Skip to main content

Overview

The Corporate Sustainability Due Diligence Directive (CSDDD, EU 2024/1760) requires large companies operating in the EU to identify, prevent, mitigate, and account for adverse human rights and environmental impacts across their entire supply chain - not just their direct suppliers. The operative word is account for: companies must document that due diligence was conducted, that suppliers were assessed, and that the supply chain can be traced to its origin. That documentation must be audit-ready. ROOTKey provides the cryptographic traceability infrastructure that makes that documentation tamper-evident, multi-party verifiable, and independently auditable.

Scope


CSDDD Due Diligence Obligations and ROOTKey

Obligation 1 - Integrating Due Diligence into Policy

CSDDD requires companies to have a due diligence policy that is updated annually and describes the approach to supply chain assessment. ROOTKey anchors:
  • Policy documents at each version approval - tamper-evident proof that the policy existed and was approved at the stated time
  • Supplier code of conduct documents - verifiable proof of the terms communicated to suppliers

Obligation 2 - Mapping the Supply Chain and Identifying Risks

Companies must identify actual and potential adverse impacts across operations, subsidiaries, and business partners. ROOTKey supports:
  • Anchoring supplier assessment records - proof that assessments were conducted and when
  • Multi-tier supply chain mapping - vaults that span multiple supply chain parties, creating a shared tamper-evident record of the supply chain structure

Obligation 3 - Preventing and Mitigating Adverse Impacts

Where impacts are identified, companies must take preventative and corrective actions and document them. ROOTKey provides:
  • Anchored corrective action plans - proof of what was committed and when
  • Follow-up audit records - immutable evidence that remediation was conducted and its outcome

Obligation 4 - Establishing a Complaints Procedure

Companies must provide a complaints mechanism for affected parties and business partners. ROOTKey can anchor:
  • Complaint receipt records - independently timestamped, preventing dispute over whether a complaint was received
  • Response and resolution records - complete audit trail of the complaints lifecycle

Obligation 5 - Monitoring the Due Diligence Framework

Companies must monitor the effectiveness of their due diligence measures. ROOTKey’s Analytics API supports continuous monitoring of anchoring activity - detecting gaps in coverage that might indicate lapses in due diligence documentation.

Multi-Party Supply Chain Architecture

CSDDD compliance requires documentation that crosses organisational boundaries - your Tier 1 suppliers, their Tier 2 suppliers, and beyond. Traditional documentation systems require trust in each party’s records. ROOTKey vaults can accept anchors from multiple parties, building a shared, tamper-evident chain of custody that no single participant controls: → See also: Supply Chain Traceability use case

Compliance Mapping


Connection to Other EU Frameworks

CSDDD overlaps with other EU supply chain and sustainability obligations:

Request a CSDDD implementation review

We’ll design a multi-party vault architecture tailored to your supply chain topology and CSDDD documentation obligations.

Supply chain traceability use case

Full implementation guide for CSDDD-ready multi-party supply chain traceability.