The Corporate Sustainability Due Diligence Directive has been through enough amendments, delays and political renegotiations that many companies have quietly stopped tracking it. That’s understandable. Following the Omnibus I changes approved in December 2025, compliance has been pushed to July 2029, and the threshold now sits at companies with 5,000 or more employees and €1.5 billion in global turnover. For a significant portion of businesses that were originally in scope, the immediate pressure has eased. But the question worth asking isn’t whether your legal entity is directly captured. It’s whether your customers are and what that means for you.
If you’re a supplier to an in-scope company, expect those requirements to cascade down via contracts, audit requests, and ESG data demands. That process is already happening. Procurement teams at large brands and retailers are building the frameworks they’ll need to evidence compliance, and they’re asking more of their supplier base in the process.
What the directive actually requires
The CSDDD requires “appropriate measures” proportionate to the severity and likelihood of impacts, the company’s ability to influence the business partner, and the nature of the business relationship. That framing matters. It’s not a checklist. It’s a proportionality test – which means the evidence a company needs to produce depends on the risk profile of the suppliers it’s working with.
The directive expects a risk-based approach that goes beyond Tier 1, covering relevant upstream partners tied to production and certain downstream partners tied to distribution, transport and storage. For companies sourcing from complex, multi-tier supply chains, that’s a significant shift from how most audit programmes currently operate. The practical implication is that periodic scheduled audits, while still necessary, are unlikely to be sufficient on their own. Most failures aren’t about intent — they’re about operating design. A single survey wave produces data, not due diligence. Suppliers change. Risks change. Allegations emerge. Programmes must be built to run continuously.
Where unannounced verification fits
The CSDDD doesn’t mandate unannounced visits by name. What it does require is that companies can demonstrate ongoing, proportionate oversight – not just a point-in-time snapshot taken once a year. For high-risk suppliers, that’s a meaningful distinction.
An unannounced verification visit sits between formal audit cycles. Its purpose isn’t to replace the scheduled programme – it’s to test whether what the audit record shows is still true in the months between visits. Whether corrective actions marked as closed have genuinely been implemented. Whether production is taking place at the declared site. Whether working conditions reflect what the last audit recorded. When regulators, auditors, customers or internal stakeholders ask “show me what you did,” scattered evidence creates delays and credibility risk. Audit readiness requires structured documentation. Verification visits, properly documented, are part of that evidence base.
Managing the visit itself
How an unannounced visit is conducted matters as much as how it’s framed in advance. Experienced verification auditors know that arriving at a site without notice requires a particular kind of professionalism, reading how management responds, knowing which questions to ask when information is slow to appear, and handling an unexpected visit in a way that doesn’t escalate unnecessarily.
The goal isn’t confrontation. It’s assessment. Suppliers that genuinely meet the standards they’ve committed to will generally cooperate with a professional, well-explained verification visit, even one they weren’t expecting. The experience of the auditor conducting the visit is what determines whether that cooperation materialises.
The cascading effect
Even if you’re not directly in scope, the practical effect of CSDDD on your supplier relationships has probably already started. Brands and retailers building compliance frameworks are passing requirements downstream – tighter contract clauses, more frequent data requests, greater scrutiny of audit histories, and in some cases specific requirements around verification between formal audit cycles.
Building that capability now, before it becomes a contractual requirement, puts sourcing teams in a stronger position than scrambling to retrofit it later. The companies that treat CSDDD as a 2029 problem are likely to find it becomes a 2027 customer problem first.
If you’re reviewing how your supplier verification programme is structured in light of CSDDD and equivalent due diligence requirements, speak to our team about where unannounced verification fits and how to prioritise it across your supplier base.