77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
CSDDD and LkSG in comparison: What the EU Supply Chain Directive will really change in 2027
Supply Chain

CSDDD and LkSG in comparison: What the EU Supply Chain Directive will really change in 2027

1 July 202614 min readBy Dr. Henrik Bauer
CIVAC

The CSDDD will tighten the German LkSG in terms of scope, liability and climate protection plan from 2027. The article shows the 12 most important differences, clarifies threshold values ​​and describes how both sets of rules can be fulfilled without duplicate structures.

The Corporate Sustainability Due Diligence Directive (CSDDD), also known as the EU Supply Chain Directive in Germany, was published in the EU Official Journal on May 24, 2024 and, following the omnibus postponement, will come into force for the largest companies on a staggered basis from July 26, 2027. It obliges companies to exercise human rights and environmental care throughout the entire activity chain and introduces civil liability and a mandatory climate protection plan for the first time. For Germany, this means an overlay with the Supply Chain Due Diligence Act (LkSG), which has been in force since 2024 and which already imposes due diligence obligations on companies with 1,000 or more employees.

Managements are therefore faced with a double question. First: How do CSDDD and LkSG differ specifically in terms of scope, catalogue of obligations, liability and sanctions? Secondly, how can both duties be covered efficiently in one structure without creating parallel tools, consultants and reports? This article works through both sets of rules along twelve comparison dimensions and describes how an integrated data architecture allows implementation without a reset. The answer rarely lies in one of the two standards alone. It lies in the combination of risk analysis, complaint procedure, climate protection plan and supplier management in a system with a documented reporting line. Practical examples from industry, trade and financial services supplement the legal classification with operational information.

Key Takeaways

  • The LkSG has been in effect for companies with 1,000 or more employees in Germany since 2024. From 2027, the CSDDD will gradually expand to companies with 5,000, then 3,000, then 1,000 employees across the EU.
  • The CSDDD introduces civil liability for damage in the activity chain, a climate protection plan in line with the 1.5 degree target and an obligation to involve indirect suppliers.
  • Anyone who sets up LkSG structures to be CSDDD-capable today avoids double data storage, double reports and double consultant days and significantly reduces the adjustment costs in 2027.

Area of ​​application: Who falls under LkSG, who falls under CSDDD

The LkSG has been valid since January 1, 2023 for companies with administrative headquarters, headquarters or branch in Germany and at least 3,000 employees, and since January 1, 2024 for companies with 1,000 or more employees. According to Section 1 LkSG, the number of employees also includes employees posted abroad as well as temporary employees with a period of employment of more than six months. The obligation applies regardless of the legal form; GmbHs, AGs, KGaAs, eG, SE as well as foreign companies with a German branch are affected.

The CSDDD defines its scope according to the number of employees and sales. Stage one from July 26, 2027: EU companies with more than 5,000 employees and more than 1.5 billion euros in global net sales as well as third-country companies with more than 1.5 billion euros in sales in the EU. Stage two from July 26, 2028: from 3,000 employees and 900 million euros in sales, analogous for EU and third-country companies. Stage three from July 26, 2029: from 1,000 employees and 450 million euros in sales. This means that the CSDDD scope of application at the end of the grading is somewhat narrower than that of the LkSG, which is based purely on the number of employees. Anyone who falls under both sets of regulations must fulfil both sets of obligations in parallel because the national LkSG is not replaced by the CSDDD, but rather overlaid. CIVAC maps the LkSG role with extensions for the CSDDD requirements in the workspace, so that the duties are combined in a single risk analysis instead of ending in two separate reports. This also covers the question of parallel reporting to BAFA and future CSDDD supervision without the company having to maintain the supplier master data twice.

Scope of due diligence: supply chain vs. activity chain

The LkSG only requires due diligence in one's own business activities, with direct suppliers (Tier 1) and with indirect suppliers on an ad hoc basis, i.e. when there is substantiated knowledge of risks. The duties include risk analysis, prevention measures, remedial measures, complaint procedures according to Section 8 LkSG, annual risk analysis and report to BAFA within four months of the end of the financial year. The downstream value chain, such as distribution and product use, is expressly not covered by the LkSG. The duty of care ends with the direct contractual partner, unless there is substantiated evidence of violations by indirect suppliers that trigger an event-related examination.

The CSDDD extends the scope of application to the entire chain of activities. This includes the company's own business activities, the subsidiaries and the business partners in the upstream chain and, to a limited extent, in the downstream chain, insofar as the business partners distribute, transport or store the products. The obligation only ends with the end customer. The CSDDD therefore systematically records indirect suppliers and includes in particular logistics, wholesale and selected sales structures. Anyone who falls under both sets of rules must map the supply chain carefully and document both levels of obligations at the same time. An integrated template in the workspace that maps the LkSG Tier 1 and CSDDD activity chain views in parallel avoids double data storage. Others run compliance like a filing cabinet. We run it like software. The supplier master data is maintained once and displayed in both reports at the same time, with clear versioning of the risk assessment per supplier and financial year. An expansion to include the CSDDD's indirect suppliers takes place in the same master data model, supplemented by risk indicators for the downstream activity chain, so that logistics, wholesale and selected sales structures can be integrated without a new tool. This means that the supplier group remains under control, even if the scope of application becomes significantly broader in 2027.

Catalog of obligations in direct comparison

Both sets of rules have a similar list of obligations with eight basic elements: policy statement, risk management, risk analysis, preventive measures, remedial measures, complaint procedure, documentation and report. The differences lie in the details. The CSDDD explicitly requires stakeholders to be involved in the due diligence process, not just consultation when necessary. It also requires the provision of compensation for damage actually caused or contributed to, which goes beyond the LkSG remedial obligation. The CSDDD calls for the adaptation of the business strategy to due diligence obligations, including remuneration systems.

The LkSG focuses on the annual risk analysis with a BAFA report, the CSDDD on continuous due diligence with an annual public declaration. The complaints procedure is mandatory in both sets of regulations, but the CSDDD requires broader access rights: not only employees and people from the supply chain, but also their representatives and civil society organisations. Anyone who operates the LkSG complaint procedure, for example in accordance with Section 8 LkSG, must expand it in accordance with the CSDDD. CIVAC combines the internal reporting point according to HinSchG with the LkSG complaint channel and the CSDDD activity chain view in one system. The templates are structured in such a way that the extension of LkSG to CSDDD does not require a new architecture, only configuration changes to the permission and stakeholder model. This means that the complaint process will remain in one hand even after 2027 instead of in two parallel mailboxes. In particular, the involvement of stakeholders required by the CSDDD, such as hearings or follow-up discussions, can be documented in the same workflow, so that the investigation process can be fully documented in the auditor's appointment. If you set this up early, you will avoid a migration shortly before the CSDDD comes into force. This applies in particular to the adjustment of the compensation systems and the business strategy, because both points require additional decision-making bodies that usually only hold their meetings quarterly.

Liability and Sanctions: Two Different Regimes

The LkSG sanctions violations under administrative law. The BAFA can impose fines of up to 8 million euros, and for companies with a group turnover of over 400 million euros, up to 2 percent of the average annual turnover. In addition, there is a risk of exclusion from public procurement for up to three years. Civil liability of the company towards those affected is expressly excluded in the LkSG, although there are procedural guardianship regulations that allow trade unions and NGOs to sue in German courts on behalf of those affected.

The CSDDD is introducing its own civil liability. According to Article 29, the company is liable for damage caused by an intentional or negligent breach of the duty of care to the extent that the damage concerns legal interests protected under EU law or the national law of a Member State. Liability extends to our own business activities, subsidiaries and business partners in the chain of activities. The national sanctions are accompanied by administrative fines, the amount of which is based on global group sales and must reach at least 5 percent. This means that the risk of sanctions under the CSDDD within the group is significantly higher than under the LkSG. The appointment certificate, signed, filed, verifiable. Anyone who can document and version the due diligence obligations structurally reduces the liability exposure. The auditor calls, the evidence is ready. The management can provide evidence of its supervisory obligation in accordance with Section 130 OWiG and the CSDDD due diligence obligation in a mandate report. Additional protection through D&O insurance makes sense, but does not replace operational documentation because many policies contain deductibles and exclusions for intentional breaches of duty. Anyone who carries out the duty of care in a system with a reporting line to management can, in the event of a dispute, provide versioned evidence of the status of the fulfilment of the duty and substantially reduces the liability risk.

Climate protection plan: The CSDDD innovation without a LkSG counterpart

One of the main innovations of the CSDDD is the obligation to have a mandatory climate protection plan according to Article 22. Companies must develop, implement and regularly update a transition plan to limit global warming to 1.5 degrees in accordance with the Paris Agreement. The plan includes time-bound climate targets for 2030, 2040 and follow-up milestones up to 2050 with absolute reduction targets for Scope 1, 2 and 3 as well as measures, investments and CapEx planning. The effectiveness must be proven using science-based methods, such as the Science Based Targets initiative (SBTi) or ISO 14068.

The LkSG does not have a comparable obligation. The interface to the CSRD/ESRS E1 is particularly important here: the CSDDD requires a plan, the CSRD requires its disclosure. Anyone who fulfils both obligations should set up climate protection planning as an integrated process, with a greenhouse gas balance according to the GHG Protocol, scenario analysis, reduction paths and a link to management remuneration, as required by the CSDDD. CIVAC represents the interface between LkSG officers, ESG officers and environmental protection officers in the workspace, so that the database on the greenhouse gas balance is not in three different tools. Audit-proof, documented, Section 130-proof. The climate protection plan is updated in a versioned manner so that the audit can understand in the following year which assumptions and measures have changed and why. The link to the management's remuneration policy is linked to the respective resolutions in the system, so that a later supervisory or investor inquiry about the effectiveness of the incentive systems can be answered from the workspace. This means that the climate protection plan is no longer an isolated strategy foil, but rather an operationally anchored process with clear people responsible. The connection to national obligations such as the Energy Efficiency Act, the Fuel Emissions Trading Act or the ETS requirements is also reflected in the same data architecture, so that the reduction figures are consistent across all reporting channels.

Complaint procedure and whistleblower protection

Both sets of rules require an effective complaints procedure. Section 8 LkSG requires an internal procedure that allows employees and people in the supply chain to report human rights and environmental risks. The procedure must be confidential, have rules of procedure and protect the identity of the whistleblower. With the Whistleblower Protection Act (HinSchG) and the obligation to have an internal reporting office for 50 or more employees, the question arises in practice as to how LkSG complaints and HinSchG reports work together technically and organizationally.

The CSDDD significantly expands the circle of those entitled to complain in Article 14. Anyone who has legitimate concerns about actual or potential adverse effects is entitled to lodge a complaint. This includes trade unions, other employee representatives and civil society organisations active in the areas in which the chain of activities runs. Anyone who has already established the LkSG procedure must expand it to include these groups of beneficiaries and add procedural steps, such as the possibility of being involved in follow-up discussions and communicating the results of an investigation. CIVAC offers an integrated module in the workspace that bundles HinSchG reports, LkSG complaints and future CSDDD complaints in a documented procedure, with versioning, deadline monitoring according to § 13 HinSchG (confirmation of receipt within 7 days, feedback within 3 months) and an audit-proof audit trail that fully demonstrates the procedural flow in the auditor's appointment and samples of the processing times allowed. This eliminates typical weak points such as lost email threads, unclear responsibilities or missing deadline protocols. Anonymous reports are possible and are processed in a protected channel that protects the identity of the whistleblower until the official end of the procedure and still remains traceable for the supervisory authority. This means that the process simultaneously fulfils the HinSchG obligation of confidentiality, the LkSG obligation of the opportunity to complain and the CSDDD obligation of stakeholder involvement.

Reporting requirements and documentation: BAFA report vs. CSDDD declaration

The LkSG requires an annual report to BAFA within four months of the end of the financial year. The report follows a structured questionnaire with over 437 questions on risk analysis, prevention measures, complaints procedure and follow-up measures. The reporting is publicly available on the company portal and in the BAFA register. Violations of the reporting obligation are sanctioned separately.

The CSDDD requires an annual public declaration of due diligence, which is integrated into the CSRD reporting if the company falls under the CSRD. Companies subject to CSDDD that do not fall under the CSRD are subject to an independent publication requirement on the company website. The content of the declaration includes the due diligence processes, the identified risks, the measures taken, the results and the climate protection plan. In comparison to the LkSG-BAFA report, the CSDDD declaration is less form-oriented, but has deeper content and is more relevant to the audit. Anyone who fulfils both obligations benefits from setting up the database cleanly and playing out the relevant sections in BAFA format and CSDDD format. CIVAC maps both reporting paths in the workspace, with the 490 audit templates and a reporting line to management. Versioning allows individual data points to be kept consistent in both reports and subsequent changes, such as after a new risk analysis, to be imported into both reports synchronously without the reporting team having to manually compare them. This also makes it possible to map special cases such as takeovers during the year, changes in the supplier structure or newly identified risks in the current year. Reporting to the management takes place in documented quarterly sequences, so that the supervisory body is able to provide information about the status of the due diligence in both sets of rules at any time. External auditors can also rely on a consolidated database and do not have to synthesize from multiple tools.

Supervision and enforcement: BAFA, supervisory authorities, EU network

The enforcement of the LkSG lies with the Federal Office of Economics and Export Control (BAFA). It checks reports, carries out event-related checks and can request information, issue orders and impose fines. Violations have been visibly punished since 2024, for example with fines and notice publications that the company has registered with BAFA. Legal action against BAFA decisions leads to the administrative court.

The CSDDD requires each member state to have a supervisory authority that monitors compliance. These authorities form a European network and are supposed to coordinate their enforcement practices. In Germany, the specific responsibility as of 2026 has not yet been conclusively regulated; a connection to the BAFA or its own supervisory structure is being discussed. According to CSDDD standards, supervisory authorities can initiate investigations, request information, carry out on-site inspections and impose sanctions. Civil liability runs parallel through the national courts. Deadline begins as soon as we become aware of it. Anyone who documents the due diligence process and maps it comprehensibly in the system can respond to both BAFA inquiries and inquiries from the CSDDD supervisory authority within the statutory deadlines. CIVAC provides the reporting line, the documentation and the audit trail module in such a way that an authority request does not become a weeks-long data collection, but can be answered from the workspace with versioned evidence. This changes the character of the supervisory audit from a research mission to a routine information request. Anyone who is prepared here typically saves 2 to 4 internal man-weeks per supervisory request and reduces the risk of an escalation into a formal procedure. The media reputational damage caused by a publicly criticized BAFA matter can also be measurably reduced because fulfilment of the obligation was already documented before the inquiry.

Implementation in practice: One architecture for both sets of rules

Anyone who will be subject to both sets of rules from 2027 should not think of the structure as two separate projects, but rather as an integrated architecture. The risk analysis is carried out once, with marking of the data points that cover LkSG Tier 1, CSDDD activity chain and, if necessary, CSRD standard S2 at the same time. The complaint procedure is set up once, with the circle of eligible parties expanded to CSDDD level. The climate protection plan is created using the CSRD/ESRS-E1 database, not in a separate tool. The supplier master data is maintained centrally, with annual risk assessment and an audit trail that is equally suitable for BAFA and the CSDDD supervisory authority.

CIVAC is structured as a compliance platform and officer-as-a-service in such a way that this integrated architecture is created without additional tool stacks. Licence the workspace for your internal representatives, or have our representatives order it. The LkSG order runs with an appointment certificate and reporting line to management, the extension to include a CSDDD activity chain view takes place in the same workspace with the same 490 audit templates. EU data residency is standard. Turn reading into a mandate.: info@civac.de or the contact form on civac.de. An initial conversation clarifies when which obligation applies and which steps make sense in which order based on the number of employees, sales, industry and supplier structure. The written indication includes the monthly cost, the SLA for ordering in 2 business days and the roadmap for extending LkSG to CSDDD without data migration. This means that the time horizon up to 2027 can be broken down into a predictable sequence of small adjustment steps, instead of setting up a new major project on the deadline. The combination of LkSG routine and CSDDD extension is managed in the workspace as a two-stage roadmap, with clear responsibilities and deadlines per quarter. The role is commissioned, not the consultant day. This changes the calculation, the speed and the verifiability in the next audit.

FAQ

What is the most important difference between LkSG and CSDDD?

The LkSG focus is on the direct supplier and on a structured BAFA report. The CSDDD extends the obligation to the entire activity chain, introduces civil liability and requires a mandatory climate protection plan in line with the 1.5 degree target. This means that the CSDDD is deeper in terms of content and stricter in terms of sanctions, while the LkSG is more form-oriented and is already established in Germany.

When does the CSDDD come into force for German companies?

The graduation begins on July 26, 2027 for companies with more than 5,000 employees and 1.5 billion euros in sales. This will be followed on July 26, 2028 by companies with 3,000 employees and a turnover of 900 million euros, and on July 26, 2029 with 1,000 employees and a turnover of 450 million euros. Implementation into German law must take place by July 2026; national supervision has not yet been finalized.

Do companies that fall under both sets of rules have to report twice?

In terms of content yes, form no. The LkSG requires a BAFA report in a structured questionnaire with over 437 questions, the CSDDD requires an annual public declaration that is integrated into the CSRD reporting. An integrated database allows both reports to be created from the same sources and to avoid inconsistencies. Duplicate data storage in multiple tools is not necessary and not recommended.

What consequences does CSDDD liability under civil law have for management?

Civil liability applies to the company, not primarily to the management personally. However, under Section 130 OWiG and liability under corporate law, there is also a personal risk if the duty of supervision is violated. Documented care with versioned evidence significantly reduces the risk. Insurance via D&O policies only covers parts, which is why operational documentation is crucial and must be kept cleanly in the system.

What does the CSDDD climate protection plan specifically cover?

The plan contains time-bound reduction targets for 2030, 2040 and follow-up milestones up to 2050 for Scope 1, 2 and 3, an implementation strategy with measures and CapEx investments, a link to the business strategy and a science-based methodology, for example via SBTi. The plan is updated and published annually. It interfaces with and should be consistent with ESRS-E1 reporting under the CSRD.

How can the effort for LkSG and CSDDD be minimised?

Through an integrated data architecture: a risk analysis, a complaint procedure, a supplier base, a reporting system with output in both formats. A compliance platform with Officer-as-a-Service typically reduces consultant days in the concept phase by 40 to 60 percent and provides continuous operation under fixed monthly conditions. Duplicate tool stacks are avoided, the audit trail remains versioned and traceable in the same workspace.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles