← Back to CSDDD Insights
CSDDD and CSRD interplay after Omnibus I: aligned scope, timelines and obligations

CSRD and CSDDD After Omnibus I: Two Directives, One Data Strategy

Generated image

Most of the conversation about Directive (EU) 2026/470 - the Omnibus I amendment - has focused on what each directive lost: fewer companies in scope, softer penalties, longer timelines. That framing misses the more interesting story. Omnibus I didn't just trim two directives; it rewired the relationship between them. The Corporate Sustainability Reporting Directive (CSRD) and the Corporate Sustainability Due Diligence Directive (CSDDD) now operate on different legal clocks, serve different legal purposes, and catch different populations of companies - yet they feed off the same underlying data. Understanding that relationship is the key to building a compliance programme that doesn't duplicate work or leave gaps.

This post focuses on how the two directives interlock after Omnibus I. For the detailed changes to the CSDDD itself, see our post on what Omnibus I changed for the CSDDD. For scope questions, see are you in scope of the CSDDD after Omnibus I?.


The core distinction: report vs. act

Before getting into timelines, it helps to be precise about what each directive actually asks.

The CSRD is a disclosure law. It requires in-scope companies to publish structured sustainability information - covering environmental, social, and governance topics - using the European Sustainability Reporting Standards (ESRS). The output is a report: auditable, standardised, publicly available.

The CSDDD is a conduct law. It requires in-scope companies to do something: identify actual and potential adverse human-rights and environmental impacts across their operations and value chains, take action to prevent or mitigate those impacts, and publish a statement on what they found and did. The output is a process - and evidence that the process ran.

As one analysis puts it, the CSRD tells you to report on sustainability; the CSDDD tells you to act on it. A company can be subject to both, only the CSRD, or neither - depending on its size. That distinction matters enormously for compliance planning, because the two obligations require different governance structures, different data flows, and different timelines.


Two directives, two clocks

Omnibus I - published in the Official Journal on 26 February 2026 as Directive (EU) 2026/470 and in force from 18 March 2026 - amended both directives simultaneously but set them on divergent schedules.

CSRD timeline:

  • Member states must transpose the CSRD-related Omnibus I provisions by 19 March 2027.
  • The revised ESRS (simplified by the Commission, with a delegated act due by 18 September 2026) apply for financial year 2027, meaning the first reports under the new regime land in 2028.
  • Under the amended CSRD, only EU companies with more than 1,000 employees on average and net turnover above €450 million are in scope.

CSDDD timeline:

  • Member states must transpose the CSDDD-related provisions by 26 July 2028 - a full 16 months after the CSRD transposition deadline.
  • Substantive due-diligence compliance is required from 26 July 2029.
  • The first Article 16 website reports (the public due-diligence statement) apply to financial years starting on or after 1 January 2030.
  • Direct CSDDD obligations apply only to EU companies with more than 5,000 employees and net worldwide turnover above €1.5 billion (and equivalent non-EU companies).

The gap between the two clocks is not a drafting accident. It reflects the political reality that CSRD reporting infrastructure - supplier data collection, ESRS-aligned disclosures, limited assurance - was already partially built, while CSDDD due-diligence processes were starting from scratch. Legislators gave companies more runway for the harder behavioural change.

CSRD vs CSDDD: Key Milestones After Omnibus I

The scope gap: who sits between the two thresholds?

The thresholds are not aligned, and that creates a meaningful middle band of companies.

CSRD (after Omnibus I)CSDDD (after Omnibus I)
What it requiresDisclose sustainability data using ESRSConduct due diligence; act on adverse impacts
EU company threshold>1,000 employees AND >€450m turnover>5,000 employees AND >€1.5bn turnover
Transposition deadline19 March 202726 July 2028
Compliance / first reportFY 2027 (reports in 2028)26 July 2029 (Article 16 reports from FY 2030)
PenaltiesSet by member statesCapped at 3% of net worldwide turnover; civil liability under national law
Value-chain data capCompanies <1,000 employees are 'protected undertakings'Due diligence focused on direct (tier-1) business partners

Companies sitting between the two thresholds - say, 2,000 employees and €600 million turnover - face a curious position: they must report on their value-chain sustainability impacts under the CSRD, but they are not directly required to run a CSDDD due-diligence programme. In practice, however, their CSRD reporting will surface exactly the kind of value-chain data that a CSDDD programme would generate. The reporting obligation effectively creates pressure to do the underlying work, even without a formal conduct duty.


How the two directives interlock in practice

1. CSRD reporting creates the evidence base for CSDDD due diligence

The ESRS require in-scope companies to disclose their material sustainability impacts, risks, and opportunities - including across the value chain. That means gathering data on supplier emissions, labour conditions, environmental exposures, and governance practices. This is precisely the information that a CSDDD due-diligence programme needs to identify and assess adverse impacts.

In practice, CSDDD due diligence generates the data that feeds CSRD disclosures - and CSRD disclosures create the audit trail that demonstrates a CSDDD programme is running. The two obligations are not parallel tracks; they are a loop.

2. The value-chain cap applies differently to each directive

Omnibus I introduced a "value-chain cap" under the CSRD: companies with fewer than 1,000 employees are designated "protected undertakings" and have a statutory right to decline information requests that go beyond the voluntary SME sustainability reporting standard. This cap applies to reporting requests - it limits what a CSRD reporter can demand from its smaller suppliers.

The CSDDD's equivalent mechanism works differently. After Omnibus I, due-diligence obligations are focused on direct (tier-1) business partners. For indirect partners beyond tier 1, companies need only engage where they have plausible information suggesting adverse impacts. The cap on CSRD data requests does not prevent a company from seeking contractual assurances from its tier-1 suppliers under the CSDDD - those are separate legal instruments.

This distinction matters for supplier-facing teams. A supplier that successfully invokes the CSRD cap to decline a detailed data questionnaire may still be asked to sign a contractual assurance under a customer's CSDDD programme. The two requests have different legal bases and different limits.

3. The climate transition plan: deleted from CSDDD, retained in CSRD

One of the most discussed Omnibus I changes is the deletion of the CSDDD's requirement to adopt and implement a climate transition plan. That obligation is gone from the conduct directive. But companies subject to the CSRD must still disclose a transition plan under ESRS E1 - if they have one. The reporting obligation survives; the conduct obligation does not.

For companies subject to both directives, this creates an asymmetry: they must report on their transition plan (if they have one) but are no longer legally required to have one. In practice, investor and customer expectations are likely to fill that gap - but the legal architecture has changed.

4. Monitoring cadence: annual vs. periodic

Under the original CSDDD, companies were required to review the adequacy and effectiveness of their due-diligence measures annually. Omnibus I changed that: the minimum review cadence is now at least every five years, with trigger-based reassessments required if there are reasonable grounds to believe measures are inadequate or if significant changes occur.

The CSRD, by contrast, requires annual sustainability reports. This means a company subject to both directives will be publishing annual CSRD disclosures - including value-chain data - while its formal CSDDD review cycle runs on a five-year clock. The annual report will, in effect, surface new information that may trigger an earlier CSDDD reassessment. The two rhythms are linked even if the legal minimums differ.


The indirect reach: why suppliers are pulled in regardless of scope

Even companies that fall below both thresholds are not insulated. In-scope CSDDD companies must obtain contractual assurances from their direct (tier-1) business partners - covering both human-rights and environmental impacts. Those assurances cascade: a manufacturer that sources from a tier-1 supplier must contractually require that supplier to obtain similar assurances from its own suppliers.

Meanwhile, in-scope CSRD companies must disclose value-chain data. To do that, they need data from their suppliers. The CSRD value-chain cap limits how much they can demand from smaller partners, but it does not eliminate the request.

The practical result: most companies of meaningful size in EU supply chains will receive due-diligence questionnaires, contractual assurance requests, or data collection forms from their customers - regardless of whether they are directly in scope of either directive. The question is not whether these requests will arrive, but whether the company has a coherent way to respond to them.

lightbulb Tip

One data foundation, not two. The emissions data, supplier assessments, human-rights risk mappings, and governance records you gather for CSRD reporting are the same inputs your customers' CSDDD programmes will ask for. Build a single, structured data layer — not separate silos for 'reporting' and 'due diligence.' This is the most practical thing a mid-market supplier can do right now, before either directive's compliance clock runs out.


What to do in the gap between the two timelines

The period between now and mid-2029 is not a waiting room. It is the window in which the underlying work - supplier mapping, data collection, risk assessment, contractual frameworks - needs to be built. Here is a practical sequence:

Now -> March 2027 (CSRD transposition)

  • Confirm whether you are in scope of the revised CSRD (>1,000 employees and >€450m turnover at group level).
  • If yes, begin building your ESRS-aligned data collection process, including value-chain data. The simplified ESRS delegated act is expected by September 2026 - watch for it.
  • If no, assess whether your customers are in scope and what data they will need from you. Prepare a standard response pack aligned to the voluntary SME sustainability reporting standard.

March 2027 -> July 2028 (CSDDD transposition)

  • If you are (or expect to be) in scope of the CSDDD, use this window to map your chain of activities, identify high-risk areas, and draft your due-diligence policy. Commission guidelines are expected by July 2027 - these will provide practical implementation guidance before national transposition.
  • Begin integrating contractual assurance language into new and renewing supplier contracts. Waiting until 2029 to start this conversation with hundreds of suppliers is not realistic.
  • Track national transposition in your key member states. The Omnibus I framework is more harmonised than before (member states have less room to gold-plate), but penalty levels and enforcement approaches will still vary.

July 2028 -> July 2029 (compliance date)

  • Finalise your due-diligence programme against transposed national law.
  • Run your first formal periodic assessment of due-diligence measures.
  • Ensure your CSRD reporting and CSDDD documentation are drawing from the same data sources - not maintained as separate systems.

The enforcement picture

One area where the two directives now diverge sharply is enforcement. The CSRD's penalty regime is set by member states (with the directive providing a framework). The CSDDD's Omnibus I amendments cap maximum fines at 3% of net worldwide turnover and - critically - removed the mandatory EU-wide civil liability regime. Civil liability now falls back to national law in each member state, which means the exposure varies significantly by jurisdiction.

The European Parliament's legislative train notes that a review clause in Article 36 of the CSDDD requires the Commission to assess existing enforcement mechanisms by July 2031 - so an EU-wide civil liability framework could return in a future legislative cycle. For now, companies should track national transposition carefully, since penalty structures and enforcement priorities will not be uniform across the EU.


The bottom line

Omnibus I simplified both directives, but it did not simplify the relationship between them. If anything, it made that relationship more important to understand: the two clocks are now out of sync, the thresholds create a meaningful middle band, and the data that feeds one obligation substantially overlaps with what the other requires.

The practical answer is not to run two separate compliance programmes - one for reporting, one for due diligence. It is to build a single, structured data foundation: supplier assessments, emissions data, human-rights risk mappings, contractual assurance frameworks. That foundation serves both directives, satisfies customer requests regardless of which directive is driving them, and positions the company for whatever the next legislative cycle brings.

The gap between 2027 and 2029 is not a pause. It is the preparation window.