Disclaimer: New EUDR developments - December 2025
In November 2025, the European Parliament and Council backed key changes to the EU Deforestation Regulation (EUDR), including a 12‑month enforcement delay and simplified obligations based on company size and supply chain role.
Key changes proposed:
These updates are not yet legally binding. A final text will be confirmed through trilogue negotiations and formal publication in the EU’s Official Journal. Until then, the current EUDR regulation and deadlines remain in force.
We continue to monitor developments and will update all guidance as the final law is adopted.
An EUDR stack is essential to automate the complex due diligence and data management needed to prove that products are deforestation-free and legally sourced, as required for compliance. Compliance means submitting a Due Diligence Statement (DDS) before every shipment is dispatched. Following the formal adoption of the delay through Regulation (EU) 2025/2650 on 19 December 2025, large and medium operators and non-SME traders must comply by 30 December 2026 . Micro and small operators established as such by 31 December 2024 have until 30 June 2027 to comply, with the exception of micro and small operators who were already subject to obligations under the EU Timber Regulation - they follow the 30 December 2026 deadline.
An EUDR stack is the set of software systems and data processes that work together to fulfil the regulation’s requirements. At its core, it connects three data domains: supply chain origin data (geolocation, harvest dates, commodity details), risk assessment data (deforestation check results, legality evidence), and compliance records (DDS submissions, reference numbers, audit trail).
The stack can be built from a single purpose-built EUDR platform, or assembled from multiple tools — ERP, supplier portal, geospatial service, and DDS submission module — integrated with each other. The choice depends on your company’s scale, existing systems, and supply chain complexity.
The December 2025 revision of the EUDR introduced three distinct compliance roles with different stack requirements:
Upstream operators (first placers on the EU market) need the full stack: supplier data collection, geolocation verification, risk assessment, DDS generation, and IS submission.
Downstream operators (those placing products already covered by an upstream DDS) need a lighter stack focused on: receiving and storing DDS reference numbers from upstream suppliers, registering in the Information System (non-SME downstream operators only), and flagging any substantiated concerns.
Micro and small primary operators (in low-risk countries, sourcing own commodities) need the lightest stack of all: information collection under Article 9 and one-off simplified declaration submission to the Information System. They are not required to perform risk assessment or mitigation.
This is where geolocation coordinates, harvest dates, legality documents, and commodity details are gathered from producers or direct suppliers. The data collection layer must handle structured and unstructured inputs — GeoJSON files, scanned documents, supplier questionnaire responses — and link them to specific product batches or shipments.
For micro and small primary operators, the data collection layer needs to support postal address submission as an alternative to GPS coordinates, where the address clearly corresponds to the plot location.
The risk assessment engine evaluates whether a sourcing origin presents a negligible, standard, or non-negligible deforestation risk. It draws on country risk classifications, satellite deforestation monitoring, and legality checks to produce a documented risk conclusion for each product.
Note: operators sourcing entirely from countries classified as low-risk under Commission Implementing Regulation (EU) 2025/1093 (22 May 2025) are not required to run risk assessment or mitigation steps under Articles 10 and 11. Their stack can skip the risk assessment engine for those supply chains, unless new information indicates a risk of non-compliance.
This module compiles the collected data and risk conclusions into the correct EU format and submits them to the EUDR Information System. It must support both full DDS submissions and simplified declarations (for micro and small primary operators).
The Information System API has been available for bulk machine-to-machine submissions since Q2 2024. Stacks that integrate directly via API avoid manual data entry and reduce submission errors at scale.
For downstream operators and traders, the stack needs to receive, store, and — if relevant — pass on DDS reference numbers from upstream suppliers. This is a passive function: the Guidance Document (3rd edition) confirms that downstream actors are not required to investigate or proactively request reference numbers. The obligation is reactive.
All EUDR documentation must be retained for at least five years. The records layer stores DDS submissions, risk assessment documentation, supplier correspondence, geolocation files, and legality evidence in a retrievable, audit-ready format.
For most operators, the EUDR stack does not stand alone — it needs to pull product and order data from existing ERP or supply chain management systems. Integration points typically include: product catalogue (commodity, HS code, description), purchase orders (supplier, quantity, origin), and inbound shipment records.
Connecting the EUDR stack to the ERP ensures that every shipment triggers the due diligence workflow automatically, rather than relying on manual tracking.
Certifications such as FSC, RSPO, and Rainforest Alliance can be incorporated into the EUDR stack as supporting evidence during risk assessment and risk mitigation steps. They do not replace due diligence — the Guidance Document confirms that operators must exercise due diligence prior to placing relevant products on the market or exporting them. However, certifications can support the EUDR due diligence by being used as a risk mitigation measure, but only if the specific risk is clearly understood. For a detailed scheme-by-scheme breakdown of what FSC, RSPO, Rainforest Alliance and other certifications actually cover, see our certification schemes guide.
A downstream operator’s stack is significantly lighter than an upstream operator’s. It needs to: receive and store DDS reference numbers from their direct upstream supplier; register the company in the Information System (if a non-SME); and log any substantiated concerns for reporting purposes. No risk assessment or DDS submission capability is required.
Micro and small primary operators submit a one-off simplified declaration rather than a DDS per shipment. Their stack needs to support: information collection under Article 9 (including postal address as an alternative to GPS coordinates); and submission of the simplified declaration to the EUDR Information System. Risk assessment and mitigation components are not required. Cooperatives and associations can submit simplified declarations on behalf of members where they act as the placing entity.
The country risk classification adopted via Commission Implementing Regulation (EU) 2025/1093 (22 May 2025) affects which components of the stack need to be active for a given supply chain. For supply chains from low-risk countries, the risk assessment engine can be bypassed unless new information indicates non-compliance. For standard- and high-risk supply chains, the full assessment and mitigation workflow must run. A well-architected stack should be configurable by country risk level.
No. EUDR guidance declares that operators must exercise due diligence prior to placing relevant products on the market or exporting them. However, certifications can support EUDR due diligence by being used as a risk mitigation measure , but only if the specific risk is clearly understood. For a detailed scheme-by-scheme breakdown of what FSC, RSPO, Rainforest Alliance and other certifications actually cover, see our certification schemes guide.
The Commission’s simplification review (COM(2026) 191 final, 4 May 2026) and the updated Guidance Document (3rd edition) clarify how the technology and data layer of an EUDR stack needs to accommodate the changes introduced by Regulation (EU) 2025/2650.
Information System changes. The EUDR Information System is being upgraded and is planned to reopen in June 2026 for both the training and production environments. New features being added include: simplified declaration submission for micro and small primary operators; registration of new compliance roles (downstream operators, non-SME and micro/small primary operators); voluntary grouping of DDS reference numbers; and updated API specifications for bulk machine-to-machine submissions. The API for bulk submissions has been available since Q2 2024. Stacks that integrate directly via API will accommodate these changes more smoothly than those relying on manual web interface entry.
Downstream operator role in the stack. The Guidance Document (3rd edition) confirms that the obligation of downstream operators and traders to collect reference numbers is passive. They are not required to investigate or proactively request information from their supply chain. For stacks serving downstream operators, this means the data collection layer needs to support receiving and storing DDS reference numbers passed on by upstream actors — not originating a full due diligence workflow.
New repositories as a reference layer. The Commission plans to launch two new repositories before the December 2026 application date: one listing relevant legislation of countries of production (supporting Article 9(1)(h) legality checks), and one listing certification schemes applicable to EUDR commodities. These will form a useful reference layer for teams building legality assessment workflows into their stacks.
Our research team walks you through every step - from supplier engagement to submitting in TRACES.

This free compliance checker scans your packaging documentation and maps it against mandatory PPWR data requirements, giving you a clear view of your compliance status. Get actionable insights on documentation gaps before they become compliance issues.
Get your systems ready for traceability, risk assessment and due diligence.
