Skip to content

Home

French Duty of Vigilance: LdV Supply Chain Law

Since the French Duty of Vigilance Law came into force in 2017, NGOs and affected communities have filed multiple high-profile lawsuits — against TotalEnergies over its Tilenga oil project in Uganda and Tanzania, against EDF over a wind farm affecting indigenous communities in Mexico, and against BNP Paribas over fossil fuel financing. In 2023 alone, four new LdV cases were filed in French courts. None resulted in an operational suspension order, but each forced the defendant company to publicly disclose and — in some cases — substantially revise its vigilance plan. The law is no longer a dormant obligation. It is being actively litigated.

The French Duty of Vigilance Law (Loi de Vigilance — LdV, Law No. 2017-399) was the first mandatory human rights and environmental due diligence law in Europe. It requires large French companies to establish, publish, and implement a vigilance plan covering their own operations, those of their subsidiaries, and those of their suppliers and subcontractors. On the Sustalium platform, we now hear from French procurement teams asking suppliers to provide structured ESG and supply chain data specifically to feed into the parent company's vigilance plan — and if a supplier cannot produce the data, they get replaced.

Supplier Onboarding Compliance Software

Manually onboarding a new supplier means chasing emails, verifying certificates one by one, re-entering data into spreadsheets, and hoping nothing slips through the cracks. It is slow, error-prone, and scales poorly. Supplier onboarding compliance software solves this by replacing manual workflows with automated data collection, risk scoring, and document verification — all in one place.

US Apparel Compliance: Flammability, Labeling & Rules

Apparel compliance in the United States is deceptively fragmented. The federal requirements are relatively minimal — a flammability standard, a fiber content label, and a country of origin marking. But state-level obligations — California's Proposition 65, the emerging NY Fashion Act, PFAS restrictions across multiple states, and packaging heavy metal rules — add layers of compliance that many apparel importers discover only at the point of enforcement.

This guide maps every US compliance requirement for apparel and textiles, from the federal baseline through the state-level obligations that increasingly define market access.

FSC Chain of Custody Certification Software

If you buy or sell FSC-certified materials, you know the administrative burden of collecting, verifying, and sharing certificates. Buyers demand proof before every transaction, suppliers scramble to find the latest PDF, and someone on your team manually checks expiry dates and scope codes. This process breaks down as soon as you handle more than a handful of certifications — and a single lapse can cost you a sale or put your own chain of custody at risk.

ISO 27001 Certification: ISMS & Buyer Sharing

As of the ISO Survey 2023, there were 71,549 valid ISO 27001 certificates across 175 countries — making it the second most adopted ISO management system standard after ISO 9001. In a 2024 Vanta survey, 78% of companies reported that ISO 27001 certification directly helped them close deals faster. The transition from ISO 27001:2013 to ISO 27001:2022 completed in October 2025, and any organization still holding a certificate against the 2013 version must now recertify against the updated standard. The market message is unambiguous: in B2B procurement, ISO 27001 has become less a security posture indicator and more a market access prerequisite.

ISO 27001 is the international standard for Information Security Management Systems (ISMS). For B2B companies — SaaS platforms, IT service providers, cloud infrastructure companies, and any organization handling client data — it is the single most requested compliance credential in vendor assessments. On the Sustalium platform, we see the real bottleneck is rarely the technical controls themselves — it is the inability to produce the certificate, Statement of Applicability, and audit reports in a single verifiable package when procurement asks for them.

US Toys: CPC, ASTM F963 & State Requirements

Toys are the most heavily regulated consumer product category in the United States — and the compliance path is fundamentally different from general consumer goods. The key difference is that toys require a Children's Product Certificate (CPC) , not the General Certificate of Conformity (GCC) that covers adult products. The CPC demands third-party testing at a CPSC-accepted laboratory, additional chemical restrictions beyond what applies to general consumer goods, and specific labeling requirements — including a tracking label on every product.

This guide covers every compliance requirement for toys sold in the US, from federal testing standards to state-level chemical warnings, and compares the US framework to the EU Toy Safety Directive for brands selling in both markets.

Canada Bill S-211 Compliance Software

Canada Bill S-211 — the Fighting Against Forced Labour and Child Labour in Supply Chains Act — came into force on January 1, 2024. It requires many businesses and government institutions to file an annual report with the Minister of Public Safety detailing the steps they have taken to prevent and reduce the risk of forced labour and child labour in their supply chains. For procurement, legal, and sustainability teams, the reporting burden is real — and the penalties for non-compliance can be severe. Sustalium's Canada Bill S-211 compliance software turns this annual headache into a guided, automated workflow that maps directly to Public Safety Canada's expectations.

EU MDR Class I Device Compliance Guide

In 2024, the European Commission acknowledged that only 45 Notified Bodies had been designated under the MDR — down from roughly 80 under the previous Medical Device Directive. The resulting bottleneck has delayed recertification across all device classes, and several EU Member States have reported that up to 20% of Class I manufacturers had not fully transitioned their technical documentation from MDD to MDR format during spot checks. A non-sterile Class I device may not need a Notified Body, but that self-declaration must still be built on the new regulation's structure — and outdated documentation is treated the same as no documentation during a competent authority audit.

Under the EU Medical Device Regulation (MDR — Regulation [EU] 2017/745), all medical devices placed on the European market require a Declaration of Conformity. Class I devices are the lowest-risk category but the documentation burden is far from trivial. On the Sustalium platform, the area where we see Class I manufacturers submit incomplete documentation most frequently is the new clinical evaluation and post-market surveillance requirements — obligations that simply did not exist under MDD.

Selling Cosmetics in the US and EU: MoCRA vs. CPSR

A cosmetic brand selling in both the United States and the European Union must comply with two regulatory frameworks that are structurally similar but operationally distinct — and neither framework accepts the other's documentation. The US system, modernized in 2022 by MoCRA, emphasizes manufacturer self-declaration of safety. The EU system, established under the Cosmetic Products Regulation (EC) 1223/2009, requires a qualified safety assessor to prepare a formal Cosmetic Product Safety Report (CPSR) and mandates notification to the EU's Cosmetic Product Notification Portal (CPNP) before the product reaches the market.

For brands selling in both markets, the compliance cost is additive — you need both a MoCRA safety substantiation and an EU CPSR. But the ingredient data and toxicological assessments that support one can inform the other, and building both in parallel from the same product data is significantly more efficient than treating them as separate compliance projects.

SOC 2 Type II Report Software

The average SOC 2 audit costs between $30,000 and $100,000 and consumes months of engineering time. Without dedicated software, security teams drown in spreadsheets, screen captures, and manual log collection — and still face costly audit failures when evidence falls short. A SOC 2 Type II report demands twelve months of continuous, defensible evidence — and most teams realise too late that their manual processes cannot deliver it.