CSDDD Compliance Timeline: EU Due Diligence Obligations Until 2029
Directive (EU) 2024/1760 entered into force on 25 July 2024. Member States must transpose it by 26 July 2026. From 2027, the largest companies fall in scope, with full coverage by 2029. This guide maps every milestone, threshold, and officer role.
Directive (EU) 2024/1760, the Corporate Sustainability Due Diligence Directive (CSDDD), entered into force on 25 July 2024 and obliges Member States to transpose it into national law by 26 July 2026. The Directive establishes a binding due diligence regime covering human rights and environmental impacts across own operations, subsidiaries, and the chain of activities. Penalties may reach 5 percent of net worldwide turnover, exceeding any current LkSG sanction.
The CSDDD does not apply to every company on the same date. Article 37 sets a phased timeline that distinguishes three waves between 2027 and 2029 based on employee headcount and global turnover. This article maps every milestone, lists the eight due diligence steps under Articles 5 to 16, and explains how an in-scope company should staff the supply chain officer function during the run-up period.
Auf einen Blick
- CSDDD applies in three waves: from 26 July 2027 for companies with more than 5,000 employees and 1.5 billion euro turnover, then 2028, then 2029 for the 1,000-employee floor.
- The eight due diligence steps under Articles 5 to 16 mirror but exceed the German LkSG; climate transition plans under Article 22 are mandatory and aligned with the 1.5 degree pathway.
- Maximum fines reach 5 percent of net worldwide turnover; a documented supply chain officer with a written appointment is the operational backbone of the regime.
Legal Basis and Entry Into Force
The CSDDD was adopted as Directive (EU) 2024/1760 of the European Parliament and of the Council of 13 June 2024 and published in the Official Journal on 5 July 2024. It entered into force on the twentieth day following publication, namely 25 July 2024, in accordance with Article 41. The Directive is a minimum-harmonisation instrument under Article 4 of the Treaty on the Functioning of the European Union.
Member States must adopt and publish the laws, regulations, and administrative provisions necessary to comply with the Directive by 26 July 2026. The Federal Republic of Germany will integrate the new requirements into the existing Lieferkettensorgfaltspflichtengesetz framework, while other Member States transpose into civil, administrative, or company law instruments. The Commission has committed to issuing guidelines on Article 5 due diligence policies by January 2027.
The legal architecture is layered. Article 1 defines the subject matter, Article 2 the scope, Articles 5 to 16 the due diligence obligations, Article 22 the climate transition plan, and Articles 27 to 30 the sanction and civil liability regime. The Directive applies extraterritorially under Article 2 paragraph 2 to non-EU companies that generate the relevant turnover within the Union.
For German addressees, the CSDDD will supersede the LkSG once national transposition is complete. The transition period therefore creates a window where both regimes apply in parallel. Operational structures built today should be designed for CSDDD logic, not LkSG logic alone, to avoid double rework. A supply chain officer should already operate under the future scheme.
The CIVAC reference page on the supply chain officer (LkSG-Beauftragter) documents how the appointment, reporting line, and audit evidence are structured to satisfy both the current LkSG and the upcoming CSDDD obligations.
Scope Thresholds and Three Phased Waves
Article 2 paragraph 1 of the CSDDD defines scope by reference to two cumulative criteria: average number of employees and net worldwide turnover during the last financial year for which annual financial statements have been prepared. The thresholds apply at the level of the ultimate parent of a group when annual financial statements are prepared on a consolidated basis.
Wave one starts on 26 July 2027. It captures EU companies with more than 5,000 employees on average and a net worldwide turnover exceeding 1.5 billion euro. Non-EU companies fall in scope when their net turnover generated in the Union exceeds 1.5 billion euro. The Commission estimates around 1,000 EU companies and a similar number of third-country undertakings in this first wave.
Wave two starts on 26 July 2028. The threshold drops to more than 3,000 employees and 900 million euro net worldwide turnover for EU companies, with the corresponding 900 million euro EU-generated turnover threshold for non-EU companies. Approximately 2,800 EU companies are expected to enter scope at this date.
Wave three starts on 26 July 2029. From this date onwards, the full Article 2 scope applies: EU companies with more than 1,000 employees and 450 million euro net worldwide turnover, and non-EU companies with 450 million euro EU-generated turnover. The phased entry gives smaller in-scope companies more time to build the operating model.
The Commission must review the thresholds by 26 July 2030 under Article 36. Companies near a threshold should monitor employee headcount and consolidated turnover annually, since crossing the threshold triggers application from the next financial year. The audit trail must capture this calculation and store it together with the Bestellurkunde of the supply chain officer.
The Eight Due Diligence Steps Under Articles 5 to 16
The CSDDD codifies a risk-based due diligence process that mirrors the OECD Guidelines for Multinational Enterprises. Article 5 requires the integration of due diligence into all relevant policies and risk management systems, accompanied by a due diligence policy that is updated at least every 24 months. The policy must be made publicly available.
Article 8 requires identification and assessment of actual and potential adverse human rights and environmental impacts within the company, its subsidiaries, and its chain of activities. The chain of activities concept in Article 3 paragraph 1 letter g is narrower than the LkSG mittelbare Zulieferer concept but extends to upstream business partners and selected downstream activities such as transport and distribution.
Articles 10 and 11 require prevention of potential impacts and the bringing of actual impacts to an end. Where impacts cannot be stopped immediately, Article 11 paragraph 2 requires the minimisation of their extent and a corrective action plan with reasonable and clearly defined timelines. Article 14 establishes the notification mechanism and complaints procedure with safeguards for whistleblowers.
Article 15 obliges companies to monitor the effectiveness of their measures, at least every 12 months and on an ad hoc basis when there are reasonable grounds to believe new risks have arisen. Article 16 mandates publication of an annual statement on the matters covered by the Directive. The statement is filed with the European Single Access Point under Regulation (EU) 2023/2859.
Each step needs a documented owner, a defined cadence, and audit-ready evidence. CIVAC structures these obligations inside the workspace so the supply chain officer can produce the Article 16 statement, the Article 14 complaints log, and the Article 22 climate transition plan from a single source of record. The motto is straightforward: Bestellurkunde, unterschrieben, abgelegt, belegbar.
Article 22 Climate Transition Plan
Article 22 of the CSDDD adds an obligation that no Member State previously imposed on the same scale. In-scope companies must adopt and put into effect a transition plan for climate change mitigation aimed at ensuring, through best efforts, that the business model and strategy of the company are compatible with the transition to a sustainable economy and with the limiting of global warming to 1.5 degrees Celsius in line with the Paris Agreement.
The plan must contain time-bound targets related to climate change for 2030 and in five-year steps until 2050, based on conclusive scientific evidence. It must describe decarbonisation levers, identify and explain financial and investment plans, and disclose the role of administrative, management, and supervisory bodies. The plan is reviewed and updated annually under Article 22 paragraph 2.
Where a company already reports a climate transition plan under Article 19a or 29a of Directive 2013/34/EU (CSRD), Article 22 paragraph 3 deems the obligation fulfilled. The CSRD and CSDDD are therefore designed to be operated jointly. Most in-scope companies will already prepare an ESRS E1 climate transition plan under the European Sustainability Reporting Standards.
The supervisory authority designated under Article 24 may impose pecuniary penalties for failure to adopt a credible plan. The plan is not a marketing document. It must withstand audit by a public authority and, where supervised, by an independent third-party assurance provider under the CSRD assurance regime.
The intersection with the role of the ESG and sustainability officer is operational. The ESG officer holds the data architecture, the supply chain officer holds the due diligence evidence, and both feed the Article 16 and Article 19a statements. CIVAC binds the two streams in a single audit trail.
Enforcement, Fines, and Civil Liability
Article 27 of the CSDDD requires Member States to lay down rules on pecuniary penalties that are effective, proportionate, and dissuasive. The maximum limit of pecuniary penalties shall be not less than 5 percent of the net worldwide turnover of the company in the financial year preceding the decision imposing the fine. This benchmark exceeds the LkSG ceiling of 2 percent under § 24 LkSG.
Penalty decisions must be published under Article 27 paragraph 5 and remain publicly available for at least five years. Reputational exposure is therefore as significant as the financial penalty itself. The Commission will issue guidelines on the methodology for setting fines and the criteria for assessing turnover under Article 27 paragraph 3.
Article 29 introduces a civil liability regime that is novel in EU law. A company is liable for damages caused to a natural or legal person where it intentionally or negligently failed to comply with the obligations under Articles 10 and 11, and as a result an actual adverse impact that should have been identified, prevented, mitigated, brought to an end, or minimised caused damage. The limitation period must be at least five years from cessation of the breach.
The civil liability provision is supplemented by a procedural framework that lowers the burden of proof for claimants. Member States must ensure access to evidence under Article 29 paragraph 3 letter e, and recognised trade unions or non-governmental organisations may bring representative actions on behalf of affected persons. The compliance posture is therefore a litigation posture.
Companies should document each due diligence step with timestamps, decision logs, and named owners. The CIVAC workspace stores the Bestellurkunde, the Article 14 complaints register, and the Article 16 annual statement in a single tamper-evident audit trail. The auditor calls, the evidence is on hand.
CSDDD Versus LkSG: What Changes for German Companies
The German Lieferkettensorgfaltspflichtengesetz currently applies to companies with at least 1,000 employees in Germany under § 1 paragraph 1 LkSG. The CSDDD threshold of 1,000 employees applies to the company-wide headcount, not the German workforce. This change alone broadens the application to German-headquartered groups with significant operations abroad.
The catalogue of protected legal positions in Annex Part I of the CSDDD is wider than the eleven international conventions referenced in the LkSG. It explicitly references the right to a clean, healthy, and sustainable environment, recognised by United Nations General Assembly Resolution 76/300 of 28 July 2022. The environmental impacts covered by Annex Part II include not only specific conventions but a generic prohibition of measurable environmental degradation.
The chain of activities concept under Article 3 paragraph 1 letter g of the CSDDD differs from the LkSG distinction between unmittelbare and mittelbare Zulieferer. Upstream coverage is risk-based across the entire chain, while downstream coverage is limited to specific activities such as distribution, transport, and storage performed for or on behalf of the company.
Civil liability and the climate transition plan are new compared to the LkSG. The BAFA reporting obligation under § 10 LkSG becomes the Article 16 annual statement filed via the European Single Access Point. The complaints procedure under § 8 LkSG remains conceptually similar but is reinforced by Article 14 procedural safeguards including timelines and remedy expectations.
German federal legislation will likely amend the LkSG rather than repeal it. The Federal Ministry of Labour and Social Affairs published a Diskussionsentwurf on 4 March 2026. Companies should now run a gap analysis between current LkSG implementation and CSDDD requirements, focusing on chain of activities mapping, Article 22 climate plan integration, and Article 29 evidence preservation.
The Supply Chain Officer Role in the CSDDD Era
The CSDDD does not prescribe a named officer role in the same explicit way as some sector regulations. Article 5 paragraph 1 letter b nonetheless requires the company to have in place a due diligence policy that includes a description of the company's approach, including in the long term, to due diligence. In practice, supervisory authorities expect a designated function with documented appointment, mandate, and reporting line.
In Germany, § 4 paragraph 3 LkSG already obliges in-scope companies to determine who is responsible for monitoring risk management, for example by appointing a Menschenrechtsbeauftragter. The CSDDD raises the operational bar. The officer must coordinate the Article 8 risk assessment, the Article 10 prevention measures, the Article 14 complaints procedure, and the Article 16 reporting cycle, often across multiple jurisdictions and business units.
A robust appointment instrument names the legal basis (§ 4 LkSG and the future CSDDD transposition), the reporting line to the management board, the budget, and the audit right within the group. The Bestellurkunde must be signed by a board member with apparent authority and stored together with the role description, the substitution rule, and the conflict-of-interest declaration.
The officer needs operational tooling: a chain-of-activities register, a risk-rating engine, a complaints workflow, a measure register, and a reporting cockpit aligned with Article 16. CIVAC delivers these as a connected workspace, so the officer produces evidence on demand rather than reconstructing it during an audit.
The dual-model frame applies. Lizenzieren Sie den Workspace fuer Ihre internen Beauftragten, oder lassen Sie unsere Beauftragten bestellen. CIVAC operates as Compliance-Plattform und Officer-as-a-Service, so a company can build the function in-house or commission an external officer with the same documentation standard.
Build Plan for the 2026 Transposition Window
The window between July 2026 and July 2027 is the operational sprint. The transposition deadline of 26 July 2026 is followed twelve months later by the first wave application date. Companies in the first wave must therefore have the operating model ready at the start of their financial year that includes 26 July 2027. Most groups will target a 1 January 2027 readiness date.
Step one is a scoping memo. The memo records the calculation of the Article 2 thresholds, identifies the ultimate parent, and confirms the wave allocation. It is signed by the General Counsel and the Chief Financial Officer and refreshed annually. The memo establishes the legal trigger for every subsequent action.
Step two is the chain of activities mapping. The mapping covers all tier-one upstream business partners, identifies high-risk upstream activities beyond tier one based on credible information, and lists the relevant downstream activities under Article 3 paragraph 1 letter g. The mapping output feeds the Article 8 risk assessment.
Step three is the appointment of the supply chain officer with a formal Bestellurkunde, a written role description, a substitution rule, and an internal communication. The officer assumes immediate accountability for steps four through eight. The CIVAC workspace pre-populates the appointment instrument, the role description, and the reporting line template.
Step four is the operating system: due diligence policy under Article 5, risk assessment cadence under Article 8, prevention and remediation registers under Articles 10 and 11, complaints procedure under Article 14, monitoring cycle under Article 15, and reporting cockpit under Article 16. The CIVAC workspace offers 490 audit-ready templates that compress the build-out to weeks rather than quarters.
From Reading to Action: How CIVAC Operationalises CSDDD
The CSDDD is not a reporting exercise bolted onto existing controls. It is a re-architecture of how an enterprise governs human rights and environmental risk across its chain of activities. The supervisory authority will not accept a binder of policies. It will inspect the operating model, the evidence chain, and the named accountabilities.
CIVAC is the Compliance-Plattform und Officer-as-a-Service for this re-architecture. The workspace ships with the Article 5 policy template, the Article 8 risk taxonomy aligned to Annex Parts I and II, the Article 14 complaints workflow with whistleblower safeguards, and the Article 16 reporting cockpit pre-mapped to the European Single Access Point taxonomy. EU data residency is the default.
The dual-model frame stays in place across all 25 officer roles operated by CIVAC. Lizenzieren Sie den Workspace fuer Ihre internen Beauftragten, oder lassen Sie unsere Beauftragten bestellen. The same documentation standard, the same Bestellurkunde, the same audit trail apply whether the officer sits inside your organisation or on the CIVAC bench.
The Berichtslinie to the management board is configured at onboarding. Every action taken by the officer becomes a timestamped entry with named owner and source document. The 24-hour early warning and 72-hour follow-up disciplines that CIVAC operates for NIS-2 carry over to the CSDDD complaints and remediation procedures.
For first-wave companies, the recommended next step is a scoping workshop that confirms threshold calculation, wave allocation, and chain-of-activities perimeter. For second- and third-wave companies, the recommended next step is a 90-day build plan that delivers the Article 5 policy and the supply chain officer appointment before financial year start.
Aus dem Lesen einen Auftrag machen. Reach out at info@civac.de or via the contact form at civac.de to schedule the scoping workshop or the build sprint with a named CIVAC officer.
FAQ
When exactly does the CSDDD start applying to my company?
Application depends on the wave. Companies with more than 5,000 employees and 1.5 billion euro turnover fall in scope from 26 July 2027. The 3,000-employee, 900 million euro band follows on 26 July 2028. The 1,000-employee, 450 million euro band applies from 26 July 2029. Non-EU companies use the turnover generated in the Union as the trigger.
Does the CSDDD replace the German LkSG entirely?
Not immediately. The Federal Republic of Germany will amend the LkSG to incorporate the CSDDD requirements by 26 July 2026. Until transposition, the LkSG continues to apply. After transposition, the amended LkSG implements the CSDDD; the original 2023 framework is therefore extended and tightened rather than removed.
What is the maximum fine under the CSDDD?
Article 27 requires Member States to set the maximum at no less than 5 percent of net worldwide turnover in the financial year preceding the decision. This ceiling exceeds the 2 percent maximum currently set in § 24 LkSG. Penalty decisions are published and remain available for at least five years.
Is a written appointment of a supply chain officer mandatory under the CSDDD?
The CSDDD does not name the role explicitly, but Article 5 requires a documented due diligence policy and a clear allocation of responsibility. In Germany, § 4 paragraph 3 LkSG already requires a designated function. A formal Bestellurkunde with reporting line and audit right is the recognised evidence standard.
Do we need a climate transition plan if we already report under the CSRD?
Article 22 paragraph 3 deems the obligation fulfilled where a transition plan is reported under Article 19a or 29a of Directive 2013/34/EU (CSRD). The ESRS E1 climate transition plan therefore counts as compliance with Article 22 CSDDD, provided it meets the substantive requirements including 2030 and five-year targets.
How does CIVAC support a CSDDD readiness programme?
CIVAC delivers the Compliance-Plattform und Officer-as-a-Service. Lizenzieren Sie den Workspace fuer Ihre internen Beauftragten, oder lassen Sie unsere Beauftragten bestellen. The workspace ships with Article 5 policy templates, Article 8 risk taxonomies, Article 14 complaints workflows, and the Article 16 reporting cockpit, all with EU data residency.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.