For chief risk officers, heads of procurement, sustainability leads and audit committees. The EU Omnibus narrowed and delayed corporate sustainability due diligence. It did not touch the rules that stop goods at the border. This is what changed, what did not, and which controls to keep, stand down or accelerate.
The short answer
Most enterprises read the Omnibus as a reduction in exposure. It is more accurate to read it as a migration of exposure. The obligation that was deferred to 2029 is the one that would have produced a report. The obligations that were not deferred are the ones that produce a detention notice, a customs refusal or an unsellable consignment.
That distinction matters because the two categories fail differently. A reporting failure produces a qualified opinion and a difficult annual general meeting. A market access failure produces a stranded container, a missed delivery window and a contractual penalty, sometimes within days. The second is a revenue continuity risk, and it belongs on the enterprise risk register with an owner, a tolerance and a control, not in the sustainability team's reporting calendar.
For companies that had already built supplier data collection to satisfy CSRD, the practical question is not whether to keep it. It is which parts of it now serve a different and harder purpose.
What the Omnibus actually changed
Omnibus I was adopted by the Council on 24 February 2026 and published in the Official Journal two days later. It amends both the CSRD and the CSDDD. The changes are substantial and, for most companies below the largest tier, decisive.
| Instrument | Scope after Omnibus I | When it applies |
|---|---|---|
| CSDDD (due diligence) | EU companies with more than 5,000 employees and more than €1.5 billion net worldwide turnover. Non-EU companies with more than €1.5 billion turnover generated in the EU. Analysts estimate roughly a 70% reduction in the number of companies covered. | Transposition by 26 July 2028. Application from 26 July 2029. First reports for financial years beginning on or after 1 January 2030. |
| CSRD (reporting) | EU companies with more than 1,000 employees and more than €450 million net turnover. Listed SMEs removed from scope entirely. | New thresholds take effect for financial years starting on or after 1 January 2027. |
Three further changes matter more than the thresholds:
Mapping became scoping. Companies in CSDDD scope no longer map the full value chain. They perform a scoping exercise using information that is already reasonably available, identify the areas where adverse impacts are most likely and most severe, and then assess in depth only those priority areas. Assessment is prioritised toward direct business partners.
Information requests were capped. Requests to business partners must be targeted, reasonable and proportionate. Requesting information from partners with fewer than 5,000 employees is permitted only as a last resort. This was designed to stop obligations cascading down to small suppliers.
The EU-wide civil liability regime was removed, along with the obligation to adopt and put into effect a 1.5°C-aligned climate transition plan. Member States now decide whether non-compliance creates civil liability, which reintroduces the national variation the CSDDD was meant to eliminate.
What it did not change: the rules that stop shipments
The Omnibus reformed directives about how companies report and behave. It did not reform the regulations about which goods may enter or leave the EU market. Those are separate instruments with separate legal bases, and none of them were reopened.
| Rule | What triggers it | Size threshold | Live from |
|---|---|---|---|
| EU Deforestation Regulation (EUDR) | Placing cattle, cocoa, coffee, palm oil, rubber, soy or wood, or listed derived products, on the EU market. Requires a due diligence statement with geolocation of the plot of production. | Applies to all operators. Timing differs by size, not the obligation. | 30 December 2026 for large and medium operators. 30 June 2027 for other micro and small operators. |
| EU Forced Labour Regulation (EU) 2024/3015 | Placing on, or exporting from, the EU market any product made wholly or partly with forced labour at any stage. This is a prohibition, not a due diligence duty. | None. Every product, every sector, any origin, including goods made inside the EU. | 14 December 2027. Commission guidelines were due by 14 June 2026. |
| Carbon Border Adjustment Mechanism (CBAM) | Importing cement, iron and steel, aluminium, fertilisers, electricity or hydrogen. Requires authorised CBAM declarant status and surrender of certificates against embedded emissions. | A single mass-based threshold of 50 tonnes per importer per year. | Definitive regime from 1 January 2026. Certificates purchasable from 2027 and surrendered retroactively for 2026. |
The Forced Labour Regulation deserves particular attention because it is structurally different from everything else on this list. It is an obligation of result rather than an obligation of effort. A company that ran a diligent, well-documented, good-faith due diligence process and still ended up with forced labour in its supply chain has not complied. The product is still prohibited. Due diligence quality affects how likely you are to find the problem first. It does not create a defence once the product is on the market.
EUDR is worth a second look for a different reason. The Commission's July 2026 simplification package adjusted the product scope and improved the information system, and the Commission estimates the package reduces compliance costs by roughly 75% against the original framework. But it explicitly left the core due diligence obligations in place and confirmed 30 December 2026 without further delay. Companies that read "simplification" as "postponement" have now lost a year of preparation time on a rule that requires plot-level geolocation data most procurement functions do not hold.
Why this is an enterprise risk question, not a reporting question
Enterprise risk management earns its place here because the Omnibus changed which risk category these obligations belong to, and most organisations have not moved them.
Before the Omnibus, supply chain sustainability sat in most risk registers as a compliance and disclosure risk. The owner was the sustainability or reporting lead. The consequence was a reporting failure. The control was a data collection exercise timed to the reporting calendar. The tolerance was expressed in terms of data completeness.
After the Omnibus, for the great majority of companies now out of CSDDD scope, that framing describes almost nothing that can actually hurt them. What can hurt them is a consignment that cannot clear customs, a customer that cannot accept delivery because their own due diligence statement fails, or an importer status they did not know they needed. Those are operational and financial risks with different owners, different tolerances and different controls.
There is a second reason to treat this as an ERM problem rather than a sustainability one. Companies below the new CSDDD thresholds are not outside the system. Their in-scope customers still owe risk-based due diligence across the value chain, and those customers will pass the requirement down contractually. The Omnibus capped what large companies may formally request from partners with fewer than 5,000 employees, but it did not stop a buyer from making supplier data a condition of the contract. Smaller suppliers should expect the requests to continue arriving through commercial channels rather than regulatory ones, which means without the proportionality protections the regulation provides.
Keep, stand down or accelerate: a control decision table
This is the judgement most risk functions are being asked to make, and it is the part no single regulatory alert answers, because the answer depends on reading all the instruments together. The table below is MASSIVUE practitioner guidance rather than a legal position, and it assumes a company that built controls in anticipation of the original CSRD and CSDDD.
| Control you may already have | Decision | Why |
|---|---|---|
| Full tier-1 to tier-n value chain mapping | Stand down | Replaced by risk-based scoping on reasonably available information. Full mapping is now disproportionate effort for most in-scope companies and irrelevant for out-of-scope ones. |
| Broad annual supplier ESG questionnaires | Stand down or replace | Low signal, high cost, and the value chain cap discourages them. Replace with targeted evidence requests in the commodity and geography combinations that actually carry exposure. |
| Commodity and country origin traceability for the seven EUDR commodities | Accelerate | Needs plot-level geolocation, not supplier-level attestation. December 2026 is confirmed. This is usually the longest lead-time item in the portfolio. |
| Forced labour screening at supplier onboarding | Accelerate | No size threshold, no sector limit, and no due diligence defence once product is on the market. Screening must be preventive, not periodic. |
| Embedded emissions data for CBAM goods | Accelerate | The definitive regime is already live. Importers over 50 tonnes need authorised declarant status and supplier emissions data now, with certificates surrendered retroactively for 2026. |
| Scope 3 category 1 emissions accounting | Keep | Still required under CSRD for companies over the new thresholds, under ISSB-aligned regimes in Asia, and under California SB 253 from 2027. It also feeds CBAM. |
| Double materiality assessment | Keep, reduce cadence | Retained under CSRD and still the cleanest way to decide where scoping should focus. It does not need annual repetition in stable portfolios. |
| 1.5°C-aligned transition plan implementation | Keep only if it earns its place | The CSDDD obligation to adopt and implement one was removed. Companies in CSRD scope must still report on a transition plan if they maintain one, and lenders and investors continue to ask. |
The pattern is consistent. Controls built for breadth should be cut. Controls built for depth on a narrow set of high-exposure inputs should be funded harder than they were before the Omnibus, not less.
The evidence problem the Omnibus created
The phrase "information that is already reasonably available" is doing an enormous amount of work in the revised CSDDD, and it is a control design instruction disguised as a scope limitation.
Under the original text, a company that failed to identify an impact could point to the difficulty of obtaining data. Under the revised text, the defensible position is that your scoping used the information reasonably available to you. Which means the question a supervisor or a court will ask is not "did you find it" but "what was reasonably available to you, and can you show what you did with it".
That converts the problem from data collection into evidence retention. What was in your procurement system at the time of the decision. What your screening tools returned on that date. What you did when a signal appeared. Companies that generate this evidence as a by-product of transactional systems will be able to answer. Companies that generate it through an annual reporting exercise will not, because the annual exercise has no record of what was known at the moment a supplier was approved.
This is where the case for automation is strongest, and it is narrower than the market usually claims. The value is not in producing a better report. It is in producing a timestamped, queryable record of what the organisation knew and when, across procurement, screening and customs data that currently sit in separate systems. MASSIVUE's AI-Powered Sustainability practice works on exactly this layer, covering ESG data and analytics, automated carbon accounting and emissions tracking, and climate risk and double materiality analysis.
The same pressure outside the EU
Reading the Omnibus as a global retreat from supply chain due diligence would be a mistake. The direction of travel outside the EU is unchanged or tightening.
United States. Enforcement of the Uyghur Forced Labor Prevention Act intensified in 2026. The Department of Homeland Security added 43 companies to the UFLPA Entity List effective 3 August 2026, the largest single expansion since the statute took effect, bringing the total to 187 entities across aluminium, apparel, copper, cotton and tomatoes. Since enactment, US Customs and Border Protection has denied entry to more than 24,300 shipments. There is no de minimis exemption: any traceable input from a listed entity can support detention of an entire shipment. California's SB 253 and SB 261 add climate disclosure with Scope 3 reporting beginning in 2027 for fiscal year 2026 data, although CARB's rules are not yet final and SB 261 enforcement is currently affected by litigation.
Germany. The Supply Chain Due Diligence Act (LkSG) is being narrowed rather than abandoned. The federal government has signalled a 1:1 transposition of the CSDDD, with the LkSG scope expected to narrow from autumn 2026 to companies with at least 5,000 employees and more than €1.5 billion turnover, aligning it with the revised CSDDD ahead of transposition by mid-2028.
Singapore and Asia-Pacific. Climate-related disclosure is being introduced through IFRS-aligned standards, given local effect as SFRS(I) S1 and S2. Straits Times Index constituents report ISSB-aligned climate disclosures from FY2025 and Scope 3 emissions from FY2026. Timelines for other listed and large non-listed companies were extended in 2025, with large non-listed companies now expected to begin from FY2030. The direction is settled even where the dates moved.
The practical consequence for a group operating across these markets is that the strictest instrument sets the design requirement. A single supplier onboarding control designed to satisfy the Forced Labour Regulation and UFLPA together will satisfy most of what else is asked. Building one control per jurisdiction is how compliance costs multiply without reducing risk.
What to do in the first 90 days
A sequence that produces a defensible position rather than a longer project plan.
Weeks 1 to 3. Establish which instruments actually bind you. Test the company against the CSDDD and CSRD thresholds, then, separately, run your product and commodity master against the EUDR commodity list, the CBAM sector list and your import volumes against the 50 tonne threshold. Most organisations discover the binding constraint is not the one their sustainability roadmap was built around.
Weeks 4 to 7. Find the data you do not have. For EUDR this is plot-level geolocation for the relevant commodities. For CBAM it is verified embedded emissions from non-EU producers. For forced labour it is beneficial ownership and site-level visibility beyond tier one in the high-risk sectors. Treat each gap as a lead-time item with an owner and a date, because none of these can be closed in the quarter they are needed.
Weeks 8 to 12. Move the control to the transaction. Put screening and evidence capture into supplier onboarding and purchase order approval rather than a periodic survey. Then rewrite the risk register entries: new owner, new impact measure in revenue at risk, new control, new tolerance. Take the revised entries to the risk committee with the scope test from week 3 attached, so the committee can see what was stood down and why.
The organisations that handle this well tend to share one characteristic: the people doing the work understand both the risk framework and the underlying sustainability subject matter. That combination is unusual, and it is what MASSIVUE Academy's ESG Risk Professional micro-credential is built around, covering double materiality, climate scenario analysis, human rights due diligence and greenhouse gas accounting inside an enterprise risk framework. Teams responsible for the carbon data specifically, including CBAM, tend to need the GHG & Carbon Management Professional micro-credential instead. The full pathway is the Certified ESG Risk Specialist certification.
Sources
- European Union, Omnibus I directive amending the CSRD and CSDDD, published in the Official Journal 26 February 2026, adopted by the Council 24 February 2026. Analysis: Clifford Chance, Omnibus I: the European Union concludes CSDDD and CSRD reforms. cliffordchance.com
- European Commission, Commission updates product scope and tools to support EUDR, 13 July 2026. ec.europa.eu
- European Commission, CBAM definitive regime, applicable from 1 January 2026. taxation-customs.ec.europa.eu
- Regulation (EU) 2024/3015 on prohibiting products made with forced labour on the Union market. In force 13 December 2024, applicable 14 December 2027.
- US Department of Homeland Security, DHS Announces the Addition of 43 Companies to the UFLPA Entity List, 31 July 2026, effective 3 August 2026. dhs.gov
- Accounting and Corporate Regulatory Authority (ACRA) and SGX RegCo, sustainability reporting requirements and revised timelines. acra.gov.sg
- Boston Consulting Group and CDP, Corporates' supply chain Scope 3 emissions are 26 times higher than their operational emissions, 25 June 2024, based on 2023 CDP disclosures. cdp.net
Regulatory position stated as at 19 August 2026. This article is editorial analysis and practitioner guidance, not legal advice. Thresholds, delegated acts and national transposition are still moving in several of these instruments.
Frequently asked questions
Does the Omnibus mean my company no longer has to do supply chain due diligence?
Only if you were in scope of the CSDDD and are now below the new thresholds of 5,000 employees and €1.5 billion turnover, and you place no EUDR commodities, CBAM goods or forced-labour-exposed products on the EU market. For most trading companies at least one of those market access rules still applies, and none of them has a company size threshold in the way the CSDDD does.
If we are below the CSDDD thresholds, will our customers still ask for supplier data?
Yes. Companies still in scope owe risk-based due diligence across their value chain and will pass the requirement down contractually. The Omnibus limits what they may formally request from partners with fewer than 5,000 employees, but a commercial contract term is not a regulatory request, so the proportionality protections in the directive do not apply to it.
Is EUDR delayed again?
No. The Commission's July 2026 package simplified the product scope and the information system but confirmed 30 December 2026 for large and medium operators, with other micro and small operators following on 30 June 2027. The core due diligence obligation, including the geolocation requirement, is unchanged.
What is the difference between the EU Forced Labour Regulation and the CSDDD?
The CSDDD is an obligation of effort: conduct risk-based due diligence and act on what you find. The Forced Labour Regulation is an obligation of result: a product made wholly or partly with forced labour may not be placed on or exported from the EU market, whatever process produced it. Good due diligence improves your chance of finding the problem first. It is not a defence once the product is on the market.
Does CBAM apply to us if we import only small volumes?
Not if your total imports of covered goods stay under the single mass-based threshold of 50 tonnes per calendar year. Above it, you need authorised CBAM declarant status and embedded emissions data from your producers. The threshold is measured on cumulative annual net mass, so companies importing steadily across the year should test it against forecast volumes rather than a single shipment.
Should we still measure Scope 3 emissions?
Yes, if you are above the revised CSRD thresholds, report under ISSB-aligned regimes in Asia-Pacific, or fall under California SB 253, where Scope 3 begins in 2027 for fiscal year 2026 data. There is also an evidential argument: BCG and CDP found that supply chain Scope 3 emissions average 26 times a company's direct operational emissions, so a carbon position built only on Scopes 1 and 2 does not describe the actual exposure.