Anyone reading the LkSG amendment as an all-clear for supplier due diligence is mistaken: the amendment removes the reporting obligation and most of the fine provisions — yet the substantive due-diligence duties of §§ 3–10 LkSG (German Supply Chain Due Diligence Act) persist, and serious violations remain sanctionable. In parallel, the European CSDDD (Corporate Sustainability Due Diligence Directive) has been postponed and narrowed, but not abolished: the transposition deadline runs until 26 July 2028, and the obligations apply from 26 July 2029. Anyone dismantling their third-party screening now will have to rebuild it at high cost in two years.
The LkSG amendment: what is removed — and what remains
The Federal Cabinet adopted the amendment on 3 September 2025; the first reading in the Bundestag took place in January 2026, so the legislative process is not yet complete. The shape of the relief is nonetheless clear: the annual reporting obligation and the majority of the fine provisions are to be dropped. The core duties, by contrast, are to continue unchanged:
- the risk analysis along your own supply chain,
- preventive and remedial measures where risks and violations are identified,
- the complaints procedure for affected persons,
- the documentation of the due-diligence processes — even without a reporting format.
For practice, this means: the administrative superstructure shrinks, the substantive duty to know your own suppliers remains. And for serious violations, the sanctions framework stays in place — the amendment is a de-bureaucratisation, not a de-obligation. Until the final statutory text is promulgated, the current legal position continues to apply in any event; anyone scaling back processes today is doing so on the basis of a draft, not a statute.
CSDDD: postponed and narrowed — not scrapped
At European level, the supply-chain directive (Directive (EU) 2024/1760) was adjusted by amending Directive (EU) 2026/470: transposition into national law is scheduled by 26 July 2028, and the obligations apply from 26 July 2029. At the same time, the scope was significantly narrowed — covered are companies with more than 5,000 employees and more than €1.5 bn in turnover. Two consequences are decisive for planning: first, many mid-sized companies fall out of the direct scope — but remain indirectly obliged as suppliers to large companies, because those companies’ due diligence reaches through to them. Second, the time gained is a transposition period, not a free pass: anyone who wants to be a viable supplier in 2029 does not start building processes in 2028.
Why dismantling your screening now would be the most expensive path
The temptation is understandable: less reporting, fewer fines, hence less screening effort. This calculation overlooks three points — and it underestimates how strongly the due-diligence duties of large buyers reach into your own supply chain via contractual clauses. First, the substantive duties of the LkSG persist — a risk analysis without robust supplier data is not one. Second, other regimes continue to demand the same screening methodology in any event: sanctions-list compliance applies independently of the LkSG, and in the financial sector free-standing third-party duties come on top. Third, screening processes, data access and documentation routines that have once been dismantled cannot be restored at the push of a button in 2028 — the rebuild then costs project budget under time pressure. On distinguishing the screening models, see One-off check or continuous monitoring; on vetting external individuals and secondees, see Interim managers, consultants, service providers.
Recommended course of action: consolidate rather than dismantle
Use the relief to streamline your third-party screening — not to discontinue it. Concretely: first, keep the risk analysis and supplier screening at their current level and continue documenting, even without a formal reporting obligation — the documentation is your evidence should a serious violation occur. Second, prioritise on a risk basis: critical suppliers, new business partners and high-risk countries first. Third, screen in a structured way across defined categories — ultimate beneficial owners (UBO), sanctions lists, register data, adverse media — and record the occasion, scope, sources and result of each check so that a third party can retrace the decision. Fourth, monitor the ongoing legislative process: only the promulgated text creates legal certainty on the final shape of the amendment. Indicium delivers audit-proof company and individual reports for this purpose, with dated sources and human final review (Art. 22 GDPR), from €79 per report. The industry overviews show which screening depth fits your sector — or go straight to a demo.
This article provides general information and does not constitute legal advice.