Asking Suppliers for Data Under CSDDD: What the Omnibus Limits on Information Requests Mean in Practice
The classic compliance reflex is to send a long questionnaire to every supplier and see who answers. After Omnibus I, that approach is harder to defend under the Corporate Sustainability Due Diligence Directive. The amended text narrows who is in scope, replaces exhaustive value chain mapping with a scoping exercise, and limits how much information a company can demand from smaller business partners. This guide explains what changed and how to rebuild supplier data requests around it.
This is a practical summary, not legal advice. Check the final text and your national transposition before you finalise policy.
Who is in scope, and by when
Omnibus I limits CSDDD to very large undertakings: EU companies with more than 5,000 employees and more than EUR 1.5 billion in net worldwide turnover, and non-EU companies with more than EUR 1.5 billion in net turnover generated in the EU (CMS). Administrative penalties are capped at 3% of net worldwide turnover, and the harmonised EU civil liability regime was removed, leaving national law to govern compensation.
The directive entered into force on 18 March 2026. Member States must transpose it by 26 July 2028, and companies must apply it from 26 July 2029 (CMS; Stibbe). The window is long enough that the quality of your data process, not the deadline, is the constraint.
The new limit on information requests
The revised directive restricts information requests to what is necessary and proportionate. For business partners with fewer than 5,000 employees, a company may request only information that cannot reasonably be obtained by other means (Stibbe).
In practice that creates a sequence you should be able to show an authority:
- Start with information you already hold or can reasonably get from public sources, such as certifications, country and sector risk data, and prior audit results.
- Only if a gap remains and the information is necessary for a specific risk, ask the supplier.
- Keep the request proportionate to the supplier's size and to the severity and likelihood of the risk.
The directive's own words are "reasonably available information," so a documented attempt to use existing sources is your evidence that a later request was justified.
Scoping replaces entity-by-entity mapping
Rather than detailed mapping of every actor in the chain, the amended CSDDD calls for a scoping exercise looking at where adverse impacts are likely in general. That allows you to assess, for example, cotton growing in a given region without investigating each individual farm (Stibbe). You then prioritise high-risk areas for deeper due diligence.
The consequence for data collection is that the questionnaire is no longer step one. Scoping tells you which suppliers or sourcing regions deserve a direct request at all. Our Article 8 risk mapping guide shows how to structure that exercise.
The CSRD companion rule you should not confuse with it
A related limit sits in the CSRD. Under the Omnibus I amendments, companies cannot request sustainability information beyond a voluntary reporting standard from suppliers with fewer than 1,000 employees. The voluntary standard is based on the Commission's recommendation for non-listed SMEs, adapted when revised ESRS were adopted on 3 July 2026 (Linklaters).
That cap protects suppliers in the CSRD context. One law-firm summary also describes a "protected undertaking" concept for entities with up to 1,000 employees that can refuse requests beyond the voluntary standard, and says stricter contractual obligations would not be binding (Stibbe). Because the two thresholds differ (1,000 for the CSRD cap, 5,000 for the CSDDD necessity test), and because the sources describe the interaction differently, confirm which rule governs each type of request with counsel. We recommend designing one request set that passes the stricter of the two.
Redesigning your supplier questionnaire
Segment first. Tier suppliers by risk and size before anything goes out. Large suppliers and high-risk categories can receive fuller requests. Small suppliers in low-risk categories may need nothing beyond what you already know.
Align with a standard data set. Where you do ask smaller suppliers for ESG data, anchor to the voluntary reporting standard so the request is one they can legitimately be asked to answer and can reuse across customers.
Record the necessity decision. For each request, note the risk it addresses, what existing sources you checked, and why they were insufficient. This record is the proof of proportionality.
Don't cascade blindly. Passing your code of conduct down the chain is not a substitute for assessment, and our contractual assurances guide explains why. Contract terms should support the process, not stand in for it.
Use verification where it replaces questions. A credible industry scheme or audit may let you skip a request. Our article on third-party verification sets out what such evidence can and cannot cover.
FAQ
Can I still send a questionnaire to all suppliers? Not as a default. Requests to business partners under 5,000 employees must be necessary and limited to information not reasonably obtainable otherwise.
Does the 1,000-employee cap apply to CSDDD? It is a CSRD rule. It matters here because CSRD and CSDDD requests often overlap in practice, so design to the stricter standard.
When does CSDDD start to apply? Companies apply the rules from 26 July 2029, after transposition by 26 July 2028.
Is value chain mapping still required? A scoping exercise based on reasonably available information is required, followed by prioritisation of high-risk areas, in place of exhaustive mapping.
Related reading

The CBAM Verifier Bottleneck: Why Booking a Slot in Late 2026 Is the Real Compliance Decision
Verifier availability - not data quality - is the binding constraint on using actual embedded emissions for 2026 CBAM imports. Here's the arithmetic, the third-country gap, and what to do in Q4 2026.

The CSDDD Guidelines Are Where Compliance Is Actually Decided - Here's What to Build Before Q1 2027
The Commission's CSDDD implementation guidelines land in Q1 2027 - a year before transposition. They set the evidentiary standard, not the directive. Here's what is unresolved and what to build now.

Three Letters, One Liability: How Your Incoterm Decides Who Pays CBAM
DDP, DAP, FCA - three letters in a contract determine who carries CBAM liability. A practical guide for procurement, trade compliance and legal teams on both sides of an EU import deal.