ESG & Responsible Sourcing

EU Omnibus I Enters Into Force: How the CSDDD Rollback Reshapes Supply Chain Due Diligence for Miners

May 1, 2026
10 min read
EU Omnibus I Enters Into Force: How the CSDDD Rollback Reshapes Supply Chain Due Diligence for Miners

The EU's Omnibus I Directive entered into force on 18 March 2026, dramatically narrowing the Corporate Sustainability Due Diligence Directive's scope. The number of companies subject to mandatory human rights and environmental due diligence has fallen by roughly 70 percent. For the critical minerals sector, the practical consequences are significant: many mid-tier miners and traders are no longer directly regulated, even as the underlying risks in their supply chains remain unchanged.

Introduction

If you source cobalt from the Democratic Republic of Congo, lithium from South America, or graphite from China, the legal framework governing how carefully you must scrutinise your supply chain just changed substantially. On 18 March 2026, Directive (EU) 2026/470, known as Omnibus I, entered into force across the European Union. It rewrites the Corporate Sustainability Due Diligence Directive (CSDDD) in ways that matter most to extractive industries and the companies that buy from them.

The CSDDD, adopted in July 2024, was designed to require companies to identify, prevent, and address human rights and environmental harms throughout their global value chains. In theory, it was going to be the most far-reaching corporate accountability law the EU had ever produced. In practice, its scope has now been cut by approximately 70 percent before most companies ever had to comply with it.

This article explains what the original law required, what changed and why, who is now in and out of scope, and what it means for companies operating in the critical minerals sector. It also looks at what critics are saying, where national law still creates obligations, and what to expect next.

What the Original CSDDD Required, and What Omnibus I Changed

The original CSDDD, adopted as Directive (EU) 2024/1760, applied to companies with more than 1,000 employees and more than 450 million euros in global turnover. It was designed to roll out in phases, starting with the largest companies in 2027 and expanding to firms with 1,000 employees by 2029. It required due diligence across both direct and indirect suppliers, mandated climate transition plans, established a harmonised EU-wide civil liability regime, and set a minimum maximum penalty of 5 percent of global turnover.

Omnibus I scraps all of that and replaces it with a single, much higher threshold. Only companies with more than 5,000 employees and more than 1.5 billion euros in annual net worldwide turnover are now required to conduct mandatory due diligence. The phased rollout is gone. The climate transition plan requirement has been deleted entirely. The civil liability regime has been removed. Penalties are now capped at 3 percent of net worldwide turnover, applied at the national level rather than through a harmonised EU framework.

The political logic behind this shift traces back to late 2024, when the European Council called for a "simplification revolution" in response to competitiveness concerns raised in reports by Enrico Letta and Mario Draghi. Commission President von der Leyen announced the Omnibus package in November 2024. Trilogue negotiations between the Parliament, Commission, and Council concluded in December 2025, and the Council gave its final approval on 24 February 2026. The directive was published in the Official Journal on 26 February 2026 and entered into force three weeks later.

It is worth noting that the process was not insulated from external pressure. Liberal MEP Pascal Canfin stated publicly that the removal of climate transition plans followed demands from the United States. A joint letter from senior US and Qatari government officials had urged EU leaders to scale back the CSDDD. Critics argue this level of foreign influence over EU lawmaking sets a troubling precedent for democratic accountability.

Who Is Now In Scope, and What the Numbers Mean

The headline figure is stark. Under the original CSDDD, somewhere between 15,000 and 20,000 companies were expected to fall within scope across the EU, according to European Commission estimates. Under Omnibus I, that number has fallen to roughly 2,907 companies globally, belonging to 1,447 corporate groups, according to updated analysis from SOMO, the Centre for Research on Multinational Corporations. For EU-based corporate groups specifically, the reduction is approximately 71 percent.

To be in scope under the amended directive, a company must have had more than 1.5 billion euros in net worldwide turnover and an average of more than 5,000 employees in the last financial year, and those thresholds must be met in two consecutive financial years. Non-EU companies are captured where they generate more than 1.5 billion euros in EU turnover. There is also a franchising and licensing carve-in for companies where royalties from EU agreements exceed 75 million euros.

For the minerals sector, the practical implication is that many mid-tier miners, traders, and processors no longer face a direct legal obligation under the CSDDD. Morrison Foerster has characterised this as a structural shift, not just a timing adjustment: it changes who is regulated and how sustainability obligations are expected to cascade through supply chains. That said, being outside direct scope does not mean being outside commercial pressure. Large in-scope buyers will still push due diligence expectations down to their suppliers through contracts, regardless of what the directive requires.

SOMO has also highlighted a point that tends to get lost in debates about compliance cost: the European Commission's own estimates of the financial burden of CSDDD compliance represent only about 0.13 percent of average shareholder payouts made by affected companies in 2023. Twenty-one German companies, including Otto, Aldi Süd, Tchibo, and Ritter Sport, wrote to the German government describing the rollback as counterproductive. KfW, Deutsche Bank, Allianz, and Amundi all publicly confirmed continued support for a robust CSDDD.

What the Rollback Means for Critical Minerals Supply Chains

Building on the analysis I have been tracking since January 2026 of how supply chain vulnerabilities concentrate at specific chokepoints, it is worth being precise about what the CSDDD rollback does and does not change for the minerals sector.

Critical minerals such as cobalt, lithium, and graphite are predominantly extracted and processed in countries where labour standards, environmental regulation, and community consent protections are weakest. The CSDDD was designed, in part, to require large buyers of these materials to actively identify and address those risks, rather than simply accepting a certificate and moving on. The amended directive still requires in-scope companies to conduct risk-based due diligence across their global chain of activities, covering upstream extraction, transport, storage, and supply. The definition of what counts as a covered value chain has not changed.

What has changed is who has to do that work. With the threshold now set at 5,000 employees and 1.5 billion euros, many mid-market miners and commodity traders fall outside the mandatory framework. This creates a genuine uneven playing field. A mid-tier miner operating in a jurisdiction with stricter national law, such as Germany under its Supply Chain Due Diligence Act (known as the LkSG), faces higher compliance obligations than a competitor of similar size that happens to fall outside scope in another member state.

Other EU frameworks remain in place and still apply to minerals specifically. The EU Conflict Minerals Regulation requires importers of tin, tantalum, tungsten, and gold to identify the smelters and refiners in their supply chains. The EU Batteries Regulation imposes due diligence and traceability requirements on battery supply chains. The Carbon Border Adjustment Mechanism, the Digital Battery Passport, and the EU Forced Labour Regulation all add layers of accountability that the CSDDD rollback does not erase. Resources for the Future, an independent research institution, has noted that whether the amended CSDDD will translate into measurable improvements at the mine level remains an open empirical question.

The Critics, the Supporters, and the Honest Contested Questions

The Omnibus I process has generated more sustained criticism from civil society than almost any piece of EU legislation in recent memory. The Business and Human Rights Resource Centre described the directive as "a massive rollback of human rights and environmental protections in the name of simplification," while acknowledging that the CSDDD, in its amended form, still constitutes a meaningful shift in corporate accountability norms.

ClientEarth stated that the CSDDD was being turned into "a political bargaining chip." The European Coalition for Corporate Justice wrote that "vital protections have been dismantled." Human Rights Watch warned that the law risked becoming "window dressing." The UN Human Rights Office expressed concern about the weakening of stakeholder engagement requirements and the reduced monitoring cadence, and urged that the amended directive remain aligned with the UN Guiding Principles on Business and Human Rights. More than 210,000 people signed a petition calling for a stronger, not weaker, supply chain law.

The competing case, made by business associations and reflected in the EU Council's own rationale, is that the original scope was too broad and too expensive for the administrative capacity of many companies. The Council argued that very large companies have the greatest influence on their value chains and are best placed to absorb compliance costs. The simplification agenda also reflects genuine concerns from SMEs about being overwhelmed by data requests from large customers. The amended directive specifically restricts information requests to business partners with fewer than 5,000 employees, allowing smaller firms to decline requests that go beyond voluntary SME sustainability standards.

These are genuinely contested policy questions. Reasonable people disagree about where the compliance threshold should sit, how civil liability should be structured, and whether a stricter law that is poorly enforced achieves more than a narrower law that is consistently applied. What is harder to dispute is that the balance has shifted significantly toward deregulation, and that the shift happened quickly, under pressure, and with the explicit removal of provisions, like the climate transition plan requirement, that had been negotiated carefully in the original directive.

Germany, National Law, and the Uneven Playing Field

The interaction between Omnibus I and national supply chain laws adds another layer of complexity for companies operating across multiple EU jurisdictions. Germany's LkSG, which came into force in January 2023 and currently applies to companies with at least 1,000 employees in Germany, represents the most significant national framework in scope.

In April 2025, Germany's incoming coalition government announced its intention to repeal the LkSG and replace it with legislation implementing the CSDDD in a "bureaucracy-light" way. In the meantime, the federal cabinet approved an amendment in September 2025 to abolish the LkSG's annual reporting obligation and ease sanctionable omissions. Germany's federal regulator, BAFA, adjusted its enforcement practice from October 2025, limiting report reviews while legislative changes work through parliament.

Omnibus I explicitly permits member states to align the scope of existing national regulations with the CSDDD's new thresholds. Whether Germany takes that step will determine whether companies currently subject to the LkSG at 1,000 employees will see their obligations narrow further. That remains an open question as of May 2026.

The broader risk is a patchwork of national standards across the EU. The amended directive still allows member states to adopt additional due diligence obligations concerning specific products, services, or situations. Civil society organisations have identified this as an opportunity: member states can set lower thresholds, adopt stronger civil liability provisions, and require climate transition plans at a national level, even if the EU floor has dropped. The Business and Human Rights Resource Centre has called explicitly for "bold political leadership" from member states to restore protections that were lost in Brussels.

What Happens Next, and What Companies Should Do Now

The amended CSDDD requires member states to transpose the directive into national law by 26 July 2028. The rules will apply to in-scope companies from 26 July 2029. Companies that remain in scope must publish their first annual sustainability due diligence statement for financial years starting on or after 1 January 2030. The European Commission is required to produce detailed implementation guidance by July 2027, covering due diligence processes, stakeholder engagement, available data sources, and model contractual clauses.

The directive also includes a review clause. By 26 July 2031, the Commission must assess whether the scope thresholds should be revised and whether a sector-specific approach is needed for high-risk sectors. This matters for the minerals sector in particular: if the evidence by 2031 shows that the 5,000-employee threshold is leaving significant harms unaddressed, there is a formal mechanism to expand the scope again.

For companies currently outside the new scope, the practical advice from most analysts is consistent: do not treat the regulatory rollback as a green light to wind down due diligence programmes. Institutional investors, lenders, and large customers in scope will continue pushing expectations down through contracts. Other regulatory frameworks, including the Batteries Regulation, Conflict Minerals Regulation, and emerging requirements in the UK, Australia, Brazil, and several Asia-Pacific jurisdictions, continue to apply. The Omnibus changes the regulatory floor, not market expectations.

For companies that remain in scope, the core obligation is unchanged. They must conduct risk-based human rights and environmental due diligence across their global chains of activities, identify and prioritise risks through a scoping exercise, take appropriate measures to address actual and potential harms, and communicate publicly on their due diligence activities. The termination-of-contract obligation has been replaced with a suspension-and-correction approach, giving suppliers more opportunity to remediate problems before a relationship ends. Monitoring cadence has been extended to at least every five years, with trigger-based reassessments required when new risks emerge or existing controls look inadequate.

The honest conclusion is that Omnibus I represents a significant retreat from the ambition of the original CSDDD. The law that enters full application in 2029 will cover a much smaller number of companies, with weaker enforcement mechanisms and no harmonised civil liability regime. Whether that smaller, narrower law produces meaningful improvements in mining communities in the Congo, Bolivia, or Indonesia is, as researchers at Resources for the Future have put it, genuinely an open question. The answer will depend on how member states choose to implement the directive, how the Commission exercises its guidance function, and whether the 2031 review clause is used to course-correct or to ratify the rollback.

Share Article