LkSG enters into force for companies with at least 3,000 employees and a registered presence in Germany.
LkSG: Supply chain due diligence obligations for German companies
The German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz, LkSG) requires companies with at least 1,000 employees and a registered presence in Germany to identify, prevent, and remedy human rights and environmental risks across their supply chains, with core due diligence obligations remaining in force through the transition to EU-level CSDDD rules.
Next deadline:
July 26, 2029: LkSG obligations are expected to be replaced when CSDDD begins to apply at EU level, though Germany's final transposition law has not been confirmed.
LkSG required companies to submit an annual report to BAFA (The Federal Office for Economic Affairs and Export Control) documenting their due diligence activities. That reporting obligation was suspended in autumn 2025, and the Bundestag (German Federal Parliament) is advancing legislation to abolish it. The due diligence activities themselves (conducting risk analyses, implementing preventive and remedial measures, operating a complaints mechanism, and maintaining internal documentation) remain legally required.
Companies in scope today need documented, auditable processes for those obligations, regardless of the reporting status.
Regulation timeline
What the regulation requires
LkSG applies to companies with at least 1,000 employees and a registered presence in Germany. A registered presence includes a registered office, principal place of business, administrative headquarters, or a branch office.
In-scope companies must annually assess human rights and environmental risks across their own operations and all direct suppliers, implement preventive and remedial measures where risks are identified, operate a complaints mechanism accessible to affected parties, and maintain internal documentation of all due diligence activities for at least seven years. For indirect suppliers, the obligation to act is triggered by substantiated knowledge of a specific risk.
The Federal Office for Economic Affairs and Export Control (BAFA) enforces the law and can impose fines of up to EUR 8 million for serious violations, or up to 2% of annual global turnover for companies exceeding EUR 400 million in annual revenue.
Common LkSG implementation challenges
Risk analysis must cover every direct supplier, every year
LkSG requires annual risk analyses covering the company's own operations and all direct suppliers. The methodology must address human rights topics (forced labor, child labor, freedom of association, fair wages, and occupational safety) and environmental topics (soil contamination, water pollution, and obligations under the mercury and persistent organic pollutants conventions). It must be documented and repeatable, as supplier bases change continuously.
Indirect supplier obligations apply without a direct contractual relationship
Once substantiated knowledge of a risk at an indirect supplier exists, the due diligence obligation applies regardless of whether a direct relationship with that tier exists. Escalation paths, remediation plans, and the basis for the substantiated knowledge determination must all be documented.
BAFA investigates documentation quality, not report submission
BAFA can initiate investigations based on complaints or its own findings, independent of the annual report suspension. Investigations focus on the methodology behind risk analyses, records of preventive measures with dates and responsible parties, and complaint handling logs.
Germany's CSDDD transposition scope remains unconfirmed
The CSDDD (as revised by Omnibus I) entered into force on March 18, 2026, with member state transposition due by July 26, 2028. Whether Germany retains a scope closer to LkSG's 1,000-employee threshold or aligns to the CSDDD threshold of 5,000 employees and EUR 1.5 billion turnover has not been confirmed.
Document (LkSG) Due Diligence across every core obligation with the osapiens HUB
The osapiens HUB for Supply Chain Compliance, part of the Supplier Intelligence Suite, covers the four core obligations of LkSG: supplier risk analysis, preventive measure tracking, complaints management, and audit-ready documentation.
Run repeatable risk analyses across every direct supplier
The osapiens HUB for Supply Chain Compliance runs structured, repeatable risk analyses for direct suppliers using methodology that maps to LkSG's human rights and environmental risk catalog. Risk scoring draws on country, sector, and commodity-level data, surfaced in a supplier profile that holds the full history of assessments, measures, and outcomes. When a supplier relationship changes or a new risk signal appears, the platform flags it for review.
Collect supplier data once and apply it across LkSG, CSDDD, and EUDR obligations
The osapiens Supplier Portal, available in 29 languages at no license cost for suppliers, collects the declarations, certifications, and disclosures LkSG risk analysis requires. Supplier responses are automatically evaluated against risk criteria and linked to the measures implemented in response. The same supplier data layer feeds CSDDD due diligence and EUDR geodata collection without a second supplier engagement exercise.
Retain audit-ready documentation across every due diligence workflow
Every risk analysis, preventive measure, remediation action, and complaint record is retained with a full audit trail, including timestamps, responsible parties, version history, and linked source data. The same documentation structure covers CSRD value chain disclosures and Scope 3.1 supplier data, so data entered once for LkSG flows into CSRD reporting without duplication.
ADDITIONAL LKSG RESOURCES
Frequently Asked Questions (FAQ)
LkSG applies to companies with their registered office, principal place of business, administrative headquarters, or a branch office in Germany, with at least 1,000 employees. The employee count includes workers posted abroad and is calculated across the fiscal year. Companies that are part of a group are assessed on an entity basis, not on consolidated group headcount. The threshold has been at 1,000 employees since January 1, 2024.
In practice, yes. BAFA deactivated its reporting portal in November 2025 and stopped reviewing annual reports following a government instruction issued in September 2025. The Bundestag (German Federal Parliament) is advancing legislation to retroactively abolish the reporting obligation from January 1, 2023. Until that law formally passes, the obligation technically exists in the text of LkSG, but BAFA is not enforcing it. The core due diligence obligations (risk analysis, preventive and remedial measures, complaints mechanism, and internal documentation) remain fully in force and subject to BAFA investigation.
BAFA can impose fines of up to EUR 8 million or, for companies with annual global turnover exceeding EUR 400 million, up to 2% of annual global turnover for serious violations. Serious violations include failure to take timely preventive or remedial measures and failure to establish or operate a complaints mechanism. Under the pending LkSG amendment, failures such as not appointing a human rights officer or not conducting a risk analysis will no longer trigger fines. Companies found in serious breach can also be excluded from public procurement for up to three years.
LkSG distinguishes between direct suppliers (tier 1) and indirect suppliers (all further tiers). For direct suppliers, companies must conduct annual risk analyses and implement risk-proportionate preventive measures. For indirect suppliers, the obligation to act is triggered by "substantiated knowledge" of a specific human rights or environmental risk. Once that threshold is met, companies must conduct a risk analysis for the relevant indirect supplier, implement appropriate remedial measures, and document the response. Substantiated knowledge can arise from media reports, NGO disclosures, industry alerts, or supplier complaints, all of which require an active monitoring process.
The amended CSDDD entered into force on March 18, 2026. Member states, including Germany, must transpose it into national law by July 26, 2028, with obligations applying to in-scope companies from July 26, 2029. Germany intends to replace LkSG with a law implementing CSDDD obligations, but the final text, including whether Germany will align the scope exactly to the CSDDD threshold of 5,000 employees and EUR 1.5 billion turnover, has not been confirmed as of mid-2026. Companies in LkSG scope today who fall below the CSDDD EU-level threshold still need their current due diligence program to function until the national transposition law takes effect.
The osapiens HUB for Supply Chain Compliance structures due diligence workflows to satisfy LkSG's current requirements while building the documentation and supplier data a CSDDD program will need. Risk analyses, supplier assessments, and remediation records are stored with full audit trails. The same supplier profile that drives LkSG risk scoring also feeds EUDR geodata collection and CSRD value chain disclosures, so companies running multiple regulatory program do not maintain parallel supplier datasets. When Germany's CSDDD transposition law is finalised, the platform adapts to the new requirements without rebuilding the underlying data foundation.
The suspension of BAFA reporting does not reduce the underlying due diligence obligations, and BAFA continues to investigate on the basis of complaints and its own findings. Companies that have relied on the annual report as their primary compliance artifact need to confirm that their internal documentation is substantive enough to withstand a BAFA inquiry. The CSDDD framework is known in broad terms even without the German transposition text, and the investment in supply chain risk infrastructure, supplier data collection, and documented processes is directly transferable. Building that foundation now means the programme is functional before the transition deadline, not being assembled at speed once the law passes.