Table of Content

CSDDD U.S. Comments: Practical Business Guide 2026

The Corporate Sustainability Due Diligence Directive, commonly known as the CSDDD, continues to reshape how companies approach human-rights and environmental due diligence across corporate operations and supply chains.

For businesses operating across the Atlantic, however, the discussion is no longer limited to the text of the Directive itself.

The U.S. Government has formally raised a series of concerns regarding the reach, implementation and enforcement of the CSDDD, together with related requirements under the Corporate Sustainability Reporting Directive (CSRD). The submission argues that the two frameworks should be considered collectively because of their interoperability and overlap, particularly in sustainability reporting.

Its concerns focus particularly on extraterritorial application, supply-chain due diligence, reporting burdens, penalties, audits, third-party verification and civil litigation. The U.S. position is that certain requirements could create duplicative or conflicting obligations for American businesses and extend EU compliance expectations to companies with only limited connections to the European market.

For compliance teams, the key question is therefore practical:

What do these U.S. comments mean for companies managing CSDDD exposure, and what should businesses be doing now?

This guide translates the main issues into practical compliance considerations.

Important legal context: The U.S. submission represents policy positions and requested changes. It does not itself amend EU law. Directive (EU) 2026/470, adopted on 24 February 2026, amended the CSDDD and CSRD framework and entered into force on 18 March 2026. Businesses should therefore distinguish between current legal requirements, national transposition, future EU guidance and the additional changes requested by the United States.

Why Is the U.S. Government Raising Concerns About CSDDD?

At the heart of the U.S. submission is a concern about regulatory reach.

The U.S. Government argues that companies established outside the EU may face CSDDD and CSRD requirements despite having limited links to the European market. It also highlights differences between EU sustainability reporting concepts and U.S. regulatory approaches, including the EU's use of impact-based and double materiality concepts.

According to the submission, applying European due-diligence requirements to businesses already operating under U.S. corporate governance and supply-chain regulations could lead to duplicated compliance activities and potentially conflicting expectations.

The U.S. Government consequently asks the EU and its Member States to substantially limit reporting and due-diligence obligations on U.S. businesses, restrict certain enforcement measures and favour regulator-led enforcement before private civil claims can proceed.
For companies, this debate matters because it could influence future guidance, enforcement practices, supplier expectations and national implementation.

What Does the U.S. Government Want the EU to Change?

The submission can be translated into seven major business issues.

Area

U.S. position in the submission

Practical issue for businesses

CSDDD scope

Limit requirements affecting non-EU businesses and focus them more closely on EU activities

Determining which entities, activities and supply-chain relationships fall within scope

Supply-chain due diligence

Keep due diligence risk-based and linked more directly to the EU market

Avoiding unnecessary information requests across low-risk or remote suppliers

Regulatory equivalence

Recognise strong third-country regulatory systems and consider presumed compliance

Reducing duplicated compliance processes

Enforcement and fines

Base penalties on EU-derived activities rather than worldwide revenue

Understanding financial exposure and enforcement risk

Verification

Require credible risk before audits and improve oversight of third-party verifiers

Preventing disproportionate audits and unreliable assessments

Litigation

Favour regulator-led enforcement before certain civil actions

Increasing predictability and reducing conflicting interpretations

Net-zero requirements

Do not restore deleted mandatory transition-plan requirements through guidance

Keeping guidance aligned with the adopted legal framework

These proposals are requests by the U.S. Government, not a description of automatically applicable CSDDD exemptions.

1. CSDDD Scope and Extraterritorial Reach

The most significant theme in the document is the scope of the CSDDD.

The submission argues that U.S. companies or subsidiaries could potentially be affected even when they have no physical presence, employees, operations or assets in the EU, particularly through relationships with an EU-headquartered company or another business that falls within the Directive's scope.

It gives the example of a U.S. supplier producing exclusively in the United States for U.S. consumers but potentially receiving CSDDD-related information requests because of its relationship with an EU-connected business.

The United States therefore proposes narrowing the Directive's application and argues that due-diligence obligations should focus on activities and products actually linked to the EU market. It particularly highlights the potential burden on upstream SMEs, producers and farmers that do not intentionally serve EU customers.

Practical takeaway for companies

Do not manage CSDDD scope simply by creating one list of suppliers.

Instead, map:

  • legal entities;
  • EU and non-EU operations;
  • customer relationships;
  • products and services;
  • relevant markets;
  • subsidiaries;
  • direct business partners;
  • relevant upstream relationships; and
  • the connection between individual supply-chain activities and EU business.

The objective is to understand why a particular entity, supplier or activity is being included in a due-diligence process.

That documented scope decision becomes increasingly important when businesses need to justify why some suppliers receive more extensive questionnaires or verification requirements than others.

2. Risk-Based Supply-Chain Due Diligence

The submission repeatedly supports a risk-based approach.

The U.S. Government asks for EU guidance that would recognise jurisdictions with robust governance and supply-chain regulations as presenting negligible risk and proposes the concept of "presumed compliance" for businesses operating under high-quality regulatory systems.

It also suggests that the EU could review third-country laws and standards to determine whether some due-diligence frameworks should be recognised as equivalent.

Separately, the submission states that actions taken under CSDDD should be evidence-based, rely on credible sources and involve consultation with the affected entity.

What a risk-based approach means operationally

For compliance teams, risk-based due diligence should not mean sending the longest possible questionnaire to every supplier.

A stronger operating model is to:

  1. establish a controlled supplier population;
  2. identify relevant regulatory and sustainability risks;
  3. define documented assessment criteria;
  4. categorise suppliers or relationships according to risk;
  5. request information proportionate to that risk;
  6. escalate higher-risk cases for additional evidence;
  7. document why enhanced verification was or was not necessary; and
  8. periodically reassess the risk.

This approach can reduce unnecessary administrative work while improving attention on suppliers, countries, materials, activities or relationships where meaningful risks actually exist.

3. Stakeholder Definitions and Due-Diligence Boundaries

Another issue raised in the U.S. submission concerns the definition of stakeholders.

The document argues that references to individuals or communities that "could be directly affected" may be too broad unless there is a reasonable-foreseeability element. It proposes language that would more closely connect stakeholder status to reasonably expected direct effects.

The submission also calls for greater clarity concerning "net turnover," procedures for changing the relevant supervisory authority and the treatment of upstream relationships in financial services.

Practical takeaway

Businesses should maintain a documented methodology for identifying relevant stakeholders rather than treating stakeholder engagement as an unlimited exercise.

The methodology should explain:

  • which groups are relevant;
  • how potential impacts were identified;
  • the evidence used;
  • how material or credible risks were prioritised; and
  • how engagement activities connect to the identified risk.

This makes stakeholder engagement easier to manage and easier to defend.

4. Avoiding Duplicate Compliance Structures

The U.S. submission argues that an EU subsidiary or EU-based firm should carry responsibility for relevant due diligence and enforcement rather than automatically transferring that responsibility to a third-country parent company.

The stated objective is to avoid duplicative compliance structures.

Even where the final legal allocation of responsibility differs from this proposal, the operational lesson is useful.

Multinational groups should establish clear responsibility matrices showing:

Responsibility

Questions to define internally

Legal scope

Which entity is formally subject to which obligation?

Supplier outreach

Which team sends and follows up questionnaires?

Risk assessment

Who assesses supplier and sustainability risk?

Evidence review

Who validates submitted documentation?

Escalation

Who decides whether further investigation is necessary?

Reporting

Which entity generates or approves regulatory outputs?

Governance

Who signs off on material compliance decisions?

Without clear responsibility, multinational groups can easily duplicate supplier requests, collect conflicting information or maintain several versions of the same evidence.

5. CSDDD Enforcement and Revenue-Based Penalties

Enforcement is another major U.S. concern.

The submission argues that criteria for fines should relate exclusively to revenue generated through activities inside the EU. It objects to references to worldwide turnover because of the potential extraterritorial effect on non-EU companies.

Whether or not this position affects future EU implementation, compliance teams should treat enforcement exposure as a governance issue rather than waiting until an investigation occurs.

Businesses should be able to demonstrate

  • why the company considered itself within or outside a requirement;
  • what risks were identified;
  • which data sources were used;
  • which suppliers were contacted;
  • what evidence was received;
  • how risk was evaluated;
  • which mitigation measures were taken;
  • who approved key decisions; and
  • when the assessment was last reviewed.

The strongest defence against compliance uncertainty is a traceable decision process.

6. Audits, Site Visits and Third-Party Verification

The U.S. Government also calls for verification measures such as audits, site visits and stakeholder engagement to remain proportionate to risk.

Its position is that intrusive verification should be used where credible and documented risks cannot be adequately assessed through less burdensome approaches. The submission particularly objects to automatic on-site audits of upstream suppliers that do not directly supply an EU buyer.

A related concern is the quality of third-party verification bodies.

The document warns that insufficient oversight could result in inaccurate assessments, inconsistent reports, conflicts of interest or assessors without appropriate sector expertise. It therefore calls for detailed EU guidance and suggests that verifiers should be independent, accredited and appropriately qualified.

Practical verification controls

Companies using external verification should establish their own governance rather than automatically accepting every third-party report.

Before relying on a verification report, consider:

  • the verifier's qualifications;
  • independence and potential conflicts;
  • sector-specific competence;
  • assessment methodology;
  • underlying evidence;
  • date and scope of the assessment;
  • whether findings relate to the correct entity, site or product; and
  • how disputed findings can be corrected or escalated.

Third-party verification can support due diligence, but responsibility for managing reliable compliance evidence should remain embedded in the company's own controlled process.

7. CSDDD Litigation and Regulatory Predictability

The submission also addresses civil litigation.

It argues for a more regulator-led approach in which certain civil claims would proceed only after an appropriate supervisory authority had assessed compliance and determined that relevant obligations were not met.

It further proposes that, where civil actions are permitted, plaintiffs should demonstrate a direct connection to harm occurring in or materially affecting the EU. The United States also asks Member States not to create additional procedural routes for litigation.

The broader business concern is predictability.

Companies operating across several Member States need procedures capable of producing consistent, evidence-backed decisions, even when legal interpretations or enforcement approaches develop differently between jurisdictions.

Centralised documentation, version control and clearly recorded decision-making therefore become critical.

8. Net-Zero Requirements and CSDDD Guidance

The final substantive issue in the submission concerns climate-transition requirements.

The U.S. Government asks the EU not to reintroduce mandatory net-zero climate-transition plans through implementing guidance following the deletion of the relevant provision identified in the submission. It also argues that national transposition should not indirectly impose OECD guidance that is not incorporated into the CSDDD.

For companies, this reinforces an important compliance-management principle:

Separate legal requirements from voluntary standards, customer expectations and corporate sustainability commitments.

All may be relevant, but they should not be classified identically.

A mature regulatory register should clearly distinguish:

  • mandatory legislation;
  • implementing and delegated rules;
  • official regulatory guidance;
  • voluntary standards;
  • contractual customer requirements; and
  • internal corporate policies.

That distinction helps prevent both under-compliance and unnecessary over-compliance.

What Do the U.S. CSDDD Comments Mean for Businesses Now?

The U.S. submission should not be interpreted as a reason to stop CSDDD preparation.

It should instead encourage companies to make their compliance processes more precise, proportionate and evidence-based.

The underlying policy debate shows why companies should avoid building rigid compliance systems around one interpretation of a developing regulatory framework.

A stronger approach is to build an operating model that can adapt when:

  • legal scope changes;
  • implementation guidance is published;
  • national transposition develops;
  • enforcement expectations become clearer;
  • supplier risk changes;
  • reporting standards are revised; or
  • equivalent-regime concepts emerge.

As of 2026, the CSDDD framework has already been amended through Directive (EU) 2026/470, demonstrating that regulatory change is not hypothetical.

Practical CSDDD Readiness Checklist for Compliance Teams

The following actions are practical recommendations arising from the issues highlighted by the U.S. submission; they are not themselves requirements stated in that document.

Document which entities, activities, products, suppliers and markets create potential CSDDD exposure.

Do not rely on an undocumented assumption that the entire corporate group or entire global supply chain has identical exposure.

2. Map business relationships and supply-chain connections

Connect suppliers to legal entities, products, components and relevant markets.

This enables the organisation to explain why a supplier is inside a particular assessment perimeter.

3. Establish a documented supplier-risk methodology

Define criteria before assessing suppliers.

Risk factors may include geography, activity, sustainability exposure, previous findings, documentation quality, supplier responsiveness and the nature of the business relationship.

4. Make supplier requests proportionate

Avoid collecting information simply because it might be useful someday.

Each questionnaire should have a defined regulatory or risk-management purpose.

5. Centralise due-diligence evidence

Keep supplier responses, risk assessments, supporting documents, follow-up correspondence, verification findings and decision records together.

Scattered evidence is difficult to defend during audits or regulatory reviews.

6. Establish escalation rules

Define when incomplete information, conflicting evidence or elevated risk should trigger:

  • additional documentation;
  • management review;
  • specialist assessment;
  • independent verification;
  • corrective action; or
  • an on-site assessment.

7. Evaluate third-party verification quality

Maintain criteria for selecting and reviewing external assessors and record why their conclusions were accepted or challenged.

8. Separate EU requirements from other obligations

Companies operating globally should map overlapping U.S., EU, national, customer and voluntary obligations rather than treating each new framework as a completely separate project.

9. Maintain version-controlled regulatory monitoring

CSDDD implementation is evolving.

Your compliance process should record not only what the company decided, but which version of the legislation or guidance informed that decision.

10. Keep management reporting decision-ready

Leadership should be able to see:

  • which entities are potentially in scope;
  • where material risks exist;
  • which suppliers have responded;
  • which evidence is incomplete;
  • which cases require escalation; and
  • which compliance decisions are approaching review dates.

What the Debate Means for Different Types of Companies

U.S. companies with EU exposure

The U.S. submission is particularly relevant to American companies with EU subsidiaries, customers or supply-chain relationships.

These organisations should map the exact basis of their EU exposure and identify where existing U.S. controls or evidence can potentially support European due-diligence requirements instead of creating duplicate processes.

EU companies sourcing from U.S. suppliers

EU companies should avoid interpreting CSDDD preparation as a requirement to impose identical, unlimited data requests on every supplier.

Risk-based segmentation and documented information needs can help reduce supplier fatigue while improving the quality of evidence collected.

Suppliers and SMEs

Smaller suppliers may receive sustainability questionnaires even when they are not directly regulated in the same way as their customers.

They should establish a reusable evidence package containing relevant corporate, sustainability and supply-chain information so that responses do not have to be rebuilt for every customer request.

Multinational corporate groups

Groups operating across several jurisdictions need one controlled architecture for regulatory mapping, supplier evidence and due-diligence decisions.

Creating separate spreadsheets and questionnaires for every legal framework can increase both workload and inconsistency.

How ComplyMarket Can Support CSDDD and Supply-Chain Due Diligence

The debate surrounding the U.S. CSDDD comments demonstrates a wider challenge: sustainability compliance must remain structured enough to withstand scrutiny while flexible enough to adapt to regulatory change.

ComplyMarket approaches sustainability compliance as a controlled operational process covering regulatory scope, supplier information, traceability, assessment, reporting, audit-ready evidence and continuous monitoring. Its published Sustainability Compliance Management framework specifically includes defining legal and market scope, maintaining regulatory registers, creating structured supplier questionnaires, collecting information systematically, generating status reporting and keeping evidence audit-ready.

Centralise regulatory scope and requirements

A changing CSDDD environment makes static compliance files difficult to maintain.

ComplyMarket supports structured legislation and regulatory-scope management so teams can connect obligations with the relevant markets, entities, products and compliance workflows.

Structure supplier data collection

Instead of managing due-diligence information through disconnected emails and spreadsheets, organisations can use structured supplier questionnaires and repeatable data-collection processes.

This makes supplier engagement more consistent and creates a clearer evidence trail.

Apply risk-based supplier assessment

ComplyMarket's Supplier Risk Assessment capabilities are designed to structure supplier information, assess the reliability of submitted data and help teams focus stronger verification on higher-risk situations rather than treating every supplier identically.

This is particularly relevant to the risk-based implementation principles discussed throughout the U.S. CSDDD submission.

Maintain traceable and audit-ready evidence

Due diligence is stronger when a company can demonstrate how a decision was reached.

ComplyMarket's sustainability compliance approach supports controlled supplier evidence, status monitoring and reporting so compliance teams can move from fragmented documentation toward a more defensible operating model.

Monitor regulatory change

As CSDDD, CSRD and related sustainability requirements evolve, companies need to understand what changed and determine which processes, suppliers or data requirements are affected.

ComplyMarket combines regulatory compliance management, AI-supported compliance identification and risk-assessment capabilities to help organisations manage changing compliance and sustainability requirements across their operations and supply chains.

Build a CSDDD Process That Can Adapt to Change

The U.S. Government's comments highlight important questions about where CSDDD obligations should begin and end, how far supply-chain requests should extend, when verification is proportionate and how enforcement should operate.

Not all of the requested changes will necessarily become part of EU law or guidance.

Businesses therefore should not build their compliance strategy around assumptions about the outcome of the policy debate.

Instead, they should establish a due-diligence system capable of answering five questions at any time:

What applies? What is the risk? What evidence do we have? What action did we take? Can we prove it?

Companies that can answer those questions consistently will be better prepared not only for CSDDD but for the broader shift toward structured sustainability and supply-chain compliance.

ComplyMarket can support organisations in turning regulatory requirements, supplier information, risk assessment and compliance evidence into one structured and scalable sustainability compliance process.

Frequently Asked Questions About the U.S. CSDDD Comments

Are the U.S. Government comments legally binding?

No. The document sets out U.S. Government concerns and requested changes. It does not itself amend CSDDD or create exemptions for U.S. companies.

Do the U.S. comments mean American businesses are exempt from CSDDD?

No. Businesses should determine their obligations according to the applicable EU legal framework, relevant national implementation and their individual circumstances. The submission asks the EU to narrow or modify certain requirements, but those requests should not be treated as existing exemptions.

Why does the U.S. submission discuss both CSDDD and CSRD?

The submission states that the two directives have significant interoperability, complementarity and overlap, particularly in reporting, and argues that concerns relating to them should therefore be considered collectively.

What is the main U.S. concern about CSDDD supply chains?

A major concern is that due-diligence and information requests could extend to upstream producers, SMEs or other businesses with limited or indirect connections to the EU market. The submission therefore advocates a more risk-based and EU-linked approach.

Should companies wait for further CSDDD guidance before preparing?

Waiting creates its own risk. Businesses can already strengthen the underlying capabilities that remain valuable under different implementation scenarios: scope mapping, supplier data management, risk assessment, evidence control, responsibility assignment and regulatory monitoring.

Comments

Leave a comment or ask a question

Loading verification...