Skip to content

Häufig gestellte Fragen

From what point is a company directly subject to the German Supply Chain Act (LkSG)?
The LkSG has applied since 1 January 2024 to companies with at least 1,000 employees in Germany; in the first application phase in 2023 the threshold was still 3,000 employees. It covers a company's own business area, direct suppliers and, on an ad hoc basis, indirect suppliers as well, where there is substantiated knowledge of possible violations. The employee count alone is decisive; unlike the EU directive CSDDD, the German LkSG has no turnover criterion. Smaller companies are not directly obligated but are frequently drawn in indirectly through the requirements of their larger customers.
Am I affected as a mid-sized company or supplier even below the threshold?
Companies below 1,000 employees are affected in practice too, because obligated large customers pass their due diligence duties on via codes of conduct, self-disclosures and audit requests — this so-called trickle-down effect reaches the entire supply chain. Obligated customers may only demand appropriate, risk-based information; according to the BAFA guidance on cooperation in the supply chain, blanket obligations without reference to the risk profile are inappropriate. For suppliers, this mainly means filling in questionnaires and being able to provide evidence about their own supply chain. Reliable supplier, material and origin data is therefore a competitive factor for smaller businesses as well.
What changed in the LkSG in 2025/2026, and does the act still apply?
On 3 September 2025, the German Federal Cabinet adopted a draft bill amending the LkSG that removes the separate reporting obligation to the BAFA (Section 10 (2) to (4) LkSG) retroactively as of 1 January 2023 and significantly reduces the administrative-fine provisions. The BAFA already suspended its review of company reports in autumn 2025. However, the substantive due diligence obligations and the internal documentation duty under Section 10 (1) LkSG remain in place, so the act has not been repealed. As the specific design is still in flux in the legislative process, companies should keep an eye on the current status at the BAFA and the legislature.
What does the EU supply chain directive CSDDD mean after the omnibus package?
The European supply chain directive CSDDD was significantly softened by the Omnibus I package (Amending Directive (EU) 2026/470) and entered into force in this version in March 2026. The EU member states must transpose it into national law by 26 July 2028, and the first directly affected companies must comply with the obligations from 26 July 2029. The thresholds were raised to companies with more than 5,000 employees and over 1.5 billion euros in worldwide net turnover, and a standalone EU-wide civil liability regime was removed. Germany plans to implement the CSDDD via a new act that is intended to replace the current LkSG in the medium term.
Which ERP data and functions are needed for the LkSG due diligence obligations?
The risk analysis relies on structured supplier master data with unique IDs, country codes, material groups and purchasing volumes, since risks can only be prioritised and documented traceably on this basis. Many companies complement the ERP with SRM functions that centrally manage self-disclosures, certificates and risk scores, as well as with interfaces to external risk databases such as sanctions lists and country indices. Also central are a tamper-proof audit trail proving when which measure was initiated, and an orderly document and archiving solution for codes of conduct, audit reports and complaint cases. Since the internal documentation duty remains in place, this data dimension retains its importance even after the reporting obligation is dropped.
How does the LkSG differ from the CSRD and ESG reporting?
The LkSG is an obligation of effort requiring risk-oriented action in the supply chain; it does not demand a flawless supply chain but demonstrably appropriate measures. The CSRD and general ESG reporting, by contrast, aim at the transparent disclosure of sustainability metrics and thus pursue a different purpose. The two areas overlap in data sources such as supplier and origin information, but in the ERP they should be connected rather than equated. An integrated data model avoids duplicate maintenance while keeping the differing legal requirements clearly separated.