From July 2029, some EU companies must run risk-based due diligence across their supply chain. Simvia gives food & beverage teams the structure for supplier, product & origin data to prove CSDDD compliance.
















Supplier and sustainability data sits across disconnected systems
Risk often sits beyond the first tier of the supply chain
Country, commodity, and supplier risks are difficult to link to actual products
Data is spread across 4 systems & email inboxes
Procurement, QA, legal, and sustainability teams each work from their own dataset
What makes CSDDD compliance challenging for food & beverage supply chains
For sustainability teams, CSDDD is more than a legal requirement. It creates an operational challenge across suppliers, origins, commodities, and internal teams.
Map suppliers, countries and commodities
The directive asks for your scope of activities, Simvia gives you that picture based on the data you already have.
Supplier relationships across different tiers
Country, region and origin data
Certifications, declarations, and documents
Producer & traceability data
Assess & prioritise impacts
Rank human rights & environmental risks by severity and likelihood, then decide where to act first.
Risk views by country, region, supplier, and product
Clear prioritisation of high-risk areas
Support for risk-based due diligence decisions
Prevent & mitigate risks
Use existing policies, declarations, certificates, and audits from suppliers first. Request extra evidence only where the gaps are.
Targeted evidence requests with automated reminders
Documentation linked directly to supplier or product
Corrective actions with clear steps & owners
Monitor effectiveness
Give sustainability, procurement, QA, and legal teams a shared view of risks, data gaps, and follow-ups.
Status tracking per supplier & action
Expiring certificates and evidence flagged
Shared view for QA, legal, & sustainability
Document & report due diligence
Keep a clear record of how risks were identified, prioritised, addressed and monitored.
Full audit trail
Reporting-ready views
One evidence base for CSDDD, PPWR, and customer requests
What this means for sustainability teams
Know where human rights and environmental risk sits in your supply chain
Prioritise action by supplier, product, country, and category
Reduce manual evidence collection and supplier follow-up
Align sustainability, procurement, QA, and legal teams
Build a defensible due diligence evidence base
Stay prepared for CSDDD, CSRD, customer requests, and future sustainability requirements
got
questions
Answers to the most asked questions
What is the current status of the CSDDD and should we still prepare for it?
The CSDDD has been revised through the EU's Omnibus I package, and the amended directive entered into force in February 2026. It now applies to EU companies with more than 5,000 employees and more than €1.5 billion in worldwide turnover, and to non-EU companies with more than €1.5 billion turnover in the EU. Member States must transpose it by July 2028, and obligations apply from July 2029. The European Commission's first guidelines on due diligence and risk assessment are due by July 2027.
If your company is in scope, now is the time to build the data foundation. If you're below the threshold, you're still likely to feel it. Companies in scope will send targeted, proportionate requests to their suppliers when they can't find the information elsewhere, and that demand is already moving through food and beverage value chains.
How does CSDDD differ from CSRD and other sustainability regulations we’re already dealing with?
CSRD is about reporting, CSDDD is about action. CSRD requires you to publish sustainability information. CSDDD requires you to identify, prevent, mitigate and account for human rights and environmental impacts across your chain of activities. Both were narrowed by Omnibus I: CSRD now covers companies with more than 1,000 employees and €450 million turnover, and CSDDD covers the very largest companies.
The connection point is supply chain data. Supplier information, country and commodity risk, certificates and audits feed into both CSDDD due diligence and CSRD disclosures. Collect it once, structure it well, and reuse it across frameworks.
How do we conduct effective risk assessments across our supply chain?
Start where risk is most likely to sit. Under the revised CSDDD, you begin with a scoping exercise: use information that's already reasonably available to identify where adverse impacts are most likely and most severe, looking at factors like country, sector, commodity and supplier. Then carry out an in-depth assessment in those priority areas.
The quality of that first scoping step depends on how well your supplier, origin and certification data is structured. Simvia brings that data together, so your team can see where risk concentrates and focus effort where it matters most.
How deep into our supply chain do we need to go for due diligence?
As deep as the risk goes. The final CSDDD doesn't limit due diligence to your direct suppliers. It covers your whole chain of activities, but in a risk-based way. You focus on the areas where adverse impacts are most likely and most severe, wherever they sit in the chain. When risks are equally likely or severe, you can prioritise direct business partners.
For food and beverage companies, that often means looking past tier 1 to origins and producers of high-risk commodities. Having traceability and producer data in place makes that far more manageable.
What are the penalties for not complying with CSDDD
Fines are capped at 3% of a company's net worldwide turnover, or consolidated turnover at ultimate parent level. Each Member State sets its own penalty rules within that cap. The European Commission will issue guidelines to help authorities apply penalties consistently.
Enforcement sits with national supervisory authorities, one or more designated by each Member State. They can investigate on their own initiative or after a substantiated concern from an individual or organisation. They can order a company to provide information, stop an infringement or put it right, and take interim measures when there's a risk of severe harm.
A risk-based approach also counts in your favour. Companies shouldn't be penalised for minor impacts they left unaddressed because they prioritised more severe risks, as long as they can show how that prioritisation was made.
Enforcement starts once obligations apply from July 2029. Supervisory authorities will assess what you did, and they'll also look at whether you can prove it. That's why a clear audit trail matters. Simvia helps you document how risks were identified, prioritised, addressed and monitored, so the evidence is ready when an authority, customer or auditor asks.



