Custom software for supply chain due diligence
Since Omnibus I, the CSDDD applies only to very large undertakings, so most Dutch businesses are no longer directly covered. What hasn't changed is that you will still receive the questionnaire. The directive explicitly targets direct business partners, and if you supply such an undertaking, you are that direct business partner. The obligation rests with them, but the work lands with you.
What Omnibus I changed
The CSDDD, Directive (EU) 2024/1760, requires undertakings to identify and address adverse impacts on people and the environment in their value chains. Shortly after its adoption, the Commission proposed the Omnibus I package. The stop-the-clock directive postponed the dates, and Directive (EU) 2026/470, published in late February 2026, amended the content.
Three changes matter. The threshold has been raised considerably, to companies with more than 5,000 employees and more than €1.5 billion in net turnover. The duty of care now focuses on a company's own operations, its subsidiaries and its direct business partners, and you only need to look further down the chain if there is plausible information about adverse impacts. And the harmonised civil liability has been dropped; this falls back on national law. Member states must transpose the directive by 26 July 2027, and the first group of companies must comply from 26 July 2028.
The practical outcome is lopsided. The number of undertakings with the obligation has become small, but because the duty focuses on tier-1, the questionnaires have become more demanding. If you supply a group that falls under it, you receive questions about working conditions, the environment and your own suppliers, and you currently answer them for each client in a separate spreadsheet.
What you know about your chain rarely starts with a questionnaire; it usually starts during a visit. For how to record those on-site observations, see the supplier visit app.
How we build this
Here the business partner is the unit, not the report. If it is recorded per partner what you know, how you know it and what you did about it, then every questionnaire is a selection from that record.
Are you carrying out due diligence or answering the questionnaire? That changes the entire system. Most businesses sit on the answering side and accidentally build the system from the other side.
Who they are, what they supply, and what risk attaches to their sector and country. This list is rarely complete, because procurement keeps it by category rather than by legal entity.
Every question you ask or answer, with the evidence attached and the date. What goes by email cannot be retrieved within a year and has to be redone.
The directive calls for follow-up when there is plausible information about adverse impacts. That is a continuous obligation rather than an annual survey, so the system must be able to process signals as they arise.
What the software actually does
The register of business partners, with their risk and their answers, carries everything. Which components you need depends on whether you are sending or answering questionnaires.
Register of direct business partners
For each partner, what they supply, in which country they produce and what risk attaches to it. Since Omnibus I, tier-1 is the starting point, so this list must be complete, not indicative.
Risk per partner substantiated
Sector, country and type of activity determine where you focus your attention. The system shows why a partner scores high, because a risk score without a reason is worthless when accounting for your decisions.
Questionnaires and responses in one place
Questionnaires out, answers and evidence back, with what is still missing visible. If you supply large buyers yourself, you answer from the same register instead of starting again for each client; see also VSME software.
Alerts and follow-up
A report, a news item, an audit finding. Every signal becomes a case with an owner and a deadline, because the directive looks at what you did after you knew.
Rationale retained for each decision
Why you accepted a partner, which measures you required and what happened. Accountability is about the process, not the outcome of a single moment.
History per partner
Answers change, ownership changes, production sites move. The system keeps what you knew at the moment you decided, not just the current state.
Who we build for
Your position determines which part of this system you need. Four situations.
Producers supplying large corporations
You are probably not covered by the directive yourself, but you are a tier-1 supplier to someone who is. Your task is to answer the questionnaires efficiently rather than handle every customer's request manually.
Trade and distribution
You sit between parties and receive questions about suppliers you only know at arm's length. What is usually missing is not willingness but the paperwork: who supplies what, from which country, and since when.
Retailers and brand owners
As a private label brand, you are the one accounting for production. Your supply chains are long and change with each season, so an annual snapshot does not cover the problem.
Companies above the threshold
If you are covered by the directive, your task is the reverse: survey, prioritise and follow up on hundreds of direct business partners. That is a questionnaire management system, not a reporting tool like CSRD.
Test your idea first: a working prototype in 1 day
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
Explore OneDayBuild →Technology and integrations
The Dutch transposition has yet to take place and will proceed without a national heading, but the precise details and guidance are still to come. Everything connected with this should be configurable.
Why Appfront
We tell you honestly whether you are covered
Since Omnibus I, the threshold is more than 5,000 employees and €1.5 billion in turnover. If you fall well below that, you do not need a CSDDD system but a response system, which is smaller and cheaper.
Your supplier data already exists
Names, countries and volumes are held in procurement or accounts payable. We connect to these via integrations rather than letting a second supplier list emerge.
Answer once, serve multiple customers
If you supply several large customers, you receive similar questions in different forms. We build the answer once and let you select from it.
The deadlines have been pushed back, not dropped
Transposition by 26 July 2027, first application 26 July 2028. For those issuing questionnaires, that is short, because building a supply chain record takes more than a year.
Security and privacy
The data in this system is commercially sensitive in two directions. Your supplier list with volumes and countries is valuable to a competitor, and what your suppliers submit about their own production is equally so for them. In the portal, a partner therefore sees only their own file, and risk scores and internal notes remain on your side.
There is also a personal data side that is often underestimated. Signals about working conditions or misconduct can be traceable to individual employees or whistleblowers, and that information deserves stricter protection than the rest of the file. We set separate access rights for it, limit who sees a signal in full, and keep follow-up separate from the source. On the evidence side, we record what you knew at the moment you decided, because accountability is about the process. How we handle security ourselves is set out in our information security policy; reports from outside come in through our CVD policy.
Frequently asked questions about the CSDDD
Since Omnibus I, the directive applies to companies with more than 5,000 employees and more than €1.5 billion in net turnover. That is considerably higher than in the original text, so the number of companies with a direct obligation has fallen sharply. If you fall well below that, you are not directly covered, but you will still receive the questionnaire if you supply such a company.
Directive (EU) 2026/470, published at the end of February 2026, raised the threshold, limited the due diligence duty to your own activities, subsidiaries and direct business partners, and removed the harmonised civil liability regime, which therefore falls back on national law. The stop-the-clock directive of April 2025 had already provided a postponement.
Member States must transpose the directive by 26 July 2027, and the first group of companies must comply from 26 July 2028. The Netherlands is transposing without national additions, so stricter requirements than the directive are not to be expected. Check the status of the Dutch transposition before you fix your planning.
The starting point is now tier 1: your own activities, your subsidiaries and your direct business partners. Further down the chain you only need to look when there is plausible information about adverse impacts. That makes the scope narrower but not optional, because once you receive such a signal, what you did afterwards counts.
The CSRD is about reporting under the ESRS, so about what you publish. The CSDDD is about action: identifying and addressing risks at your business partners. VSME is the standardised format with which a small or medium-sized enterprise answers the questionnaire of a large customer. In practice, they come together in the same data set.
Yes, and for most businesses that is the reason to build something. Once your answers and supporting evidence sit in one register, every new questionnaire becomes a selection from it rather than a new project. It matters most for customers who ask again every year and do not accept that you already answered last year.
The harmonised European civil liability regime has been removed from the directive; liability therefore falls back on the national law of the Member States. That does not mean there is no liability any more, only that the basis differs per country. This is a legal question and belongs with your lawyer, not your software supplier.
That depends heavily on which side you are on. A response system for a supplier is considerably smaller than a request system for hundreds of business partners. The register of partners and their responses is usually quick to put to use; the portal and the procurement integrations cost more. We give a reasoned estimate after the discovery phase.
Getting supply chain questionnaires under control?
Look up the last questionnaire a client sent you and count how many answers you had to search for again. That number comes back every year, with every client. We build this as a standalone application and as part of a wider custom software project.