The European Commission is currently drafting guidelines for the Corporate Sustainability Due Diligence Directive (CS3D). If your company operates in both the EU and the U.S., you're dealing with a compliance framework that these two governments disagree on. In August 2026, the U.S. Government requested the EU to narrow CS3D's scope, limit enforcement to EU subsidiaries, and exempt U.S. companies with "high-quality corporate governance regulations." The EU hasn't agreed to these changes.
This situation puts you in a tough spot. You can't wait for a diplomatic resolution, and you can't assume the rules will soften. You need a compliance map that works under both the current law and the potential U.S. interpretation.
What You Need Before Starting
Jurisdictional footprint inventory
List every entity in your corporate structure that interacts with the EU: subsidiaries, branches, joint ventures, and partnerships. Note where each is domiciled and where it generates revenue. CS3D applies based on EU turnover thresholds and global activity, not just EU-domiciled entities.
Materiality standard comparison
The EU uses impact-based and double materiality (how your operations affect people and the environment, plus how sustainability risks affect your financials). U.S. disclosure rules use single financial materiality. Document which reporting frameworks your organization follows and where they differ.
Supply chain visibility map
Identify which suppliers are direct (Tier 1) and which are upstream (Tier 2 and beyond). The U.S. wants upstream suppliers outside the EU excluded from CS3D audit and information requests. The directive as written doesn't exclude them. You need to know who's in each tier.
Existing due diligence documentation
Gather your current third-party risk assessments, supplier codes of conduct, audit reports, and remediation records. You'll use these to identify gaps between what you do now and what CS3D requires.
Step-by-Step Implementation
Step 1: Map your in-scope entities under both interpretations
Create two columns in a spreadsheet. Column A lists entities in scope under CS3D as written (based on EU turnover thresholds and global value chain obligations). Column B lists entities that would be in scope if the U.S. Government's requests are adopted (EU subsidiaries only, no upstream obligations for non-EU suppliers).
For each entity in Column A, note whether it's also in Column B. Entities in both columns are your compliance core. Entities only in Column A are your contingency zone.
Step 2: Build a stakeholder definition you can defend under either standard
The CS3D defines stakeholders as those whose interests "are or could be" directly affected. The U.S. wants this narrowed to those "who could reasonably be affected."
Start with the narrower definition: identify stakeholders directly connected to your operations (workers in your facilities, communities where you extract resources, individuals whose data you process). Then expand to those who "could be" affected (workers in supplier facilities, communities near supplier sites).
Document your rationale for including each group. If the EU guidelines adopt the broader interpretation, you're covered. If they narrow it, you haven't wasted resources.
Step 3: Set up dual-track enforcement planning
The U.S. wants penalties limited to EU revenue and no private right of action without prior regulatory enforcement. The directive currently allows penalties based on worldwide turnover and permits civil claims without waiting for regulators.
Build your risk controls assuming the stricter standard applies: calculate potential penalties on global turnover, not just EU revenue. Design your due diligence documentation to withstand both regulatory investigations and private litigation. If the rules soften, you're over-prepared. If they don't, you're protected.
Step 4: Establish verification body criteria now
The U.S. is asking for independent, accredited, experienced third-party verification bodies. The directive doesn't currently specify these requirements. Don't wait for guidance.
Draft selection criteria for any external auditors or verification partners you'll use: ISO 17021 accreditation for management system certification, sector-specific expertise, and documented independence policies. Vet your current audit firms against these criteria. If you're already working with qualified verifiers, you're ahead of any new requirements.
Step 5: Document your "high-quality governance" equivalence case
The U.S. argues that companies under strong domestic regulation shouldn't face duplicative EU obligations. Even if the EU doesn't create a formal presumption of compliance, you can build an equivalence argument for use in enforcement discussions.
Map your existing compliance program elements to CS3D requirements: due diligence procedures, stakeholder engagement, remediation processes, reporting mechanisms. Where your program meets or exceeds CS3D standards, document it. Where gaps exist, close them. This gives you a defensible position if regulators question overlapping obligations.
Validation: How to Verify It Works
Test your dual-track map with a sample supplier
Pick one Tier 1 supplier and one Tier 2 supplier. Walk through your compliance map using each supplier as a test case. Can you identify which obligations apply under Column A (CS3D as written) versus Column B (U.S.-requested scope)? Can you produce the due diligence documentation each scenario requires?
If you can't answer these questions for a sample supplier, your map isn't specific enough.
Run a penalty calculation exercise
Take your largest EU subsidiary and calculate CS3D penalties under both scenarios: worldwide turnover basis (current rule) and EU-only revenue basis (U.S. request). The difference between these numbers tells you how much financial exposure you're carrying if the rules don't change.
Audit your stakeholder engagement records
Pull three months of stakeholder engagement documentation. Can you demonstrate that you've consulted with affected parties? Can you show how their input influenced your due diligence decisions? If your records don't support this, you're not meeting the directive's engagement requirements.
Maintenance and Ongoing Tasks
Monitor the EC's implementation guidelines (quarterly)
The European Commission is drafting CS3D guidelines now. Set a calendar reminder to check for updates every quarter. When guidelines are published, compare them to your dual-track map and adjust.
Track Turnberry Agreement commitments (semi-annually)
The U.S.-EU Joint Statement from August 2025 included EU commitments to reduce administrative burden. Review progress reports and public statements twice a year. If the EU makes concrete concessions, update your Column B assumptions.
Update your jurisdictional footprint (annually or after M&A)
Corporate structures change. Every year, and immediately after any merger, acquisition, or divestiture, refresh your entity inventory. New EU subsidiaries or revenue streams can change your in-scope status.
Reassess supplier tiers (annually)
Your supply chain isn't static. Annually review which suppliers are Tier 1 versus upstream. If a Tier 2 supplier becomes Tier 1, your due diligence obligations may expand even under the narrower U.S.-requested interpretation.
Document enforcement developments (ongoing)
As EU member states begin enforcing CS3D, track public enforcement actions and private litigation. Note which interpretations regulators and courts adopt. This case law will clarify ambiguities faster than any guideline document.
You're building compliance infrastructure during an active regulatory negotiation. That's uncomfortable, but it's manageable if you plan for both outcomes. The companies that struggle will be those who wait for clarity that may never come.



