Home › Insights › Sustainability
Sustainable Supply Chain Management After the 2026 Omnibus
A sustainable supply chain stopped being a values exercise the moment it became a filing obligation, and then in 2026 the obligation moved. The EU's Omnibus package cut the corporate due diligence directive back to the largest companies and pushed it out to 2029, while the deforestation regulation kept a much nearer date. Anyone who built a 2027 programme on the old timetable is now working to the wrong calendar, and anyone who concluded the rules had gone away has read only half the story.
What a sustainable supply chain actually means
Stripped of the language, it is four questions answered with evidence rather than assertion:
- Who is actually in the chain? Not your tier one suppliers, whom you can name, but the sub-suppliers and raw material sources behind them, whom most organisations cannot.
- What harm could plausibly happen there? Forced and child labour, unsafe sites, wage theft, deforestation and land conversion, water stress, hazardous discharge, corruption.
- What are you doing about the most serious risks? Prioritised action, not a questionnaire sent to everyone.
- How do you know it worked? Verification that does not rely on the supplier marking its own homework.
Every regulation in this area is a variation on those four questions. The differences are scope, evidence standard and penalty.
What changed in 2026
The Omnibus cut the due diligence directive back hard
Omnibus I, Directive (EU) 2026/470, was published in the Official Journal on 26 February 2026 and entered into force on 18 March 2026. It amends both the corporate sustainability reporting directive and the corporate sustainability due diligence directive. The changes to CSDDD are substantial:
- Scope thresholds raised to more than 5,000 employees and more than €1.5 billion turnover, which takes the directive from roughly 13,000 companies to roughly 6,000.
- A single application date of 26 July 2029 for every in-scope company, replacing the original staggered timetable.
- Penalties capped at 3 per cent of worldwide turnover.
- The climate transition plan adoption requirement deleted, and the EU-wide civil liability regime removed, leaving liability to national law.
Member states have twelve months to transpose the CSRD-related provisions, so the national detail is still being written. Treat 2029 as the outside date and the transposing national law as the thing to watch.
The deforestation regulation kept a much nearer date
The EU Deforestation Regulation is the near-term problem, and it is the one being under-planned. After a second postponement agreed at the end of 2025, EUDR applies from 30 December 2026 for large and medium operators and traders, with micro and small operators getting until 30 June 2027. In May 2026 the Commission published a simplification review report, updated guidance and FAQs, and a draft delegated act on product scope.
EUDR matters more than its low profile suggests because it is a market access rule rather than a reporting rule. Cattle, cocoa, coffee, oil palm, rubber, soya and wood, and products made from them, cannot be placed on the EU market without a due diligence statement covering geolocation of the plot of land. If you sell into the EU and your product contains any of those commodities, the date is fourteen months closer than the CSDDD date and the consequence of missing it is that the goods do not go.
The UK position did not change
None of this touches UK law. Section 54 of the Modern Slavery Act 2015 still requires a slavery and human trafficking statement from commercial organisations over the turnover threshold, and it is still a transparency duty rather than a due diligence duty: it obliges you to say what you did, including nothing. Our guides to Modern Slavery Act compliance and writing a modern slavery statement cover the mechanics, and UK ESG reporting requirements sets out what else a UK business is already on the hook for.
Out of scope does not mean out of reach
This is the point most commentary on the Omnibus misses. Cutting the directive from 13,000 companies to 6,000 does not remove the obligation from the other 7,000, it moves it into their customer contracts. A company inside the threshold has to conduct due diligence across its chain, and the only practical way to do that is to push obligations down through supplier terms: data requests, audit rights, remediation commitments, termination clauses.
So the realistic question for a mid-sized supplier is not "am I in scope" but "how many of my customers are, and what will they now be asking for". The answer usually arrives as a contract renewal rather than a piece of legislation, and it arrives well before 2029 because large companies build these programmes years ahead.
Building the programme: six steps that work
- Map the chain properly. Tier one from your purchase ledger, then the tier two and raw material picture for your highest-risk categories only. Trying to map everything is how these projects die.
- Risk-assess by category and geography, not by supplier size. A small supplier in a high-risk sector matters more than a large one in a low-risk sector. Sector and country risk indices are the starting point; your own commodity mix is the refinement.
- Set the standard in the contract. A supplier code, audit rights, subcontracting disclosure and a remediation obligation. A code that is published but not contractual is a communications exercise.
- Verify the top tier of risk. Self-assessment questionnaires are a screening tool, not evidence. For the highest-risk suppliers, that means announced and unannounced audits, worker voice channels that do not run through the supplier's management, and document checks.
- Build remediation before you need it. Every serious programme eventually finds something. Deciding in advance what triggers improvement plans and what triggers exit is what separates a real programme from a discovery you then have to bury. Responsible exit matters: cutting a supplier immediately after finding child labour frequently makes the outcome worse for the children.
- Measure and report honestly. Which includes reporting the gaps. See building a compliance programme for the governance wrapper.
Carbon: Scope 3 is a supply chain problem
For most businesses outside heavy industry, the great majority of emissions sit in the value chain rather than in owned operations. That makes carbon accounting a procurement exercise, and it runs into the same wall as everything else: supplier data quality. Spend-based estimates are easy and nearly useless for driving reductions; supplier-specific data is hard and actually works. Start with the suppliers representing the largest share of spend in your most carbon-intensive categories. Our guide to measuring a carbon footprint covers the methodology and creating a net zero plan covers what to do with the answer.
Four ways these programmes fail
- The questionnaire trap. A 90 per cent response rate to a self-assessment questionnaire is a measure of administrative compliance, not of supply chain conditions.
- Audit theatre. Announced audits in jurisdictions where coaching suppliers before an audit is an established business tell you what the supplier prepared, not what happens on a normal Tuesday.
- Buying practices that contradict the code. Demanding a 30 per cent price cut and a shorter lead time, then asking the supplier to certify no excessive overtime, is a contradiction the supplier resolves by lying to you.
- Claiming more than you can show. UK green claims rules bite here, and a sustainability claim about a supply chain you cannot evidence is the easiest enforcement target there is. See how to make green claims and the UK rules on greenwashing.
What to do in the next twelve months
If you sell EUDR commodities into the EU, that is the whole priority: geolocation data, a due diligence statement process and supplier readiness before 30 December 2026. If you do not, the sensible work is unglamorous: know who your suppliers actually are, know which of your customers are inside the CSDDD threshold, and get the contractual architecture in place before a customer hands you theirs. For the wider strategy, start with building an ESG strategy, or return to the E-Business Ethics homepage for the rest of the governance and compliance library.
Frequently asked questions
Is CSDDD still happening after the Omnibus?
Yes, but smaller and later. Omnibus I, Directive (EU) 2026/470, entered into force on 18 March 2026, raised the thresholds to more than 5,000 employees and more than €1.5 billion turnover, and set a single application date of 26 July 2029 for all in-scope companies.
How many companies are still caught by CSDDD?
Roughly 6,000, down from around 13,000 under the original directive. The reduction comes from the higher employee and turnover thresholds introduced by the Omnibus.
When does the EU Deforestation Regulation actually apply?
From 30 December 2026 for large and medium operators and traders, and from 30 June 2027 for micro and small operators, following the postponement agreed at the end of 2025.
Does any of this apply to a UK business?
Not directly, unless you place goods on the EU market or supply a company that does. UK duties are unchanged: section 54 of the Modern Slavery Act 2015 still requires an annual statement from organisations over the turnover threshold.
We are too small to be in scope. Can we ignore it?
No. In-scope customers meet their obligations by pushing requirements into supplier contracts, so smaller suppliers typically feel the rules through a contract renewal rather than through legislation, and usually well before the 2029 date.
What is the biggest practical mistake in supply chain due diligence?
Treating supplier self-assessment questionnaires as evidence. They are a screening tool. For high-risk suppliers you need verification that does not depend on the supplier's own account, including worker voice channels outside the supplier's management.
Sources
- European Commission, Regulation on deforestation-free products, for the scope and obligations.
- European Commission, delay until December 2026 and other developments in EUDR implementation, for the application dates.