EU Compliance for U.S. Companies
The EU Gateway for U.S. Companies.
Any connection to the EU — ownership, customers, suppliers, or digital services — triggers compliance obligations under an expanding set of regulations. Regweaver helps you map your exposure and operationalise compliance across your entire value chain.
What's your EU connection?
Regulations that apply to you.
CSRD
Corporate Sustainability Reporting Directive
Requires structured sustainability reporting including value chain data. Your EU entity or EU customers will need Scope 3 emissions, supplier attestations, and lifecycle metrics from you.
- EU companies: >1,000 employees AND >€450M net turnover (both required)
- Non-EU companies: >€450M EU net turnover (2 of last 3 years) + an EU 'large undertaking' subsidiary (2 of 3: >250 employees / >€50M turnover / >€25M balance sheet) OR an EU branch with >€50M turnover
- Wave 1 (PIEs >500 employees) already reporting — temporary exemptions possible
- Indirect: suppliers receive data requests, but SME burden now capped by Omnibus
- Value-chain cap: the cap on what in-scope companies may request from smaller value chain partners is created by the Directive (Accounting Directive as amended); the voluntary standard (VS) delegated act supplementing Directive 2013/34/EU — adopted 3 July 2026, in Parliament/Council scrutiny, not yet applicable — defines its informational boundary. The cap is not restated in figures here until the act is published in the Official Journal.
CSDDD
Corporate Sustainability Due Diligence Directive
Mandates human rights and environmental due diligence across the entire value chain. EU companies must ensure their U.S. suppliers meet these standards — or face enforcement.
- EU companies: >5,000 employees AND >€1,500M worldwide net turnover
- Non-EU companies: >€1,500M net turnover generated in the EU
- Transposition deadline: 26 July 2028 — application: 26 July 2029
- Indirect: due diligence obligations flow through the entire value chain
NIS2
Network and Information Security Directive
Cybersecurity governance at board level. EU entities must prove their suppliers' security posture — meaning U.S. vendors will be asked to provide risk policies, certifications, and incident data.
- Essential entities: 250+ employees OR €50M+ turnover in Annex I highly critical sectors
- Important entities: medium-sized (50+ employees OR €10M+ turnover) across NIS2 Annex I and II sectors
- Non-EU: applies if you provide services within the EU in a defined sector (EU representative required)
- Indirect: suppliers to essential/important entities — obligations via contract
Thresholds reflect the EU Omnibus I Directive (entered into force March 2026). Scope may vary by Member State transposition.
The cost of inaction.
Even if your company isn't legally bound under EU jurisdiction, the consequences of non-compliance are real and immediate.
Contract loss
EU partners are required to ensure supplier compliance. Failure to provide structured evidence means lost contracts — not just risk.
Value chain exclusion
Under CSDDD, EU companies must exclude non-compliant suppliers from their value chain. No data, no relationship.
Reputational exposure
Non-compliance is public. EU enforcement databases, investor screening, and media coverage create reputational risk that crosses borders.
Board accountability
NIS2 and CSDDD make cybersecurity and due diligence a board-level responsibility. U.S. parent companies inherit this governance obligation.
Built for regulator-grade evidence.
Regweaver doesn't generate reports from templates. It structures your value chain data according to how EU regulators actually work — EFRAG standards, ESRS data points, NIS2 frameworks — so your evidence is audit-ready from day one.
- Every data point mapped to its regulatory source
- Activate the regulations that apply to you
- Collect and structure evidence across entities
- Track, respond, and stay audit-ready
Ready to map
your EU exposure?
Start with your value chain. Activate the regulations that matter. Get audit-ready — without the complexity.

