Press Release | Find My Factory is now Speya™

Press Release | Find My Factory is now Speya™

CSDDD Omnibus I Amendments — What Changed for Procurement in 2026

AW

Adam Wessling

·

8 min read

·

Updated

CSDDD Omnibus I Amendments — What Changed for Procurement in 2026

TL;DR

The Corporate Sustainability Due Diligence Directive (CSDDD) is still law. What changed in December 2025 is the timeline and scope. The Omnibus I amendments pushed the main transposition deadline to July 2028 and primary compliance to July 2029, and narrowed the directive’s direct scope by roughly 70%. But the operational reality has not changed. If you sell to a large EU buyer, you will feel CSDDD indirectly, through cascading compliance requirements, supplier-data requests, and audit documentation your enterprise customers now owe their regulators. This article walks through what changed, what still applies, what your procurement team should do in 2026, and how to prepare without waiting for 2028.

What Omnibus I actually changed

In late 2025 the European Commission finalized a package of amendments known as Omnibus I, which revised several sustainability frameworks including CSDDD, CSRD, and the EU Taxonomy. Three changes matter most for procurement teams.

First, the scope was narrowed. The thresholds for which companies fall under direct CSDDD obligations were raised. Early estimates put the narrowing at around 70% fewer companies in direct scope compared to the original text. Second, the timeline was extended. Transposition into national law is now required by July 2028, and primary compliance obligations kick in from July 2029. Third, several operational requirements were softened. The expectation of full value-chain monitoring has been replaced with a risk-based focus on the most severe adverse impacts in an organization’s own operations and direct suppliers.

None of these changes removed the directive. They delayed it and focused it.

Why mid-market procurement teams should not relax

If your company sits below the raised thresholds, you might assume Omnibus I moved the target off your back. In practice, it did not. Three forces keep mid-market procurement teams squarely inside the compliance envelope.

The first is cascading obligation. Companies that remain in direct scope — large enterprises and EU-listed groups — are legally required to identify and mitigate adverse impacts across their chain of activities. That means their procurement teams will now formally push compliance obligations down to you, their supplier. You will see new supplier questionnaires, new data-access requirements in contracts, new attestation schedules, and new audit windows even if you are not directly regulated.

The second is Member State gold-plating. When EU directives are transposed into national law, several Member States — Germany, France, the Netherlands — have a track record of lowering thresholds below the directive’s floor. The German Supply Chain Act (LkSG) already applies below the CSDDD threshold, and there is no indication it will be relaxed to match Omnibus I. If you export to Germany, you are already in the LkSG envelope.

The third is buyer sophistication. Enterprise procurement teams are not waiting for 2029. Most of them have already started building supplier-due-diligence capabilities to answer their own board and audit pressure. What they build in 2026 and 2027 will be the standard you need to meet.

What CSDDD still requires operationally

The underlying operational shape of CSDDD has not changed. Procurement teams still need to be able to do five things.

1. Governance integration. The directive expects a single accountable owner for due diligence design inside the organization. That person needs to sit high enough to make decisions across procurement, legal, and operations. Anonymous accountability — “the sustainability team owns it” — does not satisfy regulators.

2. Living risk registers. A static annual supplier assessment spreadsheet does not meet the standard. The directive expects ongoing, risk-based prioritization where supplier risk is continuously reassessed based on new information, geography, sector, and specific incidents. This is one of the most expensive operational upgrades for procurement teams that still work in Excel.

3. Preventive measures. Procurement teams must be able to demonstrate what they did to prevent adverse impacts before they happened. Supplier codes of conduct, contractual clauses, supplier training, and supplier data-access requirements all count, but only if there is evidence they are actively enforced.

4. Accessible complaints procedures. A whistleblowing or grievance mechanism must exist and be reachable by anyone in the value chain, including third-party workers at supplier sites. Most procurement teams do not run this today.

5. Audit-ready documentation. The directive does not reward year-end heroics. Regulators expect continuous monitoring and clear evidence trails: what was known, when it was known, what decision was made, and who made it. If your documentation is reconstructed at audit time, you have already failed the standard.

The indirect pressure pattern

The operational pattern most mid-market procurement teams are already seeing works like this. A large EU customer sends a supplier questionnaire that now includes scope-3 emissions data, human-rights incident history at your Tier-2 suppliers, and a request to attest to your own supplier due diligence. The questionnaire is a contract gate — answer it or lose the renewal. You answer it by pulling data from spreadsheets, emailing your own suppliers, and writing best-effort responses for what you do not know.

That pattern is sustainable exactly once. The next time the questionnaire arrives, it will ask for more, and it will ask more precisely. By 2029, the enterprise customers sending those questionnaires will themselves be under direct CSDDD audit, and their attestations will be your attestations.

The procurement teams that win this transition are the ones that stop treating supplier questionnaires as ad-hoc work and start treating them as data queries against a living supplier intelligence system.

What to do in 2026

If you are a procurement leader at a mid-market or enterprise company, a reasonable 2026 agenda looks like this.

Q2 2026 — audit what you have. Inventory every piece of supplier data you hold today. Where does it live? What is the refresh cadence? Who owns each field? Where do your current supplier questionnaires break? You cannot plan the transition until you know the baseline.

Q3 2026 — pick a data spine. You will not meet a living-risk-register standard with spreadsheets. Choose the platform that will own continuous supplier monitoring. This does not need to be a full rip-and-replace of your ERP or procure-to-pay. The smart move for most mid-market teams is an intelligence layer. A system that sits on top of your existing stack and continuously vets, scores, and monitors your supplier base.

Q4 2026 — connect governance. Assign the single accountable owner the directive expects. Draft the supplier code of conduct. Rewrite the standard supplier contract to include data-access and on-site audit clauses.

2027 — operate. Run the intelligence layer in production. Answer supplier questionnaires out of the system, not out of spreadsheets. Start receiving your first continuous-monitoring alerts. Iterate on the contract templates.

2028–2029 — audit readiness. By the time the transposition deadline hits, your procurement team should be able to answer every CSDDD-adjacent question with a timestamp, a source, and a documented decision.

A note on the “millions of suppliers” trap

Several vendors selling into this space market themselves on the size of their supplier database. The larger the number, the better the claim — 120 million suppliers, 200 million, counting higher every year. In a CSDDD context this framing is exactly wrong.

The operational requirement is not to have access to millions of unknown entities. The requirement is to have a defensible, monitored, continuously-vetted shortlist of the specific suppliers your business actually uses. Volume is cognitive load. Curation is compliance. If you are choosing between two supplier intelligence platforms and one markets on size while the other markets on vetting cadence and data freshness, the one marketing on vetting is the one you want for CSDDD work.

“The procurement teams that handle CSDDD well will not be the ones with the biggest supplier database. They will be the ones who can tell you, on demand, which suppliers they actually work with, what they know about each one, when they last verified it, and what they did when a red flag appeared.” — Adam Wessling, CMO, Speya (formerly Find My Factory)

How Speya helps

Speya is an AI-vetted supplier intelligence platform used by European enterprise procurement teams. For CSDDD-adjacent work, three capabilities matter.

First, continuous vetting. Every supplier in the active workspace is re-vetted on a running cadence by AI agents, not by a one-time certification. This maps directly to the living-risk-register requirement.

Second, sourced documentation. Every supplier attribute — compliance status, financial signal, certification, ownership change — has a timestamp and a source attached. When the audit question comes, you do not reconstruct the answer. You export it.

Third, intelligence-layer integration. Speya sits on top of SAP Ariba, Coupa, Ivalua, or whatever your current procurement spine is. The supplier records in your ERP stay canonical; Speya enriches and monitors them. No rip-and-replace.

Book a 30-minute CSDDD readiness review with our team if you want a structured walk-through of your current supplier-data footprint and where the gaps are.

FAQ

Did Omnibus I cancel CSDDD? No. It amended scope and timelines. Transposition into national law is now due July 2028, and primary compliance obligations apply from July 2029. The directive itself remains in force.

Who is still in CSDDD scope after Omnibus I? Scope was narrowed — estimates suggest roughly 70% fewer companies in direct scope. Direct obligations still apply to the largest EU companies and EU-listed groups above the raised thresholds. Mid-market companies below the thresholds face indirect pressure through upstream customer requirements.

Does the German Supply Chain Act (LkSG) go away because of Omnibus I? No. LkSG is a separate German national law with its own thresholds, which are lower than the revised CSDDD thresholds. LkSG obligations continue regardless of CSDDD scope.

What is the difference between CSDDD and CSRD? CSDDD is about action, identifying, preventing, and mitigating adverse human-rights and environmental impacts in your chain of activities. CSRD is about reporting, disclosing how you handle those impacts. Most procurement teams need both, but CSDDD is the operational burden.

Do I need new supplier data tools to comply? You need a data spine that supports continuous monitoring, not static annual assessment. Whether that is a new tool or an upgrade to your existing stack depends on what you have today. An intelligence layer on top of your existing ERP or P2P is usually less disruptive than a full replacement.

When should I start? Now. The 2028 transposition deadline is a legal gate, but the indirect pressure from your enterprise customers is already here and is already escalating. Teams that wait until 2027 will be meeting a higher standard than teams that start in 2026.

About the author. Adam Wessling is CMO at Speya, a European supplier-intelligence platform used by enterprise procurement teams at IKEA, PwC, Deloitte, EY, Ahlsell, and Stark Group. He writes about AI-driven supplier discovery, procurement operations, and European regulatory compliance. Connect on LinkedIn.

Where Speya fits

Compliance starts with the suppliers you consider. Speya screens suppliers for ESG, certifications, and financial health at the point of discovery, so every shortlist already clears your compliance bar, and the data your CSDDD obligations depend on is captured up front rather than chased after the fact. Related: CSDDD.

Authority

Why you can trust this.

Speya runs ESG, certification and compliance screening for enterprise buyers on infrastructure independently audited to ISO 27001 and SOC 2 Type II, hosted entirely in the EU.

Enterprise procurement

IKEA, Roche, Clas Ohlson, Rusta, Ahlsell and STARK Group source with Speya.

Global consultancies

PwC and Deloitte run client sourcing on the platform.

Independently audited

ISO 27001 and SOC 2 Type II, third-party audited.

EU by default

Hosted in the EU. Supplier data never leaves EU borders.

AW

Adam Wessling

CMO of Speya. Over a decade of B2B marketing across SaaS, procurement tech, and enterprise sales.

Last updated

Sourcing, examined.

See how Speya finds, vets, and monitors your suppliers.

Book a demo