Skip to content

Every assessment connects conclusions to official sources.

Guide

CPSC eFiling: electronic certificates of compliance

What importers must file, when, and how — under the CPSC eFiling final rule.

By Regulatory Research Team, Market Access ResearchPublished 2026-09-27Last verified 2026-09-27 Fresh

# CPSC eFiling: electronic certificates of compliance

Short answer: Under the [CPSC eFiling](/glossary/efiling) final rule published 8 January 2025 (90 Fed. Reg. 1800), which amends 16 CFR Part 1110, importers of consumer products subject to a CPSC rule, ban, standard or regulation must electronically file certificate data at the time of entry. Filing is mandatory for most imports from 8 July 2026, and for goods withdrawn from Foreign Trade Zones from 8 January 2027.

Key facts

  • The final rule published 8 January 2025 (90 Fed. Reg. 1800) amends 16 CFR Part 1110, moving from certificates produced on request to certificate data filed at entry.
  • It covers importers of finished consumer products subject to a CPSC rule, ban, standard or regulation, including Children's Product Certificates (CPC) and General Certificates of Conformity (GCC).
  • It applies at every shipment value, including low-value entries that previously received informal low-documentation treatment.
  • The PGA message set in CBP's ACE system carries product identification, the certifying party, each safety rule certified to, manufacture and test details, and the test-record custodian's contact details.
  • Importers can file full data per entry, use disclaimer codes where a flagged HTS code needs no certificate, or pre-register certificates in the CPSC Product Registry and reference them per entry.
  • Mandatory for most imports from 8 July 2026; for goods withdrawn from Foreign Trade Zones for consumption or warehousing, from 8 January 2027.
  • The rule changes how certificate data is managed, not which products require a certificate.

1. What changed: from on-request to at-entry

Since 2008, importers of consumer products subject to CPSC safety rules have been required to maintain Certificates of Compliance, but those certificates only had to be produced when CPSC or CBP asked for them. In practice, that meant certificate data lived in filing cabinets and inboxes, inconsistent in format and often incomplete, and enforcement depended on physical examination or post-entry audit.

The eFiling final rule changes the timing and the medium. Importers must now transmit certificate data electronically into CBP's Automated Commercial Environment (ACE) at the time of entry, using the CPSC Partner Government Agency (PGA) message set. CBP shares the data with CPSC, which uses it to target high-risk shipments, verify compliance before release, and build enforcement intelligence. The policy logic is straightforward: structured data at entry lets the agencies screen every regulated shipment, not just the ones they physically examine.

For importers, the practical shift is from document storage to data management. The certificate still exists as a legal attestation, but its data elements must now be systematised, validated, and transmittable per entry line.

2. Who must file

The duty falls on the importer of record for finished consumer products subject to a mandatory CPSC safety rule. That includes children's products requiring a Children's Product Certificate (based on third-party testing by a CPSC-accepted laboratory) and general-use products requiring a General Certificate of Conformity. Private labellers and importers who specify the product are importers for this purpose; the duty follows the import transaction, not the brand name on the box.

Two scope points deserve attention. First, the rule applies at every shipment value, including entries that previously used informal low-documentation treatment and de minimis shipments. Low value does not mean low risk in the agencies' view, and small-parcel e-commerce is explicitly within the enforcement logic. Second, different lines in a single entry may use different filing methods: one line can carry full data, another can reference the Product Registry, and a third can carry a disclaimer code. Design the process line by line, not entry by entry.

3. What data is filed: the PGA message set

The PGA message set in ACE carries a defined set of certificate data elements for each regulated product line: product identification (sufficient to identify the finished product), the certifying party (the domestic manufacturer or importer certifying compliance), each CPSC safety rule, ban, standard or regulation certified to, the date and place of manufacture, the date and place of testing, and contact details for the custodian of the test records.

Each element has an operational implication. Product identification must tie the filing to the actual goods in the shipment; vague descriptions create mismatch risk. The safety rules cited must be the rules that actually apply to the product; citing the wrong rule is worse than citing none, because it signals the compliance analysis was not done. Manufacture and test dates and places must be real and current; stale test data attached to a new production run will not survive scrutiny. And the custodian contact must reach a person who can actually produce the test records, because the filing invites the follow-up request.

4. Filing options: full filing, disclaimers, and the Product Registry

Importers have three methods, usable in combination within a single entry. Full filing transmits the complete certificate data set in the PGA message set for the entry line; it is the default and the most transparent. Disclaimer codes are used where an HTS code flagged for CPSC review does not in fact require a certificate for the specific goods (for example, a product class that includes both regulated and unregulated items); the disclaimer tells the system why no certificate data accompanies the line. The CPSC Product Registry allows importers to pre-register certificate data and then file only a reference identifier per entry, which suits high-volume importers with stable product lines.

Choose the method per product line based on stability and volume: registry references for steady, high-volume SKUs; full filing for new, changed, or low-volume products where the data is freshly assembled; disclaimers only where genuinely applicable, with the analysis documented, because systematic disclaimer use on regulated goods is an enforcement signal.

5. Deadlines and the Foreign Trade Zone track

Filing is mandatory for most imports from 8 July 2026. For goods withdrawn from a Foreign Trade Zone for consumption or warehousing, the mandatory date is 8 January 2027, reflecting the different entry mechanics of FTZ withdrawals. Between the rule's publication and the mandatory dates, the programme has operated on a voluntary basis, with importer participation, system testing, and operational guidance releases.

Treat the mandatory dates as the date by which the full process must be working, not the date to start building it. The work includes mapping HTS codes to CPSC rules, confirming certificate data exists for every regulated SKU, registering with the Product Registry where that method will be used, configuring the ACE message set with the customs broker or software provider, and running test filings. Each of those steps has its own lead time, and the broker's readiness is not your readiness until you have tested your own data through the chain.

6. Preparation checklist for importers

Work through this sequence. First, inventory every imported SKU and map its HTS classification to the CPSC rules, bans, standards and regulations that apply; record the analysis, including why a flagged HTS code needs a disclaimer where applicable. Second, confirm that a current certificate exists for every regulated SKU, with the underlying test reports from the appropriate laboratory (CPSC-accepted third-party lab for children's products). Third, systematise the certificate data elements so they can be produced per shipment without manual reassembly: product identification, certifying party, rules cited, manufacture and test details, custodian contact. Fourth, decide the filing method per product line and register with the Product Registry where references will be used. Fifth, configure the PGA message set with the customs broker or ACE software provider and run test filings well before the mandatory date. Sixth, assign ownership: a named person responsible for certificate data quality, broker coordination, and CPSC correspondence.

ElementFull filingProduct Registry referenceDisclaimer
Data transmitted per entryComplete certificate data setReference identifier onlyDisclaimer code with reason
Best forNew, changed, or low-volume productsStable, high-volume SKUsFlagged HTS codes with no certificate requirement
Setup effortPer-entry data assemblyUpfront registration; light per-entryDocumented applicability analysis
Risk if misusedData errors per entryStale registry dataEnforcement signal if overused

Frequently asked questions

Does eFiling change which products need a certificate?

No. The rule changes how certificate data is managed (filed electronically at entry) not which products require a certificate. Any consumer product subject to a CPSC rule, ban, standard or regulation continues to require a Certificate of Compliance; eFiling is the new transmission mechanism for its data.

Do low-value and de minimis shipments have to eFile?

Yes. The rule applies at every shipment value, including entries that previously used informal low-documentation treatment. Build the process for small parcels with the same rigour as for container loads.

What is the CPSC Product Registry?

A system in which importers pre-register certificate data and then reference it by identifier in the per-entry PGA message set, instead of transmitting the full data set each time. It suits importers with stable, high-volume product lines and reduces per-entry data assembly.

When should we start testing with our broker?

As soon as the certificate data is systematised. The mandatory dates (8 July 2026 generally; 8 January 2027 for FTZ withdrawals) are the dates the process must be working, and broker configuration, message-set validation, and data quality fixes all take time. Test filings during the voluntary period are the low-risk way to find problems.

What happens if we fail to eFile after the mandatory date?

Expect shipment delays, increased examination and targeting, and enforcement exposure. CPSC has indicated it will use the submitted data to adjust risk scoring; missing or poor data marks the shipment as higher risk. The commercial cost of border delays on a just-in-time supply chain usually exceeds the cost of building the filing process properly.

Who is the importer for eFiling purposes when we use a customs broker?

The importer of record remains responsible for the certificate and its data. The broker transmits the PGA message set as your agent, but the duty, and the liability for inaccurate data, sits with the importer. Oversee the broker's work; do not outsource the responsibility.

Official sources

Last verified

September 2026. Dates verified against the Federal Register final rule. Filing mechanics and operational guidance continue to evolve; confirm the current CBP/CPSC implementation guides before configuring the ACE message set.

Ready? Check your product's requirements.

Common questions

Keep reading

Related guides

Keep reading

Related regulations

Keep reading

Related articles

Start free

Check a Product Free

Instant screen against verified regulations: evidence-backed, source-cited.

Check a Product FreeGet a Market Access Report

Free initial check, no signup required. Save or export after you see the result.