Supply Chain Due Diligence in Europe: Your Regulatory Map from 2025 to 2029

In short
A company operating in Europe can face up to four supply chain due diligence obligations at once — the French Loi de Vigilance, Germany’s LkSG, the EU’s CSDDD, and the CSRD — each with its own threshold and enforcement route. Omnibus I (March 2026) narrowed the two EU-level regimes but left the two national statutes untouched, opening a coverage gap between them. The practical next step: build one supplier evidence base that feeds all four regimes, rather than four parallel programmes.
A company operating across Europe today can face supply chain due diligence obligations from up to four different sources at once: a French statute, a German statute, an EU directive on due diligence, and an EU directive on reporting — each with its own thresholds, its own trigger, and its own enforcement mechanism. Most legal and compliance content treats these frameworks one at a time, which leaves exactly the gap a multinational compliance team actually needs filled: a single map of where each regime applies, how they interact, and what changed when the Omnibus I Directive entered into force on 18 March 2026. This article builds that map.
Which of the Four Supply Chain Due Diligence Frameworks Applies to You?
Before going deeper into each regime, it helps to see them side by side, because the differences in scope and enforcement mechanism are exactly where compliance programmes go wrong when they treat “supply chain due diligence” as a single, uniform obligation.
The French Loi de Vigilance (Law n° 2017-399) applies to companies employing at least 5,000 employees in France, or 10,000 in France and abroad, over two consecutive financial years. It requires a vigilance plan covering human rights, health and safety, and environmental risks, and it is enforced through civil liability before French civil courts, triggered by a formal notice from associations, NGOs or local authorities.
The German Supply Chain Due Diligence Act (LkSG) applies to companies with 1,000 or more employees in Germany. It requires risk analysis, preventive and remedial measures, a grievance mechanism, and documentation, enforced administratively by BAFA (the Federal Office for Economic Affairs and Export Control) — though, as detailed below, this enforcement is currently being narrowed by a pending legislative amendment.
The EU Corporate Sustainability Due Diligence Directive (CSDDD), following Omnibus I, applies to companies — or EU parent companies of a group — with more than €1.5 billion in worldwide turnover and an average of more than 5,000 employees over two consecutive years, plus certain franchisors and licensors above separate thresholds. It requires active due diligence across the value chain and is enforced through civil liability, allowing third parties harmed by a company’s failure to bring a claim.
The EU Corporate Sustainability Reporting Directive (CSRD), also narrowed by Omnibus I, applies to companies — or parent undertakings on a consolidated basis — with more than €450 million in net turnover and an average of more than 1,000 employees. Unlike the other three, it is not a due diligence obligation at all: it is a disclosure obligation, enforced through national competent authorities and tested by an independent auditor issuing an assurance opinion.
Must-Read
ESG data strategy for the supply chain : ESG Strategy for the Supply Chain: Assessment and Management Methods
What Actually Changed Under Omnibus I in March 2026?
The Omnibus I Directive ((EU) 2026/470) was published in the Official Journal on 26 February 2026 and entered into force on 18 March 2026. It amends the CSRD and the CSDDD directly — it does not touch the French Loi de Vigilance or the German LkSG, both of which are national statutes outside its scope. That distinction matters more than it might first appear, because it means the two EU-level regimes just got narrower while the two national regimes did not move at all, creating a gap between them that did not exist before.
Under the revised CSRD, scope now requires both more than €450 million in net turnover and an average of more than 1,000 employees, with EU companies reporting in 2028 on financial year 2027 data, and non-EU ultimate parent entities reporting in 2029 on financial year 2028 data. Under the revised CSDDD, scope now requires more than €1.5 billion in worldwide turnover and an average of more than 5,000 employees, tested over two consecutive financial years. Member States must transpose the Directive by 26 July 2028, its core provisions apply from 26 July 2029, and the reporting obligations attached to it apply to financial years starting on or after 1 January 2030.
The practical consequence for a compliance map is this: a company with 6,000 employees in France and €800 million in worldwide turnover now falls outside the narrowed CSDDD (it doesn’t clear the €1.5 billion threshold) and outside the narrowed CSRD (it clears the employee count but not the turnover threshold), yet it remains squarely inside the French Loi de Vigilance, whose 5,000-employee threshold was never touched by Omnibus I. Scope narrowing at EU level does not automatically mean reduced exposure — it can simply shift which regime is the operative one.
The French Loi de Vigilance : Still in Force, Still Civil Liability
The French law requires a vigilance plan built on five measures: a risk mapping to identify, analyse and rank risks; regular assessment procedures covering subsidiaries, subcontractors and suppliers with an established commercial relationship; appropriate mitigation and prevention actions; a whistleblowing mechanism built in consultation with trade unions; and a monitoring scheme to evaluate the effectiveness of the measures in place.
Liability under Article L. 225-102-2 of the French Commercial Code runs to the company itself, assessed by a civil court following a mandatory formal notice that must clearly set out the alleged breaches. This is not a theoretical exposure: the Paris Court of Appeal ruled on 17 June 2025 that La Poste’s vigilance plan had to be completed, finding its risk mapping too generic and its whistleblowing mechanism not properly negotiated with unions, and in June 2024 the same court ruled on the admissibility of claims against TotalEnergies, EDF and Suez, opening the door to trials on the merits. Because Omnibus I leaves this statute entirely untouched, none of this exposure has changed — if anything, it now stands out more clearly as the more durable of the two civil-liability regimes covered here, precisely because it does not move with each EU legislative cycle.
The German LkSG : What’s Changing and What Remains
The LkSG has applied to companies with 1,000 or more employees in Germany since 1 January 2024 (having applied to companies with 3,000 or more since 2023). Since autumn 2025, its enforcement has been substantially de-escalated ahead of formal legislative change: BAFA stopped reviewing companies’ annual reports from October 2025, deactivated its digital reporting portal in November 2025, and was instructed by the Federal Ministry to pursue only “serious” violations.
A government draft bill to amend the LkSG has been working through the Bundestag since a first reading on 16 January 2026, and remained in committee as this article was prepared. The draft proposes retroactively abolishing the reporting obligation to BAFA from 1 January 2023, and narrowing the range of sanctionable offences to four categories: failing to take or delaying preventive measures, failing to take or delaying remedial measures, failing to draw up or implement a remediation concept, and failing to establish or implement a complaints procedure. What the draft does not touch is the substance of the law: risk analysis, preventive and remedial measures, the complaints mechanism, and internal documentation all remain mandatory obligations, only the reporting channel to the regulator is being removed.
Seventeen German trade associations have called for the LkSG to be suspended entirely, or at minimum aligned to the CSDDD’s much higher 5,000-employee, €1.5 billion threshold, on the basis that it makes little sense to hold German companies with 1,000 employees to national obligations that will not apply to comparable companies elsewhere in the EU. The German government has so far explicitly rejected this alignment. The practical reading for a compliance map: companies with between 1,000 and 4,999 employees in Germany should expect to remain covered by LkSG’s substantive due diligence duties for the foreseeable future, even as the reporting burden eases and even though these same companies will sit outside CSDDD’s narrower scope entirely.
CSRD : Where Reporting and Due Diligence Intersect
CSRD does not ask a company to act on supply chain risk — it asks the company to disclose what its double materiality assessment found, including, where material, under ESRS S2 (Workers in the Value Chain): policies on forced labour, child labour and human trafficking, targets set for value chain workers, and — under EFRAG’s amended draft standards published for consultation in November 2025 — an explicit datapoint on substantiated human rights incidents involving value chain workers specifically.
The overlap with the due diligence regimes is structural rather than incidental. A company running a CSDDD or LkSG due diligence process generates exactly the kind of evidence — risk assessments, remediation records, incident logs — that a CSRD disclosure under ESRS S2 needs to report on. Building the two as separate exercises means collecting the same underlying facts about the same suppliers twice, once for an internal due diligence file and once for an externally assured disclosure. For the CSRD-specific supply chain obligations in more depth, see our methodology guide on structuring third-party governance for CSRD compliance.
How Can You Satisfy All Four Frameworks with a Single Compliance Architecture?
Every one of these four frameworks, despite their different triggers and enforcement mechanisms, is built on the same underlying architecture: a risk assessment that identifies and ranks exposure across the supply chain, a supplier or third-party evaluation process proportionate to that risk, a grievance or whistleblowing mechanism, remediation action where risk materialises, and a monitoring process that keeps all of the above current. A compliance function that builds four separate programmes — one per regulation — ends up running four parallel supplier questionnaires, four separate risk registers, and four separate reporting calendars for what is, in substance, one underlying body of evidence about the same suppliers.
The alternative is a single supplier risk data model, tagged against each framework’s specific thresholds and requirements, that feeds every regulatory output as a formatted export rather than as a separately maintained system. This is precisely where a third-party risk management (TPRM) solution earns its role in the architecture: rather than running parallel evaluations, a TPRM platform centralises supplier identity, risk scoring, certification status, adverse media and sanctions screening, and documentation in one place, then applies the specific lens each regulation requires — French vigilance plan reporting, LkSG risk analysis and remediation records, CSDDD due diligence case files, CSRD-ready ESRS S2 disclosure data — on top of that single evidence base. It also solves the maintenance problem that a purely calendar-driven mapping exercise cannot: supplier risk changes continuously, and a TPRM solution built around event-driven triggers — a change in ownership, a lapsed certification, a new sanctions listing, an adverse media hit — keeps the underlying data current across all four frameworks at once, rather than requiring four separate teams to each rediscover the same change independently.
Marie-Soisick Floc’h, Compliance and Internal Control Mission Lead at the Société des Grands Projets — the French public body overseeing major infrastructure programmes including the Grand Paris Express — describes exactly this shift, in the context of consolidating her organisation’s third-party evaluation process (testimonial translated from the original French): “The solution allowed us to structure our processes, eliminate double data entry, and centralize all documentary information. We gained in traceability, responsiveness during our compliance assessments, and day-to-day efficiency. It’s a genuine change of posture for our organisation, with greater visibility over our third parties.” The specific compliance regime behind that quote is the French anti-corruption law Sapin II rather than one of the four supply chain frameworks mapped in this article, but the underlying discipline — one third-party data model instead of parallel, duplicated evaluations — is exactly what running four overlapping supply chain regimes on a single architecture requires. What a TPRM solution does not do is make the underlying regulatory judgment calls; classification of a supplier as high-risk under CSDDD, or the decision to accept a remediation plan under the LkSG, remains a decision for the compliance function, exercised on evidence the platform has organised rather than replaced.
What Should Companies Outside Direct Scope Do Now?
Scope narrowing at the EU level does not mean the pressure disappears for smaller companies — it relocates. A company that falls below all four thresholds discussed here will still be asked for supply chain data by any customer that remains in scope of the French law, the LkSG, the CSDDD or the CSRD, because each of those regimes requires the in-scope company to assess risk across its own value chain regardless of the size of the supplier at the other end. The CSRD’s value chain cap, introduced by Omnibus I, limits how much a reporting company can demand from suppliers with 1,000 employees or fewer — but it does not eliminate the request, it standardises it around the forthcoming VSME voluntary standard.
For a company outside direct scope today, the practical read is not to wait until it crosses a threshold before building proportionate readiness — the far more common trigger, in practice, is a customer’s due diligence questionnaire arriving well before the company itself would ever be directly regulated. Building the same underlying architecture described above — a documented risk assessment, a proportionate evaluation process for higher-risk relationships, a grievance channel, and a record of what changed and when — early and at a scale appropriate to the company’s own size means that when a large customer’s compliance team eventually asks, the answer already exists rather than needing to be assembled from scratch under deadline pressure.
See where your organisation stands across all four frameworks
Explore how Aprovall supports Legal and Compliance teams, or talk to our team directly.
These articles might interest you
-
05 March 2026Scope3 CSRD: Why Procurement Must Lead Supplier ESG Data CollectionRèglementationScope3 CSRD: How to Industrialise Supplier ESG Data in Source-to-Pay Scope3 CSRD forces organisations to collect ESG and emissions data outside their perimeter—across hundreds or thousands of suppliers—while meeting audit-ready traceability expectations. Procurement is best placed to industrialise collection through onboarding, contracts, and recurring supplier governance, improving data quality over time without creating supplier fatigue. […]Read more
-
05 August 2026CSRD Supply Chain Compliance After Omnibus I: What Auditors Will Actually CheckRèglementationIn short CSRD supply chain reporting now applies to a narrower set of companies after Omnibus I, but the evidentiary bar for those still in scope hasn’t dropped. This piece covers what changed, what ESRS actually requires from supply chain data, the four things a limited assurance auditor checks, and a 5-step roadmap for building […]Read more