CSDDD and LkSG Implementation: Why Companies Need Resilient Supplier Processes Now
What’s changing with LkSG and CSDDD, what the timeline for CSDDD implementation in Germany means, and why companies should integrate due diligence obligations into resilient supplier processes.
In brief
- CSDDD implementation refers to transposing the European due diligence directive into national law
- Affected companies must systematically identify, prioritize, and address human rights and environmental risks in their supply chains
- In Germany, the CSDDD will replace the LkSG; it applies from July 26, 2029, for companies with 5,000 or more employees and €1.5 billion or more in revenue.
The rules around corporate due diligence obligations are in flux. CSDDD implementation was adjusted through the Omnibus package. As a result, the scope, individual requirements, and timeline have changed.
For many companies, one thought seems obvious: wait until it’s finally clear who has to meet which requirements and when.
But that reduces the European supply chain directive, the CSDDD, too much to thresholds and deadlines. The underlying task remains the same: companies must identify, prioritize, and appropriately address human rights and environmental risks in their supply chains. Directly affected companies need their own due diligence processes, and smaller companies and suppliers will continue to be drawn in through their customers’ data requests, evidence, and measures.
Waiting to build resilient structures doesn’t automatically buy time. Supplier data can’t be completed on short notice, responsibilities can’t be clarified overnight, and supplier relationships can’t be developed through a one-time questionnaire.
For efficient LkSG and CSDDD implementation, companies shouldn’t treat due diligence as an isolated compliance task. It makes more sense to embed it firmly into existing supplier and risk management.
What does CSDDD implementation mean?
CSDDD stands for Corporate Sustainability Due Diligence Directive. In German, it’s often referred to as the EU supply chain law or European supply chain directive.
The directive obligates the companies it covers to embed human rights and environmental due diligence into their own operations, subsidiaries, and relevant business relationships. The goal is to identify negative impacts on people and the environment and, where possible, prevent, mitigate, or end them.
Core due diligence obligations include, in particular:
- integrating due diligence into policies and risk management systems,
- identifying and prioritizing actual and potential negative impacts,
- implementing prevention and remediation measures,
- enabling complaint and grievance mechanisms,
- monitoring the effectiveness of measures,
- and documenting implementation in a traceable way.
The CSDDD therefore doesn’t describe a one-time review process. Due diligence forms a cycle: risks are identified, measures are decided, progress is reviewed, and processes are adjusted as needed.
A completed supplier questionnaire can provide information for a risk analysis. However, it replaces neither the prioritization of risks nor the tracking of measures nor continuous supply chain monitoring.
What are the differences and similarities between CSDDD and LkSG?
Germany’s Supply Chain Due Diligence Act, known as LkSG, has been in effect since 2023. It currently forms the German legal framework for human rights and certain environmental due diligence obligations in supply chains.
The CSDDD applies a similar underlying logic at the European level. It, too, requires systematic risk management, prevention and remediation measures, complaint mechanisms, and monitoring of effectiveness.
| Criterion | LkSG | CSDDD |
|---|---|---|
| Legal level | German law | EU directive, to be transposed nationally |
| Applicable from | Since 2023 | July 26, 2029 (first wave) |
| Threshold | Currently 1,000 employees (restructuring planned) | 5,000 employees / €1.5 billion revenue |
| Core obligations | Risk analysis, prevention/remediation, complaints, documentation | Largely equivalent, risk-based approach |
What do LkSG and CSDDD implementation have in common?
For companies in Germany, LkSG and CSDDD aren’t two entirely separate tasks. Existing structures from LkSG implementation can form an important foundation for CSDDD implementation. These include, for example:
- defined responsibilites,
- structured supplier and risk analyses,
- prevention and remediation measures,
- complaint procedures,
- as well as documentation and effectiveness monitoring.
What changes with the CSDDD?
While the LkSG is a German law, the CSDDD creates a common European framework. It must be transposed into national law by member states, which will further develop Germany’s existing regulations.
Until national transposition takes place, the LkSG formally remains in effect, though enforcement has already become more restrained. Details on implementation status can be found in the timeline section.
What matters for you in procurement: don’t build a separate process for every new law — build one resilient system for corporate due diligence obligations.
When does the CSDDD apply? Germany’s implementation timeline
The CSDDD is already in force and was adjusted as part of the Omnibus package. The changes affect, among other things, the scope, individual due diligence obligations, and the timeline.
The following requirements remain particularly relevant for companies:
- systematically identifying and prioritizing human rights and environmental risks,
- implementing appropriate prevention and remediation measures,
- providing a complaint mechanism,
- monitoring the effectiveness of measures,
- and documenting implementation in a traceable way.
In Germany, the amended CSDDD still needs to be transposed into national law. Until a corresponding new regulation is in place, the LkSG remains the existing legal framework. It’s expected, however, that Germany will implement the CSDDD largely in close alignment with the European requirements.
The direction in Germany is now clear: the federal government has decided to transpose the CSDDD into German law on a one-to-one basis. The LkSG will be restructured accordingly; its scope is set to be limited to companies with 5,000 or more employees and revenue exceeding €1.5 billion. The external LkSG reporting obligation is effectively already obsolete: BAFA has not reviewed it since fall 2025, and its formal repeal is underway.
For preparation purposes, waiting for every regulatory detail makes little sense. The operational fundamentals are already clear: companies need resilient supplier data, a risk-based approach, documented measures, and clear responsibilities.
Companies that wait to build these structures until after the legislative process concludes will then be starting with the most time-intensive tasks.
Which companies are affected by the EU supply chain law?
Following the adjustments made through the Omnibus package, the so-called EU supply chain law, the CSDDD, applies from July 2029 to companies with more than 5,000 employees and worldwide net revenue exceeding €1.5 billion. This covers both companies headquartered in the EU and certain companies from non-EU countries, provided they meet the relevant revenue criteria in the European single market.
In practice, however, direct legal applicability isn’t the only factor that matters. Smaller companies and suppliers can also have requirements passed on to them through their business relationships. This makes it worth distinguishing between direct and indirect applicability.
Which companies are directly affected by the CSDDD?
Directly affected companies must integrate the statutory due diligence obligations into their organization and risk management. These include, among others:
- identifying risks and negative impacts,
- prioritizing them,
- implementing prevention and remediation measures,
- providing complaint mechanisms,
- monitoring the effectiveness of measures,
- and documenting implementation.
These tasks can’t be handled by legal, compliance, or sustainability teams alone. They directly affect procurement, supplier, and risk processes.
Are mid-market companies affected by the CSDDD?
Mid-market companies generally don’t fall directly within the CSDDD’s scope. Even so, they can be affected through their business relationships.
Large customers need information to assess their own risks and meet their due diligence obligations. As a result, they may request from suppliers, for example:
- information on production sites and supply chains,
- evidence of human rights or environmental standards,
- self-disclosures and risk information,
- contractual assurances,
- and participation in prevention or improvement measures.
This doesn’t create automatic legal equivalence with directly affected companies. In practice, however, requirements are passed down through the supply chain. Not being directly affected doesn’t automatically mean there’s no need to act.
What does CSDDD implementation mean for procurement and supplier management?
Responsibility for the CSDDD sits at the company level. For operational implementation, though, procurement plays a central role: this is where suppliers are selected and assessed, requirements are communicated, and measures are carried out within the business relationship.
A resilient data foundation comes first. Companies need to know which suppliers and production sites they work with, and which countries, industries, or activities may carry elevated risks. Often, however, this information is scattered across ERP systems, spreadsheets, emails, and various departments.
The task, therefore, isn’t just about collecting more data. Information needs to be current, plausible, and clearly assigned to a supplier or site. Only then can companies meaningfully assess and prioritize risks.
Why supplier questionnaires aren’t enough for CSDDD implementation
One-time supplier questionnaires only capture a snapshot. Production conditions, sites, and risk situations can change, evidence can become outdated, and new information can emerge. Completeness and quality of responses also often vary considerably.
Above all, the due diligence process doesn’t end with data collection. When risks are identified, companies must initiate appropriate prevention or remediation measures, assign responsibilities, and review effectiveness.
For procurement, this means in particular:
- bringing supplier and risk data together in a usable way,
- continuously assessing and prioritizing risks,
- clearly communicating requirements and evidence needed,
- tracking measures and deadlines,
- and documenting decisions and supplier communication in a traceable way.
Supplier management shouldn’t be reduced to control, though. Smaller suppliers in particular may not yet have the systems or resources to meet every requirement immediately. Effective due diligence therefore pairs clear expectations with targeted supplier development.
How are companies preparing for CSDDD implementation?
The CSDDD’s core requirements are set. Companies should now align their existing supplier and risk processes to systematically capture risks, track measures, and document implementation in a traceable way.
Five areas are especially important here:
1. Clarify responsibilities
Procurement, sustainability, compliance, legal, and management need to be clearly aligned. Companies should define who assesses risks, requests information, decides on measures, escalates critical cases, and documents effectiveness.
2. Bring supplier and risk data together
Much of the relevant information already exists — supplier master data, audit reports, certificates, or quality assessments, for example. What’s often missing is a shared view. Companies should therefore check what data exists, how current it is, and where gaps remain.
3. Establish continuous risk management
Risk assessments should be updated regularly and whenever specific triggers arise. New suppliers, changed production sites, incidents, or complaints can all call for a renewed assessment. A risk-based approach helps focus limited resources on the most important cases.
4. Document measures and evidence centrally
Risk analyses, supplier communication, evidence, measures, deadlines, and effectiveness checks should be documented in one shared process. This keeps companies audit-ready and avoids time-consuming reconstruction from emails and spreadsheets.
5. Automate recurring processes
Requests, reminders, deadlines, and monitoring are difficult to manage manually on an ongoing basis for large supplier bases. Automation reduces the burden of recurring tasks and creates a consistent documentation history.
Companies shouldn’t build a separate structure just for the CSDDD. A more sustainable approach is supplier management that can accommodate different due diligence obligations, customer requirements, and other regulatory requirements (EUDR, PPWR, CBAM, etc.).
Software for LkSG and CSDDD implementation
Efficient implementation requires connecting supplier data, risk analyses, requests, measures, and evidence.
VERSO Supply Chain Hub helps companies map these tasks into one central process. You can:
- bring supplier and risk data together in a structured way,
- assess and prioritize suppliers based on relevant risks,
- automate requests and reminders,
- continuously monitor risks,
- manage prevention and remediation measures,
- track responsibilities and deadlines,
- and centrally document evidence and supplier communication.
This doesn’t create an additional standalone solution for the CSDDD. Requirements are embedded where supplier relationships are already managed.
Assess CSDDD requirements and implement them efficiently with us
Want to know which requirements are relevant for your company and how to integrate them into existing supplier processes?
In a no-obligation conversation, we’ll show you how VERSO Supply Chain Hub supports you with LkSG and CSDDD implementation.
Frequently asked questions about LkSG and CSDDD
CSDDD stands for Corporate Sustainability Due Diligence Directive. The EU directive is often referred to as the EU supply chain law and governs human rights and environmental due diligence obligations for large companies.
The CSDDD requires affected companies to systematically identify and prioritize risks to people and the environment across their operations and business relationships. This must be followed by appropriate prevention or remediation measures and regular effectiveness checks.
The LkSG is an already applicable German law. The CSDDD creates a common European framework that member states transpose into national law. Both regimes require, among other things, risk management, prevention and remediation measures, complaint procedures, and documentation.
Yes. The CSDDD entered into force on July 25, 2024, and its scope was significantly reduced through the Omnibus package (Directive (EU) 2026/470, finalized March 18, 2026). Member states must transpose it into national law by July 26, 2028; the obligations apply uniformly to affected companies from July 26, 2029.
Application starts July 26, 2029, for the largest companies. Germany has also decided on a one-to-one transposition of the CSDDD, combined with a restructuring of the LkSG. That doesn’t mean you should wait until then, though: since you’ll need a lot of information from your supply chain, you should start preparing your data foundation and processes well before that.
Mid-market companies generally aren’t directly covered by the CSDDD. They can, however, be indirectly affected when larger customers request information, evidence, contractual assurances, or improvement measures to meet their own due diligence obligations.
As a supplier, you demonstrate due diligence through self-disclosures on human rights and environmental risks within your own operations. This is supplemented by concrete evidence such as certificates, audit reports, or questionnaires that your customers may request. When risks are identified, this often leads to involvement in the customer’s prevention or remediation measures. Ideally, your customers set clear expectations and support you with targeted supplier development.
The CSDDD applies across industries in principle. The specific need for action, however, depends heavily on supply chain structure, production countries, raw materials used, and the human rights and environmental risk profile.
You fundamentally need resilient supplier and site data. You’ll also need risk indicators by country or industry, evidence, and the status of measures on hand.
Due diligence means systematically identifying, prioritizing, and appropriately addressing risks and negative impacts on people and the environment. Companies must also enable complaints, monitor measures, and document implementation in a traceable way.
Companies must systematically identify actual and potential negative impacts and prioritize them by severity and likelihood. Based on this, suitable measures must be defined, reviewed regularly, and adjusted as needed.
Companies must establish appropriate procedures through which affected individuals, employee representatives, or relevant organizations can submit reports and complaints. These reports must be reviewed, handled, and factored into risk management in a structured way.
Violations can result in regulatory action and financial penalties. Companies also face liability, reputational, and business risks — for example, if customer requirements aren’t met or supply chain risks aren’t adequately addressed.
The Omnibus package adjusted the CSDDD’s scope, individual requirements, and timeline. The core obligation remains, though: affected companies must establish a risk-based process for identifying, addressing, and monitoring human rights and environmental impacts.
Critics point mainly to added administrative burden, high implementation costs, and indirect strain on smaller suppliers. Supporters, on the other hand, expect more consistent European standards, greater transparency, better protection for people and the environment, and more systematic risk management.
Suitable CSDDD software connects supplier data, risk analysis, continuous monitoring, and measure management. Automated requests and reminders are also important, along with central documentation of evidence, deadlines, and supplier communication.
* This information is summarized editorial content and should not be construed as legal advice. VERSO accepts no liability.
This might be also interesting for you:
Subscribe to our newsletter!
Sign up to receive regular updates on:
Current ESG topics and regulatory changes
Best practices in ESG and sustainable supply chains
VERSO news
Sustainability events, and more







