Menu
Website designed by SA / Build by MMD

On 16 December, the European Parliament voted in favour of Omnibus I which includes revisions to the Corporate Sustainability Due Diligence Directive (CSDDD) and the Corporate Sustainability Reporting Directive (CSRD) following trilogue negotiations. As a next step, the final text needs to be approved by the Council. It will then enter into force for all in-scope companies simultaneously in 2029. 

This alert summarises the key changes to the CSDDD, with a short update on the CSRD. 

Key changes to the CSDDD

Key changes relate to the scope of companies covered, penalties, civil liability, the removal of climate obligations, and information companies can ask from their business partners. Core due diligence requirements under the CSDDD are still intact. The CSDDD still covers the full value chain, but updated prioritisation rules will allow companies to concentrate programmes on direct business partners (e.g. Tier 1)  if they identify severe risks there.

Scope, Timeline, Liability 

  • Scope – EU companies with 5,000 employees and €1.5 billion turnover are in scope, an increase from 1,000 employees and €450 million. Non-EU based companies with €1.5 billion turnover in the EU are also in scope (Article 2). 
  • Timeline – The Directive goes into force for all companies equally on 26 July 2029. The previous cascading timeline has been removed (Article 37). 
  • Penalties – Maximum penalties decrease from 5% to 3% of net worldwide turnover (or consolidated turnover for parent companies), based on the previous financial year. If a company prioritises impacts in line with the Directive, failure to address less significant impacts will not trigger penalties (Articles 9, 27). 
  • Civil liability – Civil liability will be determined by existing national rules (Article 29). 

Due Diligence Requirements  

  • Risk Assessment / Scoping – Companies must conduct a “scoping exercise” using reasonably available information to identify where human rights and environmental risks are likely and most severe. The Directive specifically states that companies can use digital tools, such as DDD’s ADA to support this.  
  • Prioritisation – If, during the scoping exercise, companies identify severe and likely risks at several points in the value chain, they may prioritise addressing risks at their direct business partners (Article 9). 
  • Limitations on information requests – Based on the risk assessment findings, companies are required to carry out in-depth assessments where risks are more likely and severe. However, in this process, “companies may request information from business partners only where that information is necessary, and in case of business partners with fewer than 5,000 employees only when the information cannot reasonably be obtained by other means” (Article 8). 
  • Responsible disengagement – Companies are no longer required to exit a business relationship as a last resort if a severe risk cannot be addressed. Instead, they can suspend the relationship (where legally allowed) and implement an enhanced prevention action plan if there is a reasonable expectation of success (Article 10). 
  • Monitoring – Monitoring is required every five years rather than annually, unless there are reasonable grounds to believe existing measures are inadequate or ineffective (Article 15). 
  • Stakeholder engagement – Stakeholders are now limited to those directly affected by a company, and engagement is required when identifying, assessing, prioritising, and addressing adverse impacts. Engagement is no longer required when suspending or terminating relationships, or when developing qualitative and quantitative indicators  (Article 13). 
  • Climate transition plans deleted – The obligation to adopt and implement climate transition plans has been removed (Article 22). 
  • What remains unchanged – There are no major changes to risks covered (Article 3), management systems (Article 7), grievance mechanisms (Article 14), prevention and mitigation requirements (Article 10), or remedy (Article 12). 
  • EU-wide harmonisation – Member States cannot exceed the Directive’s requirements in key areas, including impact identification (Article 8), prioritisation (Article 9), grievance mechanisms (Article 14), monitoring and communication (Articles 15–16), group-level due diligence support (Article 6), prevention obligations (Article 10), and requirements to end adverse impacts (Article 11). This strengthens harmonisation and limits national gold-plating.  

Key changes to the CSRD 

  • Scope – Only large companies with more than 1,000 employees and €450 million turnover will be required to conduct sustainability reporting. (Article 19) 
  • Transition exemption – Companies originally due to begin reporting in 2024 (“wave one”) are exempt from reporting in 2025 and 2026. 
  • Consolidated sustainability reporting – Groups may report at the consolidated level rather than at subsidiary level, reducing duplication. (Article 29) 
  • ESRS simplification – The ESRS are being streamlined to reduce reporting burden and increase clarity. On 3 December, EFRAG submitted a draft simplified ESRS to the European Commission for approval, which includes a reduction of mandatory datapoints by 61%. The Commission will now prepare a Delegated Act based on this draft. 
Contact
If you have a project you would like to discuss
email: info@duediligence.design