CPSC eFiling: A Practical Guide for Importers of Consumer Products
CPSC eFiling has been mandatory since July 8, 2026. Who must file, the 7 certificate data elements, filing options, and how to prepare your products.
By Complir
CPSC eFiling is the requirement to submit certificate of compliance data electronically to US Customs and Border Protection (CBP) when a regulated consumer product is imported into the United States. Under the US Consumer Product Safety Commission's (CPSC) final rule at 16 CFR Part 1110, eFiling became mandatory on July 8, 2026 for most imports, and it extends to products entered from Foreign Trade Zones on January 8, 2027.
The rule affects any company that imports regulated consumer products into the US: US brands that manufacture overseas, retailers importing private-label goods, and foreign brands shipping to US customers. A certificate that used to sit in a folder until someone asked for it now has to exist as structured data, per product, at the moment of entry. If your certificate data is scattered across supplier test reports, emails and spreadsheets, the border is where that gap will show.
This guide explains what CPSC eFiling requires, who is responsible for filing, what data you need, and how to prepare your product portfolio.
The Basics
What CPSC eFiling is, which certificates it covers, and when it applies
What is CPSC eFiling?
CPSC eFiling is the electronic transmission of the data elements from a certificate of compliance through CBP's Automated Commercial Environment (ACE), the US system for processing imports. The rule was published in the Federal Register on January 8, 2025 and took effect 18 months later.
The obligation to certify products is not new. Section 14 of the Consumer Product Safety Act (CPSA) has long required importers and manufacturers of regulated products to issue certificates. What changed on July 8, 2026 is that the certificate data must now be filed electronically with the entry, not just kept on file.
According to CPSC, the program followed more than a decade of development, including pilot testing from 2016 to 2024. The stated purpose is to help CPSC target non-compliant and dangerous products at US ports.
Which certificates does eFiling cover?
eFiling covers the two types of certificate required under the CPSA:
- A General Certificate of Conformity (GCC) is the certificate for non-children's products subject to a CPSC rule, ban, standard or regulation. It must be based on a test of each product or a reasonable testing program.
- A Children's Product Certificate (CPC) is the certificate for children's products, meaning products designed or intended primarily for children 12 and under. It must be based on testing by a CPSC-accepted third-party laboratory.
If your products fall under a CPSC requirement (for example children's products, toys, certain textiles, or products covered by mandatory safety standards), a certificate is required and its data must be eFiled at import.
When did CPSC eFiling become mandatory?
CPSC eFiling became mandatory on July 8, 2026 for regulated products imported for consumption or warehousing. For products entered into a Foreign Trade Zone and then entered for consumption or warehousing, the requirement applies from January 8, 2027.
| Date | Milestone |
|---|---|
| January 8, 2025 | Final rule on certificates of compliance (16 CFR Part 1110) published in the Federal Register |
| August 29, 2025 | US suspends the de minimis exemption for all countries (Executive Order 14324) |
| June 24, 2026 | CBP makes the de minimis suspension permanent for all modes except international post |
| July 8, 2026 | eFiling mandatory for regulated imports entered for consumption or warehousing |
| January 8, 2027 | eFiling extends to products entered from Foreign Trade Zones |
Who Must File
The importer of record carries the obligation, but the data often sits elsewhere
Who is responsible for CPSC eFiling?
Under 16 CFR 1110.13, the "finished product certifier" is responsible for eFiling the certificate data for imported products. For imports, the rule defines this party as the importer, meaning the Importer of Record (IOR) eligible to make entry under the Tariff Act. If the IOR is a customs broker, the rule allows the broker to identify the owner, purchaser or consignee as the party responsible for the certificate requirements.
In practice, the obligation lands on these groups:
- US brands that manufacture overseas. A US company sourcing from factories in Asia, Europe or elsewhere is typically its own IOR, and files certificate data at every entry.
- US retailers and distributors that import directly. This includes private-label goods and products bought from foreign suppliers, where the retailer is the IOR.
- Foreign brands shipping to US customers. A non-US company that ships DDP (Delivered Duty Paid), runs its own US e-commerce fulfillment or imports through a US subsidiary may be the IOR itself.
CPSC states that eFiling does not apply to domestic US manufacturers. They must still issue a certificate on or before the date the product is distributed in commerce, and make it available to CPSC within 24 hours of a request, under 16 CFR 1110.13(a)(2). They just do not file at entry.
Can a manufacturer or supplier file on behalf of the importer?
Yes, with permission. CPSC's eFiling Quick Start Guide notes that trade partners can act on the importer's behalf, for example by entering certificates into the Product Registry or filing message sets in ACE, "if granted appropriate permissions." The importer remains responsible.
This lets the work sit with whoever holds the product data. A factory can maintain certificates for the products it makes, or a brand can maintain them for its distributors, while the IOR's broker files at entry.
The Seven Data Elements
What every certificate must contain, and where importers usually get stuck
What data does a CPSC eFiling certificate need?
16 CFR 1110.11(a) sets seven data elements that every finished product certificate must contain. These are the fields you will eFile:
- Product identification. At least one unique identifier (GTIN, model number, registered number, serial number, SKU, UPC or an alternate identifier) plus a description sufficient to match the product to the certificate.
- Citations. Each CPSC rule, ban, standard or regulation the product is certified to.
- Certifier identification. The finished product certifier's name, street address, city, state or province, country, email and telephone number.
- Records contact. Name and full contact details of the individual who maintains the test records on the certifier's behalf.
- Date and place of manufacture. Month and year at a minimum, plus the manufacturer's name, full address, email and telephone number.
- Date and place of testing. The most recent test date, and the name and full contact details of each laboratory or other party whose testing the certificate relies on.
- Attestation. A statement by the certifier that the product complies and the information is accurate, acknowledging that a knowingly false statement is a US federal crime.
Certificates must be in English, according to 16 CFR 1110.9(a). They may also include other languages. The certifier must keep supporting records for five years from creation, under 16 CFR 1110.17.
For most importers, elements 5 and 6 are the hardest to keep current. The manufacturing date and factory details come from suppliers and change with each production run, and the testing details depend on reports the importer often did not commission itself.
How does CPSC check the testing lab?
CPSC's eFiling implementation guide (CATAIR) makes lab status checkable at the border. When a certificate lists an independent third-party lab, the filer must reference it by its four-digit CPSC Lab ID, taken from CPSC's published list of accepted labs. This applies to the third-party testing required for children's products. A supplier's test report from a lab that is not on the list will not support a Children's Product Certificate.
“eFiling does not create a new compliance obligation; it exposes the quality of the one you already had. A certificate that was assembled once from a supplier PDF and filed away cannot survive being transmitted at every entry. The teams that handle this well stop thinking of certificates as documents and start treating them as product data: one record per SKU, linked to the rules it is certified to and the test reports that actually support it, updated whenever the factory, the batch or the lab changes.”
Complir Team
Product Compliance, Complir
Filing Options
Full PGA Message Set versus the CPSC Product Registry
CPSC offers two ways to transmit certificate data through ACE. Both use CPSC's Partner Government Agency (PGA) Message Set, the structured data format other government agencies use to collect data at entry.
Full PGA Message Set. The filer transmits all seven certificate data elements in ACE at the time of entry. CPSC's Quick Start Guide recommends this for importers with limited regulated products or items that are not imported repeatedly.
Reference PGA Message Set. The certifier (or a permitted trade partner) enters the certificate data once into the CPSC Product Registry, a CPSC-hosted repository for certificate data. At entry, the broker transmits only the certificate identifier. CPSC recommends this route for companies that repeatedly import the same certified products.
Note that the Product Registry does not connect to ACE directly. According to CPSC, it "serves as a stand-alone central data repository and does not communicate with CBP's ACE system." Your broker still has to file the reference at each entry.
For most importers with recurring SKUs, the Reference route will be the practical choice. It separates the compliance work (keeping the certificate accurate) from the logistics work (filing the entry), which usually sit with different teams or companies.
What about de minimis and mail shipments?
Under 16 CFR 1110.13(a)(1), certificate data for products imported by mail or under the de minimis duty exemption must be entered into the Product Registry before the products arrive in the United States. In practice, this route now matters mainly for postal shipments. The US suspended the de minimis exemption for all countries from August 29, 2025 under Executive Order 14324, and CBP made the suspension permanent in its regulations on June 24, 2026 for every mode of transport except the international postal network. Low-value shipments by courier, air cargo or freight now go through a regular customs entry, which carries the CPSC PGA Message Set like any other import.
What happens if CPSC certificate data is missing?
Missing CPSC data does not automatically reject an entry in ACE. In a CBP message to the trade (CSMS #69177694), CPSC confirmed that it has not required CBP to reject entries for missing PGA Message Set data, unlike some other agencies.
That does not make eFiling optional. The filing obligation under 16 CFR 1110.13 still applies, and CPSC uses the data to target shipments for inspection. Under Section 17(a)(2) of the CPSA (15 U.S.C. 2066(a)(2)), a consumer product offered for import that is not accompanied by a required certificate, or is accompanied by a false one, must be refused admission into the US.
The honest read: the risk right now is not a hard stop at the border but a greater chance of being held and inspected.
EU and Non-US Brands
Why the importer of record and EU test reports are the two most common gaps
Foreign brands face the same seven data elements, but two issues come up more often.
First, the IOR is not always obvious. If you sell to a US distributor or retailer who imports the goods, that company is typically the IOR and the certifier. They still need your certificate data to file, and they may make it a condition of the purchase order. If you ship DDP or fulfill US orders yourself, the obligation may sit with you or your US entity. Map the IOR per sales channel before assuming someone else is filing.
Second, testing done for other markets does not transfer automatically. A certificate must cite the specific CPSC rules the product complies with, such as ASTM F963 for toys under 16 CFR Part 1250, and the testing must support those rules. Testing to EN 71 for EU toy safety does not by itself show compliance with ASTM F963, even where the tests overlap. For children's products, the lab must also be CPSC-accepted.
This is where EU brands most often hit trouble. The test report exists, but it was commissioned for the EU market, cites EU standards, or was issued by a lab not on CPSC's accepted list. The same pattern shows up in the other direction: a US certificate does not replace the technical file behind CE marking or the safety documentation required under the EU General Product Safety Regulation.
How to Prepare
A practical sequence for getting a product portfolio eFiling-ready
Getting ready for eFiling is mostly a data problem. The following steps follow the structure of CPSC's own Quick Start Guide, adapted for a brand or retailer rather than a customs broker.
Identify which imported products are CPSC-regulated
Not every consumer product needs a certificate. List the SKUs you import, check which fall under a CPSC rule, ban or standard, and flag the children's products that require a CPC.
Confirm the importer of record per channel
Direct imports, wholesale, DDP e-commerce, marketplace fulfillment and subsidiaries can all have different IORs. The eFiling obligation follows the IOR, so map it per route to market.
Collect certificate data from suppliers
Manufacturing date and place, factory contact details and test reports usually sit with suppliers. Agree what they send, in what format, and when, ideally before each shipment leaves the factory.
Check your testing against CPSC rules
For each regulated SKU, confirm the test report cites the relevant CPSC rules and, for children's products, that the lab is on CPSC's accepted list with a valid Lab ID.
Structure the seven data elements per product
Build one record per SKU with identifier, citations, certifier, records contact, manufacturing, testing and attestation. Plan how manufacturing fields update with each production run.
Choose Full or Reference filing and set up change control
Decide who enters data in the Product Registry and how certificate identifiers reach your broker. A new supplier, factory, batch or retest means an updated certificate, so treat certificates as living records.
Most of this work sits upstream of customs. The broker files, but the importer and its suppliers hold the test reports and product data that make the certificate accurate. It is the same foundation described in our guide to product compliance management: one structured record per product, reused across every market that asks for it.
Key Takeaways
What importers need to remember about CPSC eFiling
CPSC eFiling is live: since July 8, 2026, certificate data for regulated imports must be filed electronically at entry, with Foreign Trade Zone entries following on January 8, 2027. The importer of record is responsible, which is usually the US brand or retailer, but foreign brands shipping DDP or through US entities may carry it too; domestic US manufacturers are exempt from eFiling, not from certification. 16 CFR 1110.11 defines seven data elements per product, in English, with records kept for five years. Supplier data is the bottleneck, because manufacturing and testing details come from factories and labs and change with every production run or retest. Missing data will not bounce the entry today, but it raises inspection risk, so build the process now rather than after your first held shipment.
If your certificate data lives in supplier emails, test reports and spreadsheets, eFiling will expose it one entry at a time. See how Complir collects supplier documentation and structures compliance data per product, so every SKU has a single, current record your team, your suppliers and your broker can rely on.
Sources & References
- 16 CFR Part 1110, Certificates of Compliance: Electronic Code of Federal Regulations
- CPSC Final Rule, Certificates of Compliance, 90 FR (January 8, 2025): Federal Register via GovInfo
- CPSC, "CPSC Implements Mandatory eFiling for Certificates of Compliance, Targeting Dangerous Foreign Imports": CPSC.gov
- CPSC eFiling Quick Start Guide (January 2025): CPSC.gov
- CPSC Product Registry: CPSC.gov
- CPSC eFiling Frequently Asked Questions: CPSC.gov
- CPSC eFiling CATAIR Implementation Guide (PGA Message Set): CPSC.gov
- List of CPSC-Accepted Testing Laboratories: CPSC.gov
- Consumer Product Safety Act, Section 17, 15 U.S.C. 2066: Office of the Law Revision Counsel, US Code
- CBP, Indefinite Suspension of the De Minimis Exemption (June 24, 2026): Federal Register
- CBP CSMS #69177694, Information from CPSC related to CPSC's PGA Message Set (eFiling): CBP via GovDelivery
This article is for informational purposes only and does not constitute legal advice. Regulatory requirements may vary by product category, market, and specific circumstances. Consult with a qualified legal professional for compliance guidance specific to your situation.
Related articles

EU Toy Safety Regulation: What Changed and When It Applies
The new EU Toy Safety Regulation is in force. What changed vs the Toy Safety Directive, deadlines to 2030, and the toy Digital Product Passport explained.

A child must never come to harm!
When your entire business revolves around products for children, compliance is a matter of life and death. That is why Konges Sløjd partnered with Complir.

Product Compliance Management: How to Build a Scalable Compliance Process
What product compliance management involves, how to structure the workflow, team, and tools, and how to scale it across markets and thousands of SKUs.
Launch products globally without compliance bottlenecks.
Complir's AI agents handle the regulations and documentation across every market you sell in - and keep your entire catalogue audit-ready.
