The CSDDD (Corporate Sustainability Due Diligence Directive, Directive 2024/1760) is not about adding another report to your compliance pile. It mandates concrete operational action: map risks across your direct and indirect supplier tiers, prevent and mitigate human rights and environmental harm, and document every step. With the Omnibus I Directive published in the EU Official Journal in February 2026 (COM(2025)80 final), the scope was narrowed to the largest organisations, but the substantive obligations remain unchanged for companies that fall within the threshold.
The question IT and procurement teams are asking today is no longer “do we need to prepare?” but “what technical architecture will automate ESG data collection from hundreds or thousands of suppliers?”. Five approaches are available on the market. They target different company profiles, carry different implementation timelines, and cover different use cases. This comparison puts them side by side to help you choose.
For a full breakdown of CSDDD obligations and the post-Omnibus compliance calendar, see our CSDDD and ERP guide.
What CSDDD Requires from Procurement and IT Teams
The Post-Omnibus Scope
Following the adoption of the Omnibus I Directive, the first wave of companies subject to compliance are those exceeding 5,000 employees and €1.5 billion in global turnover, with a deadline set for 26 July 2028 (sources: CSDDD page on the European Commission website and Directive 2024/1760 on EUR-Lex). Non-EU companies generating more than €1.5 billion in EU territory fall under the same scope and thresholds.
The European Commission estimates that approximately 5,000 companies will be subject to the directive in its post-Omnibus form. For these organisations, penalties can reach 5% of net global turnover for the preceding financial year (Article 27 of Directive 2024/1760). A quantifiable financial risk — not merely a reputational one.
The Four Operational Obligations Your IT Systems Must Cover
The directive structures obligations into four linked processes.
Identify: map significant suppliers across the full value chain scope, including indirect third parties identified as at risk for human rights or environmental issues.
Assess: collect structured ESG data by supplier and produce a risk score covering human rights, working conditions, environmental impact, and business ethics. Assessment is periodic (at minimum annual) and documented.
Prevent and mitigate: trigger corrective action plans when a supplier crosses a critical risk threshold, with tracking and proof of execution.
Document and retain: archive questionnaires, audit reports, action plans, and correspondence for a minimum of five years, and produce an annual due diligence statement.
These four obligations define the functional scope that your ERP module or ESG platform must cover. The five approaches below cover them to varying degrees.
The 5 ERP Approaches to Automate CSDDD Compliance
Approach 1: Native ERP Supplier Management Module with ESG Extension
The major ERP platforms offer configurable supplier qualification functions: SAP S/4HANA with SAP Business Network Sustainability and SAP Ariba Supplier Risk Management, Oracle Fusion Cloud with Supplier Qualification Management in its Procurement Cloud module, and Microsoft Dynamics 365 Supply Chain Management with ISV add-ons via AppSource.
What they cover natively: supplier master data management, configurable qualification questionnaires, certification management (ISO 14001, SA 8000), approval workflows, and configurable risk threshold alerts.
What requires an extension or specific configuration: multi-criteria ESG scoring, indirect tier management (tier 2 and beyond), integration with external country and sector risk databases, and structured production of a due diligence declaration.
Suited to: large groups already deployed on SAP S/4HANA, Oracle Fusion, or Dynamics 365 that want to stay within a single ecosystem and avoid integration breaks. The value of this approach is highest when the ERP already covers end-to-end procurement processes and supplier data is consolidated in a single master repository.
Approach 2: Specialised ESG Platform Connected to the ERP
Dedicated supplier due diligence and ESG rating platforms position themselves as ERP complements. The most widely deployed in Europe include EcoVadis, covering more than 150,000 rated companies in 180 countries (ecovadis.com); IntegrityNext, which offers native SAP connectors and documented CSDDD coverage (integritynext.com); Sedex with its widely adopted SMETA social audit framework across food and retail; and osapiens, which explicitly targets automated CSDDD due diligence (osapiens.com).
What they bring: a database of already-rated suppliers (reducing collection cost), standardised questionnaires recognised by European buyers, comparable scores across suppliers in the same sector, and a “multi-client” model that allows a supplier to respond once for multiple buyers.
What requires integration effort: bidirectional synchronisation with the ERP (supplier records, alerts, workflow triggers) requires an API connector or ETL integration to set up with your technical team or a systems integrator.
Suited to: mid-sized and large companies with 200 to 2,000 significant suppliers, whose procurement ERP is in place but does not natively cover ESG scoring. This approach typically offers the best value-to-implementation-time ratio, particularly for organisations that have not yet deployed a GRC module.
Approach 3: Extended GRC Module with Supplier Due Diligence Workflow
The GRC (Governance, Risk, Compliance) modules within major ERP suites — notably SAP GRC and Oracle Risk Management Cloud — were designed to drive structured compliance processes with audit trails, approval workflows, and regulatory reporting. They can be configured to cover CSDDD supplier due diligence.
What they bring: risk management logic that maps directly to the CSDDD structure (identification, assessment, mitigation, remediation), a native audit trail requiring no additional development, and strong integration with other ERP modules for sharing supplier data and procurement flows.
The main limitation: these modules are designed to drive internal processes, not collect data from external entities. Sending questionnaires to suppliers, automated follow-ups, and response collection require an additional layer — either a supplier portal or an integration with a third-party ESG platform (Approach 2).
Suited to: large groups with a structured compliance function, already using SAP GRC or an Oracle risk module, that want to manage CSDDD within the same tool as their other regulatory obligations. Approach 3 combines well with Approach 2: the ESG platform handles collection, the GRC module handles oversight and audit trail.
Approach 4: iPaaS Platform for Multi-Source Supplier Data Aggregation
For groups running multiple ERPs simultaneously, multiple procurement systems, and suppliers transmitting data in heterogeneous formats (spreadsheets, multiple portals, various APIs), a data integration layer can act as a CSDDD collection hub.
Platforms such as Celonis (process mining and ESG supply chain), MuleSoft, or Informatica enable orchestration of supplier data collection from multiple sources, format normalisation, and feeding of a centralised repository used for scoring and reporting. Celonis offers specific use cases around traceability and sustainability in the supply chain.
What they bring: the ability to process heterogeneous data at scale, end-to-end flow visibility (which data, from which source, at what date), and greater modelling flexibility than native ERP modules.
The main limitation: this approach requires an in-house data team or a specialist integrator. Deployment and maintenance costs are significantly higher than other approaches. It is only relevant when SI heterogeneity is real and structural — not remediable in the short term through ERP consolidation.
Suited to: large international groups running multiple ERPs, with a multi-country supply chain and a data team capable of sustaining the integration over time. Approach 4 is often positioned as a cross-cutting layer, complemented by Approach 2 for supplier-side collection.
Approach 5: Open Source ERP with Custom Development
Odoo and ERPNext offer a supplier management foundation that can be extended through community modules or bespoke development to cover CSDDD requirements: ESG questionnaires, certification management, escalation workflows, per-supplier scoring.
What they bring: zero or low licence cost (Odoo Community), full personalisation flexibility, and an active module ecosystem with a developer community.
What requires specific investment: the native modules do not cover multi-criteria ESG scoring or integration with EcoVadis, IntegrityNext, or osapiens. A development project of three to six months minimum is needed to reach coverage comparable to Approaches 1 or 2. Maintaining these developments over time represents a recurring cost that is often underestimated at project scoping.
Suited to: mid-sized organisations in a preparation phase with a constrained budget and an in-house technical team capable of maintaining custom developments long-term. This approach is better suited to future CSDDD entrants (next wave) than to companies that must be compliant by 2028.
Comparison Table: 5 Approaches at a Glance
| Criterion | App. 1 Native ERP | App. 2 ESG Platform | App. 3 GRC | App. 4 iPaaS | App. 5 Open Source |
|---|---|---|---|---|---|
| Tier 1 coverage | Full | Full | Full | Full | Partial |
| Indirect tier coverage | Partial | Good | Partial | Full | Weak |
| Questionnaire automation | Configurable | Native | Configurable | Custom | Custom |
| ERP integration | Native | Via API | Native | Custom | Native |
| Implementation timeline | 4–9 months | 2–5 months | 4–8 months | 6–12 months | 4–9 months |
| CSDDD coverage | Good | Excellent | Good | Good | Weak without development |
| Dual CSRD use | Partial | Good | Partial | Good | Development-dependent |
Recommendations by company profile:
Large industrial group above 5,000 employees (wave 1, 2028 deadline), already on SAP or Oracle: Approach 1 or 3 depending on whether responsibility sits primarily with the procurement function (Approach 1) or the compliance function (Approach 3). Combining both offers the most complete coverage for groups with separate procurement and compliance structures.
Mid-sized industrial or services company (1,000 to 5,000 employees) with 200 to 800 significant suppliers: Approach 2 as the primary choice, selecting EcoVadis, IntegrityNext, or osapiens according to your sector and desired supplier-side pooling. Implementation timelines are short, CSDDD coverage is directly operational with no custom development.
Multi-ERP group with heterogeneous IT landscape: Approach 4 as a cross-cutting layer for aggregation, complemented by Approach 2 for supplier-side collection. The additional integration cost is justified only when SI heterogeneity is structural.
Organisation in preparation phase with a constrained budget: Approach 5 for core processes (questionnaires, certification management), complemented by a lightweight ESG SaaS subscription for scoring and supplier response pooling.
Supplier Data to Collect and How to Structure It in Your ERP
The 5 Blocks of a CSDDD Due Diligence Questionnaire
The European Commission has not published an official standardised questionnaire at this stage. Templates from major ESG platforms (EcoVadis, IntegrityNext, Sedex) and recommendations from professional organisations such as BSR (Business for Social Responsibility) converge on five structured data blocks.
Block 1 — Identification and location: registered address, countries and regions of operation, contact details for production or service delivery sites. This block determines country risk assessment — one of the key levers of CSDDD scoring.
Block 2 — Human rights and working conditions: child labour policy, working hours and conditions, freedom of association, health and safety policy, current SA 8000 or SMETA certifications.
Block 3 — Environment: ISO 14001 or equivalent certification, waste and chemical substance management policy, available emissions data (relevant for the CSRD Scope 3 interface), compliance with local environmental regulations.
Block 4 — Governance and business ethics: anti-corruption policy and compliance with relevant frameworks (UK Bribery Act, FCPA, or equivalent national legislation), internal whistleblowing mechanisms, ongoing or past legal sanctions.
Block 5 — Subcontracting management: list of significant subcontractors, countries of operation of third parties, policy for monitoring the subcontracting chain and extending ESG requirements to tier 2 suppliers.
Automated Scoring and Workflow Triggers
Once responses are collected, the ERP or ESG platform must calculate a risk score per supplier. This score must be weighted across two dimensions: the supplier’s criticality (purchase volume, operational dependency, exclusivity) and the country and sector risk level. A components supplier in South-East Asia is not assessed against the same alert thresholds as a service provider based within the European Union.
When a supplier falls below the acceptability threshold, the system must automatically trigger three actions: notification to procurement and compliance teams, creation of an action plan with a named owner and a deadline, and — if the risk is classified as critical — a block on new purchase orders until documented remediation is in place. This is the same mechanism as CAPA (corrective and preventive actions) in an ISO 9001 quality system, applied to the ESG scope of the supply chain.
Collection frequency: annual for low- or medium-risk suppliers; semi-annual for high-risk suppliers or those operating in countries with a degraded country risk index.
Avoiding Compliance Silos: CSDDD, CSRD, and EUDR Together
The most common trap is deploying one tool per regulation. A module for CSDDD, another for CSRD, a third for EUDR if you import at-risk raw materials. The result is an archipelago of applications with duplicate supplier data and inconsistent scores across reports.
CSDDD and CSRD: data collected for CSDDD (supplier assessments, ESG indicators, action plans) feeds directly into CSRD’s ESRS indicators — notably ESRS S2 (workers in the value chain) and ESRS E1 (climate change, upstream Scope 3 emissions). A centralised supplier repository avoids double entry and ensures consistency between the CSDDD due diligence statement and the CSRD sustainability report. See our CSRD and ERP guide and our article on Scope 3 supplier data collection for further detail.
CSDDD and EUDR: for importers of timber, cocoa, soy, palm oil, coffee, rubber, or cattle products, the EU Deforestation Regulation (EUDR) imposes geographic traceability of sourcing that connects directly with CSDDD obligations. The same extended supplier record can carry data for both regulations. Our EUDR and ERP guide covers this specific scope.
Omnibus Directive and residual scope: the Omnibus I Directive reduced the mandatory CSDDD scope, but mid-sized companies that now fall outside the threshold may still be asked by CSDDD-bound customers to transmit ESG data. Voluntary compliance remains a commercial argument. Our article on Omnibus and ERP details who remains within which scope after the 2026 reform.
CSDDD Compliance Roadmap Through ERP: 3 Phases
Phase 1 (now to end of 2026): mapping and approach selection
Audit your existing supplier base: how many have a complete address, a reliable country code, a populated industry classification? Calculate your actual CSDDD perimeter: which suppliers are significant by purchase volume or by country/sector risk level? Assess your current ERP against the five approaches described above: which module already exists, what is missing, what project budget is realistic?
This phase produces a functional specification and a data remediation plan for missing fields. It is short (two to three months) and essential for avoiding a mismatched approach at the outset.
Phase 2 (2027): module or platform deployment and pilot campaign
Deploy the selected solution. Configure ESG questionnaires, scoring thresholds, escalation workflows, and follow-up sequences. Launch a pilot campaign with your 50 to 100 most critical suppliers (by purchase volume or risk level identified in Phase 1). Verify that the full cycle works: questionnaire dispatch, response collection, score calculation, alert triggers, action plan creation, and traceability.
Allow four to six months for this phase — more if your ERP requires custom development (Approach 5) or complex multi-source integration (Approach 4). For Approach 2 with EcoVadis or IntegrityNext on an SAP or Oracle ERP with a native connector, the timeline can fall to two to three months.
Phase 3 (2028 and beyond): continuous reporting and indirect tier extension
After entry into application, produce your first annual due diligence statement from system data. Verify consistency with your CSRD report if you are also subject to that directive. Progressively extend scope to tier 2 suppliers identified as at risk during the pilot. Refine scoring thresholds and weighting criteria based on first-cycle feedback.
Further Reading
For a deeper look at supplier mapping and scoring in your ERP, see our complete guide to supplier risk management. For SRM platforms (Ivalua, Jaggaer, SAP Ariba) that complement the procurement stack, our SRM module comparison details available supplier qualification features. For the Scope 3 data angle that links to CSDDD, our Scope 3 and ERP article covers upstream supplier emissions collection and reliability.