Top rated on OMR Reviews, Trusted, G2, and others
Our customers value ContractHero for efficiency, reliability and first-class support.
The due diligence requirements under the LkSG remain in effect; you must demonstrate compliance internally, even without a BAFA report.
ContractHero helps procurement, legal, and compliance teams centrally review supplier contracts, maintain risk classifications, and document evidence right where the contract is located.

Risk analysis, preventive measures, and corrective actions always relate to specific suppliers and, therefore, to specific contracts. Missing codes of conduct, unagreed-upon monitoring rights, or expired certificates remain undetected when scattered across various drives and end up costing time and money—at the latest—when the next customer inquiry or complaint arises.
I don't know which supplier contracts are missing the LkSG clauses.
If we have reliable information, we must react immediately and start searching right away.
I am responsible for due diligence without having a complete picture of the supply chain.

ContractHero uses centralized templates and checks existing contracts for the clauses required by the Supply Chain Act. The code of conduct, monitoring rights, subcontracting, and sanctions are clearly displayed for each contract.
The risk analysis requires prioritization by product category, country of origin, and criticality. For indirect suppliers, this obligation applies on a case-by-case basis as soon as substantiated information becomes available. ContractHero categorizes this information based on the contract’s characteristics.


Code of Conduct certifications, self-declarations, audits, and certificates document working conditions and environmental standards. They expire, usually unnoticed. ContractHero tracks them along with their validity periods and sends timely reminders to the appropriate individuals.
The CSDDD replaces the Supply Chain Act and will take effect on July 26, 2029. Those who currently include clause sets, risk classes, and supporting documentation in their contracts will simply need to expand the fields in 2029, rather than having to process their existing data a second time.

Demonstrably fulfill due diligence obligations without management having to make decisions blindly.
.avif)
Management can document which measures were taken, when, and by whom.
Missing clauses and expired documentation are noticed before they become an issue.
Customer inquiries regarding due diligence measures can be answered in minutes with supporting documentation.
Risk analyses, clauses, and certificates are attached to the respective contract in an audit-proof manner.
ISO 27001, the GDPR, German data centers, and granular access rights protect sensitive documents.
The current structure will be expanded in 2029, not replaced.
Enterprise-level security standards with ISO 27001 certification, GDPR compliance, and hosting in Germany, as well as clear roles, permissions, and a traceable change history for audit security.

Our customers value ContractHero for efficiency, reliability and first-class support.

_BestSupport_QualityOfSupport%20(5).png)


The LkSG has been directly applicable since January 1, 2024, to companies with headquarters or a branch in Germany and at least 1,000 employees in the country; temporary agency workers are counted after six months. Indirectly, significantly more companies are affected, as large clients pass on their obligations contractually through codes of conduct, audit rights, and documentation requirements. For many small and medium-sized enterprises, this requirement thus arises from the customer contract, not from the law.
Not yet. On September 3, 2025, the Federal Cabinet approved a draft bill intended to eliminate the annual reporting requirement entirely and limit fines to serious violations. The Bundestag debated the bill in its first reading on January 16, 2026. Until the bill is enacted, the LkSG remains in effect unchanged. However, the BAFA has not been reviewing company reports since fall 2025. Due diligence obligations remain in place and must be documented internally.
Common provisions include a code of conduct as part of the contract, obligations to provide information and disclosure, audit and monitoring rights, the requirement to pass on these requirements to subcontractors, training commitments, and the right to terminate the contract and impose sanctions in the event of serious violations. What is appropriate in each individual case depends on the risk analysis and the product category, and blanket clauses are subject to review under the law governing standard terms and conditions. This should be included in the legal review.
“Substantiated knowledge” refers to reliable evidence of a potential violation by an indirect supplier, such as information from government agencies, reports on conditions in the production region, or the supplier’s involvement in a high-risk industry. Once such evidence is identified, a risk analysis must be conducted immediately, and a plan to minimize risk must be implemented. The key factor at this point is how quickly the relevant contracts can be located.
The Supply Chain Act does not require a guarantee, but rather appropriate measures. Four criteria determine the extent of these measures: the nature and scope of business activities, the ability to influence the party responsible, the likelihood of a violation, and the severity of the potential harm. What this means in concrete terms has not been definitively clarified. This makes it all the more important to maintain transparent documentation of one’s own assessment.
The CSDDD is intended to replace the national supply chain law. Under the Omnibus I package, it applies to EU companies with more than 5,000 employees and global net revenue exceeding 1.5 billion euros; it must be implemented by July 26, 2028, and take effect on July 26, 2029. Fines are capped at 3 percent of global net revenue. In Germany, a law on international corporate responsibility is expected to follow. (As of September 2026)