Ask your compliance data anything. Sienna Insights, now available.
Join the webinar

CSDDD grievance mechanism requirements: what companies need to have in place

Yes, the CSDDD requires in-scope companies to establish a grievance mechanism. This article covers who is now in scope after Omnibus I, the current timeline, and how to build a mechanism that satisfies the directive.

August 5, 2026
5 min read

Yes, the CSDDD requires in-scope companies to establish a grievance mechanism. The EU Corporate Sustainability Due Diligence Directive obliges large companies to set up, or participate in, a notification and complaints procedure that allows affected people and other stakeholders to raise concerns about adverse human rights and environmental impacts across the company's chain of activities. The mechanism must accept complaints, give complainants a way to follow up, and feed into how the company prevents and remediates harm.

What changed in 2026 is who must comply and when, not whether a grievance mechanism is required. Following the Omnibus I simplification package, the directive now applies to a smaller group of the very largest companies, on a later timeline. This article explains the grievance mechanism requirement specifically: who is now in scope, the current timeline, and how to build a mechanism that satisfies the directive rather than just ticking a box.

What changed under Omnibus I (read this first)

A lot of CSDDD content still circulating online describes the original 2024 rules. Those thresholds and dates have been superseded. The Omnibus I Amending Directive (Directive (EU) 2026/470) was published in the EU's Official Journal on 26 February 2026 and entered into force on 18 March 2026.

Scope was narrowed. The directive now targets companies with more than 5,000 employees and more than €1.5 billion in net worldwide turnover, up from the original 1,000 employees and €450 million threshold. Large non-EU companies generating significant turnover within the EU are also captured.

The timeline was pushed back and unified. Member States must transpose the directive into national law by 26 July 2028, and in-scope companies must comply from 26 July 2029. The earlier tiered, phased start dates were replaced with a single application date.

Some obligations were streamlined, including changes to the civil liability regime and the climate transition plan requirement. Review clauses remain, so the Commission can revisit scope and obligations, and the rules may tighten again.

Even with a narrower scope and a 2029 application date, the grievance mechanism requirement is intact, and the practical work of building one takes time. Companies that wait until 2028 to start will be building under pressure.

Who needs a CSDDD grievance mechanism

Three groups should be planning now.

Companies directly in scope, those above the 5,000-employee and €1.5-billion thresholds, must have a functioning notification and complaints mechanism by the 2029 application date.

Companies still covered by national laws. Germany's LkSG, for example, continues to require a complaint procedure for companies with 1,000 or more employees, and other national regimes may apply below the CSDDD thresholds.

Suppliers and business partners of in-scope companies. Even if your own organization sits below the threshold, your large customers will extend grievance and due diligence expectations down their chain of activities through contracts and supplier requirements.

What the grievance mechanism must do

The directive frames the requirement around a notification and complaints procedure. To meet it, your mechanism needs to demonstrate the following.

Accept complaints from the people who are actually affected

The mechanism must be open to people affected by adverse impacts, including workers, communities, and their legitimate representatives such as trade unions and civil society organizations, across the company's own operations, its subsidiaries, and its business partners. That means reaching beyond head office and direct employees into the supply chain.

Be accessible and safe to use

Affected people in supply chains are often vulnerable to retaliation. A compliant mechanism supports anonymous submissions, confidentiality, and protection against retaliation, and it is available through channels and languages that the relevant people can actually use.

Provide follow-up and a fair procedure

Complainants must be entitled to request appropriate follow-up and to meet with company representatives at an appropriate level to discuss the issue. That means secure two-way communication with anonymous reporters and a predictable, documented procedure with clear stages.

Feed into prevention and remediation

A grievance mechanism is not a complaints inbox that ends in an acknowledgment. Information from complaints must inform the company's risk identification, prevention, and, where harm has occurred, remediation. You need to show that grievances were received, assessed, and addressed.

Produce an audit-ready record

To demonstrate compliance, you must be able to evidence what was reported, how it was handled, what was decided, and what changed. That requires a structured, time-stamped record rather than scattered emails and notes.

How to build a mechanism that satisfies the directive

A few principles separate a credible CSDDD grievance mechanism from a paper one.

Reach every tier. Configure intake so concerns can come from direct (Tier 1) and indirect suppliers, communities near operations, and workers without corporate accounts.

Localize properly. Multilingual, multi-channel intake is the difference between a mechanism that gets used and one that doesn't. When your suppliers span continents, language access is a compliance requirement, not a preference.

Standardize case handling. Structured case management gives you the predictability, traceability, and documentation the directive expects, across jurisdictions and supplier tiers.

Turn data into prevention. Trend analysis across suppliers and regions lets you act on systemic issues before they become incidents, and demonstrates the continuous improvement that regulators look for.

Supply chain grievance software brings these elements together in a repeatable system. SpeakUp Report supports anonymous, multilingual intake across more than 100 languages, structured case management across supplier tiers, remediation tracking, and audit-ready reporting, so you arrive at the 2029 deadline with a working mechanism rather than a last-minute build.

Note: this article is a general guide, not legal advice. National transposition of the CSDDD may introduce country-specific variations, so confirm your obligations with qualified legal counsel.

Frequently asked questions

Does the CSDDD require a grievance mechanism? Yes. In-scope companies must establish or participate in a notification and complaints procedure that lets affected people and their representatives raise concerns about adverse impacts in the company's chain of activities, with follow-up and protection against retaliation.

Who is in scope of the CSDDD after Omnibus I? Following the Omnibus I amendments in force from March 2026, the directive applies to companies with more than 5,000 employees and more than €1.5 billion in net worldwide turnover, plus large non-EU companies with significant EU turnover.

When does the CSDDD apply? Member States must transpose it by 26 July 2028, and in-scope companies must comply from 26 July 2029.

Is the grievance mechanism requirement affected by the delay? No. The application date moved, but the requirement to have an effective mechanism remains a core part of the directive. Building one that actually works takes time, so early preparation is advisable.

Table of contents

Share
Subscribe to newsletter
By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share