Supplier contracts are quietly becoming one of the most exposed points in any EU business strategy, and autumn trading will test every gap you have not yet closed.
Why the regulatory baseline has shifted
On February 26, 2026, the European Union published Directive (EU) 2026/470, which simplifies and reshapes both the Corporate Sustainability Due Diligence Directive (CSDDD) and the Corporate Sustainability Reporting Directive (CSRD). For procurement teams, this is not background noise. It directly changes what your supplier contracts must say and prove.
The Omnibus Directive significantly reshaped the CSRD and the CSDDD. The most consequential change for compliance officers is the shift to a risk-based due diligence approach. Companies no longer need to audit every supplier in their value chain. They focus documented effort on the highest-risk relationships instead.
Documentation half-life is shrinking. Supplier certificates expire, regulations change quarterly, and audit windows are narrower. Autumn is a peak trading window for most European sectors. If your supplier contracts carry outdated clauses now, you carry the liability through your busiest months.
What the CSDDD and CSRD now require in contracts
The CSDDD is a European Union directive that establishes legal accountability for businesses concerning environmental and human rights matters. It sets obligations for companies to address actual and potential adverse impacts, including those related to their own operations, their subsidiaries, and their suppliers.
Article 18 on Model Contractual Clauses clarifies that Commission guidance “should aim to facilitate a clear allocation of tasks between contracting parties and ongoing cooperation.” The guidance confirms that “the mere use of contractual assurances cannot, on its own, satisfy the due diligence standards provided for in this Directive.” In practical terms, your supplier contracts must describe real processes, not just written promises.
The CSDDD requires in-scope companies to identify, prevent, and address human rights and environmental risks across their supply chains, making supplier due diligence and contractual accountability a core procurement responsibility. Pre-autumn is the right moment to verify that each agreement reflects this standard.
A practical audit checklist for procurement teams
Start with scope. For EU companies, the CSDDD now applies to those with 1,000 or more employees and a net turnover of EUR 450 million. Even if your business falls below this threshold, your large customers may cascade their own compliance requirements directly into their contracts with you.
Out-of-scope companies face obligations indirectly via customer cascades. Tier-1 focus does not mean Tier-1 only. Plausible-risk indicators trigger deeper investigation, meaning manufacturers still need multi-tier supply chain transparency on demand.
Next, review each contract against 4 specific audit points. First, confirm the contract includes an explicit right to audit. The audit checklist must explicitly include the right to audit, participation in inspections, cascade management, proof of written consent prior to re-subcontracting, and access to critical documentation. Second, check termination and remediation clauses. Third, verify traceability obligations. Fourth, confirm that data rights align with the EU Data Act. The EU Data Act obliges suppliers of connected products and digital services to provide customers with free, usable access to operational data. The Data Act became applicable from 12 September 2025.

Expert perspective on supplier contract readiness
EU companies are entering a phase where contractual governance is as important as operational delivery. A supplier contract that lacks an explicit audit right, a remediation workflow, or traceability obligations is not simply incomplete, it is a direct liability under the current EU framework. The Omnibus simplification reduced scope for some companies, but it did not reduce the depth of obligation for those in scope. If anything, enforcement attention will now concentrate on a smaller number of companies, making contractual precision even more critical. Procurement teams should treat this pre-autumn period as an opportunity to close gaps before regulators or major customers do it for them.
Industry perspective, sustainability and procurement compliance professionals across the European Union
Key documents to gather before the audit begins
Before you review contract language, collect the right evidence. Typically, employment contracts, wage statements, time records, safety instructions, training records, supplier management documents, environmental permits, energy consumption, and waste records are examined.
The OECD Due Diligence Guidance for Responsible Business Conduct remains the underlying framework, but EU law has shifted toward a risk-based, evidence-led model rather than blanket value-chain mapping. This means you prioritize depth over volume. 10 well-documented high-risk supplier contracts are more defensible than 100 shallow ones.
Non-compliance is no longer just a reputational risk. It is a direct financial liability that can lead to significant fines and restricted access to capital markets. For companies in sectors such as retail, manufacturing, and logistics, autumn cash flow depends on supply chains that regulators and customers alike can verify.

Why timing matters: act before October
Supply chain ESG compliance is no longer voluntary. The EU CSDDD, Germany’s LkSG, and France’s Duty of Vigilance Law impose binding legal obligations. These are not future risks. They are current exposure.
The EU AI Act requires procurement teams to identify and classify AI used by suppliers, ensure high-risk systems meet strict compliance standards, and embed transparency, audit, and traceability obligations into supplier contracts. If any of your suppliers use AI in their operations or deliverables, this adds a new layer to your contract review.
Document your materiality determination process rigorously. Regulators view this documentation as evidence of due diligence under the Corporate Sustainability Due Diligence Directive. A clear, dated record of your pre-autumn audit gives you a defensible position if a dispute or inspection arises after October.
Conclusion: close the gaps now
Supplier contracts are not static documents. They are live compliance instruments, and the EU regulatory environment has moved faster than most contract templates. Complete your audit before autumn trading begins. Prioritize the highest-risk supplier contracts first, gather evidence, update audit-right clauses, and align data obligations with current law. Companies that treat supplier contracts as a strategic asset today will trade with confidence throughout the autumn and beyond. Start your review this week, not next month.












