The Corporate Sustainability Due Diligence Directive — CSDDD, or CS3D if you prefer — is the EU law that makes the largest companies legally responsible for human rights and environmental harms in their supply chains. It has had a turbulent two years: adopted in 2024, paused in 2025, and substantially rewritten by the Omnibus package in early 2026. Most of what was written about it before this year is now out of date, which makes it worth setting out where the directive actually stands — and why it matters to Irish businesses that will never come close to its thresholds.
The CSDDD (Directive (EU) 2024/1760) requires the EU’s largest companies to identify and address human rights and environmental harms across their own operations and their chains of activities. After the Omnibus amendments in force since March 2026, it applies only to companies with more than 5,000 employees and over EUR 1.5 billion net worldwide turnover, with obligations applying from 26 July 2029. Very few Irish companies will be in scope directly — but many Irish SMEs will meet the directive anyway, through supplier codes, contract clauses, and data requests cascading down from in-scope customers.
Key Takeaways
- The CSDDD entered into force on 25 July 2024, but its obligations have not yet applied to anyone — member states must transpose it by 26 July 2028, and companies apply the rules from 26 July 2029
- The Omnibus directive (Directive (EU) 2026/470, in force since 18 March 2026) raised the scope thresholds to more than 5,000 employees and over EUR 1.5 billion net worldwide turnover
- The Omnibus also deleted the obligation to adopt a climate transition plan, dropped the EU-wide civil liability regime in favour of national rules, and capped fines at 3% of net worldwide turnover
- Due diligence is now explicitly risk-based: companies scope for where harms are most likely and most severe, rather than mapping their entire value chain
- The practical route by which the CSDDD reaches Irish SMEs is contractual — supplier codes of conduct, ESG questionnaires, and emissions data requests from large customers building their compliance programmes now
What the CSDDD Actually Requires
Strip away the acronyms and the CSDDD does one thing: it converts a set of expectations that have existed for years in voluntary frameworks — the UN Guiding Principles on Business and Human Rights, the OECD Guidelines — into a binding legal duty for the largest companies operating in the EU.
That duty is to conduct due diligence on actual and potential adverse impacts on human rights and the environment. In practice, an in-scope company must build due diligence into its policies and management systems, identify where harms such as forced labour, unsafe working conditions, pollution, or ecosystem damage could arise in its operations and its chain of activities, act to prevent or mitigate the potential ones, bring actual ones to an end or minimise them, provide for remediation, maintain a complaints channel, monitor whether any of it is working, and say publicly what it has done.
The critical word is chain of activities. The duty does not stop at the company’s own gates or even at its direct suppliers — it follows the risk. A food group headquartered in Dublin is expected to concern itself with labour conditions on the farms that supply its ingredients, and a construction materials multinational with the mines and mills behind its inputs. That reach is precisely what makes the directive relevant to companies far too small to be named in it.
Where the Rules Stand After the Omnibus (July 2026)
The CSDDD’s legislative history matters because so much published guidance describes obligations that no longer exist. The original directive entered into force on 25 July 2024 with a three-wave phase-in starting in 2027. The “stop-the-clock” directive (Directive (EU) 2025/794) then pushed everything back a year in April 2025 while the substance was renegotiated. The Omnibus directive — Directive (EU) 2026/470, published in the Official Journal on 26 February 2026 and in force since 18 March 2026 — is that renegotiation made law. It is the same directive that narrowed the CSRD, and it changed the CSDDD in five substantial ways.
Scope is far narrower. The directive now applies to EU companies with more than 5,000 employees and net worldwide turnover above EUR 1.5 billion, and to non-EU companies generating more than EUR 1.5 billion of net turnover in the EU. The original thresholds — 1,000 employees and EUR 450 million — are gone, and with them most of the companies the 2024 text would have covered.
The timeline moved again. Member states must transpose the directive by 26 July 2028, companies apply the rules from 26 July 2029, and the annual due diligence statement under Article 16 applies for financial years starting on or after 1 January 2030. The phased waves are gone: one application date for everyone in scope.
Due diligence became explicitly risk-based. Companies are no longer expected to comprehensively map their entire value chain. Instead they carry out a scoping exercise using reasonably available information to identify where adverse impacts are most likely to occur and most severe, and concentrate in-depth assessment there, prioritising direct business partners. This is a genuine reduction in breadth — but it puts far more weight on the quality of the scoping judgement, because a poorly reasoned scoping exercise is where enforcement scrutiny will start.
The climate transition plan obligation was deleted. The 2024 text required in-scope companies to adopt a transition plan for climate change mitigation aligned with the Paris Agreement’s 1.5°C goal. The Omnibus removed that obligation from the CSDDD entirely. Companies still in scope for CSRD reporting continue to disclose whatever transition plans they have, but the freestanding duty to adopt one is gone.
Liability and penalties were softened. The harmonised EU-wide civil liability regime was dropped — whether an affected person can sue now depends on each member state’s national rules, a question the Commission must revisit by 2031. Fines are capped at 3% of net worldwide turnover for the most serious violations, a lower ceiling than the original text envisaged.
Two things remain genuinely in flux as of July 2026. The Commission has yet to issue the guidelines and model contractual clauses the amended directive promises, and no member state — Ireland included — has enacted its transposing legislation, which means the domestic detail, including which Irish body will supervise compliance, is still to be settled. Anything you read that presents those details as decided is ahead of the law.
Who the CSDDD Touches in Ireland
Directly: a short list
At more than 5,000 employees and EUR 1.5 billion in worldwide turnover, direct scope in Ireland is confined to the largest Irish-headquartered groups and the Irish operations of multinationals whose parent companies qualify. If your group is anywhere near those numbers, the work is group-level and should already be under discussion: the scoping methodology, the policy framework, and the supplier engagement model all take longer to build than the 2029 application date suggests, and they interact directly with the group’s CSRD reporting and double materiality assessment.
Indirectly: the actual Irish story
For everyone else, the CSDDD arrives by a different route. An in-scope company cannot discharge its duty by inspecting its own sites — the duty follows its chain of activities, and its chain of activities is made of other people’s businesses. The mechanism that connects a Brussels directive to a fifty-person Irish manufacturer is the commercial relationship: the in-scope customer pushes its obligations downward through supplier codes of conduct, contractual clauses requiring compliance and audit access, ESG questionnaires, and requests for emissions and workforce data.
Irish SMEs supplying large pharmaceutical, agri-food, technology, construction, and retail customers have been receiving versions of these requests for several years, driven by CSRD reporting and voluntary commitments. The CSDDD hardens the trend, because for the customer this is no longer reputational housekeeping — it is a supervised legal duty with fines attached, and the evidence for it has to come from suppliers. It is also worth remembering that many large companies began building their due diligence programmes against the original 2024 scope and have not dismantled them; the contractual expectations they formed then are still circulating in procurement processes now.
The amended directive does build in protections for smaller partners. Information requests must be limited to what is necessary, and where a business partner has fewer than 5,000 employees, an in-scope company should turn to it only where the information cannot reasonably be obtained another way. Those safeguards matter, and an SME facing a disproportionate demand should know they exist. But they are a ceiling on what can be demanded, not a shield against being asked — and they offer no help with the commercial reality that the supplier who answers well is easier to keep than the one who answers late, thinly, or not at all.
Why Cascade Requests Are Harder Than They Look
The difficulty with a due diligence questionnaire is rarely the form itself. It is that the questions assume underlying systems most SMEs have never needed: a documented view of your own supply chain and where its risks sit, workforce and grievance policies that exist on paper and in practice, environmental data that stands up to being checked, and a coherent account of your emissions rather than a number typed in from memory.
Answering without those foundations creates two problems. The immediate one is commercial — a weak response invites follow-up audits, remediation conditions, or quiet de-prioritisation next time the contract renews. The slower one is liability-shaped: statements made to customers in due diligence processes are exactly the kind of claims that can come back as greenwashing exposure if they were optimistic rather than accurate. The businesses that handle the cascade well treat the first serious customer request as the prompt to build a proportionate, reusable evidence base — one set of policies, data, and documentation that answers every subsequent request — rather than improvising each questionnaire as it lands.
Judging what “proportionate” means for your size and sector is the real skill, and it is where outside experience earns its keep: enough substance to satisfy an in-scope customer’s compliance team, without building the machinery of a directive that does not apply to you.
How the CSDDD Fits With CSRD
The two directives are siblings and are routinely confused. The CSRD is a reporting obligation — it requires in-scope companies to disclose sustainability information, anchored in a double materiality assessment. The CSDDD is a conduct obligation — it requires companies to actually do something about harms in their chain of activities, whether or not anyone reads the report. After the Omnibus they share a family resemblance in scope design, but their thresholds differ: CSRD catches companies from 1,000 employees and EUR 450 million turnover, the CSDDD only from 5,000 employees and EUR 1.5 billion.
For an Irish SME on the receiving end, the distinction explains the two kinds of request in your inbox: CSRD-driven requests want your data for the customer’s report, while CSDDD-driven requests want evidence about your conduct and your own suppliers. The same underlying evidence base serves both — which is the strongest argument for building it once, properly.
How Clearscope Helps
Our ESG advisory team works on both sides of the cascade. For large Irish organisations in or near direct scope, we support the design of risk-based due diligence frameworks that align with the amended directive and integrate with existing CSRD and materiality work, so the same evidence serves both duties. For the far larger group of Irish businesses being pulled in through their customers, we build the proportionate response: assessing what your key customers are actually entitled to ask for, closing the genuine gaps in policies and data, and assembling supplier-facing documentation that holds up to compliance scrutiny without over-engineering it.
The directive’s own deadlines sit in 2028 and 2029, but the cascade is not waiting for them — the requests are already arriving, and the suppliers who can answer them credibly are already easier to buy from. If a customer questionnaire has landed on your desk, or you want to be ready before one does, talk to us.
Common Questions
What is the CSDDD?
The Corporate Sustainability Due Diligence Directive (Directive (EU) 2024/1760) is the EU law requiring the largest companies to identify, prevent, and address adverse human rights and environmental impacts in their own operations and their chains of activities. It entered into force on 25 July 2024 and was substantially amended by the Omnibus directive in March 2026.
Who is in scope for the CSDDD after the Omnibus?
EU companies with more than 5,000 employees and net worldwide turnover above EUR 1.5 billion, and non-EU companies with more than EUR 1.5 billion net turnover generated in the EU. The original 1,000-employee threshold is gone — direct scope is now confined to the very largest groups.
When does the CSDDD apply?
Member states must transpose the directive by 26 July 2028, in-scope companies apply the rules from 26 July 2029, and the annual due diligence statement applies for financial years starting on or after 1 January 2030. As of July 2026, Ireland has not yet enacted transposing legislation — the domestic detail is still to come.
Does the CSDDD still require climate transition plans?
No. The original directive required in-scope companies to adopt a climate transition plan aligned with the Paris Agreement, but the Omnibus directive deleted that obligation. Companies in scope for CSRD continue to report on any transition plans they have, but the freestanding CSDDD duty to adopt one is gone.
My company is nowhere near the thresholds — why am I getting CSDDD-related requests?
Because in-scope companies must evidence due diligence across their chains of activities, and that evidence comes from suppliers. Supplier codes of conduct, contract clauses, ESG questionnaires, and data requests are how the obligation cascades to Irish SMEs. The directive limits what can be demanded from partners with fewer than 5,000 employees, but it does not stop customers asking — and answering well is a commercial advantage.
What is the difference between the CSRD and the CSDDD?
The CSRD is a reporting directive — it requires in-scope companies to disclose sustainability information. The CSDDD is a conduct directive — it requires the largest companies to actively identify and address harms in their operations and value chains. They have different thresholds (1,000 employees and EUR 450m for CSRD; 5,000 employees and EUR 1.5bn for CSDDD) and generate different kinds of supplier requests.