Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
CSDDD Compliance for Security and Risk TeamsThird-Party Risk Management
4 min readFor CISOs

CSDDD Compliance for Security and Risk Teams

Your board just asked if your company is ready for the EU's Corporate Sustainability Due Diligence Directive (CSDDD). If you're a CISO or GRC leader, this is now your responsibility.

Scope of This Guide

This guide focuses on the CSDDD's governance, risk, and compliance implications for security and risk functions at EU companies with over 1,000 employees and €450 million in turnover. It details the directive's phased rollout, due diligence obligations, and integration with existing compliance frameworks. Although the directive emphasizes human rights and environmental impacts, its implementation requires the same control architecture, vendor management processes, and evidence collection systems you already use.

Key Concepts and Definitions

Value Chain Due Diligence: Unlike the German Supply Chain Act (LkSG), which limits checks to direct suppliers, the CSDDD demands visibility into both upstream (raw material extraction, component manufacturing) and downstream activities (distribution, storage, disposal). You're responsible for identifying risks throughout the entire chain.

Substantiated Knowledge Standard: The LkSG triggers indirect supplier review only upon receiving credible reports. The CSDDD removes this reactive threshold for companies in scope.

Transformation Plan: Companies with €150 million+ annual turnover must document how they'll contribute to Paris Climate Agreement emission reduction targets. This is a forward-looking commitment requiring monitoring and evidence.

Complaint Mechanism: You must establish an accessible procedure for anyone in your value chain to report concerns, extending your whistleblower program beyond employees to suppliers, their workers, and affected communities.

Requirements Breakdown

The CSDDD structures due diligence as a continuous cycle:

Risk Identification: Map actual and potential negative impacts on human rights and the environment across your value chain. For high-risk industries, focus on serious violations specific to your sector.

Policy Integration: Embed due diligence into corporate policies and management systems. This modifies how procurement, vendor management, and operational risk functions operate.

Preventive and Remedial Measures: Take action to prevent, mitigate, and remedy identified impacts. Document what "appropriate" means in your context.

Monitoring and Control: Continuously verify the effectiveness of your measures. Your control testing program now includes sustainability commitments.

Public Reporting: Publish annual information on how you're fulfilling due diligence obligations. Expect scrutiny from NGOs, investors, and regulators.

Board Oversight: Supervisory and administrative boards must obtain information from management and ensure compliance. Your board reporting cadence changes.

Implementation Guidance

Phase 1: Determine Your Timeline

The directive applies in stages:

  • Three years after adoption: 5,000+ employees and €1,500 million turnover
  • Four years: 3,000+ employees and €900 million turnover
  • Five years: 1,000+ employees and €450 million turnover

Count from the directive's publication in the EU Official Journal, expected in May 2024. Member states have two years to transpose it into national law.

Phase 2: Extend Your Vendor Risk Program

Your existing third-party risk management (TPRM) infrastructure is your foundation. You're already collecting vendor questionnaires, reviewing certifications, and tracking remediation. Now expand the scope:

  • Add human rights and environmental criteria to your vendor risk assessments
  • Map your full value chain, not just Tier 1 suppliers
  • Establish ongoing vendor monitoring for sustainability commitments, not just security controls
  • Build evidence collection for downstream activities (your customers' use of your products)

Phase 3: Integrate With Existing Frameworks

Don't build a parallel compliance program. The CSDDD's structure mirrors what you already do for ISO 27001, SOC 2, or NIST CSF:

  • Risk assessment (ISO 27001 Clause 6.1) → Value chain impact identification
  • Control objectives (SOC 2 CC1.2) → Preventive measures
  • Monitoring and measurement (ISO 27001 Clause 9.1) → Effectiveness verification
  • Management review (ISO 27001 Clause 9.3) → Board oversight

Use your GRC platform's control objective mapping to link CSDDD obligations to existing controls. If you're already maintaining a data processing register for GDPR, you understand the documentation burden.

Phase 4: Expand Your Complaint Mechanism

Your whistleblower hotline likely covers employees and maybe direct vendors. The CSDDD requires accessibility for:

  • Indirect suppliers' workers
  • Communities affected by your value chain
  • NGOs acting on behalf of affected parties

This means multilingual support, external-facing interfaces, and intake processes for non-employees. Review your retaliation protection procedures; they now extend beyond your organization.

Common Pitfalls

Treating This as a Sustainability Initiative: Your ESG reporting team can't own this alone. The CSDDD creates civil liability with a five-year claims period. Trade unions and NGOs can bring claims under certain conditions. This is enterprise risk management.

Stopping at Direct Suppliers: The LkSG trained German companies to focus on Tier 1 vendors. The CSDDD's value chain scope is broader. Your risk universe must expand.

Ignoring Downstream Obligations: You're responsible for how customers use your products. If you manufacture components, you need visibility into final product applications.

Underestimating Documentation Requirements: Annual public reporting, transformation plan evidence, complaint mechanism records, effectiveness monitoring results. Plan for significant evidence collection overhead.

Assuming SME Exemption Means No Impact: If you're below the employee and turnover thresholds, you're still affected as a supplier to in-scope companies. Your customers will push requirements down to you.

Quick Reference Table

Obligation Owner Integration Point Evidence Required
Value chain risk identification Risk/Compliance Vendor risk assessments Impact analysis documentation
Policy integration Legal/Compliance Policy gap analysis Updated policy documents
Preventive measures Procurement/Operations Vendor contracts, SLAs Control implementation records
Complaint mechanism Ethics/Compliance Whistleblower hotline Intake logs, investigation records
Effectiveness monitoring Internal Audit Ongoing vendor monitoring Testing results, metrics
Transformation plan (€150M+ turnover) Sustainability/Risk Scenario analysis Emission reduction roadmap
Board reporting GRC Management review meetings Compliance status reports
Public annual reporting Compliance/Communications ESG reporting Published due diligence report

The CSDDD doesn't require new capabilities. It requires extending the governance, vendor management, and control testing systems you already operate to cover a broader risk universe. Start mapping your value chain now.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like