The EU Corporate Sustainability Due Diligence Directive (CSDDD) places legal responsibility on supply chain accountability. The question is: Should your organization prepare for CSDDD compliance even if you don't meet the thresholds? The answer depends on your position in the supply chain and how your partners define risk.
The Decision You're Facing
You're deciding whether to implement CSDDD-level due diligence now or wait. This isn't a simple yes/no choice. The directive creates three distinct positions:
- Direct compliance obligation, you meet the employee and revenue thresholds.
- Indirect exposure, you supply or partner with covered entities.
- Strategic positioning, you're outside the scope but want to preempt future requirements.
Each position requires different resource allocation, timeline planning, and risk mitigation strategies. Choose wrong and you'll either waste budget on premature compliance or scramble when a major customer demands proof of your due diligence program.
Key Factors That Affect Your Choice
Your Revenue and Headcount Profile
The March 2024 revision sets clear thresholds: EU companies need more than 1,000 employees and €450 million in global revenue. Non-EU companies need €450 million in EU market revenue over the past two years. If you're close to these numbers, anticipate coverage within your next growth cycle.
Your Customer Base
Review your contracts. Do you supply organizations that meet CSDDD thresholds? The directive establishes legal liability for violations in supply chains. Covered entities will push due diligence requirements downstream through contractual terms, audit rights, and vendor qualification criteria. You don't need to be covered to face compliance pressure.
Your Industry Classification
The revised directive removed lower thresholds for high-risk sectors (textiles, agriculture, extractive industries, food and beverage), but that doesn't mean sector risk disappeared. If you operate in these industries, your customers will still apply heightened scrutiny. The regulatory relief is procedural, not substantive.
Your Risk Tolerance for Penalties
Member states can impose fines up to 5% of net worldwide turnover for violations. That's not a compliance cost, it's an existential threat. Calculate what 5% represents for your organization, then decide whether your current due diligence program could withstand regulatory examination.
Path A: Build Full CSDDD Compliance Now
Choose this path if:
- You meet or will soon meet the 1,000-employee and €450 million thresholds.
- Your largest customers have indicated they'll require CSDDD-equivalent due diligence from suppliers.
- You operate in sectors where environmental or labor violations carry high reputational risk.
- You're pursuing public procurement contracts in EU member states (non-compliance can trigger exclusion).
What this requires:
Start with supply chain mapping. You need visibility into your value chain beyond tier-one suppliers. The directive holds you liable for harm caused by business partners, so document your commercial relationships and their risk profiles.
Establish a due diligence governance structure. Designate ownership, typically split between procurement, legal, and risk functions, and define escalation protocols. The COSO ERM Framework provides a useful reference for integrating supply chain risks into your enterprise risk taxonomy.
Implement monitoring and remediation processes. You're not just identifying risks; you're required to prevent and mitigate them. Build contractual terms that give you audit rights, termination provisions for non-compliance, and collaborative remediation mechanisms.
Document everything. When enforcement authorities investigate, they'll examine your process, not just your outcomes. Maintain records of risk assessments, supplier communications, corrective action plans, and board reporting.
Timeline:
The phase-in periods range from three to five years depending on your size. If you have 5,000+ employees and €1.5+ billion turnover, you'll face compliance requirements by 2027. Don't wait for national transposition, member states have two years to incorporate the directive into local law, but your preparation should start now.
Path B: Implement Targeted Due Diligence for Key Relationships
Choose this path if:
- You're below the coverage thresholds but supply covered entities.
- Your customer contracts already include sustainability or ethical sourcing clauses.
- You want to protect market access without full program build-out.
- Your industry faces increasing ESG scrutiny even without regulatory mandates.
What this requires:
Segment your customer and supplier base by CSDDD exposure. Prioritize relationships where the counterparty is covered or likely to be covered. Apply enhanced due diligence to these segments while maintaining baseline practices elsewhere.
Develop questionnaires and self-assessment tools that mirror CSDDD requirements. When covered customers audit your practices, you'll need evidence of environmental and labor risk management. Create documentation that demonstrates your process even if you're not legally required to have one.
Negotiate contractual protections. If you're accepting flow-down compliance obligations, ensure your contracts include reasonable limitations on liability, clear definitions of what constitutes adequate due diligence, and shared responsibility for supply chain visibility.
Build escalation triggers. Define the circumstances that would move you to Path A. These might include: customer requirements affecting more than 30% of revenue, regulatory signals that thresholds will drop, or material supplier violations that expose you to reputational risk.
Timeline:
Align your implementation with customer demands rather than regulatory deadlines. If your largest customer is covered and faces a 2027 compliance date, expect their vendor requirements to tighten in 2026. Work backward from their timeline.
Path C: Monitor and Prepare for Future Expansion
Choose this path if:
- You're well below coverage thresholds with no immediate customer pressure.
- Your supply chain is short and transparent (you control most production).
- You operate in low-risk sectors with minimal environmental or labor exposure.
- Your strategic plan doesn't include EU market expansion.
What this requires:
Establish a watching brief. Assign someone to track CSDDD developments, including national transposition laws and enforcement guidance. The directive includes provisions for future reconsideration of sector-specific thresholds, if you're in textiles or extractives, regulatory expansion remains possible.
Document your current state. Even if you're not building a compliance program, map your existing due diligence activities. You'll need this baseline if circumstances change. Include: supplier qualification processes, contract terms related to labor or environmental standards, incident response protocols, and any certifications or audits you currently maintain.
Assess your gap to compliance. Run a hypothetical CSDDD readiness assessment. Identify what you'd need to implement if requirements changed. Estimate costs, timelines, and resource needs. This exercise converts regulatory uncertainty into a quantified contingency plan.
Timeline:
Review your position annually or when triggered by: significant revenue growth, new customer relationships with covered entities, regulatory amendments to thresholds or scope, or material incidents in your supply chain that indicate control weaknesses.
Summary Matrix
| Factor | Path A: Full Compliance | Path B: Targeted Approach | Path C: Monitor |
|---|---|---|---|
| Coverage status | Meet thresholds or imminent | Supply covered entities | Well below thresholds |
| Customer pressure | Explicit requirements | Contractual clauses present | No current demands |
| Implementation cost | High (full program build) | Moderate (segmented) | Low (documentation only) |
| Liability exposure | Direct regulatory + civil | Contractual + reputational | Minimal current exposure |
| Timeline urgency | 2027 for largest entities | Align with customer dates | Annual review cycle |
| Resource allocation | Cross-functional team | Procurement + legal leads | Part-time monitoring role |
The directive's liability provisions mean your choice isn't binary. Even if you're not covered, your customers' obligations will reshape your commercial relationships. Decide based on where you sit in the value chain, not just where you fall on the threshold chart.



