Discuss a matter
INSIGHTS

CPSC eFiling Is in Effect: Certificate and Supplier Controls After July 8, 2026

CPSC eFiling requirements, certificate responsibilities, supplier data controls and the agency’s stated enforcement posture after July 8, 2026.

On this page

Current as of: September 6, 2026. This Insight reflects authorities available as of the date above; rules, agency guidance, and enforcement posture may change. The U.S. Consumer Product Safety Commission's stated enforcement intentions described below are administrative policy, not codified rule text, and may be revised.

Executive summary

On July 8, 2026, electronic filing of Certificate of Compliance data with U.S. Customs and Border Protection (CBP) became the operative requirement for most regulated consumer products imported into the United States. The rule was published on January 8, 2025 (90 FR 1800) and amends 16 CFR Part 1110. A September 2025 correction (90 FR 45917) restructured the dates into one effective date and two applicability dates without changing the underlying timing.

The central point for importers is this. eFiling is a transmission layer. It is not the certificate. The duty to certify that a regulated product complies with the applicable consumer product safety rules has existed since the Consumer Product Safety Improvement Act and rests on 15 U.S.C. 2063. What changed on July 8, 2026 is that this pre-existing certificate, and its underlying data, must be surfaced to CBP electronically at the time of entry. A filing is only as sound as the certificate beneath it. Importers that treat July 8 as a software task, rather than a certificate-readiness task, may expose missing or defective certificates to regulatory visibility precisely when that visibility carries consequence.

This Insight is written for the parties across the cross-border supply chain who carry or touch that obligation: importers of record; Mexican and other foreign manufacturers selling into the United States; ecommerce brands and private labelers; operations and compliance teams; customs brokers; and product-safety consultants. For goods sourced from Mexico, manufacturers and laboratories may supply manufacture and testing data, but responsibility turns on the importer definition and entry route under §1110.3, rather than simply who supplies that data. An authorized broker acting as importer of record may identify a qualifying owner, purchaser, or consignee as the responsible importer; mail and other specified routes require separate allocation analysis. That allocation of responsibility, and the supplier-data flow it depends on, is where much of the readiness work lies.

CPSC's FAQ, checked September 6, 2026, states that, at this time, it does not intend to ask CBP to deny entry solely because certificate data was not eFiled, and that the ACE system is expected initially to send warning rather than reject messages for missing CPSC data. This Insight describes that posture accurately below. It is administrative grace, expressed in conditional terms, not a safe harbor, and it does not suspend the underlying certificate requirement or CPSC's authority to request seizure of noncompliant product. Nothing here should be read as a prediction that any particular shipment will be admitted.

The operative dates and scope

The operative date for most imports. For most CPSC-regulated consumer products and substances required to be certified, the final rule became applicable on July 8, 2026. CPSC's implementation release confirms that mandatory eFiling has begun, while preserving the January 8, 2027 FTZ date. CPSC's own foreign-trade-zone guidance frames it the same way: "The effective date for most imports is 18 months after publication of the Final Rule, or July 8, 2026" (CPSC eFiling Guidance for Foreign Trade Zones, July 2025).

A separate, later date for foreign-trade-zone goods. Goods admitted into a foreign-trade zone (FTZ) and then entered from the zone for consumption or warehousing carry a later applicability date of January 8, 2027, an additional six months beyond the general date. CPSC's guidance states that "Foreign Trade Zone (FTZ) operators and users have until January 8, 2027 to comply with the revised part 1110, providing an additional 6 months beyond the initial effective date," and that an importer making entry for merchandise withdrawn from an FTZ "must provide CBP with all requisite admissibility data at entry, including CPSC certificate data, as of January 8, 2027" (CPSC FTZ Guidance). The distinction matters: the relevant trigger for the FTZ date is the withdrawal and entry of the goods into U.S. commerce, not their initial admission into the zone.

Why there are now "two dates." The September 2025 correction was a technical fix. The Office of the Federal Register requires a single effective date for the regulatory text, so CPSC restructured the dates section to contain one effective date (July 8, 2026) and two applicability dates (July 8, 2026 generally; January 8, 2027 for FTZ-entered goods). The correction states that it "has no substantive effect on the dates by which the subject products must be in compliance" (90 FR 45917). Readers comparing older summaries that referenced different date framing should treat this correction as the controlling source on date structure.

Where the data is filed. Certificate data is transmitted through CBP's Automated Commercial Environment (ACE), as a supplement to the entry, using the CPSC Partner Government Agency (PGA) Message Set. CPSC's FTZ guidance states that "the importer is required to submit certificate data upon filing entry into CBP's Automated Commercial Environment (ACE) for all CPSC-regulated merchandise withdrawn from an FTZ for consumption, warehousing, or distribution in U.S. commerce" (CPSC FTZ Guidance).

Scope of covered goods. Certification requirements cover specified finished products subject to a CPSC rule, ban, standard or regulation that are imported for consumption or warehousing or distributed in U.S. commerce. Mandatory eFiling addresses the specified imported products; domestic manufacturers remain subject to their applicable certification and availability duties. CPSC has structured the rule so that each finished-product certificate describes only one product. Its guidance quotes the amended rule directly: "each finished product certificate must describe only one product (16 CFR § 1110.13(a), 90 Fed. Reg. 1845)" (CPSC FTZ Guidance). Determine the appropriate product identity and whether any variants may be covered based on their applicable rules and testing basis. The one-product rule does not itself require a separate certificate for every shipment.

What is not changing. The duty to hold a valid certificate predates this rule and is independent of eFiling. A General Certificate of Conformity or a Children's Product Certificate was already required under 15 U.S.C. 2063 and Part 1110. The July 8, 2026 change governs the method by which that certificate's data reaches CBP.

Why this is not just a data-upload step

eFiling presupposes a legally sufficient certificate. The Message Set transmits the contents of, and a representation about, an underlying certificate. If that certificate is missing, stale, or defective, eFiling does not cure it; it renders the deficiency legible to CBP and CPSC at the moment of entry. The work that determines exposure happens upstream of the filing screen.

Identify the responsible certifier before allocating the filing work. Under 16 CFR §§1110.3 and 1110.7, the responsible importer is the finished product certifier for products manufactured abroad. Where an authorized broker acts as importer of record, the rule permits identification of a qualifying owner, purchaser, or consignee as the responsible importer. Mail and other specified entry routes require separate analysis. For domestically manufactured products, the manufacturer certifies; for domestic private-label products, the private labeler certifies unless the manufacturer issues the certificate. A transmission arrangement alone does not settle which party bears the certificate obligation.

General-use products: the testing basis. For a General Certificate of Conformity, 15 U.S.C. 2063(a)(1) requires every manufacturer of a product subject to a consumer product safety rule "(and the private labeler of such product if such product bears a private label)" to issue a certificate that certifies, "based on a test of each product or upon a reasonable testing program," that the product complies with all applicable rules, bans, standards, or regulations, and that specifies each such rule. The statutory phrasing is conjunctive and conditional: the private labeler is drawn in only where the product bears a private label, so a reader should track that language rather than assume a private labeler is always a required co-certifier.

Children's products: assess the applicable third-party testing requirements. For children's products, the basis is more demanding. 15 U.S.C. 2063(a)(2) requires the manufacturer to submit samples "to a third party conformity assessment body accredited under paragraph (3) to be tested," and, "based on such testing, issue a certificate." Applicable statutory and regulatory testing exclusions and permitted reliance on component testing must be considered. Where third-party testing is required, a laboratory must be CPSC-accepted for the relevant rule; competent testing under another standard does not itself suffice. Part 1110 does not define every substantive testing requirement.

The stated no-denial posture is grace, not a safe harbor. As checked September 6, 2026, CPSC's eFiling FAQ states that "CPSC does not intend to request that CBP deny entry of products into the U.S. solely based on failure to eFile certificate data via a Full PGA Message Set or a Reference PGA Message Set," and that CPSC "does not intend initially to have the ACE system send reject messages for missing PGA data, only warning messages" (CPSC eFiling FAQ). In the same breath, CPSC states that it "will continue to enforce certificate requirements for imported consumer products and submit requests to CBP to initiate seizure of non-compliant products." The conditional verbs ("does not intend," "initially") signal an administrative posture that can shift. It can reduce the friction of a missing transmission; it does not reduce the consequence of a missing or invalid certificate.

Recordkeeping and availability are part of the obligation. An electronic certificate must be retrievable. Under the amended 16 CFR 1110.13, a finished-product certificate must accompany the imported product, must be furnished to distributors and retailers, and must be available to CPSC for inspection within 24 hours of request. The electronic-access mechanics sit in 16 CFR 1110.9. Satisfying the furnishing and availability duties requires the prescribed certificate identification and electronic access arrangements; transmitting a reference identifier alone does not establish compliance with all of those duties. Confirm the required placement of the identifier, access for the required recipients, and any password arrangements under §1110.9(c). For imported goods, the separate accompaniment requirement is met through eFiling as provided by that section. Retain certificates and supporting records for at least five years from certificate creation under §1110.17. A certificate that cannot be produced on request is a readiness gap even where the substance is sound.

US-Mexico overlay. For products manufactured in Mexico, obtain the required manufacturing and testing information from the parties that hold it, including the manufacturer and any testing laboratory. Identify the responsible importer under §1110.3 and document that allocation. Under §1110.9(a), eFiled certificates must be in English; other certificates must include English and may also contain the same content in another language. The importer's filing is therefore only as reliable as the data flow from its supplier. Assess the applicable Mexican product-safety requirements, including relevant Normas Oficiales Mexicanas (NOMs), separately from U.S. certification. Do not assume that documentation prepared for one regime alone satisfies the requirements of the other.

What importers should review now

The following is illustrative and not exhaustive; the right scope depends on a company's product mix, sourcing, and entry profile.

  • Identify which products are in scope. Determine, at the SKU level, which imported items are subject to a CPSC rule, ban, standard, or regulation and therefore require a certificate.
  • Confirm a current certificate exists for each finished product. Determine product identity and permitted variant coverage from the applicable rules and testing basis; avoid combining distinct products in one certificate or assuming each shipment requires a new certificate.
  • For children's products, confirm the applicable testing basis, including any exclusions or permitted component-test reliance, and required testing at a CPSC-accepted laboratory and that the Children's Product Certificate is current and tied to the tested product configuration.
  • For general-use products, confirm a documented basis in a test of each product or a reasonable testing program, consistent with 15 U.S.C. 2063(a)(1).
  • Verify that the required data elements are obtainable for every SKU, including manufacturing information, applicable testing information or a permitted testing-exclusion basis, and the required laboratory information where relevant.
  • Confirm the certifying party is the correct one. For imported goods, determine the responsible importer under §1110.3, including the broker-as-IOR and entry-route qualifications; for domestic privately labeled goods, it is generally the private labeler unless the manufacturer issues the certificate.
  • Map the broker data flow. Determine how, and by when, the importer will furnish the certificate or the reference identifiers to the broker so the broker can transmit at entry.
  • For FTZ users, begin the operational work toward January 8, 2027, including inventory-accounting method and entry mechanics (discussed below).
  • Address supplier onboarding. Where data originates with a Mexican or other foreign manufacturer, consider contractual provisions obligating the supplier to deliver and update certificate data and testing. This is a corporate and commercial-document question as much as a regulatory one.

Product Registry vs. Full PGA Message Set (and the broker workflow)

CPSC's implementation materials describe more than one way to transmit certificate data. There are, in fact, three filing methods, and conflating them is a common source of confusion.

Three filing methods. CPSC's eFiling implementation guidance describes a Disclaimer PGA Message Set (used for tariff codes that CPSC flags but that do not require certificate data), a Reference PGA Message Set, and a Full PGA Message Set (CPSC eFiling Document Library). The two that carry certificate data are the Full and Reference methods.

The Full PGA Message Set. Under the Full method, the certificate data elements are transmitted with each entry. The codified content of a certificate is set by 16 CFR 1110.11 as amended by the final rule (operative July 8, 2026). It includes product identification; the applicable rules, bans, standards, or regulations; identification of the certifier and records contact; manufacturing and testing information; and the required attestation. Where §1110.11(c) permits a testing exclusion, identify its basis in place of the testing date and place for that rule, while retaining the applicable-rule identification and other required information. Confirm the current message-set field mapping with the filer using CPSC implementation materials. CPSC's eFiling FAQ states the certificate's required content in consistent terms: a certificate "must state all applicable rules, bans, standards, and regulations; the most recent date of testing; and identify each testing lab that conducted such testing" (CPSC eFiling FAQ).

The Reference PGA Message Set and the Product Registry. The Reference method is built for repeat imports of the same certified product. The full certificate data for a product is filed once, in advance, into the CPSC Product Registry; while the certificate data remain accurate, the importer transmits a shorter Message Set, keyed to reference identifiers, each time the product is imported (CPSC eFiling FAQ; current implementation materials). The trade-off is straightforward: the Full method handles per-shipment data each time; the Reference method front-loads the data once and reduces per-entry handling for high-velocity SKUs, at the cost of maintaining accurate registry records and a disciplined data-correction process.

The broker workflow. Coordinate the certificate-data submission with the ACE entry process. Before filing, have the broker or other authorized filer confirm the current CATAIR transmission, identifier and field requirements using the current implementation materials. Whichever method a company uses, the importer must furnish the broker either the full certificate data or the registry reference identifiers before entry. The broker's role is governed by 19 CFR Part 111: a broker transacts customs business on behalf of others, must exercise responsible supervision and control (19 CFR 111.28), and must exercise due diligence in preparing or assisting in the filing of records (19 CFR 111.29). Part 111 also makes clear that payment to a broker does not relieve the importer of liability owed the government. Identify the responsible importer under Part 1110 separately from the party transmitting data; the broker-as-IOR provision described above must be considered.

Mail shipments require a dated transition analysis. Section 1110.13(a)(1) provides a Product Registry route before arrival for imported mail. CPSC's mail guidance announces that mail shipments must use Full or Reference Message Sets through ACE Entry Type 13 beginning October 22, 2026. Do not treat registry-only filing as a permanent postal exception. Confirm the applicable route and transition requirements with the current CPSC and CBP instructions before a shipment; this article is not a field-level postal filing guide.

Use the current implementation specification. Consult the CPSC library’s current CATAIR guide and confirm the operational specification with the filer before configuring transmissions. Field requirements and entry procedures should be checked against the version applicable to the shipment.

What a warning message does and does not mean. The FAQ's conditional initial-warning posture, checked September 6, 2026, is not an assurance that any entry will proceed with incomplete certificate data. A warning is not a determination that the certificate obligation has been satisfied, and, as noted, it does not displace CPSC's enforcement and seizure authority over noncompliant product.

Common certificate readiness gaps

Each item below is a discrete failure mode. The list is illustrative.

  • No certificate at all for a product that is in fact subject to a CPSC rule.
  • A single certificate covering multiple products, which is inconsistent with the one-product-per-certificate structure.
  • A testing basis that no longer supports the current product or applicable testing requirements, including a test tied to a superseded product configuration. The age of a test date alone does not establish that it is invalid.
  • A children's product whose testing was performed at a laboratory not accepted by CPSC for the relevant rule, or whose acceptance scope does not match the test.
  • A general-use product with no documented testing basis in either a test of each product or a reasonable testing program.
  • Missing or incorrect identity or address of the manufacturing party, or of the third-party laboratory on whose testing the certificate depends.
  • The wrong party listed as certifier, most commonly the foreign factory issuing a certificate where the importer is the responsible finished product certifier for imported goods.
  • A mismatch between the product identifier in the Product Registry and the identifier transmitted at entry, for companies using the Reference method.
  • An FTZ inventory-accounting method that cannot reliably map a withdrawn unit to the correct certificate, which can surface as the January 8, 2027 date approaches.
  • Treating the no-denial posture as permission to defer the certificate itself, which conflates a transmission allowance with the substantive obligation.

Allocate professional and operational responsibilities

A certificate-control review should separate legal responsibility and supplier contract terms from customs entry preparation, product engineering, and laboratory testing. Define who maintains certificates, validates product changes, communicates updates to the filer, and responds to a CPSC records request. The responsible certifier, authorized filer, laboratory, and product-safety team may be different parties; their contracts and procedures should reflect those roles.

Practical next steps

The following is a general sequence, not a deadline-driven mandate, and the right order depends on the facts.

  • Build a SKU-level inventory of which imported products are subject to a CPSC rule and require a certificate.
  • Conduct a certificate gap review across those SKUs: existence, one-product structure, currency of testing, and identification of the correct finished product certifier.
  • For children's products, arrange required testing with CPSC-accepted laboratories where the existing basis no longer supports the current product or applicable testing requirements.
  • Decide, by product line, between the Full and Reference filing methods, and stand up the supporting records and controls.
  • Align the broker power of attorney and the certificate-data handoff so the broker can transmit at entry.
  • For FTZ operations, work the inventory-accounting and entry mechanics toward the January 8, 2027 applicability date.
  • Where data originates abroad, consider supplier contract amendments that obligate the Mexican or other foreign manufacturer to deliver and update certificate data and testing.
  • Review actual transmissions and warning messages under the operative requirements, using the current CPSC eFiling materials and the filer's current implementation instructions. Earlier voluntary-stage assurances should not be assumed to apply after launch.
  • Calendar the October 22, 2026 mail transition where relevant, and retain certificates and supporting records for at least five years from certificate creation.

Responsible lawyer: Rene Hinojosa. Primary practice location: San Antonio, Texas.

Important notice (general information; no attorney-client relationship)

This Insight is provided by Hiro Law for general informational and educational purposes only. It does not constitute legal, tax, customs, or other professional advice and should not be relied upon as such. No attorney-client relationship is created by your receipt of or access to this material. The information contained herein may not reflect the most current legal developments, including changes to CPSC guidance or enforcement posture, and is not warranted to be complete, correct, or up to date. You should not act or refrain from acting based on any information in this Insight without first seeking qualified counsel licensed in the relevant jurisdiction(s). Each import, certification, and cross-border compliance matter involves unique facts and circumstances that require individualized analysis. Nothing in this Insight is a guarantee or prediction regarding the admission, clearance, or treatment of any shipment. Prior results do not guarantee a similar outcome.

More perspectives on cross-border transactions.

Explore insights