Operational notes Regulation

CSDDD: the threshold rises to 5,000 employees, the supplier data stays scattered

7 min read

Close-up black-and-white photograph of a thick rope made of twisted strands, backlit texture
You can see the whole rope. No one can follow a single strand from end to end.

A typical scenario, not our own case. An Italian precision-engineering component manufacturer — a supplier to a large European defence group — receives a sustainability due-diligence questionnaire from the client’s procurement office: working conditions at its own plants, a list of its raw-material suppliers, environmental safety measures. The sales office knows how much it invoices that client. Procurement knows who the direct suppliers of steel and special alloys are. Neither can say, with certainty, whether the subcontractor that carries out the surface treatment follows workplace-safety standards at its own plant, or where the nickel it uses comes from.

Two amendments in two years: the threshold rises to 5,000 employees

Directive (EU) 2024/1760 of 13 June 2024 — the corporate sustainability due diligence directive, known by its acronym CSDDD — was published in the Official Journal of the European Union L 2024/1760 of 5 July 2024. Article 1 sets out the subject matter: obligations regarding “human rights adverse impacts and environmental adverse impacts” affecting companies, their subsidiaries and their business partners in the “chain of activities”. The text as originally adopted, though, is not the one in force today: two directives have since amended it.

The first, Directive (EU) 2025/794 of 14 April 2025 — published in OJ L 2025/794 on 16 April 2025, in force the following day — pushed the transposition deadline and the application dates back by one year, without touching the scope thresholds. The second, Directive (EU) 2026/470 of 24 February 2026 — published in OJ L 2026/470 on 26 February 2026, in force on 18 March 2026, the first package of the so-called Omnibus — rewrote Article 2(1)(a): the directive now covers companies that “had more than 5 000 employees on average and had a net worldwide turnover of more than EUR 1 500 000 000 in the last financial year”. Against the 2024 text — one thousand employees, EUR 450 million — the direct scope shrinks to a far narrower group of companies. The same two directives also rewrote Article 37: Member States transpose by 26 July 2028; the rules apply from 26 July 2029 to all companies in scope, “with the exception of the measures necessary to comply with Article 16”, the annual public statement, which applies for financial years starting on or after 1 January 2030.

Where the data actually sits

A company above the threshold is not answerable only for its own operations: it is answerable for the “chain of activities”, defined in Article 3(1)(g). Upstream, this covers “activities of a company’s upstream business partners related to the production of goods or the provision of services by that company, including the design, extraction, sourcing, manufacture, transport, storage and supply of raw materials, products or parts of products”. Downstream, only the distribution, transport and storage of the company’s own product — not the full end of life — with an exclusion that speaks directly to anyone working for defence: a product “subject to export controls” under the dual-use regulation, or to export controls on weapons, munitions or war materials, stays out. It is the same boundary that shapes dual-use compliance: whatever falls under export control stays outside the chain of activities, everything else does not.

The Omnibus also rewrote how that chain must be examined. The new Article 8(2) sets out a two-step process: first a “scoping exercise, based solely on reasonably available information”, to identify the sectors and geographies where “adverse impacts are most likely to occur and to be most severe”; only then, an “in-depth assessment”. The scoping exercise draws on data that today lives in separate systems inside the lead company: the supplier map by geography and product category sits in procurement; past reports sit in the notification mechanism and complaints procedure of Article 14; country-risk ratings are bought in from an external ESG data provider. None of these systems, on its own, answers the question the scoping exercise asks.

The new paragraph 2a adds a safeguard for smaller suppliers: information is requested from a business partner with fewer than 5,000 employees — which covers almost every mid-sized Italian company — “only when the information cannot reasonably be obtained by other means”, and direct partners are asked first. For the Italian supplier, that means the request lands only once its sector or geography has already been flagged upstream — but once it does land, the data to hand over sits in HR (hours, contracts, workplace safety), in the environmental office — the same documentary logic as Italy’s waste-tracking system —, in the quality archive (third-party audits, certifications) and in the procurement register, with the list of the company’s own raw-material suppliers.

The one piece of data no corporate system holds in full

The piece that is almost always missing is recursive. The chain of activities, by definition, also covers the “indirect business partner” — the one the direct supplier uses in turn, and whom the lead company cannot even name. But no company along the chain holds, in a single system, an up-to-date map of its own second-tier sub-suppliers: who does the surface treatment, where the metal it works comes from, whether that relationship has changed since anyone last asked. It is the same gap already seen with the battery passport, where the verified supply chain for critical raw materials is born at the mine and passes through suppliers the final assembler often cannot even name — the same pattern already told for packaging. Here, though, the gap repeats at every link: every company asked discovers it must, in turn, ask a supplier that has never had to put that data in writing before.

If the lead client’s questionnaire landed on your desk tomorrow morning, how many systems — HR, procurement, quality, environmental — would you need to open to answer it, and how long would it take to find out whether your map of sub-suppliers is still the right one?

See the service · Talk to an engineer

Where we stop

We do not provide legal advice on the duty of due diligence, nor do we determine whether a specific company falls within the Article 2 thresholds: that calculation depends on net worldwide turnover, including on a group basis, and has to be made case by case. Italy’s transposition deadline is 26 July 2028: as things stand, no implementing decree exists to check, and we make no assumptions about its content. On penalties, Article 27(4), as rewritten by the Omnibus, requires that “the maximum limit of pecuniary penalties is set at 3 % of the net worldwide turnover of the company”: that is a harmonised ceiling, not a guaranteed level, and the actual penalty will depend on Italy’s transposing law, which does not yet exist. The scenario in the opening paragraph is a typical model, stated as such: we do not describe how any specific company or supply chain actually operates.

The two axes, applied

Complying. The scoping exercise and the in-depth assessment under Article 8 become, in our system, a control that runs on the client’s documents and systems — supplier map, risk areas, past reports, audits already carried out — with an alert when a direct supplier changes a sub-supplier or when an assessment is no longer backed by the underlying data. The file comes out exportable and dated, ready for the lead client’s request or for the supervisory authority.

Deciding. The same system brings HR, environmental, procurement, quality and supplier archives — including second- and third-tier ones, once mapped — together into a single operating model, on which AI agents execute decisions with a human operator in command: not just answering the questionnaire when it arrives, but knowing in advance which supplier weighs on which client, and where to step in before the request lands. For large enterprises, defence, government and healthcare. Always in two delivery modes: on-premises, on autonomous machines that need no deep integration into the client’s network, or dedicated cloud, with a dedicated VPN and a data centre in Italy — always with shared management.

From the first session, at no cost, comes the dated map of which due-diligence data is already available, which system holds it and who updates it — blank boxes included. It stays yours even if we do not go on together. Talk to one of our engineers.

Sources