LkSG enters into force for companies with at least 3,000 employees and a registered presence in Germany.
LkSG: Supply chain due diligence obligations for German companies
The German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz, LkSG) requires companies with at least 1,000 employees and a registered presence in Germany to identify, prevent, and remedy human rights and environmental risks across their supply chains, with core due diligence obligations remaining in force through the transition to EU-level CSDDD rules.
Next deadline:
July 26, 2029: LkSG obligations are expected to be replaced when CSDDD begins to apply at EU level, though Germany's final transposition law has not been confirmed.
LkSG required companies to submit an annual report to BAFA (The Federal Office for Economic Affairs and Export Control) documenting their due diligence activities. That reporting obligation was suspended in autumn 2025, and the Bundestag (German Federal Parliament) is advancing legislation to abolish it. The due diligence activities themselves (conducting risk analyses, implementing preventive and remedial measures, operating a complaints mechanism, and maintaining internal documentation) remain legally required.
Companies in scope today need documented, auditable processes for those obligations, regardless of the reporting status.
Regulation timeline
What the regulation requires
LkSG applies to companies with at least 1,000 employees and a registered presence in Germany. A registered presence includes a registered office, principal place of business, administrative headquarters, or a branch office.
In-scope companies must annually assess human rights and environmental risks across their own operations and all direct suppliers, implement preventive and remedial measures where risks are identified, operate a complaints mechanism accessible to affected parties, and maintain internal documentation of all due diligence activities for at least seven years. For indirect suppliers, the obligation to act is triggered by substantiated knowledge of a specific risk.
The Federal Office for Economic Affairs and Export Control (BAFA) enforces the law and can impose fines of up to EUR 8 million for serious violations, or up to 2% of annual global turnover for companies exceeding EUR 400 million in annual revenue.
Common LkSG implementation challenges
Risk analysis must cover every direct supplier, every year
LkSG requires annual risk analyses covering the company's own operations and all direct suppliers. The methodology must address human rights topics (forced labor, child labor, freedom of association, fair wages, and occupational safety) and environmental topics (soil contamination, water pollution, and obligations under the mercury and persistent organic pollutants conventions). It must be documented and repeatable, as supplier bases change continuously.
Indirect supplier obligations apply without a direct contractual relationship
Once substantiated knowledge of a risk at an indirect supplier exists, the due diligence obligation applies regardless of whether a direct relationship with that tier exists. Escalation paths, remediation plans, and the basis for the substantiated knowledge determination must all be documented.
BAFA investigates documentation quality, not report submission
BAFA can initiate investigations based on complaints or its own findings, independent of the annual report suspension. Investigations focus on the methodology behind risk analyses, records of preventive measures with dates and responsible parties, and complaint handling logs.
Germany's CSDDD transposition scope remains unconfirmed
The CSDDD (as revised by Omnibus I) entered into force on March 18, 2026, with member state transposition due by July 26, 2028. Whether Germany retains a scope closer to LkSG's 1,000-employee threshold or aligns to the CSDDD threshold of 5,000 employees and EUR 1.5 billion turnover has not been confirmed.
Document (LkSG) Due Diligence across every core obligation with the osapiens HUB
The osapiens HUB for Supply Chain Compliance, part of the Supplier Intelligence Suite, covers the four core obligations of LkSG: supplier risk analysis, preventive measure tracking, complaints management, and audit-ready documentation.
Run repeatable risk analyses across every direct supplier
The osapiens HUB for Supply Chain Compliance runs structured, repeatable risk analyses for direct suppliers using methodology that maps to LkSG's human rights and environmental risk catalog. Risk scoring draws on country, sector, and commodity-level data, surfaced in a supplier profile that holds the full history of assessments, measures, and outcomes. When a supplier relationship changes or a new risk signal appears, the platform flags it for review.
Collect supplier data once and apply it across LkSG, CSDDD, and EUDR obligations
The osapiens Supplier Portal, available in 29 languages at no license cost for suppliers, collects the declarations, certifications, and disclosures LkSG risk analysis requires. Supplier responses are automatically evaluated against risk criteria and linked to the measures implemented in response. The same supplier data layer feeds CSDDD due diligence and EUDR geodata collection without a second supplier engagement exercise.
Retain audit-ready documentation across every due diligence workflow
Every risk analysis, preventive measure, remediation action, and complaint record is retained with a full audit trail, including timestamps, responsible parties, version history, and linked source data. The same documentation structure covers CSRD value chain disclosures and Scope 3.1 supplier data, so data entered once for LkSG flows into CSRD reporting without duplication.
ADDITIONAL LKSG RESOURCES
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290029-CMH 1790620759 2120258407
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290029-CMH 1790620759 2120258407
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290029-CMH 1790620759 2120258407
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290029-CMH 1790620759 2120258407
Varnish cache server