliance based on risk assessments.

Except for SMEs, companies must also publicly report on risk assessments, due diligence processes, and mitigation measures. If your company is subject to the CSRD, you can integrate EUDR reporting into your sustainability report.

What are the EUDR sanctions?

Violations or non-compliance may result in:

  • Confiscation of unlawful profits
  • Fines proportional to the damage caused, minimum 4% of annual turnover
  • Seizure of goods or products
  • Temporary import bans
  • Exclusion from public funding or tenders
  • Public naming and shaming of the company and its violation

Background on the EUDR

In the past 30 years, global deforestation has wiped out an area larger than the EU. Forest loss accelerates climate change and biodiversity loss.

The EUDR follows the EU Timber Regulation (EUTR) from 2013, which was criticized for weak enforcement. As part of the European Green Deal, the EUDR strengthens these efforts.

From 2025 onwards, it will be prohibited to place, make available, or export certain products in the EU market if they are linked to deforestation or forest degradation since January 2021 — regardless of whether the forest is in Germany, Romania, or Brazil.

EUDR Compliance Guide: From Data Collection to Due Diligence Statement

Don’t get lost in the EUDR. Download our free guide with handy checklists, infographics, and FAQs!

*This information is summarized editorial content and should not be considered legal advice. VERSO assumes no liability. 

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Pragmatic all-in-one solution for ESG reporting, climate and supply chain management
  • Best practices in the areas of ESG and sustainable supply chains
  • Developed with expertise from 12+ years of sustainability management
  • Sustainability events and much more.

Get to know the software!

Ältere Frau arbeitet am Laptop und guckt sehr konzentriert
15.05.2024

Sanctions at a Glance: The Cost of Mistakes in Reporting and Implementing Sustainability

A slap on the wrist and, if it becomes public, a brief outcry from the public: until a few years ago, companies didn’t have to worry too much if they put sustainability on the back burner or engaged in greenwashing. This is now a thing of the past. Read here about the consequences if the new requirements are not implemented correctly – and get tips on how to do it right!

Some simply lack an overview of their own data. Others are overwhelmed by the numerous requirements of the new ESG regulations. Still others underestimate the effort involved and start far too late. And then, of course, there are companies that try to cover up their lack of commitment to sustainability with falsified information. The possible reasons for inadequate implementation of the new regulations in sustainability, climate and supply chain management are as varied as the people who implement them for their companies.

Until a few years ago, there were hardly any consequences. There might have been a shitstorm and a few calls for a boycott, but over time – or a lot of PR work – these soon petered out. However, with the introduction of the new regulations and guidelines for sustainable business practices, which are being rolled out across Europe as part of the Green Deal, this is now a thing of the past. Errors and misrepresentations can be expensive. How expensive exactly? We have summarized this for you in this article – including recommended reading to help you get it right!

This information is editorial content that should not be construed as legal advice. VERSO accepts no liability.

Stress-free CSRD compliance

Make CSRD as easy as possible: Our new CSRD Suite provides tools and support for every stage of CSRD compliance.

Sanctions for EU taxonomy, CSRD and SFDR

As far as uniform sanctions are concerned, the trio is unfortunately still rather incomplete. This is because the three directives have yet to be transposed into national law. Each EU member state must independently determine the extent to which it wishes to sanction errors in financial and non-financial reporting. In line with the CSR-RUG – the predecessor of the CSRD – errors in reporting in accordance with the CSRD, SFDR and EU taxonomy will presumably also be penalized in accordance with §331 and §334 HGB. In figures, this means

  • Prison sentences of up to 3 years
  • For members of authorized representative bodies or supervisory boards of a corporation: prison sentences of up to 3 years; companies face fines of up to 2 million euros or twice the economic benefit they have derived from the incorrect report – whichever is higher.
  • For capital market-oriented companies: Fines of up to 10 million euros, 5 percent of annual turnover or twice the economic benefit – the highest amount is also chosen here.

On top of this – as the fermented icing on the cake, so to speak – there may also be legal action for breach of competition law, exclusion from public procurement procedures and “naming and shaming”, i.e. publicity including loss of reputation.

Important to know: Only intentional errors and errors due to gross negligence are punishable. Incidentally, the Auditors’ Association wants to relax the CSRD for auditors: With a cap on the amount of liability and limited liability for gross negligence. However, this demand has been heavily criticized – so there is still some way to go here. In the next few years, the first court proceedings will show the exact direction of sanctions for breaches of the EU taxonomy, CSRD and SFDR.

Read more:

Practical guide to CSRD

Our practical guide, including a checklist, will help you prepare for CSRD reporting.
Find out what challenges there are and how you can overcome them.

Sanctions for LkSG and CSDDD

CSDDD

After a long back and forth, an agreement was reached in March 2024 on the CSDDD; the European supply chain law. Here, too, there is still some time before it is transposed into national law. However, the liability and sanction framework in the event of a breach of the due diligence obligations for people and the environment enshrined in the CSDDD is already clear. Affected companies are liable for all damages that occur along the upstream supply chain due to inadequate or missing risk prevention or remedial measures – unless these are caused by a business partner. In other words:

  • If your company knows about irregularities and ignores them, supervisory authorities can impose fines of up to 5% of global turnover.
  • Civil liability will also be introduced.
    Those affected can therefore assert claims against your company with the help of NGOs or trade unions, for example.
  • There is also the threat of naming and shaming and exclusion from public procurement.

LkSG

In contrast to the CSDDD, there is no civil liability under the German Supply Chain Act. However, there are expensive fines if the legal obligations are not complied with. Under the LKSG, these include environmental and human rights due diligence obligations towards indirect suppliers and, if known, also towards direct suppliers. Under the LkSG, risks must also be identified, documented and then eliminated or at least minimized. Otherwise there is a risk of fines of up to 8 million euros. For companies with an annual turnover of more than 400 million euros, the fine increases to up to 2% of global annual turnover. And: companies can be excluded from public procurement.

Read more:

EU ETS and CBAM sanctions

EU ETS

With the EU Emissions Trading System (EU ETS), the EU aims to cap the emissions of the member states. Companies only have a certain amount of freedom to emit emissions – otherwise certificates must be purchased. Non-compliance could result in fines:

  • 100 euros per metric ton of CO2 equivalents emitted without a certificate

In order to avoid certificate prices on the one hand and sanctions on the other, some companies relocated their production to non-EU countries (“carbon leakage”). The CBAM was therefore also introduced as part of the EU ETS reform.

CBAM

Since January 2024, the CBAM reporting obligation has applied to all companies that import certain emission-intensive goods from non-EU countries. The so-called “climate tariff” supplements the EU ETS – and entails a whole range of possible sanctions:

  • Transitional phase: If the CBAM report is incomplete, contains incorrect information or is not submitted at all, or is not corrected after being requested to do so, a penalty of 10 to 50 euros per ton of unreported emissions will be imposed.
  • Implementation phase: In accordance with the EU ETS, fines of EUR 100 per tonne of CO2 equivalent are imposed for missing certificates.
  • Anyone importing CBAM goods without the status of authorized user must expect even higher penalties.
  • In addition to the financial sanctions, it is also possible that the “Authorized Declarant” status will be withdrawn – the company concerned would then no longer be allowed to import CBAM goods from 2026.

Good to know: As a CBAM applicant, you will have noticed that there was a delay in activating the registration options. As a result, the first CBAM reports could not be submitted on time. According to the Federal Environment Agency, however, this delay will not be penalized.

Read more:

Is your purchasing department ready for the ESG requirements?

Companies are now affected by a large number of sustainability requirements – and purchasing is no exception. Use our checklist to find out whether your purchasing organization is optimally prepared for ESG requirements.

Sanctions with the EUDR

Supply chain officers and buyers must prepare themselves for even more sanctions. If you place products on the EU internal market that have been produced without deforestation, you could face the following penalties under the directive:

  • Skimming off profits unlawfully made as a result of non-compliance with the EUDR
  • Fines in proportion to forest damage and value of goods, but at least 4 % of annual turnover
  • Seizure of goods or products
  • Temporary import bans
  • Exclusion from public funds and public tenders
  • Inclusion in a public list incl.
    Information on the violation

Also important: If you do not have the relevant geo-information and proof of origin for your goods, you will no longer be allowed to import them into the EU once the EUDR comes into force. Keep this in mind now if you are ordering goods that you want to import into the EU single market from December 31st, 2026.

Read more:

Greenwashing sanctions under the EmpCo

With EmpCo, misleading environmental claims and unlawful sustainability labels will be regulated more strictly from 27 September 2026. In Germany, the requirements will be implemented through the Act Against Unfair Competition. Violations may therefore primarily result in warnings, cease-and-desist claims, interim injunctions and legal action by competitors or associations.

In certain cases, fines may also apply. For widespread infringements, the fine can amount to up to EUR 50,000. For companies with annual revenue of more than EUR 1.25 million, the fine may amount to up to 4% of the affected EU annual revenue.

Read more:

Save money and nerves with VERSO

To ensure that companies do not approach the sustainable transformation too carelessly, the EU provides for “effective, proportionate and dissuasive” measures in any case.

In view of the possible sanctions, we are happy to believe this – and help you to correctly implement the guidelines and regulations that apply to you. Not only our top software, but also our experienced consultants and our specialized partners are at your side. Feel free to get in touch with us!

Subscribe to our newsletter!

Register now to arrange a free demo appointment and get to know our solutions at first hand.

  • Pragmatic all-in-one solution for ESG reporting, climate and supply chain management
  • Individual advice from the VERSO experts
  • Developed with expertise from 12+ years of sustainability management
  • Trusted by 250+ customers

Get to know the software!

Stakeholder-Anforderungen von ESG-Informationen an KMU
12.02.2024

5 Reasons Why A Sustainability Report Is Also Worthwhile for SMEs

Many companies – large and small – are affected by sustainability regulations such as the CSRD, the LkSG or the European supply chain law CSDDD. But what about those that are not subject to these regulations? Are they exempt from reporting?

Watch out: Not being directly affected does not mean that you do not have to deal with sustainability! We explain here why SMEs also have to provide sustainability data and what information is required.

Which stakeholders request ESG data from SMEs

1. business partners create transparency in the supply chain

Are you a supplier to another company? Many SMEs supply larger companies that fall under the LkSG (Lieferkettensorgfaltspflichtengesetz) and are or will be affected by the EU CSRD (Corporate Sustainability Reporting Directive) and CSDDD (Corporate Sustainability Due Diligence Directive).

Large companies not only have to make their own ESG information transparent, but also that of their suppliers.

This means that you are also affected by the requirements of the regulations and will be asked by your customers for comprehensive sustainability information.

As a result, you have to undergo extensive due diligence checks, such as the EcoVadis sustainability assessment, which identifies potential risks for people and the environment in the supply chain.

Incidentally, it is not only you as a supplier who must provide evidence, but often also sub-suppliers.

Your customers are also bound by industry-specific guidelines and laws.
Sustainability information from the supply chain is also required from this side.
Examples of this include the Agricultural Organizations and Supply Chain Act (AgrarOLkG), the chemical industry standard or the industry-specific guidelines of the OEC.

2. financial sector pays more attention to sustainable investments

SMEs that are supported by investors or have received project-related investments should definitely be prepared for ESG inquiries.
The reasons for this:

  • Due to the SFDR (Sustainable Finance Disclosure Regulation), financial market players and financial advisors are obliged to provide ESG information on financial products and services.
  • Investors are themselves capital market participants and must report on sustainability goals and positioning within the financial sector.
  • Rating agencies now also include ESG criteria in their investment ratings.
  • Prior to the final M&A transaction, the sustainability strategy is reviewed – if not already requested in advance, measurable sustainability indicators are required from you by then at the latest.

All information about the SFDR

The Sustainable Finance Disclosure Regulation (SFDR) is one of the EU’s levers for promoting a sustainable economy. Get an overview of the SFDR, the categorization of financial products and the disclosure requirements.

3. banks require ESG disclosures in loan and funding procedures

If you want to apply for a loan or a grant from the bank, you will need a number of documents.
In the past, it was mainly about creditworthiness, business concept, collateral and the like.
Today, the issue of sustainability also plays a decisive role.

This is because banks need sustainability information from you when granting loans in order to meet the requirements of the European Banking Authority (EBA) and the German Federal Financial Supervisory Authority (BaFin).

In addition, banks are increasingly adhering to self-imposed frameworks and sustainable finance targets.

In practice, this means that lending costs are directly influenced by your ESG rating: better rating, cheaper loan.

This data decides on loans

Read this article to find out how ESG data affects financing and what data companies need to provide now to ensure their loan applications continue to be approved.

4. insurance companies also include ESG risks in their financial statements

Insurance companies also rely on and request ESG data from customers. Two perspectives need to be understood here: Firstly, (re)insurers also fall under the CSRD reporting obligation.

They must therefore report on the status quo of their sustainability ambitions themselves.
This also includes the customer area, for which your insurer naturally needs information from you as a customer.

The second perspective is about the insurance risk when you want to take out a new insurance policy.

It is common practice here to first assess the risk potential of an insured person. Sustainability risks are now also taken into account. Anyone who does not have this issue on their radar may be classified as having a higher insurance risk and lower insurance benefits.

 

5. customers and partners expect proof of ESG efforts

New partnerships, collaborations and tenders are increasingly demanding certifications that prove a company’s sustainability ambitions.

When you enter into negotiations, you need to be well prepared:

  • No Open Doors without ESG certifications: In addition to known information security standards, for example, certifications from the ESG sector are increasingly a prerequisite for a serious discussion.
    Go through the assessments at an early stage – they are often lengthy and cannot be “handed in quickly”.
  • Sustainability and ESG criteria in the tendering process: If there is a tender, your company could fall out of the selection process due to a missing or unsound sustainability strategy.
    You can prove this with recognized ESG certificates, among other things.
    With sustainability and ESG criteria in tendering processes, companies want to ensure that ecological and social standards are adhered to in the supply chain right from the start.

In addition to special ESG certifications, ESG criteria are also asked for in other quality standards that have a high priority in the industry and are actually “only” concerned with corporate processes:

  • Fairtrade
  • Organic certifications
  • Employer rankings
  • ISO standards

CSRD compliance made easy

From the CSRD basics to the finished report: Our practical software package guides you step by step to CSRD compliance!

How do SMEs best prepare for sustainability requirements from stakeholders?

As you can see, sustainability issues come from every corner. You not only have to collect and communicate ESG data to fulfill legal requirements – keyword: LkSG, CSDDD and CSRD-compliant.

Your stakeholders also ask for this data for a variety of reasons. The problem with these queries is that if SMEs are affected by one or more of these scenarios and are not prepared for them, this usually means a lot of work. This is because very different information is required from different stakeholders. They are confronted with different reporting standards and find themselves in a flood of questionnaires.

However, you can avoid these problems with a voluntary sustainability report.
It is best to report in accordance with a recognized standard that is suitable for your company, such as the DNK, the GRI Standards or the ESRS – the latter will enable you to meet the regulatory requirements of the CSRD in the future. Frameworks such as the SDGs or the UN Global Compact also form a good basis for the sustainability report.

EFRAG is currently also working on its own voluntary standards(VSME) for SMEs, which are adapted to the size, resources and needs of these companies.
The advantages of a voluntary report in a nutshell:

  • As a rule, you already collect all the important data that you also need for other purposes.
    In the best case even in a single tool, in which you can also control measures and write the report.
  • In the case of inquiries, the report already contains most of the required information, giving you more time for detailed questions.
  • If you do have to report later, you are already optimally prepared for CSRD, LkSG and CSDDD!
  • Although this may sound like a lot of effort at first, the introduction of ESG structures brings with it great opportunities: innovation and long-term growth are promoted, risks are minimized and, not to forget, you also consolidate and strengthen relationships with your customers.

Step-by-step to the sustainability report

A meaningful sustainability report can be quite a challenge. Where do you start? What data is important? And how should the CSR report be published? Our practice-oriented playbook answers your questions.

Do you want to be prepared for the next request?

The voluntary sustainability report puts you ahead of the game!
If you have any questions about the sustainability report or the legal requirements, we are here for you – with over 12 years of experience in sustainability management.

* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.

Subscribe to our newsletter!

Sign up and receive regular news about:

  • Pragmatic all-in-one solution for ESG reporting, climate and supply chain management
  • Individual advice from the VERSO experts
  • Developed with expertise from 12+ years of sustainability management
  • Trusted by 250+ customers

Get to know the software!

Klaus Wiesen, Head of Sustainable Supply Chains bei VERSO
05.01.2023

The Importance and Future of Sustainable Supply Chains: Interview with Klaus Wiesen

In this interview, Klaus Wiesen, Head of Sustainable Supply Chain at VERSO, answers relevant questions on the challenges and solutions for more sustainability in supply chains and the role of the supply chain in the future viability of companies.

Companies currently have to deal with several requirements. In addition to the German Supply Chain Act, the CSRD, which has been in force since 2024, is on the table, while CBAM and EUDR also pose new challenges. The CSDDD is on the horizon. In this interview, Klaus Wiesen, Head of Sustainable Supply Chain at VERSO, answers relevant questions on the challenges and solutions for more sustainability in supply chains, the role of the supply chain in the future viability of companies and how the VERSO Supply Chain Hub supports the implementation of sustainability requirements and legal requirements such as the LkSG or the CSRD now and in the future.

7 questions for Klaus Wiesen on challenges and opportunities in the supply chain

1. Why is the supply chain so important for protecting the climate and human rights?

On average, more than 80 per cent of CO2 emissions in the value chain come from the supply chain. The supply chain also plays a key role when it comes to respecting human rights and protecting biodiversity. Sustainable companies and sustainable products are only possible with a sustainable supply chain – which makes the supply chain a decisive factor for the future viability of companies.

2. What obligations do companies face with regard to their supply chains now and in the future?

The obligations are extensive. A lot has happened in terms of regulation. For example, the CSRD (Corporate Sustainability Reporting Directive) requires companies to report extensively on their commitment to sustainability, with the supply chain forming an important part of the reporting.

In addition, the member states have agreed on the EU Supply Chain Act (European Directive on Corporate Sustainability Due Diligence) and the EU law to stop deforestation has been passed.

Last but not least, the German Supply Chain Act, the “Lieferkettensorgfaltspflichtengesetz” (LkSG), came into force on January 1, 2023. All of this ensures that companies are required to procure in a way that takes climate neutrality, environmental protection and respect for human rights fully into account. The biggest challenge for companies in fulfilling the upcoming obligations is that a supply chain cannot be made sustainable in the blink of an eye. The transition to a sustainable supply chain takes time.

Accordingly, sustainable procurement cannot be achieved in a one-off project, but the path to it requires new structures within the company and continuously ties up resources. It is important that companies start early enough. Due to the current crises, however, the opposite is often the case: the issue of sustainability is put off for as long as possible. This will backfire on companies later on.

3. What are the most important steps in achieving sustainable procurement and which departments should be involved?

In purely organisational terms, purchasing should always be involved with a central function, especially as purchasing typically maintains the most intensive contact with suppliers. It is therefore important to build up sustainability expertise in purchasing – in addition to close coordination with the CSR department, if this already exists in the company. For procurement, this is an opportunity to reposition itself strategically within the company.

Transparency is also required in the supply chain: where are the suppliers’ production sites located and who is the right contact person for sustainability at suppliers? Which sustainability standards do the suppliers fulfil? And do their own suppliers in turn purchase from sustainable sources? In most cases, companies do not have the answers today.

4. How can such transparency be achieved across the supply chain?

One key to transparency is co-operation with suppliers. It is no longer just information on price or quality that needs to be obtained from suppliers. Sustainability information is also required. And not just one-off information on how risky suppliers are. A continuous assessment and development of suppliers in terms of sustainability is required.

Many companies shy away from the effort involved in collecting data – for fear of high costs and negative reactions from suppliers. At VERSO, however, we see every day that the effort involved in collecting data via our cloud platform is minimal – both for our customers and for suppliers – and the feedback from suppliers is positive.

5. How does VERSO support data collection along the supply chain?

VERSO provides support at various levels: In view of the many regulatory requirements, it is very challenging for companies to define the scope of the required information. In addition, the requirements are dynamic and new laws and standards are constantly being added. Sustainability standards are currently still in their infancy. The scope of the data query must therefore be continuously supplemented or adapted.

The VERSO Supply Chain Hub receives standardized self-disclosures on all relevant sustainability requirements. The questionnaires are sent automatically, data is collected and evaluated. In addition to information on which sustainability requirements a company fulfills, VERSO also helps to create transparency in the upstream supply chain. This is where the risks are sometimes greatest. If the company procures high-risk raw materials, it is essential to create transparency for the supply chains of the raw materials.

6. What opportunities does sustainable supply chain management offer, even if your own company is not affected by the LkSG?

First of all, companies that are not covered by the LkSG will most likely have to fulfil reporting obligations in accordance with the CSRD, which also applies to capital market-oriented SMEs. And the European Supply Chain Act also applies to more companies than the LkSG.

But regardless of whether companies are affected by regulation or not, there are many reasons for sustainable supply chain management: I currently see the greatest opportunity in differentiating ourselves from the competition – precisely because corporate customers and consumers are paying more attention to this. In addition, the crisis has shown that companies with sustainable procurement are more resilient, meaning they have had fewer supply disruptions. And with rising CO2 prices and the planned ‘Carbon Border Tax’ (CBAM), companies that are already implementing climate targets for the supply chain will be affected by significantly lower cost increases.

7. To what extent can companies position themselves for the future with VERSO when it comes to sustainability requirements in the supply chain?

Our promise to our customers is that all sustainability requirements for the supply chain can be covered with VERSO now and in the future. The VERSO Supply Chain Hub already covers the topic of due diligence as required by the LkSG as well as climate protection and the recording of CO2 footprints, biodiversity or simply the question of where certain raw materials come from. The platform therefore offers the ideal starting point for meeting the reporting requirements of the CSRD, the EU Supply Chain Act or the EU law to stop deforestation. And, of course, to go beyond regulatory requirements and differentiate yourself from the competition.

Practical guide LkSG Compliance

Find out how to implement the risk analysis in accordance with the LkSG efficiently and in line with legal requirements.

Sign up to our newsletter!

Sign up and receive regular news about:

  • Pragmatic all-in-one solution for ESG reporting, climate and supply chain management
  • Individual advice from the VERSO experts
  • Developed with expertise from 12+ years of sustainability management
  • Trusted by 250+ customers

Get to know the software!