← Back to CSDDD Insights
CSDDD transition from Germany's LkSG: BAFA enforcement pullback in 2025-2026 and the coalition's replacement plan

LkSG to CSDDD: What Germany's Retreat From Its Own Supply Chain Law Means for Compliance Teams

LkSG to CSDDD: What Germany's Retreat From Its Own Supply Chain Law Means for Compliance Teams

Germany built the EU's first serious corporate human rights due diligence law. Now it is quietly dismantling the enforcement side of that law while it waits for a Brussels-designed replacement that will not fully apply until 2029. For any company with LkSG obligations - or any supplier to one - the years in between are the part nobody planned a compliance program around.

What actually happened in 2025 and 2026

The German coalition government has been moving to align the Supply Chain Due Diligence Act (LkSG) with the incoming EU Corporate Sustainability Due Diligence Directive (CSDDD) rather than run both regimes in parallel. The practical steps came fast, in this order:

  • 3 September 2025 - the government released a draft bill to scale back LkSG.
  • 26 September 2025 - BAFA, the federal enforcement authority, was instructed to pursue only "serious" human rights and environmental violations rather than review every company's report as a matter of course.
  • 7 November 2025 - BAFA deactivated the digital reporting form companies had used to file their annual LkSG reports.
  • 31 December 2025 - the last LkSG reporting deadline under the old regime passed.
  • 16 January 2026 - the Bundestag held its first debate on the formal amendment bill (Taylor Wessing).

The upshot: the routine external reporting cycle that anchored LkSG compliance programs since 2023 has effectively stopped, months before any formal replacement law has cleared parliament (Fieldfisher).

What's gone, and what isn't

It's tempting to read "BAFA stopped checking reports" as "LkSG is over." It isn't.

Annual reporting to BAFA is gone, and administrative offenses have been narrowed to four categories: failure to implement prevention measures, failure to implement remedial measures, failure to run a complaints procedure, and failure to produce a remedy concept for identified human rights risks. But the underlying due diligence obligations for companies with 1,000+ employees in Germany "remain in place," and the obligation to maintain internal documentation in accordance with the LkSG is explicitly unchanged (Taylor Wessing). BAFA can still act on complaints and serious violations; it has just stopped doing routine desk reviews of every filed report.

In other words: the audience for your compliance file got smaller, not the file itself.

The scope mismatch nobody has resolved

Here is the detail compliance teams tend to miss. LkSG applies to companies with 1,000+ employees in Germany. The CSDDD, as finalized after Omnibus I, applies only to companies with more than 5,000 employees and over €1.5 billion in worldwide turnover. That is a much higher bar. A large share of companies currently doing LkSG due diligence will fall outside CSDDD's direct scope entirely once the transition completes - creating a real question about what, if anything, replaces their obligations, and whether Germany will legislate a national floor beneath the EU threshold. That mismatch is still unresolved in the draft amendment working through the Bundestag (Taylor Wessing).

Why "don't pause" is the right call, not just the cautious one

It would be easy to read a suspended reporting portal and a softened enforcement posture as permission to stand down. The better read is the opposite. Companies that keep their LkSG-built risk management systems running gain "a significant head start" once CSDDD's full obligations land, because the two frameworks share the same core architecture: risk-based prioritization, prevention and mitigation measures, grievance mechanisms, and remediation (CORE).

That head start matters more than it looks, because CSDDD asks for more than LkSG ever did. LkSG-compliant programs are generally built around direct, tier-1 suppliers. CSDDD's "chain of activities" concept reaches further upstream and, in some cases, into downstream partners such as distribution and recycling. It also introduces enforcement exposure beyond administrative fines - a dimension German companies accustomed to BAFA's penalty-only model have not had to manage before (Policy-Insider.AI).

What to actually do during the gap (2026-2029)

  1. Keep internal documentation current, even though nobody is checking it externally right now. The obligation didn't move; the audience did.
  2. Map your company against both thresholds - LkSG's 1,000-employee German test and CSDDD's 5,000-employee/€1.5bn test - so you know now whether you're headed for a scope gap, not in 2028.
  3. Start widening supplier mapping beyond tier 1 where you have leverage to do so. CSDDD's chain-of-activities standard will ask for this eventually; building it into existing LkSG workflows now is cheaper than retrofitting it later.
  4. Track the Bundestag amendment, not just Brussels. The German replacement law - not just the EU directive - will set your actual domestic compliance floor, and it is still being drafted.
  5. Don't let a quiet enforcement authority become a quiet compliance function. BAFA's reduced review capacity is a resourcing decision, not a legal signal that the underlying risks companies are meant to manage have gone away.

The regulatory noise here is real, but the underlying question for a compliance team hasn't changed: can you show, with evidence, that you identified and addressed the human rights and environmental risks in your supply chain? Everything else - who reads the report, and how often - is administrative detail sitting on top of that same core obligation.