Supply chain due diligence 2026: what the CSDDD requires
Supply chain due diligence is, in 2026, primarily a matter of European law. The Corporate Sustainability Due Diligence Directive (CSDDD) requires very large companies to carry out risk-based due diligence on human rights and the environment in their chain of activities. The Omnibus I package, which entered into force in March 2026, cut the scope back considerably and softened the obligations. The Dutch private member’s bill never became law. Even so, supply chain due diligence reaches medium-sized and small companies too, through the contracts and information requests of their customers.
The short answer
After Omnibus I the CSDDD applies to companies with more than 5,000 employees and more than EUR 1.5 billion in worldwide net turnover. Member States must transpose the Directive by 26 July 2028 at the latest. Companies apply it from 26 July 2029, reporting on financial years beginning on or after 1 January 2030.
At its core lies a continuous process: policy, identifying risks, prioritising, taking measures, opening a complaints mechanism, monitoring and communicating. It is an obligation of effort, not a guarantee of result.
What does due diligence involve?
Due diligence comes from the OECD Guidelines for Multinational Enterprises and the UN Guiding Principles on Business and Human Rights. The CSDDD codifies that approach. You assess your own activities, those of your subsidiaries and those of your business partners in the chain.
Since Omnibus I the approach is expressly risk-based and staged. You begin with a general high-level mapping exercise, the scoping. In it you determine where adverse impacts are most likely and most severe. Only then does an in-depth assessment of those areas follow. An exhaustive survey of the entire chain is no longer the starting point.
Prioritisation is permitted. Leaving a less severe risk aside for the time being does not in itself attract a sanction. You must, however, be able to explain and substantiate that choice.
Who does the Directive apply to?
| Category | Threshold after Omnibus I |
|---|---|
| EU company | More than 5,000 employees and more than EUR 1.5 billion in worldwide net turnover |
| Company established outside the EU | More than EUR 1.5 billion in net turnover generated in the Union |
| Transposition by Member States | By 26 July 2028 at the latest |
| Application by companies | From 26 July 2029 |
| Reporting | On financial years from 1 January 2030 |
By way of comparison: after Omnibus I the CSRD applies from more than 1,000 employees and more than EUR 450 million in net turnover. Its first report covers financial years from 1 January 2027. The reporting duty therefore catches a wider group than the due diligence duty.
The steps in practice
- Policy. Embed due diligence in your policies and management systems, and update them periodically.
- Scoping. Map at a high level where the severe risks in your chain lie.
- In-depth assessment. Examine those areas more closely, using information reasonably available to you.
- Measures. Prevent, mitigate or bring to an end the impacts identified, with an action plan and measurable deadlines.
- Contractual assurances. Seek undertakings from business partners and support them where that is needed.
- Complaints mechanism. Set up a reporting channel for affected persons, trade unions and civil society organisations.
- Monitoring. Assess periodically how your measures are working.
- Communication. Account publicly for your approach and your results.
Omnibus I reduced the mandatory periodic assessment from once a year to once every five years. Where there are concrete indications of new or changed risks, you will of course assess sooner.
What Omnibus I deleted or softened
- The duty to adopt and implement a climate transition plan has been deleted.
- The harmonised EU regime for civil liability has been deleted. Liability is assessed under national law, which in the Netherlands means the law of tort in Article 6:162 of the Dutch Civil Code.
- Administrative fines are capped at 3 per cent of worldwide net turnover.
- Terminating a business relationship is no longer mandatory. Suspension is the heaviest measure.
- Requesting information from smaller business partners is limited. You may ask them only for what you cannot reasonably obtain by another route.
What became of the Dutch private member’s bill?
The private member’s bill on responsible and sustainable international business conduct was introduced in the House of Representatives (Tweede Kamer) on 11 March 2021 (file 35761). The bill was never put to a vote and is therefore not law in force. Responsibility for defending it passed to new sponsors over the years; the file remains pending, without a plenary conclusion.
The centre of gravity now lies with the European route. The Netherlands is preparing an implementing act under the name Wet internationaal verantwoord ondernemen (Wivo). A public internet consultation on an amended version ran in 2026. In the consultation version the Netherlands Authority for Consumers and Markets is designated as the supervisory authority. The Rotterdam District Court and the Trade and Industry Appeals Tribunal (College van Beroep voor het bedrijfsleven) are envisaged as the competent administrative courts. The final statutory text and the parliamentary process are still to come.
You fall outside it, but you are in the chain
Most Dutch companies come nowhere near the CSDDD thresholds. You will still notice the Directive. Your large customers must assess their chain and will pass part of that exercise on to you. It reaches you through three channels.
- Contract. Supplier codes of conduct, audit and information clauses, and rights of termination or suspension.
- Information requests. Questionnaires on working conditions, provenance, emissions and policy.
- Procurement. Selection requirements and award criteria that weigh sustainability and chain policy.
Note the limit that Omnibus I introduced. Under the CSRD, companies with fewer than 1,000 employees may refuse information requests that go beyond the voluntary standard for SMEs. That protection applies to requests arising from the reporting duty. A contractual commitment you enter into of your own accord falls outside it. Assess the legal basis of an information request, therefore, before you agree to it.
A practical suggestion: record what you already know. A simple overview of your suppliers, their country of establishment and the main risks will save a great deal of work later. Align it with your ESG reporting and with your wider policy on corporate social responsibility.
Frequently asked questions
Does my company have to comply with the CSDDD already?
No. The Directive is to be transposed by 26 July 2028 at the latest and applies to companies from 26 July 2029. Customers may, however, already impose contractual requirements that anticipate it.
Can my company be liable even though the CSDDD does not apply to it?
Yes. Liability for loss caused by human rights or environmental breaches is assessed in the Netherlands under Article 6:162 of the Dutch Civil Code. The unwritten standard of care may be given content partly by international instruments, including outside the scope of the Directive.
Must I drop a supplier where there is a severe risk?
Termination is not mandatory under the CSDDD. Suspension of the relationship is the heaviest measure. You first explore remediation, improvement and support, and record those steps.
Are you unsure whether your contracts, information requests or chain policy will hold up? We are glad to think it through with you. You are welcome to contact Law & More in Eindhoven or Amsterdam, in Dutch or in English, for an initial assessment of your position.