CPSC eFiling in ACE: Requirements, Dates, and Data Elements
By: Samantha Rose
CPSC eFiling is the requirement that certificate of compliance data be transmitted electronically to U.S. Customs and Border Protection’s Automated Commercial Environment (ACE) at the time of entry, using the CPSC Partner Government Agency (PGA) Message Set. It applies to imported finished consumer products that require certification under a CPSC rule, at any shipment value, and took effect on July 8, 2026.
The requirement comes from the Consumer Product Safety Commission’s final rule revising 16 CFR part 1110. This guide covers the effective dates, which products and parties are in scope, the data elements involved, the two available filing methods, how the requirement is being enforced at entry, and the related obligations that eFiling does not replace.
Effective dates
The rule phases in by entry type:
| Entry type | Effective date |
|---|---|
| CPSC-regulated consumer products entered for consumption or warehousing | July 8, 2026 |
| Regulated products entered from a foreign trade zone for consumption or warehousing | January 8, 2027 |
Products moving into an FTZ are not subject to the requirement on admission. It applies when they are subsequently entered for consumption or warehousing, from the FTZ effective date onward.
Who files
CPSC generally treats the party responsible for certification as the importer of record named on the entry, or the domestic manufacturer for goods produced in the United States. In practice, the customs broker transmits the data, while the importer remains responsible for the accuracy of the certificate and for the underlying compliance of the product.
These are separate roles, and the distinction matters when a broker acts as importer of record on an entry. Brokers in that position can disclaim responsibility for certifying CPSC compliance within the message set. Confirming in writing which party is transmitting and which party is certifying avoids a gap that only becomes visible during a records request.
Which products are covered
The requirement applies to finished consumer products subject to a CPSC rule, ban, standard, or regulation that requires certification. In practice that means products needing either of the following:
- A Children’s Product Certificate (CPC), required for products designed or intended primarily for children 12 and under, and supported by third-party testing at a CPSC-accepted laboratory.
- A General Certificate of Conformity (GCC), required for general-use consumer products subject to a CPSC rule.
The general-use category is wider than it first appears. It reaches ordinary housewares, apparel subject to drawstring requirements, textiles subject to flammability standards, mattresses, candles, portable electronics containing lithium cells, and furniture subject to tip-over or stability rules, among others.
Two scope points are commonly misread:
- There is no low-value or de minimis exemption, and no direct-to-consumer exception. A single parcel shipped from overseas to a customer carries the same filing obligation as a full container.
- Raw materials and component parts are generally outside the requirement, since certification attaches to the finished consumer product. This boundary should be checked against the flagged tariff codes rather than assumed.
CPSC has published a list of roughly 600 Harmonized Tariff Schedule codes flagged CP1 or CP2, covering categories where certification is commonly required or where the agency has particular enforcement interest. Running that list against the codes your broker files under is the practical way to establish scope.
What has to be filed
The data elements are set by 16 CFR 1110.11 and are unchanged from the previous paper-certificate regime. What changed is that they must now be structured and transmitted at entry.
| Element | Requirement | Typical source |
|---|---|---|
| Product identification | Identification of the product covered by the certificate | Catalog or PIM |
| Rules cited | Each applicable safety rule, ban, standard, or regulation, listed separately | Regulatory mapping by SKU |
| Certifier | Name, full mailing address, and telephone number of the certifying importer or domestic manufacturer | Entity records |
| Date and place of manufacture | Month and year at minimum; city and state, country, or administrative region | Supplier and purchase order data |
| Date and place of testing | Month and year, and location where the product was tested for compliance | Laboratory report |
| Testing laboratory | Name, full mailing address, and telephone number of any third-party laboratory the certificate relies on | Laboratory report |
| Records custodian | Name, email address, full mailing address, and telephone number of the individual maintaining test records | Internal assignment |
Three of these elements originate with a supplier or laboratory rather than inside the importer’s own systems, and two of them change when sourcing or testing changes. A new factory changes the place of manufacture; a requalification changes the test date and potentially the laboratory. Each change requires the certificate to be updated before the next affected entry.
The two filing methods
CPSC supports two ways of getting certificate data into ACE.
| Full PGA Message Set | Reference PGA Message Set | |
|---|---|---|
| What is transmitted at entry | Every certificate data element | Three identifiers |
| Where certificate data is stored | Nowhere in advance; sent each time | CPSC Product Registry |
| Setup required | None beyond broker coordination | Registry account and loaded certificates |
| Best suited to | Small catalogs, few suppliers | Larger catalogs, frequent entries |
Under the Full PGA Message Set, the broker transmits all certificate elements with each entry, on each applicable line.
Under the Reference PGA Message Set, certificate data is entered into the CPSC Product Registry in advance. Once a certificate is complete and certified in the registry, the system issues three identifiers — a Certifier ID, a product identifier, and a certificate version ID. The broker transmits those three values at entry, and CPSC resolves them against the stored record.
Registering for the Product Registry follows a set sequence: self-register with your company name, email, and importer of record number; create product certificates by entering the required elements; certify each completed certificate; then provide the three resulting identifiers to your customs broker. Because certificates are versioned, updating one issues a new version ID, and that updated identifier has to reach the broker for subsequent entries.
How the requirement is being enforced
CPSC has not asked CBP to reject entries or deny admission solely for missing or incomplete PGA Message Set data. This differs from some other partner government agency programs, where a “MUST” flag causes broker software to block an incomplete entry before transmission.
The practical effect at entry is that a flagged tariff line filed without certificate data generates a warning message, and the entry proceeds. Filing is not blocked for HTS codes carrying CP1 or CP2 flags.
That posture governs entry processing only. It does not change the underlying certification requirements, and CPSC has stated it will continue to enforce them, including through detention and seizure of non-compliant goods. Warning messages also inform the risk scoring that determines which shipments receive additional scrutiny.
Obligations eFiling does not replace
Electronic filing sits alongside existing requirements rather than replacing them.
Certificates must still accompany the product or shipment and be furnished to each distributor and retailer, under section 14(g)(3) of the Consumer Product Safety Act. An electronic certificate satisfies these requirements when it carries a unique identifier and can be accessed by a URL or other electronic means, provided both the identifier and access are available to the Commission or to customs authorities as soon as the shipment is available for inspection. Retailers frequently request this access during vendor onboarding.
Recordkeeping obligations also continue. For children’s products, 16 CFR 1107.26 requires manufacturers to maintain the Children’s Product Certificate, third-party certification test records for each manufacturing site, and periodic or production testing plans and results for at least five years, available in hard copy or electronically for CPSC inspection on request.
Products subject to a CPSC rule but exempt from third-party testing still require a certificate. The certificate must cite the applicable rule and identify the exemption being relied on, so an exemption from testing is not an exemption from certifying.
Penalties for non-compliance
Failing to furnish a required certificate, or issuing a false certificate, is a violation of the Consumer Product Safety Act independent of whether the product itself is defective. Violations can result in civil penalties, criminal penalties, asset forfeiture, and product recalls.
Civil penalty maximums are set per violation with a separate cap on a related series of violations, and both are subject to periodic inflation adjustment. Because those adjustments are not applied every year, current figures should be confirmed against CPSC’s published schedule rather than quoted from secondary sources.
Preparing to file
For importers still working toward compliance, the sequence below reflects the order in which each step unblocks the next.
- Obtain CPSC’s flagged HTS code list and compare it against the tariff codes your broker files under. The overlap defines your scope.
- Inventory certificate status across those SKUs, separating products with a current complete certificate from those holding only a test report and those with neither. A passing laboratory report is not a certificate.
- Choose a filing method. The Reference message set suits catalogs where the same products are imported repeatedly; the Full message set avoids setup for small or infrequent programs.
- If using the registry, self-register under your importer of record number and load certificates, starting with the SKUs that carry the most entry volume.
- Collect the supplier-sourced elements at the purchase order and supplier onboarding stage rather than per shipment, since date and place of manufacture, test date, and laboratory identity all originate outside your systems. This fits alongside the data you already collect through vendor scorecards.
- Assign a records custodian by name and confirm they can produce five years of test records on request.
- Document who transmits identifiers and who owns their accuracy, and reconcile registry versions against broker records periodically so version drift is caught before an entry is filed against a superseded certificate.
- Define the events that require recertification — factory change, component change, standard revision, lot-level retesting where required — and connect them to the systems where those events are recorded.
Because the required elements are attributes of a SKU that change over time, certificate data ages the same way other product data does. Keeping it accurate is easier where purchase orders, supplier records, and the product catalog share a single source of truth, so a sourcing change surfaces as a certificate review rather than depending on manual follow-up. The same principle applies to identifier hygiene and to marketplace compliance.
Frequently asked questions
Is CPSC eFiling required for low-value shipments?
Yes. The requirement applies regardless of the value of the shipment, entry, or goods. There is no low-value threshold and no exemption for direct-to-consumer parcels.
Will my entry be rejected if I do not file certificate data?
Not at present. CPSC has not asked CBP to reject entries or deny admission solely for missing message set data, so flagged lines filed without certificate data generate a warning and clear. Certificate and product compliance requirements remain enforceable through other means.
Does eFiling apply to components and raw materials?
Generally no. Certification attaches to the finished consumer product. Verify against the flagged tariff codes, since classification determines whether a given import is treated as a finished product.
When does the requirement apply to foreign trade zone goods?
January 8, 2027, for regulated products entered from an FTZ for consumption or warehousing.
What are the three identifiers used in the Reference message set?
A Certifier ID, a product identifier, and a certificate version ID, all issued by the CPSC Product Registry once a certificate is entered and certified. All three are provided to the customs broker for transmission at entry.
Do products exempt from third-party testing still need a certificate?
Yes. The certificate is still required and must cite the applicable rule and identify the exemption relied on.
Commerce is chaos.
Tame your tech stack with one system that brings it all together—and actually works.
Get a DemoInsights to master the chaos of commerce
Stay ahead with expert tips, industry trends, and actionable insights delivered straight to your inbox. Subscribe to the Endless Commerce newsletter today.