Regulations

CSDDD: the EU corporate due diligence directive and how it relates to the DPP

What the CSDDD is, which companies are still in scope after the Omnibus reform, how due diligence, thresholds and the timeline work after the revision, and how corporate due diligence overlaps with the Digital Product Passport.

Author: myDPP Team

CSDDD: the EU corporate due diligence directive and how it relates to the DPP

Key takeaways

CSDDD stands for Corporate Sustainability Due Diligence Directive - the EU directive on corporate sustainability due diligence, set out in Directive (EU) 2024/1760. It requires large companies to identify, prevent, mitigate and bring to an end adverse human rights and environmental impacts along their chain of activities - in other words, to run a risk-based due diligence process. The Omnibus reform (in force 18 March 2026) sharply narrowed the scope: only companies with more than 5,000 employees and over EUR 1.5 billion net worldwide turnover are now covered - cutting the number of directly affected companies from roughly 13,000 to about 6,000. CSDDD is a process-level obligation at entity level, not a product-labelling law, and it does not replace a Digital Product Passport. But both rely on the same foundation of supply-chain and product data. myDPP does not perform due diligence and does not produce a due diligence report; it stores and communicates the verified product and supply-chain data that both the DPP and the due diligence process need.

If you would first like to understand the basics of the passport itself, we recommend the introductory article Digital Product Passport in 15 minutes: what the DPP is and why the EU is introducing it.


What is the CSDDD?

The CSDDD (Corporate Sustainability Due Diligence Directive) is the EU directive that puts human rights and environmental due diligence on a single, mandatory footing. Its legal basis is Directive (EU) 2024/1760, in force since 25 July 2024. It complements the CSRD reporting obligation with a duty to act: a company in scope must not only report, but demonstrably take action.

At its core is a risk-based due diligence process across a company’s own operations and its chain of activities. A company in scope must

  • identify actual and potential adverse impacts on human rights and the environment,
  • prevent, mitigate or bring to an end those impacts,
  • provide a complaints mechanism,
  • monitor the measures taken, and
  • communicate publicly about them.

Who does the CSDDD apply to after the Omnibus reform?

Scope is the most fast-moving issue in the CSDDD file. Originally, the obligation was to cascade in waves down to companies from 1,000 employees and EUR 450 million turnover. The Omnibus reform changed this fundamentally.

The Omnibus I package entered into force on 18 March 2026 and amends the CSDDD on key points:

  • Much higher thresholds: only EU companies with more than 5,000 employees and over EUR 1.5 billion net worldwide turnover are now covered (or non-EU companies with EU turnover above EUR 1.5 billion). This cuts the number of directly covered companies from roughly 13,000 to about 6,000.
  • New deadlines: transposition into national law is set for 26 July 2028, with first application for all covered companies aligned on a single date of 26 July 2029 - the previously staggered application dates fall away.
  • Focus on direct business partners: the due diligence process is recalibrated around direct (tier-1) business partners and an upfront scoping exercise, rather than mapping every partner in the chain entity by entity. Deeper checks apply only where there is plausible information of a problem.
  • Less frequent assessment: periodic reviews are stretched from annual to every five years.
  • Climate plan and liability: the obligation to actively “put into effect” the climate transition plan was deleted; the EU-harmonised civil liability regime was removed and left to national law.

Important: if you do not meet the new thresholds, you are no longer directly required to run the process - but you often remain indirectly affected as a supplier (see below).

CSDDD and national supply-chain laws

Several member states already have national supply-chain laws with a similar thrust - Germany’s Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz, LkSG) is the best-known example. The CSDDD creates an EU-wide framework to which national law is being aligned: very large companies will follow the EU rules, and national acts are adapted accordingly. For companies in scope this means one due diligence process and one data foundation, not two parallel systems.

CSDDD and the Digital Product Passport: where they overlap

The CSDDD and the Digital Product Passport are two different instruments. The CSDDD governs a process at entity level - how a company manages risks in its chain; the DPP describes a single product over its lifecycle. Yet they draw on the same supply-chain and product data.

  • Origin and suppliers: due diligence presupposes that a company knows where materials come from and who its suppliers are. That same traceability is the backbone of the DPP under the ESPR.
  • Environmental data: resource use, material composition and the Product Carbon Footprint (PCF) are both environmental risk indicators for due diligence and fields in the DPP.
  • Product-level due diligence regimes: the EUDR deforestation regulation, with its geolocation and due diligence statement, and the battery-specific supply-chain due diligence in the battery passport are product-level expressions of the same logic - and draw on the same data.

The common denominator is an auditable data foundation per product and supplier: origin, materials, suppliers and the environmental figures derived from them. Maintain that foundation once, and it serves the DPP, the CSDDD due diligence process, EUDR and CSRD reporting from a single source.

Even outside the scope: the value-chain effect

The Omnibus reform removes many companies from the direct obligation - but that does not make supply-chain data irrelevant. The very large companies still in scope have to obtain information from their direct business partners for their due diligence process. A supplier outside the CSDDD will still receive these requests.

The reform does cap what large companies may request from small and medium-sized partners (the “trickle-down” safeguard). Even so, a company that keeps its product and supplier data structured anyway answers such requests with far less effort. This is where a DPP-ready data foundation pays off twice: for your own passport and for the due diligence requests coming down the supply chain.

What the CSDDD is not

An honest framing belongs here:

  • The CSDDD is a process-level due diligence obligation at entity level, not a product-labelling law. It produces no QR code and no consumer-facing product page.
  • A Digital Product Passport does not replace a due diligence process. It does not flag human rights risks and is not proof that due diligence obligations have been met.
  • myDPP does not perform due diligence, does not assess human rights risks and does not produce a due diligence report. The process is the responsibility of the company and its specialist functions.

What a Digital Product Passport - and myDPP - does is to store, version and communicate the verified product and supply-chain data in structured form, so that the same figures on origin, materials and environmental impact are reusable for the DPP and for due diligence documentation, instead of being captured anew in every system.

Preparing for the CSDDD: five steps

1. Check whether you are in scope

Compare your company against the new Omnibus thresholds (5,000 employees and EUR 1.5 billion turnover). Also check whether you are indirectly affected as a direct business partner of an in-scope customer.

2. Map your chain of activities

Get an overview of your direct business partners and the upstream material flows - that is the basis for the scoping and risk assessment.

3. Identify data gaps

Map the due diligence requirements to your existing data sources. Figures on origin, suppliers and environmental impact are typically the ones most often missing.

4. Build the product- and supplier-data foundation

Capture origin, material composition and PCF where they are needed for the DPP anyway - so you avoid maintaining the same data twice for CSDDD, DPP, EUDR and CSRD.

5. Ensure traceability

Prepare to document and communicate the measures you take. Versioned, traceable product and supplier data makes this considerably easier.

Frequently asked questions (FAQ)

What is the CSDDD in simple terms?

The CSDDD is the EU corporate due diligence directive. It requires very large companies to identify, prevent and bring to an end adverse human rights and environmental impacts along their chain of activities - that is, to run a risk-based due diligence process and communicate about it.

Who is still in scope after the Omnibus reform?

After the Omnibus reform that entered into force on 18 March 2026, only companies with more than 5,000 employees and over EUR 1.5 billion net worldwide turnover. This cuts the number of directly covered companies from roughly 13,000 to about 6,000.

When does the CSDDD apply?

Transposition into national law is set for 26 July 2028, with first application for all covered companies aligned on 26 July 2029. The previously staggered application dates fall away.

What is the difference between CSDDD and CSRD?

The CSRD is a reporting obligation (what a company discloses); the CSDDD is a duty to act (what a company must actually do in its chain). Both belong to the same Omnibus package and rely on the same supply-chain and product data.

Does the Digital Product Passport replace a due diligence process?

No. The DPP does not flag human rights risks and does not prove that due diligence has been met. It stores and communicates the underlying product and supply-chain data that the due diligence process also needs, but it does not carry out the due diligence itself.

Read more


Sources