The EU's Corporate Sustainability Due Diligence Directive (CSDDD) isn't a one-size-fits-all mandate. Your compliance path depends on three variables: where you operate, how much revenue you generate in the EU market, and which sectors drive that revenue.
Here's how to determine which track you're on.
The Decision You're Facing
You need to determine if CSDDD applies to your organization, and if so, when and how extensively. Misjudging this could mean either over-investing in unnecessary controls or missing regulatory obligations, leading to enforcement penalties and civil liability.
The directive creates multiple compliance tiers based on employee count, revenue thresholds, and sector risk profiles. Your path determines your due diligence scope, reporting timeline, and third-party assurance requirements.
Key Factors That Affect Your Choice
Geographic Footprint: Are you an EU-domiciled entity, or do you operate from outside the EU but generate revenue in EU markets?
Revenue Threshold: Does your organization exceed €150 million in global or EU-market turnover, or does it fall between €40 million and €150 million?
Sector Classification: Do you operate in manufacturing or wholesale of textiles, leather products, agriculture, forestry, fisheries, extractive industries, or food and beverage? The directive defines these as high-risk sectors where lower revenue thresholds trigger compliance obligations.
Employee Count: Organizations with over 500 employees face different requirements than those with 250-500 employees, even at similar revenue levels.
These aren't abstract policy questions. They determine whether you're building a full Environmental, Social, and Governance (ESG) reporting program with supply chain auditing infrastructure or watching from the sidelines.
Path A: Full-Scope Compliance (€150M+ Threshold)
Choose This Path If: Your EU organization employs over 500 people and generates global turnover exceeding €150 million, or you're a non-EU organization generating €150 million or more annually in the EU market.
What You're Committing To: Comprehensive due diligence across your entire supply chain. You'll conduct supplier audits, perform site visits, review third-party policies, and verify regulatory alignment at each tier. Your grievance mechanisms must handle worker complaints while respecting GDPR Individual Rights protections.
Your reporting obligations go beyond internal documentation. You'll publish annual sustainability reports or maintain publicly accessible online disclosures detailing your due diligence methodology, identified risks, and mitigation strategies. National supervisory authorities will have enforcement jurisdiction.
Technology Considerations: At this scale, manual spreadsheet tracking won't suffice. You need a GRC Platform that can maintain a Data Processing Register for GDPR compliance while simultaneously tracking supplier environmental and human rights risk assessments. Look for systems that support Ongoing Vendor Monitoring with automated risk scoring based on sector, geography, and audit findings.
Competitive Advantage Opportunity: Organizations on this path can differentiate through transparency. If you're already conducting rigorous third-party due diligence for other regulatory programs, integrate CSDDD requirements into existing workflows rather than building parallel processes. Document your methodology rigorously and publish it. Procurement teams at other large organizations increasingly filter suppliers based on ESG reporting maturity.
Path B: High-Risk Sector Compliance (€40M+ Threshold)
Choose This Path If: Your EU organization employs over 250 people with global turnover exceeding €40 million, and at least half that revenue comes from high-risk sectors. The same applies to non-EU companies generating over €40 million in the EU market with half from high-risk sectors.
What You're Committing To: The same due diligence requirements as Path A, but triggered at lower revenue thresholds because your sector carries inherent environmental or human rights risk. If you're manufacturing textiles or operating in extractive industries, you're subject to enhanced scrutiny regardless of total organizational size.
Risk Mitigation Focus: Your sector classification means regulators expect more granular controls. For textile manufacturers, that means tracing labor practices through complex multi-tier supply chains. For extractive industries, it means documenting environmental impact assessments and community engagement protocols.
Don't treat this as a checkbox exercise. Organizations in high-risk sectors face higher reputational exposure when due diligence failures surface. Civil liability provisions mean you could be held responsible for supplier violations you failed to identify through reasonable due diligence.
Business Continuity Integration: Use CSDDD compliance as an opportunity to strengthen your business continuity plans. Identify alternative suppliers now, before you need them. Document which suppliers are critical versus replaceable. Test your ability to shift production or sourcing within 30 days.
This isn't just about regulatory compliance. It's Digital Operational Resilience Testing applied to your supply chain.
Path C: Monitor and Prepare (Below Thresholds)
Choose This Path If: You're below the employee and revenue thresholds, or your revenue doesn't meet the high-risk sector criteria.
What You're Committing To: You're not subject to CSDDD requirements today, but that doesn't mean you're exempt from action.
If you supply organizations on Path A or Path B, expect them to cascade due diligence requirements down to you. Your customers will ask for environmental impact documentation, labor practice certifications, and grievance mechanism evidence. Prepare those materials now.
Track your growth trajectory. If you're approaching the thresholds, start building your due diligence infrastructure 12-18 months before you cross them. Retrofitting supplier audits and grievance mechanisms after you're in scope creates compliance gaps that supervisory authorities will flag.
Competitive Positioning: Organizations below the thresholds can still use ESG reporting as a differentiator. If your competitors aren't publishing sustainability reports, you can capture market share by demonstrating proactive environmental and human rights management. Procurement teams at large organizations increasingly favor suppliers who can demonstrate ESG maturity, regardless of whether they're legally required to do so.
Summary Matrix
| Factor | Path A | Path B | Path C |
|---|---|---|---|
| Revenue Threshold | €150M+ global or EU-market | €40M+ with 50% from high-risk sectors | Below thresholds |
| Employee Count | 500+ (EU entities) | 250+ (EU entities) | Any |
| Due Diligence Scope | Full supply chain | Full supply chain, sector-focused | Voluntary or customer-driven |
| Reporting Obligation | Annual public disclosure | Annual public disclosure | None (but recommended) |
| Enforcement Exposure | National supervisory authorities | National supervisory authorities | Indirect (customer requirements) |
| Technology Need | GRC Platform with ESG modules | GRC Platform with sector-specific controls | Spreadsheet or basic system |
| Timeline to Compliance | Immediate | Immediate | Monitor for threshold approach |
The CSDDD doesn't give you wiggle room on which path applies to you. The thresholds are objective and the penalties for non-compliance include fines, exclusion from public procurement, and civil liability. Know your numbers, classify your sectors accurately, and build your compliance program accordingly.





