Executive summary
Due diligence is not a new concept. What the Corporate Sustainability Due Diligence Directive (CS3D)1 introduces is a shift in its purpose: the obligation is no longer to protect organisations from external risk, but to ensure they do not create adverse risk for people and the planet. This carries legal weight, pecuniary penalties and commercial consequences extending well beyond formal scope. Whether directly in scope or operating in the chain of activities of an in-scope company, the considerations in this article are relevant.
CS3D is at the centre of the EU’s regulatory shift. It requires in-scope companies to implement continuous risk-based due diligence from upstream raw material sourcing to downstream distribution, address human rights and environmental impacts, and cascade these obligations within their chain of activities.
The 2026 OECD Responsible Business Outlook2 – the first global assessment of due diligence practices across the 10,000 largest listed companies released earlier this month – quantifies the gap CS3D is designed to close: 45% of practices reported relate to policies and management systems; under 20% relate to identifying or addressing adverse impacts, around half use human rights or environmental criteria to select suppliers, but fewer than 20% assess supplier risk against them, and roughly 70% of social audit programmes reach Tier 1 suppliers only – yet an estimated 78% of forced labour cases occur at Tier 2 and beyond.
CS3D is part of a deliberate regulatory ecosystem that includes the CSRD3, the FLR4, the EUDR5, the EUBR6, the CMR7, the CRMA8, the REACH9, the EU Taxonomy10, and the Whistleblower Directive11, among others.
Treating each obligation as a silo leads to unnecessary duplication of effort. Designing a programme around their common features, with one risk map, one complaints procedure and one monitoring framework that feed multiple regulatory outputs, can be more effective and cost-efficient.
The core of CS3D is a structured due diligence process: embed due diligence into policies and governance; identify and assess adverse impacts across chain of activities; prioritise and take action; provide remediation where harm has occurred; engage with stakeholders throughout; maintain a complaint mechanism; monitor effectiveness; and communicate publicly. These obligations are anchored in a defined list of international human rights and environmental standards set out in the Directive’s Annex.
1. Introduction: ESG due diligence and the regulatory ecosystem
ESG due diligence focuses on environmental, social, and governance risks and impacts. It takes different forms: transactional (M&A, investments, partnerships, where ESG risk informs valuation and deal structuring); portfolio monitoring (ESG screening and integration into financial decisions); or regulatory compliance-driven, where companies must by law identify and manage adverse human rights and environmental impacts across their value chains. CS3D falls in this third category.
Over the past decade, the EU has built a sustainability regulatory architecture. The NFRD12 required large public-interest entities to disclose non-financial information; the CSRD expanded those requirements, introducing mandatory sustainability reporting under the European Sustainability Reporting Standards (ESRS) and the SFRD13 and the EU Taxonomy extended sustainability obligations into financial markets. CS3D built on the UNGP, the OECD Guidelines and the ILO Tripartite14 to make due diligence a legal obligation rather than a voluntary commitment.
These frameworks are designed to interconnect as a regulatory ecosystem that can be read in layers: companies must identify impacts and risks and act (CS3D and sector-specific due diligence regulations), report on how they act with regard to their material impacts, risks and opportunities (CSRD) and effectively communicate (greenwashing regulations), ensure investments are sustainability-aligned (SFDR, EU Taxonomy) and that projects and products meet sustainable objectives, and protect those who report wrongdoing (the Whistleblower Directive).
Each instrument retains its own scope and requirements. A well-designed CS3D programme provides a solid foundation adaptable to multiple compliance targets, generating the data, documentation, and evidence that feeds into CSRD disclosures and demonstrates alignment with EU Taxonomy minimum safeguards. For out-of-scope companies, value chain pressure for traceability may drive voluntary alignment with these principles.
The EU legislative initiative in February 2022 was triggered by fragmentation from divergent national due diligence laws: France had enacted the Loi de Vigilance (2017); Germany, the LkSG (2021), and the Netherlands, Belgium and Austria had advanced draft legislation, each with different scope, thresholds and substantive requirements. Recital 7 of CS3D identifies this as the internal market justification for EU action: divergent national regimes imposed unequal compliance costs and risked distorting competition.
CS3D aims to harmonise that landscape and restore a level playing field. Companies under existing national laws will need to assess how CS3D complements or, where Article 4(1) maximum harmonisation applies, supersedes their existing obligations. Furthermore, under Article 4(2), Member States may adopt more stringent or more specific provisions in areas outside those core articles, including in relation to specific products, services, or situations.
No Luxembourg implementing bill has been introduced as of July 2026. The first draft is not expected before the end of 2026 or early 2027, against an implementation deadline of 26 July 2028 and an application date of 26 July 2029. Luxembourg companies should monitor the designation of the competent supervisory authority, which must be communicated to the EU Commission (EC) by 26 July 2028, while preparing for national implementing measures.
2. Overview of CS3D’s main elements
2.1 Scope and timeline
Following the Omnibus I amendments, CS3D applies to two principal categories of company, subject to a two-consecutive-financial-year condition:
- EU companies meeting one of the following:
i. more than 5,000 employees on average and net worldwide turnover exceeding EUR 1.5 billion
ii. being the ultimate parent of a group exceeding those thresholds on a consolidated basis
iii. being a company or ultimate parent acting as a franchisor or licensor, generating royalties exceeding EUR 75 million in the EU and having net worldwide turnover exceeding EUR 275 million
- Third-country companies
i. meeting equivalent thresholds by reference to EU net turnover: more than EUR 1.5 billion generated in the EU in the preceding financial year;
ii. ultimate parents of groups exceeding those thresholds
iii. being a franchisor or licensor generating royalties exceeding EUR 75 million in the EU and having EU net turnover exceeding EUR 275 million
Holding companies whose primary function is owning stakes in operational subsidiaries, without taking management or financial decisions affecting the group, may apply to the competent supervisory authority to be relieved of the CS3D obligations directly, on the condition that it designates one of its EU-established subsidiaries to fulfil those obligations on its behalf. The parent company remains jointly liable with the designated subsidiary for any failure to comply.
The current timeline is as follows:
- 26 July 2027: Deadline for EC guidelines on CS3D (EC Guidelines) and guidance on voluntary model contractual clauses.
- 26 July 2028: Member State implementation deadline.
- 31 March 2029: Deadline for EC delegated acts specifying the content of the annual communication.
- 26 July 2029: Application date. The full due diligence obligations apply to in-scope companies.
- 1 January 2030: The annual communication obligation applies for financial years starting on or after that date.
- 1 January 2031: Annual statements must be submitted to ESAP.
The window to the 2029 application date is shorter than it appears. Building a due diligence programme across a global chain of activities – from supply chain mapping and risk assessment to policy development and data infrastructure– takes time. Companies using this period for readiness and gap assessments will be better positioned.
2.2 Eight obligations: what CS3D actually requires
CS3D’s due diligence process consists of eight interconnected obligations. Each is continuous and risk-based, not a one-off audit:
- Integrate due diligence into policies and risk management: adopt a due diligence policy covering code of conduct, implementation, and verification, applicable to subsidiaries and direct and indirect business partners, developed in consultation with employees and reviewed at least every 24 months.
- Identify and assess adverse impacts: a two-stage process – scoping using reasonably available information, followed by in-depth assessment of high-risk areas. Information requests to partners are permitted only where necessary and are restricted for partners with fewer than 5,000 employees; industry tools and third-party reports can substitute.
- Prioritise adverse impacts: where simultaneous action is not feasible, prioritise by severity and likelihood. A documented prioritisation rationale can protect against penalties for impacts not yet addressed.
- Prevent potential adverse impacts: take proportionate measures to prevent or mitigate identified risks, using prevention action plans with KPIs and timelines, contractual assurances, financial and operational adjustments, and targeted SME support.
- Bring actual adverse impacts to an end: act through corrective action plans, contractual assurances, and purchasing practice adjustments. Suspension of a business relationship is a last resort, requiring assessment of whether disengagement would cause more harm than it prevents.
- Provide remediation: where the company caused or jointly caused an actual adverse impact, it must restore affected persons, communities, or the environment as far as possible to their pre-impact state. Where the impact is caused solely by a business partner, remediation is voluntary, though the company may use its influence to encourage it.
- Engage meaningfully with stakeholders at four stages: identifying and assessing impacts; developing standard action plans; developing enhanced plans as a last resort; and adopting remediation measures. Industry initiatives supplement but cannot replace direct engagement with employees and their representatives.
- Complaints procedure, notification mechanism, monitoring, and communication: two legally distinct instruments are required: a formal complaints procedure with real procedural weight, open to affected persons, workers’ representatives, and civil society; and a separate notification mechanism allowing anyone to raise concerns anonymously or confidentially. Together they function as an early-warning risk intelligence channel, surfacing issues that may never reach the formal procedure.
2.3 Chain of activities: what’s in scope?
CS3D’s obligations extend across the company’s chain of activities to cover both upstream and downstream operations.
- Upstream: the activities of business partners related to the production of goods or provision of services, including design, extraction, sourcing, manufacture, transport, and storage of raw materials and inputs.
- Downstream: activities of business partners related to distribution, transport, and storage of the company’s products, but only where these are performed for or on behalf of the company. The exclusion applies to distribution, transport and storage of products subject to export controls under Regulation (EU) 2021/821 or to export controls relating to weapons, munitions, or war materials, once the export of the product has been authorised.
In Luxembourg, the companies most likely to be in scope are large industrial and manufacturing groups, logistics operators, and multinationals with significant EU operations. Luxembourg’s financial sector may also meet the thresholds, but the chain-of-activities definition limits their obligations to their own operations and upstream procurement, not to investment portfolios or loan books. The obligations are narrower, but they are not negligible.
Direct business partners (those with a commercial agreement with the company) and indirect business partners (those performing operations related to the company’s products or services without a direct commercial link) are in scope. However, the tools available differ: for direct partners, contractual assurances are the primary mechanism; for indirect partners, companies may seek contractual assurances only where direct measures have proved insufficient. Identifying indirect business partners is significantly more difficult than the CS3D implies.
Company input anticipated in the EC Guidelines consultation (open until 24 July 2026) is expected to confirm that no automated tool maps indirect partners reliably at scale. The most effective mechanism is a contractual flow-down requirement obliging Tier 1 partners to disclose their own upstream relationships as a condition of supply.
2.4 Impacts of Annex I
CS3D anchors its due diligence requirements to a specific set of rights and prohibitions listed in its Annex, which functions as both a constraint and a clarification.
Part I covers human rights, drawing on 16 rights and prohibitions from international instruments. The groupings below illustrate principal supply-chain risks and are not exhaustive. Refer to the full Annex for the complete list:
- Labour rights: forced labour, child labour, the right to freedom of association and collective bargaining, equal remuneration and non-discrimination, and the right to just and favourable conditions of work and an adequate living wage. Relevant in manufacturing and agriculture, among others.
- Physical integrity and personal security: the right to life, the prohibition of torture and cruel, inhuman or degrading treatment, and the right to liberty and security. These address risks from private security forces, unlawful detention of workers and exploitation of migrant workers in high-risk sectors.
- Land rights and livelihoods: the right of individuals, communities and indigenous peoples not to be unlawfully deprived of lands, forests and waters that secure their livelihood. Relevant for extractive industries, agribusiness, and forestry supply chains.
- Environmental rights and health: the prohibition on causing measurable environmental degradation that impairs access to food, water or sanitation, damages health or safety, or adversely affects ecosystems.
Part II covers environmental obligations derived from 16 prohibitions and obligations from approximately 11 international environmental instruments and protocols:
- Biodiversity and ecosystems: the Convention on Biological Diversity, including obligations under the Cartagena Protocol and the Nagoya Protocol. Relevant for pharmaceuticals, cosmetics, agriculture and sectors relying on biological resources.
- Endangered species and wildlife trade: the Convention on International Trade in Endangered Species of Wild Fauna and Flora (CITES). Relevant for companies in food, fashion, pharmaceuticals and luxury goods sectors.
- Hazardous substances and waste: the Minamata Convention, the Stockholm Convention, the Rotterdam Convention, the Montreal Protocol, and the Basel Convention. Relevant across manufacturing, electronics, chemicals and mining.
- Marine and water environments: MARPOL 73/78 and UNCLOS. Relevant for shipping, fisheries and offshore operations.
- Natural heritage and wetlands: the World Heritage Convention and the Ramsar Convention. Relevant for infrastructure, construction and extractive industries operating in or near sensitive natural sites.
Annex I defines the risk universe, telling companies what kinds of impact may constitute an adverse impact triggering their obligations. The risk-based nature of the due diligence process then determines how deeply to investigate, based on where those impacts are most likely to occur and most severe in the company’s specific chain of activities.
2.5 Enforcement and civil liability
Member States must designate supervisory authorities under CS3D. For EU companies, the competent authority is that of the Member State of the registered office; for third-country companies, the competent authority is that of the Member State in which the company has a branch. Where the company has no branch in any Member State or has branches in several different Member States, competence falls to the supervisory authority of the Member State in which the company generated the highest net turnover in the EU in the financial year preceding the last one.
Supervisory authorities have broad investigative powers, including the right to order cessation of infringements, impose penalties and adopt interim measures for imminent risk of severe and irreparable harm.
The maximum pecuniary penalty is 3% of the company’s net worldwide turnover in the financial year preceding the penalty decision or, in the case of in-scope ultimate parent companies of groups, 3% of the net consolidated worldwide turnover of the ultimate parent company in the same reference year. Penalty decisions must be published and remain publicly accessible for at least five years. The EC, in collaboration with Member States, will issue guidelines to help supervisory authorities determine the level of penalties.
Member States must ensure that limitation periods are at least five years and do not begin before the infringement has ceased. The claimant must also know, or be reasonably expected to know, cumulatively: (i) the behaviour and the fact that it constitutes an infringement; (ii) the fact that the infringement caused harm to them; and (iii) the identity of the infringer. Where damage was caused jointly by the company and its subsidiary or a direct or indirect business partner, they are jointly and severally liable, without prejudice to national rules on the conditions of joint and several liability and rights of recourse. Protections provided under the EU Whistleblowing Directive apply to breaches of CS3D.
Under Luxembourg law, directors owe a duty of care assessed against the standard of the reasonably prudent and competent director – an obligation of means, not of result. Fault requires proof that an error was made that a normally prudent director would not have made; mere failure to achieve a desired outcome does not suffice. Breach of a regulatory norm can ground a civil liability claim by individuals harmed, given that rules enacted in the general interest also protect private parties. Once CS3D applies, directors of in-scope companies will face binding due diligence obligations: a total failure to implement the required measures is likely to constitute misconduct in management.
The implementing legislation will also need to designate a competent supervisory authority and determine how CS3D’s civil liability regime, which requires national law to afford victims a right to full compensation with a minimum five-year limitation period, interacts with the existing Luxembourg tort law framework under the Civil Code.
Directors of in-scope companies should therefore not take the deletion of Article 22 by Omnibus I to mean that CS3D is a management-level compliance matter that does not require board engagement. The risk exposure is real: it runs through multiple legal channels and is material.
3. Operational considerations: Building a programme that works
3.1 Start with a gap analysis
Before launching a CS3D implementation programme, every company should assess its readiness. Many already have due diligence elements in place – supplier codes of conduct, human rights policies, environmental management systems, whistleblower procedures or audit programmes. The question is whether these are aligned with CS3D’s specific requirements, cover the right scope, and generate the evidence expected by a supervisory authority.
A structured gap analysis maps existing practices against each of CS3D’s eight obligations, identifies the regulatory perimeter, assesses compliance against related regulations, and provides a starting point for remediation. Early action avoids the costly mistake of building from scratch when key building blocks already exist. For companies that have completed a double materiality assessment (DMA) under CSRD, cross-referencing that output against the CS3D risk map is a useful additional step. OECD analysis of 2025 CSRD disclosures found that the share of companies reporting a significant negative impact consistently exceeds the share treating that issue as a material financial risk – the gap is largest for workers in the value chain (37 percentage points) and water and marine resources (35 percentage points). The adverse impacts most likely to surface in an Annex I assessment are precisely those historically excluded from the financial risk framework.
3.2 Risk mapping: understanding the business model
CS3D’s risk identification methodology is not a compliance checklist.
It is a structured inquiry into where Annex I impacts are most likely to occur and be most severe within a company’s business model and supply chain. Done well, it forces companies to ask questions they should already be asking: where do our materials come from? Who do we buy from, who do they buy from and what are the working conditions? In which geographies do we operate and what does the rule of law look like there?
The scoping exercise is permitted to rely on reasonably available information, meaning that companies do not need to contact every supplier. Public risk databases, sector intelligence, industry multi-stakeholder initiatives, and the company’s own procurement experience count as valid inputs. Recital 39 of Omnibus I clarifies that companies are required to scope general areas, not to systematically identify adverse impacts at entity level.
The in-depth assessment uses the scoping output to focus investigation on where risk is concentrated. Companies may use digital solutions, industry initiatives and third-party verification. Where information is needed from business partners, CS3D limits the ability to demand it: information may only be requested where necessary, and, for partners with fewer than 5,000 employees, only where it cannot be obtained by other means. This is a significant protection for smaller suppliers with direct impacts on how companies design their supply chain questionnaires.
State-imposed forced labour – where the practice arises from national laws or policies rather than from private actors – requires a distinct approach. Traditional on-site audits are unreliable in these contexts: the EC Guidelines on the FLR confirm that assessments must instead draw on desktop research, reports from international organisations and credible civil society data. A scoping exercise anchored in supplier self-assessment risks being structurally blind to it.
The risk map underpins the prioritisation exercise. Not all adverse impacts are weighted equally. CS3D requires prioritisation by severity and likelihood, and explicitly provides that focusing on more severe impacts while deferring less significant ones will not attract penalties. A company that documents its rationale clearly – showing it addressed the highest risks first – is in a far stronger position with supervisory authorities. On indicator design, company submissions anticipated in the EC CS3D Guidelines consultation are expected to show that the most effective sets combine human rights and labour indicators with environmental indicators on a single platform, require documentation rather than self-declaration, and are cross-referenced against the ESRS indicator framework so that the same dataset serves both the CS3D risk assessment and CSRD reporting.
3.3 Supply chain contractual architecture: build smart, not heavy
CS3D’s primary mechanism for extending obligations into the supply chain is the contractual assurance, a commitment from business partners to comply with the company’s code of conduct and, where relevant, its prevention or corrective action plans. The Directive is also explicit that the contractual architecture must be fair, reasonable and proportionate, particularly where business partners are SMEs.
Several principles should guide the design of a supplier contractual framework:
- Risk-proportionate coverage: not every supplier requires the same level of contractual engagement. A Tier 1 supplier of raw materials from a high-risk jurisdiction warrants more intensive contractual requirements and verification than a Tier 2 service provider in a low-risk geography. The risk map drives the contractual architecture, not the other way around.
- Code of conduct and supplier code grounded in Annex I: the code must reflect CS3D’s normative framework of the rights and prohibitions in Annex I in concrete, sector-specific behavioural expectations.
- Verification without over-burden: contractual assurances must be accompanied by appropriate verification that is risk-proportionate and, where possible, consolidated through industry schemes or multi-stakeholder initiatives to avoid duplicative audits. Where SME suppliers are subject to third-party verification, the cost must be borne by the company. The evidence base supports a deliberate weighting towards collaboration over compliance. OECD research finds that investment in supplier capabilities is more consistently associated with sustained improvements in working conditions than codes of conduct, auditing and certification schemes alone, some of which have been shown to have limited effects on worker empowerment. Audit and assurance are complements to supplier support, not a substitute for it.
- Support for SME business partners: companies should offer targeted support where compliance with the code of conduct or action plan would jeopardise the SME’s viability. Company input anticipated in the EC Guidelines consultation (open until 24 July 2026) is expected to identify a systemic problem: SMEs simultaneously receiving multiple inconsistent information requests from different in-scope buyers, each applying different frameworks and terminology. Companies can reduce this burden by standardising requests against the Annex I categories, accepting third-party verification already provided to other buyers, and participating in sector initiatives that pool the due diligence effort.
- Responsible disengagement as a last resort: the suspension provisions are a last resort. Before suspending, companies must assess whether the adverse impacts of suspension would outweigh the harm that cannot be mitigated. Where a company elects to continue a relationship despite identified adverse impacts supervisory authorities will reasonably expect contemporaneous documentation of the comparison made, the improvement milestones set and the conditions under which continuation would no longer be justifiable.
3.4 Complaints procedure and notification mechanism: from compliance requirement to strategic tool
CS3D establishes two distinct instruments. The complaints procedure is an operational-level channel open to employees, value chain workers, affected communities, civil society organisations and trade unions, covering actual or potential adverse impacts. Complainants have follow-up rights, the right to meet with company representatives and are entitled to a written justification if their complaint is deemed unfounded. The notification mechanism allows anyone to raise concerns anonymously or confidentially, without triggering formal procedural obligations. It acts as an early-warning system – a channel for reports that may never surface through the formal complaints route. When well designed, the instruments function together as a primary risk intelligence tool, raising gaps that the risk mapping exercise may have missed.
A single, well-designed complaints procedure satisfies, alongside CS3D requirements, several other instruments:
- EU Taxonomy minimum safeguards: aligns with the OECD Guidelines and UN Guiding Principles on Business and Human Rights, which require operational-level complaints procedures.
- The Whistleblower Directive: secure, confidential reporting channels and anti-retaliation protections for persons reporting breaches of EU law.
- CSRD / ESRS: several ESRS standards require disclosure of impacts identified, grievances and complaints, remediation processes, and corrective measures, making the mechanism a direct input into sustainability reporting.
- The EUBT: mandatory complaints procedure and early-warning risk-awareness system for battery supply chains as part of the operator’s due diligence obligations.
- The CMR: requires that due diligence schemes incorporate complaints procedure align with OECD standard as a condition of recognition.
Beyond their multi-compliance value, these mechanisms serve a core governance function. A system that collects and categorises complaints by ESG topic – aligned with Annex I and CSRD categories – enables companies to establish which adverse impacts are occurring in practice, assess their severity and frequency, escalate material issues to the appropriate governance level, and provide remedy. It also satisfies the EUBR’s mandatory grievance and early-warning risk-awareness system for battery supply chains, and the CMR’s requirement that recognised due diligence schemes incorporate grievance mechanisms. Treated as a risk intelligence tool rather than a formal complaints box, it becomes a core element of the CS3D’s monitoring obligation.
3.5 Governance: accountability without bureaucracy
CS3D demands cross-functional governance: the risk identification exercise requires operational knowledge from procurement, legal/compliance and supply chain; the complaints procedure requires HR and compliance involvement; and monitoring requires data from across the business.
The following governance design principles are worth emphasising:
- Clear accountability at board and management level: directors of in-scope companies face reputational, regulatory, and financial exposure from non-compliance. Boards should have sufficient understanding of the due diligence framework to discharge meaningful oversight, whether from internal experts or external advisors.
- Cross-functional ownership: a cross-functional due diligence committee or steering group drawing on different departments is the natural home for CS3D programme ownership. This group oversees the annual due diligence process, escalates material findings to board level and ensures integration across regulatory workstreams without interfering in previously established tool or process ownership.
- Integration with procurement processes: due diligence cannot be effective unless it is built into all stages of the procurement life cycle. Risk criteria informed by the Annex I framework should be built into supplier questionnaires, approval processes and contract templates. KPIs for supplier sustainability performance belong in procurement scorecards.
- Proportionate data infrastructure: the monitoring obligation requires periodic, qualitative and quantitative assessment of due diligence effectiveness, which requires data. This means adapting existing enterprise resource planning or supplier management platforms or looking into the growing market of purpose-built supply chain due diligence solutions.
- Training and culture: training on the CS3D framework, the Annex I standards, the company’s due diligence policy, and the available tools is not optional. Teams that understand the programme will implement it more effectively.
3.6 Leveraging CS3D across the EU sustainability compliance ecosystem
CS3D sits at the centre of a deliberate regulatory ecosystem, and almost none of the work it requires is new: many elements are already required in similar form by other regulations that apply to the same companies operating in the same supply chains. One qualification applies: CS3D sets the floor, not the ceiling. EUDR and the EUBR override CS3D where they impose stricter or more specific due diligence obligations for particular products. The FLR operates on a different legal logic: it imposes a product prohibition with an obligation of result and runs in parallel to CS3D instead of displacing it. Compliance with CS3D does not satisfy them.
The points of interconnection centre on four themes.
- One chain map, many regulatory outputs. CS3D requires that companies map their chain of activities. That same map could be a starting point for the CSRD’s DMA and the ESRS value chain disclosure requirements; the EUDR’s supply chain traceability and geolocation obligations and the FLR’s identification of product suppliers at the steps of the supply chain closest to forced labour risk. The EUBR and the CMR each require supply chain traceability systems for their respective raw material categories. The underlying exercise is similar for all: know, document and demonstrate the supply chain.
- One risk assessment methodology, four frameworks. CS3D’s risk identification and prioritisation methodology closely mirrors the DMA framework under CSRD. The EUBR’s risk management obligations follow the same OECD-based logic for conflict-affected and high-risk areas. The CMR requires risk-proportionate due diligence using the same OECD Due Diligence Guidance that CS3D references. The FLR directs enforcement towards economic operators based on two distinct criteria: proximity to the stage of production where forced labour is suspected, and leverage, i.e. the ability to effect change in the practices of the entity causing the harm. This targeting logic differs from CS3D’s severity-and-likelihood prioritisation and may point to different actors within the same supply chain.
- One complaints procedure, multiple compliance boxes ticked. A well-designed mechanism simultaneously satisfies CS3D Article 14, the EU Taxonomy minimum safeguards, the Whistleblower Directive, the EUBR, the CMR, and ESRS disclosures. This is no coincidence, as every instrument is anchored to the same OECD and UN international standards.
- One disclosure infrastructure, consolidated reporting. CS3D’s annual due diligence statement is, for companies also subject to CSRD, not a separate publication, it is embedded in the CSRD sustainability report. The EUBR requires an equivalent annual public report on battery due diligence practices. The FLR requires operators to provide supply chain information to authorities on request. The underlying data is similar for all: what is in the supply chain, what risks were identified, what action was taken and what were the outcomes?
One limitation of the integrated approach must be stated directly: CS3D compliance does not create a safe harbour under the other due diligence obligations. The EC Guidelines on the FLR (June 2026) confirm that CS3D due diligence documentation is relevant evidence during an FLR investigation, and that companies may submit it in response to authorities’ information requests, which will cover actions taken to identify, prevent, mitigate or remediate forced labour risks – a category to which CS3D due diligence documentation is directly relevant – but relevance as evidence is not the same as protection from enforcement.
4. Conclusions
CS3D reach extends beyond companies in scope. Any business operating somewhere in the chain of activities of an in-scope company will feel the practical effect of these obligations through contractual assurances, codes of conduct, supplier questionnaires, audits, and corrective action plans. The core message of the Directive is simple: companies of sufficient size and influence cannot be indifferent to what happens in their chains of activities, nor can the businesses that make up these chains.
Several conclusions stand out:
- CS3D is about understanding the business model. The scoping and in-depth assessment requirements are not a compliance audit to outsource to a consultant every five years. They are a structured task for identifying where risks are greatest in the company’s specific supply chain and operations. Companies that take this seriously will gain a clearer understanding of their operational vulnerabilities, which has value beyond regulatory compliance. For companies outside formal scope, the same logic applies in reverse: understanding where you sit in your customers’ and partners’ chains of activities, and what their due diligence programmes will require of you, is a commercial and reputational necessity.
- An integrated approach saves money and produces better results. The connection between CS3D and other frameworks is deep and genuine. The chain of activities map, the complaints procedure, the monitoring framework and the stakeholder engagement strategy all serve multiple regulatory instruments at once. Building a programme around these points in common allows companies to achieve multi-compliance at a lower cost and with a more coherent and defensible result. For companies outside CS3D’s direct scope, many of these same instruments may still apply.
- The Annex I framework defines the standard against which customers’ codes of conduct and contractual assurances will be built. These rights and prohibitions are the starting point for anticipating what in-scope buyers will require of them– the risk-based process determines where they will focus, proportionate to where adverse impacts are most likely and most severe in their specific supply chain.
- Three years to application, with EC Guidelines not arriving until 2027, is a narrower window than it appears. Those that begin a gap assessment now, understand where they stand against CS3D’s requirements and related regulations, and use the preparation period to build their programme systematically will be better positioned than those that wait. Pressure starts early: customers and business partners conducting their own scoping exercises and in-depth assessments will begin requesting information, contractual commitments, and verification evidence well before the 2029 application date. Preparing now is prudent, not premature.
- Civil liability has not disappeared, nor has reputational risk diminished, but neither is confined to companies within formal scope. National civil liability, with minimum five-year limitation periods and a right to full compensation, remains available to victims of adverse impacts. Penalties of up to 3% of worldwide turnover, published and publicly accessible for five years, are a significant deterrent. This enforcement pressure will cascade through the supply chain, as in-scope companies demand traceability. Where in-scope companies face liability for harms caused jointly with a business partner, that liability is joint and several.
Done well, CS3D reshapes the standards that govern responsible business across the supply chain. The most successful companies will treat CS3D as responsible business, not a regulatory obstacle, and invest in lasting compliance.
5. Practical insights from companies
5.1 How to approach a CS3D gap assessment
Insights from companies show that a gap assessment is the right starting point for CS3D readiness: a proactive approach produces a more coherent, defensible and cost-effective programme.
The gap assessment is a structured readiness exercise that indicates where a company stands against each of the eight CS3D obligations and what work remains. The assessment follows four phases, each building on the last:
- Step 1: Identify and prepare perimeter, regulations and existing infrastructure
Confirming which entities and group structures are in CS3D’s direct scope, identifying which related regulations apply and to which parts of the business, and conducting a first-pass map of the company’s business model and chain of activities. A full inventory of all existing policies, processes, systems, and governance structures should also be compiled. The gap analysis is then carried out based on this inventory.
- Step 2: Analyse the outcomes of mapping and requirements
Comparing existing infrastructure against each obligation: for each of the eight CS3D obligations, the analysis asks whether a relevant policy exists, covers the right scope, is reviewed at the required frequency, is owned by an identifiable function, and generates the evidence a supervisory authority would expect. The chain of activities map is then overlaid against the Annex I impact categories to identify where in the supply chain each risk is most likely to materialise. For each obligation, the analysis also checks whether a parallel requirement exists under another instrument and whether the same policy, process, or function could satisfy both.
- Step 3: Evaluate current status
Classifying each obligation and sub-obligation as compliant, partially compliant, or not yet addressed. For each area, the company records the applicable regulatory reference, the current state of the relevant policy, process, system, and function, the specific gap, its severity and urgency, and a preliminary view of the remediation required. Cross-referencing CS3D obligations against parallel requirements makes the integration logic visible and allows leadership to identify which remediation actions serve multiple compliance targets simultaneously.
- Step 4: Convert findings into an action plan
Each identified gap generates a corrective action assigned to a named function, with a target timeline and classified by urgency and severity. The plan should be sequenced logically because later workstreams depend on the outputs of earlier ones. Where companies have these elements in place but they fall short, the remedy is targeted adaptation, not reinvention. Companies that design for multi-regulatory efficiency from the outset will be in a far stronger position than those that treat the exercise as a reason to start from scratch.
5.2 Driving change through regulatory input
CS3D implementation is an ongoing process, not a fixed event. Three parallel workstreams are currently underway, and companies can engage with all three simultaneously: national implementation in each Member State; the EC Guidelines consultation (open until 24 July 2026) to inform the guidelines, and the voluntary and collaborative due diligence schemes that the CS3D recognises as tools for sector-wide implementation.
These provide an opportunity to seek clarity, shape the rules and reduce the uncertainty that currently surrounds several of the Directive’s most impactful provisions. Companies that take advantage of this and provide concrete, evidence- and experience-based input are more likely to see their concerns addressed in guidelines and national law.
In Luxembourg, the Ministry of Economy retains discretion on several points, including the appointment of the supervisory authority, calibration of sanctions, and the interaction between CS3D and existing national frameworks. The Ministry has invited concrete drafting input from companies and their associations on these questions.
The EC Guidelines will govern how companies demonstrate and authorities assess compliance and they are being designed with stakeholder input before any national law takes full effect. This is a window for companies to contribute to the interpretive framework before those concepts are crystallised in enforcement practice.
Companies have consistently flagged, in Luxembourg and at EU level, the following issues:
(i) Risk-based and process-oriented framing. The core due diligence obligations under CS3D are obligations of means, not of result. A company that implements reasonable and proportionate processes, documents its prioritisation rationale and acts in good faith on the information available at the time is not liable simply because an adverse impact persists. This distinction must be reflected in national law and in the explanatory memorandum accompanying the implementing legislation to avoid, in practice, supervisory authorities or courts treating the persistence of an adverse impact as evidence of non-compliance, even where appropriate measures were taken.
(ii) Enforcement architecture. Companies want a guidance-first, process-oriented supervisory model that assesses whether appropriate due diligence mechanisms are in place rather than assuming non-compliance from the persistence of adverse impacts.
(iii) Civil liability. Companies have flagged the need for national implementation to confirm expressly that CS3D establishes process-based obligations of means, not strict or result-based liability, and that existing national tort frameworks apply without procedural expansion.
(iv) Sanctioning design. Companies are seeking, at both national and EU level, a graduated regime that treats good-faith prioritisation decisions, cooperation, and remedial action as explicit mitigating factors, and reserves pecuniary penalties for serious or persistent non-compliance.
(v) Treatment of voluntary frameworks. The EC Guidelines and national implementation need to clarify that participation in voluntary initiatives, certifications or industry schemes carries no binding effect, no evidentiary presumption and no implicit compliance value under CS3D unless formally recognised under the Directive’s own mechanisms. A concern raised repeatedly by companies is that soft-law instruments will be transformed into de facto benchmarks through supervisory practice or litigation before the rules are properly settled.
The broader point is that the compliance framework is still being written, and companies are legitimate participants in that process.
6. Closing observations
CS3D represents a genuine shift in what due diligence means and who it is for: rather than protecting the company from external risk, it ensures the company does not impose adverse risk on people and the planet. The three years to the 2029 application date should be seen as an opportunity for deliberate programme design, not a period to wait out regulatory uncertainty.
The gap assessment is the ideal starting point: it identifies what already exists, maps it against Annex I and the broader regulatory ecosystem, and produces an action plan that can be tracked rather than simply declared.
The regulatory framework itself is still being shaped through national implementation, the EC’s Article 19 guidelines process, and the development of recognised industry schemes, which companies with operational experience and documented compliance positions are well placed to influence.
The best-positioned companies in 2029 will not be those that move fastest, but those that move deliberately. A programme that holds up under scrutiny must rest on a clear understanding of the business model, a rigorous assessment of obligations and existing measures, and a governance structure connecting procurement, legal, compliance, sustainability and the board. The ultimate goal is to be demonstrably compliant.