What the CSDDD is
The CSDDD is a conduct rule rather than a reporting rule. Where the Corporate Sustainability Reporting Directive tells companies what they must disclose, the CSDDD tells them what they must do about the risks they find. It codifies the due diligence concept developed in the OECD Guidelines for Multinational Enterprises and the UN Guiding Principles on Business and Human Rights, and turns it into an enforceable obligation supervised by a national authority.The Directive was published in the Official Journal on 5 July 2024 and entered into force in the same month. It was then amended twice. Directive (EU) 2025/794, known as the stop-the-clock directive, postponed the transposition and application dates while the substantive review was under way. Directive (EU) 2026/470, the Omnibus I directive, was published in the Official Journal on 26 February 2026 and rewrote the scope, the sequencing of the due diligence duty, the enforcement architecture and the liability regime. Anything written about the CSDDD before that date should be read with care.Two definitions carry most of the weight. An adverse impact is a negative effect on one of the human rights or environmental interests listed in the annexes to the Directive, ranging from freedom of association and the prohibition of child labour to pollution and biodiversity loss. Appropriate measures are measures capable of achieving the objectives of due diligence and reasonably available to the company, taking into account the circumstances of the case and the company degree of influence over the party causing the harm. The second definition is the one that decides most disputes: the CSDDD is an obligation of means, not a guarantee of a clean value chain.What Omnibus I changed in 2026
The changes are substantial enough that the original compliance plans of most companies are now wrong in several respects.The scope was narrowed to a single tier. The staggered thresholds of 5,000, 3,000 and 1,000 employees have gone, together with the corresponding turnover bands. Only EU companies above 5,000 employees and 1.5 billion euro of worldwide net turnover, and non-EU companies above 1.5 billion euro of EU turnover, are caught. There is now a single date of application for everyone in scope, 26 July 2029, instead of three successive waves.The due diligence duty itself was restructured into a two-step, risk-based exercise. A company first carries out a general scoping across its own operations, its subsidiaries and its chain of activities on the basis of reasonably available information, in order to identify where severe impacts are most likely. It then performs an in-depth assessment only in those areas. Where several areas rank equally, the Directive allows the company to start with its direct business partners. The effect is that indiscriminate questionnaires sent to every supplier are no longer the expected standard of conduct; targeted work on identified risk areas is.The harmonised European civil liability regime was deleted. The 2024 text contained a stand-alone right of action with an EU-wide limitation period of at least five years. That article has gone, and claims for damage now proceed under the tort law of the Member State concerned. In the Netherlands that means article 6:162 of the Burgerlijk Wetboek (Dutch Civil Code) and the ordinary rules on causation, relativity and limitation, together with the collective action regime of the WAMCA for representative claims.The obligation to adopt a climate transition plan was removed from the CSDDD. Companies that fall under the CSRD may still have to report on a transition plan where they have one, but the Directive no longer requires them to put one in place. The maximum penalty was capped at 3 per cent of net worldwide turnover, and the obligation on Member States to link penalties to turnover was dropped. Finally, the core mechanics of due diligence became fully harmonised, which limits the ability of Member States to add stricter national requirements to the same architecture.Which companies are in scope
Scope now turns on two figures and nothing else. An EU company is in scope if, on average, it had more than 5,000 employees and a net worldwide turnover of more than 1.5 billion euro in the last financial year for which annual financial statements have been adopted. A company established outside the Union is in scope if it generated a net turnover of more than 1.5 billion euro inside the Union. Employee numbers are irrelevant for third-country companies, which is why a large American or Asian group with a modest European headcount can be caught while a similarly sized group that sells nothing in Europe is not.Thresholds are measured at group level, so a Dutch holding company aggregates the figures of the companies it consolidates. That matters for internationally structured groups: the entity that carries the obligation is not always the operating company where the risk sits, and the group needs to decide early which legal entity holds the compliance function and how information flows to it. Our overview of the Dutch corporate law framework explains how those group relationships are structured.The sector-specific carve-outs that appeared in earlier drafts, with lower thresholds for textiles, agriculture and mineral extraction, did not survive the negotiations and have not returned. Regulated financial undertakings remain in scope for their own operations and their upstream chain, but the provision of financial services to clients stays outside the due diligence duty; the Commission is to revisit that question in a later review.What in-scope companies must actually do
The Directive builds a cycle rather than a list, and the cycle is what a supervisor will test.It starts with policy. The company must integrate risk-based due diligence into its policies and risk management systems and adopt a due diligence policy, updated periodically, that describes its approach, a code of conduct for employees and subsidiaries, and the processes used to implement it. This is the document that makes the rest auditable, and it is best integrated into existing governance rather than bolted alongside it.Identification comes next, in the two-step form described above: a scoping exercise across own operations, subsidiaries and the chain of activities, followed by an in-depth assessment where the scoping points to the most severe and most likely impacts. The rationale for the prioritisation must be recorded, because the reasonableness of that choice is precisely what will be examined afterwards.The company must then prevent potential impacts and bring actual impacts to an end. The Directive expects a graduated response: a prevention or corrective action plan with reasonable timelines, contractual assurances from the business partner supported by verification, investment and capacity building where the partner cannot comply on its own, and adjustment of the company own purchasing practices where those practices are part of the problem. Suspension or termination of the relationship is the last step, not the first, and the company must weigh whether ending the relationship would create a worse impact than continuing it. Contractual mechanisms and their limits are set out in more detail in our articles on supplier codes of conduct and on drafting ESG clauses in contracts.A notification and complaints mechanism must be available to the people who are actually affected: workers in the chain, their trade unions and representatives, and civil society organisations active in the relevant area. The company must be able to receive substantiated concerns, respond to them and follow up, and it must keep the process accessible in practice rather than only on paper.Monitoring closes the loop. The company periodically assesses whether its measures work, updates the risk picture, and reports publicly on its due diligence unless it already covers the same ground in its CSRD sustainability statement, in which case the reporting duty is satisfied there. Where the company has caused or jointly caused an actual adverse impact, it must provide remediation, which means restoring the affected person, community or environment to a situation equivalent to the one that would have existed had the impact not occurred.Enforcement, penalties and liability
Every Member State designates a supervisory authority with powers to investigate, to order a company to stop an infringement, to require remedial action and to impose penalties. Those authorities cooperate in a European network, and the Commission maintains a public list of designated authorities. Penalties must be effective, proportionate and dissuasive, and the maximum that a Member State may set is 3 per cent of net worldwide turnover. Publication of a decision finding an infringement is one of the available measures, which for a listed group is frequently the more expensive consequence.Liability towards victims is now a matter of national law. Because Omnibus I deleted the harmonised civil liability article, a claimant in the Netherlands has to rely on article 6:162 BW and establish an unlawful act, attributability, damage, causation and relativity in the ordinary way, or bring a collective action under the WAMCA. The practical significance of the CSDDD in such a case is evidential rather than constitutive: the standards in the Directive and the company own due diligence documentation are precisely the material a court uses to determine what a reasonable company in that position should have known and done. A well-kept due diligence file is therefore both a compliance obligation and a defence.Directors are affected indirectly. The separate directors duty proposed in earlier drafts did not make it into the final architecture, but the ordinary Dutch rules stand: under article 2:9 BW a director owes a duty of proper performance to the company, and personal liability towards third parties can arise where a serious personal reproach can be made. A board that ignores a known and documented risk in the value chain is exposed on both fronts, as we explain in our article on liability of directors and the more recent overview of directors liability for Dutch BV directors.How the Netherlands is implementing the CSDDD
The Directive is transposed in the Netherlands through the draft Wet internationaal verantwoord ondernemen (Wivo). A first version went out for public consultation at the end of 2024, and a revised version reflecting the Omnibus I amendments was consulted on until 3 August 2026. The draft designates the Autoriteit Consument en Markt (Netherlands Authority for Consumers and Markets) as the supervisory authority, including for regulated financial undertakings, and sets out the investigation and sanctioning powers, the procedural rules and the routes to court.Two points deserve attention. First, the transposition deadline is 26 July 2028 and the obligations apply from 26 July 2029, so the Dutch statute is expected well before companies have to comply, but the final text is not yet fixed and the parliamentary stage still has to run. Second, because Omnibus I made the core due diligence mechanics fully harmonised, the room for a stricter Dutch regime has narrowed considerably. The long-running initiative bill on responsible and sustainable international business conduct, which aimed at a broader Dutch duty of care applying to far more companies, cannot simply be layered on top of the harmonised architecture, and its future depends on the room the Directive leaves for national rules pursuing specific objectives. Companies planning on the basis of that initiative bill should plan on the basis of the Directive instead.What it means for suppliers and mid-sized companies
Most Dutch companies are far below the thresholds and will never be addressees of the Directive. They will still meet it, through their customers. In-scope buyers pass their obligations down the chain in the form of codes of conduct, contractual assurances, audit and information rights, corrective action plans and termination clauses, and banks and investors increasingly ask for the same material before lending.Omnibus I tried to limit that trickle-down effect. An in-scope company may only request from a business partner the information that is necessary for its due diligence, and the requests must be targeted, reasonable and proportionate. For a company with fewer than a defined number of employees there are further limits on the information that may be demanded. This gives a supplier a genuine argument against disproportionate questionnaires, and it is worth using it: the right response to an unreasonable request is a negotiated one, not a refusal or a signature.For a mid-sized supplier the sensible preparation is modest and mostly contractual. Know who your own critical suppliers are and where they operate. Have a short, honest code of conduct and a channel through which someone can report a problem. Read the ESG clauses your customer proposes before signing them, in particular the audit rights, the unilateral termination triggers and any indemnity, because those clauses survive long after the political debate about the Directive has moved on.What to do between now and July 2029
Companies in scope should use the interval deliberately rather than waiting for the Dutch statute. Establish first whether the group actually meets the thresholds on a consolidated basis, and record the calculation; for third-country groups this means measuring EU turnover on the correct basis. Map the chain of activities well enough to run a credible scoping exercise, and document why certain areas were prioritised. Align the work with the CSRD reporting cycle so that the same data serves both regimes instead of two parallel bureaucracies.Then look at the contracts. Supplier agreements signed today will still be running in 2029, and it is far cheaper to include proportionate information, audit and remediation provisions now than to renegotiate them under time pressure. Finally, decide where the function sits: which board member is accountable, which team maintains the risk map, and who answers when the ACM asks how a prioritisation decision was made.Common questions from businesses about the CSDDD
Is the CSDDD mandatory or voluntary?
Mandatory. Once the Dutch implementing act transposes Directive (EU) 2024/1760, as amended by Directive (EU) 2026/470, compliance becomes a legal duty. The supervisory authority can impose penalties of up to 3 per cent of net worldwide turnover, and claims for damages run through national law, in the Netherlands through article 6:162 of the Dutch Civil Code.
What is the threshold for CSDDD applicability?
After the Omnibus I amendments of February 2026 there is a single tier. EU companies are in scope with more than 5,000 employees and net worldwide turnover above 1.5 billion euro; non-EU companies are in scope with net turnover above 1.5 billion euro generated inside the Union, for which headcount is irrelevant. The obligations apply from 26 July 2029.
How does CSDDD differ from CSRD?
Think “do” versus “disclose.” The CSDDD obliges firms to run human-rights and environmental due diligence and fix problems; the CSRD obliges a wider set of firms to report sustainability data under ESRS standards. One is an operational duty, the other a transparency duty.
What does the Directive mean for companies operating in the Netherlands?
The Netherlands transposes the Directive through the draft Wet internationaal verantwoord ondernemen (Wivo), which designates the Autoriteit Consument en Markt (ACM) as the supervisory authority and sets out the procedural rules. A consultation on the amended bill closed on 3 August 2026. The transposition deadline is 26 July 2028.
Will SMEs have to do anything?
SMEs fall outside the legal thresholds, yet they will be asked by larger customers and banks to share data, sign codes of conduct, and remedy issues. Early preparation—basic policies, traceability, grievance channels—will keep them competitive in tenders and financing rounds.


