Compliance stacking: EUDR, NIS2, CSDDD and VS-Standard at once as an SME
Five years ago, an SME supplier faced an ISO question at most. Now the European obligations are stacking up: sustainability (VS-Standard/CSRD), human rights (CSDDD), cybersecurity (NIS2) and, more recently, deforestation (EUDR). All of it through the same large customers.
Why it all lands on your desk
You yourself rarely fall directly under these laws — they apply to large companies. But those companies pass their obligations down the chain. The result: four kinds of questionnaires, four departments, four formats, the same underlying data.
Where the rules overlap — and where they don't
Policies and codes of conduct partly overlap (CSDDD and the social VS data points touch each other). But NIS2 asks for technical cybersecurity the others do not, and EUDR asks for plot-level data that is unique. Treat them as complementary, not as duplicates.
The Omnibus relief (March 2026)
The Omnibus Directive 2026/470 narrowed the direct CSRD obligation to companies with more than 1,000 employees and €450 million in revenue. That eases the direct burden, but changes nothing about the indirect pressure: your large customers still fall under it and still need your data.
One profile for all four
verified.supply bundles the VS-Standard, the CSDDD declaration, the NIS2 assessment and the EUDR module into a single supplier profile. You complete each part once and share it with every customer who asks — regardless of which of the four rules is driving them.
Read also
Build your VS profile (formerly VSME) once
Create an account and get started today.
No password needed — we email you a login link.