The Challenge
The Corporate Sustainability Due Diligence Directive (CSDDD) passed in June 2023, creating a compliance threshold problem that many organizations didn't anticipate. This directive's lower tier affects mid-sized manufacturers and wholesalers with 250-500 employees operating in high-risk sectors, who are often overlooked in ESG discussions.
The directive's primary threshold is well-known: €150 million global turnover and 500+ employees. However, the secondary provision is less familiar. If your organization has more than 250 employees and a global turnover exceeding €40 million, with half of that turnover from sectors like textiles, leather, agriculture, forestry, fisheries, extractive industries, or food and beverage, you're in scope. Non-EU companies face the same rule if they generate over €40 million in the EU market with half from these high-risk sectors.
This creates a divided compliance landscape. Large multinationals typically have ESG teams and supplier audit programs in place. Mid-tier organizations in high-risk sectors often do not. They must now conduct human rights due diligence, establish grievance mechanisms, and publish annual sustainability reports, or face enforcement from national supervisory authorities.
Operational Constraints
The CSDDD operates alongside the EU Corporate Sustainability Reporting Directive (CSRD), which mandates comprehensive ESG reports from approximately 50,000 organizations. Both directives emphasize that transparency is mandatory and greenwashing carries liability.
Organizations at the €40 million threshold face specific challenges. They often lack dedicated sustainability officers, and their procurement teams may not be trained in human rights screening. Legal departments might not have GDPR-compliant grievance channels, and finance teams may not track environmental risk metrics by supplier.
High-risk sector designation has operational implications. For example, textile manufacturers often source from countries with weak labor protections. Extractive industries have environmental footprints across jurisdictions with varying regulatory standards. The directive requires identifying these risks, mitigating them through supplier engagement, and publicly reporting efforts.
Liability extends beyond direct operations. You're responsible for ensuring suppliers and third parties meet CSDDD standards. Non-compliance by them can result in penalties for you, shifting procurement from price-and-delivery negotiations to ongoing compliance monitoring.
Required Actions
Organizations meeting the threshold must implement five core processes:
Due Diligence Procedures: Screen and audit suppliers and business partners for environmental and human rights risks. Mandatory site visits and policy reviews are necessary to ensure adequate labor protections. Regulatory compliance checks must cover every jurisdiction in your supply chain.
Risk Mitigation Protocols: When identifying issues like child labor or improper waste disposal, you must engage with suppliers to address these, document mitigation efforts, and track progress.
Public Reporting Mechanisms: Showcase your due diligence and risk management strategies through annual sustainability reports or dedicated website sections. Information must be accessible and verifiable.
Grievance Channels: Establish responsive mechanisms for workers and stakeholders to raise concerns. Ensure GDPR compliance and accessibility to encourage reporting. Document processes for addressing complaints and resolutions.
Third-Party Compliance Verification: You share liability if suppliers violate environmental standards. Build compliance into contracts, conduct regular audits, and maintain documentation of preventative measures.
Consequences and Metrics
The directive includes enforcement provisions with penalties ranging from fines to sanctions. National supervisory authorities can take legal action against organizations ignoring environmental and human rights risks.
Non-compliance leads to reputational damage, exclusion from public procurement processes, and civil liability exposure if damages could have been prevented. Organizations with robust business continuity plans fared better during supply chain disruptions, maintaining operations while others struggled.
Lessons Learned
Organizations that delayed compliance program development faced tight timelines and resource constraints. Early starters learned that supplier engagement takes longer than policy drafting. Writing a human rights due diligence policy is quick; implementing it across a global supply chain takes months. Auditing suppliers, negotiating compliance terms, and building grievance mechanisms require sustained effort and coordination.
Another lesson: business continuity planning must consider compliance-driven supplier exits. If a key supplier violates labor standards and refuses remediation, you need an alternative ready. Organizations that hadn't mapped supply chain dependencies faced tough choices between compliance and continuity.
Strategic Steps for Your Organization
If your organization meets the €40 million threshold in a high-risk sector, begin with supply chain mapping. Identify every entity in your value chain, note their locations, and flag jurisdictions with weak environmental or labor protections.
Develop your grievance mechanism proactively. Ensure it complies with GDPR and has proper escalation procedures. Test it internally before external use.
Integrate CSDDD compliance into procurement contracts now. Update supplier agreements to include human rights audit rights and environmental compliance warranties. Renegotiating terms takes time.
Review business continuity plans for supply chain compliance risks. If a critical supplier operates in a high-risk sector, have contingency options ready. The directive doesn't exempt you from compliance during disruptions.
Finally, integrate CSDDD reporting into your risk management framework. The due diligence, risks identified, and mitigation steps should inform your enterprise risk assessments. National supervisory authorities will expect sustainability risks to receive the same governance attention as financial and operational risks.
The €40 million threshold is not a suggestion. It's a firm compliance requirement with established enforcement mechanisms.



