Key takeaways
- CPSC eFiling is mandatory, and it started on July 8, 2026. Certificate data for CPSC-regulated consumer products must now be filed electronically with the customs entry. A customs broker can transmit that data for you — but the rule lets the broker name the owner, purchaser, or consignee as the party responsible for the certificate, and only the importer, domestic manufacturer, or private labeler can issue it.
- The rule's own words assume the duty rather than create it. It applies to importers, domestic manufacturers, and private labelers "who are required to issue certificates." That clause is doing quiet work. The obligation to certify comes from the statute; the new rule only changes how the certificate data travels. Hiring someone to transmit it doesn't move the obligation.
- "Consumer product" reaches further than toys. Certification covers products subject to a consumer product safety rule under the Consumer Product Safety Act (CPSA) "or a similar rule, ban, standard, or regulation under any other law enforced by the Commission." And there is no size carve-out: "The CPSA does not exclude small businesses from certification requirements."
- If your goods arrive by international mail, the mechanism is different. The rule's premise is that mail shipments "cannot relay the PGA Message Set," so importers using international mail "must enter certificate data into the Product Registry before arrival of the shipment" — a deadline that runs against arrival, not against a filing. CBP started a new postal entry process on July 24, 2026, but merchandise with Partner Government Agency requirements is "ineligible to use the new informal postal entry process" — so the registry path stands.
- The low-value route the rule points to was already gone before the rule took effect — and it wasn't CPSC that closed it. The January 2025 text sends de minimis shipments to Entry Type 86. CBP had announced that "type 86 entries may no longer be utilized" effective August 29, 2025 — more than ten months before this rule's July 8, 2026 start date.
What CPSC eFiling changed on July 8, 2026 — and the one date that hasn't arrived yet
The Consumer Product Safety Commission's certificates-of-compliance rule (16 CFR part 1110) says it plainly: "the Final Rule is effective on July 8, 2026." From that date, certificate data for CPSC-regulated consumer products is transmitted electronically to CBP as part of the customs entry, in what the rule calls CPSC's PGA Message Set — the block of agency data that rides along with the entry filing.
Two things about the calendar are worth pinning down before anything else.
First, this rule was published on January 8, 2025 (90 FR 1800), with an eighteen-month runway. That gap matters later in this brief, because the world the rule described in January 2025 is not the world it landed in.
Second, one effective date hasn't arrived. A later date — "effective on January 8, 2027" — applies to exactly one narrower path, and both halves of it run through a foreign trade zone (FTZ). The rule's dates clause carves out products "imported into a foreign trade zone (FTZ) and subsequently entered for consumption or warehousing," and gives that path until January 2027. Read the FTZ condition carefully before you claim the later date: goods entered for warehousing without passing through an FTZ are not in the carve-out, and have been on the July 8, 2026 clock like everything else.
That's the whole "what changed" story, and it's the part every announcement covers. The useful questions start one step down.
Filing the data and issuing the certificate are two different jobs
Is CPSC eFiling mandatory? Yes — since July 8, 2026, certificate data for CPSC-regulated consumer products must be filed electronically with the customs entry. A customs broker can transmit that data for you, but the rule lets the broker name the owner, purchaser, or consignee as the party responsible for the certificate, and only the importer, domestic manufacturer, or private labeler can issue it.
Start with the rule's applicability sentence, and read it slowly. It "applies to importers, domestic manufacturers, and private labelers who are required to issue certificates for consumer products and substances regulated by CPSC that are imported for consumption or warehousing into the United States or are distributed in commerce in the United States."
That relative clause is the hinge. The rule doesn't say "importers must now certify." It says it applies to the people already required to certify — a duty that sits in the statute (CPSA section 14(a)(1), 15 U.S.C. 2063(a)(1)), not in the filing rule. So eFiling changed the plumbing: where the certificate data goes, in what form, and when. It didn't change whose signature is underneath it.
That three-way list covers domestic production as well as imports. If your goods are made abroad, the rule narrows it to one party: under 16 CFR 1110.7(a), for a finished product "manufactured outside of the United States" that must be accompanied by a certificate, "the importer, as defined in this part, is the finished product certifier." For an import, the certifier is the importer — full stop.
Now put that next to who actually touches the keyboard. The importer of record on an entry can be "an owner, purchaser, or authorized customs broker." Very often, for a small importer, it's the broker. And the rule anticipates exactly that:
"if the IOR is an authorized customs broker, the customs broker may identify the owner, purchaser, or consignee of the finished products who authorized the customs broker to make entry, as the party responsible for compliance with CPSC certificate requirements as part of the finished product certificate data filed in CPSC's PGA Message Set"
Read the verb precisely: may identify. That's a permission, not a command — the rule allows the broker to name someone else as the responsible party in the data it files. It doesn't promise that yours will, and this brief isn't going to tell you it will.
But look at why the option exists. The rule explains that a broker "may not have sufficient knowledge of the consumer products to be held responsible for testing and certification," while the owner, purchaser, or consignee is "the party that CPSC would expect to have sufficient knowledge of the products."
That reasoning is the point, and it holds whether or not the box gets ticked. The rule carved out a way to name you because you are the one who knows what the product is, who tested it, and to what standard. Which means the sentence founders should carry out of this is not "my broker might name me." It's this: the job of transmitting data and the job of standing behind the product were never the same job, and the rule quietly says so. Your broker files. You certify.
None of these facts is hidden. The Commission publishes the registration steps, brokers and carriers publish "we'll file it for you," and test labs publish "get tested." Each of them is describing their own lane accurately. What almost nobody does is walk you through the lanes in the order a founder actually hits them — which is what the rest of this brief is.
Whether your product is subject to CPSC eFiling — the line is wider than toys
The most common way to get this wrong is to assume "consumer product safety" means children's products.
The certification requirement reaches "all consumer products subject to a consumer product safety rule under the CPSA, or a similar rule, ban, standard, or regulation under any other law enforced by the Commission." That second half is the wide part. The Commission enforces more than the CPSA, and a product can be pulled in by a rule, a ban, a standard, or a regulation under any of those other laws.
The rule names two certificate types:
| Certificate | Applies to |
|---|---|
| Children's Product Certificate (CPC) | Children's products subject to a CPSC rule |
| General Certificate of Conformity (GCC) | Non-children's consumer products subject to a CPSC rule |
Which one is yours — and whether either is — depends on your specific product and how it's classified, and that is genuinely product-by-product. Don't take a general list from anyone (including us) as an answer for your SKU; check your own product and its classification against the rules the Commission enforces, and if you're unsure, that question goes to a testing lab or a customs broker before your next shipment, not after.
And put the size question to bed early, because it's the assumption that costs founders the most:
"The CPSA does not exclude small businesses from certification requirements."
One order, one pallet, one product line, one person — the certification duty doesn't scale down. What scales is how much work it takes to satisfy it, which is the subject of the Product Registry section below.
If your goods arrive by international mail, the rule works differently
This is the section least likely to reach you from anyone else, for a structural reason: brokers and express carriers don't handle your postal shipments, so their guidance has no reason to mention it.
The rule addresses mail head-on, and the mechanics are unusual:
"CBP does not collect entry data for products imported into the United States via international mail; thus, these shipments cannot relay the PGA Message Set"
When the rule was written, no entry data was collected on mail at all, so there was no vehicle for the certificate data to ride in. CPSC built a separate path:
"Importers using international mail to import consumer products regulated by CPSC must enter certificate data into the Product Registry before arrival of the shipment in the United States"
That premise has since shifted — and it's worth seeing why the conclusion didn't move with it. CBP opened a new postal entry process on July 24, 2026, so mail is no longer a data-free lane. But that process excludes precisely the goods this brief is about: merchandise subject to "import and entry-related Partner Government Agency (PGA) requirements" is "ineligible to use the new informal postal entry process." CPSC's requirements are PGA requirements. (CBP set a delayed compliance date of October 22, 2026 for that exclusion; the customs side of the postal change is a separate story.) The Product Registry duty is CPSC's own, it runs against arrival, and none of this moves it.
Notice what the deadline is attached to. Everywhere else in this rule, certificate data moves with a filing. Here it's tied to arrival — the shipment's physical landing in the United States, a moment you don't control and can't easily reschedule once the parcel is in the mail stream. Practically, that means the registry entry is something you do before or as you ship, not something you handle when a broker calls you.
If any part of your inbound flow uses international mail — supplier samples, small replenishment batches, replacement parts, a first production run you didn't want to freight — that's the piece to check this week. It's easy to be fully organized on your container shipments and completely unaware that the box coming by post has its own rule.
The low-value route the rule points to was already gone
Here is where reading the rule literally will send you to a door that isn't there anymore. It's a timing artifact, and untangling it takes two agencies kept strictly apart.
What CPSC wrote, in January 2025:
"The Final Rule requires de minimis shipments containing finished products regulated by CPSC to file CPSC's PGA Message Set via an entry type capable of transmitting this message set, which is currently limited to ET86"
The word to hold onto is "currently." That was a description of the filing landscape as it stood when the rule was published — eighteen months before it took effect.
What had already happened by the time it took effect. Entry Type 86 stopped being usable on August 29, 2025. Implementing Executive Order 14324, CBP said so without hedging (90 FR 42418):
"Pursuant to section 4(c) of Executive Order 14324 directing the Secretary of Homeland Security to take all necessary actions to implement and effectuate that order, type 86 entries may no longer be utilized."
CBP wrote that suspension into its regulations about ten months later, in an interim final rule published June 24, 2026 (91 FR 37789) — and the tense there gives the sequence away: "CBP has also suspended the Entry Type 86 Test." That rule is recording a closure, not performing one. It also recorded that the "release from manifest" process "will no longer be available for formerly de minimis shipments pursuant to Section 321(a)(2)(C)" and, for goods arriving by modes other than the international postal network, described where they go instead: "This leaves Entry Type 11 as the main appropriate informal entry method for these shipments, although formal entry remains an option."
So line up three dates. CPSC published the rule in January 2025. The route that rule names died in August 2025. The rule itself took effect in July 2026 — still pointing, on the page, at a door that had been bricked up for more than ten months.
Now the attribution, because this is the easiest thing in the topic to get backwards. CPSC did not remove a low-value exemption. CPSC requires certificate data to travel with the entry. It was the CBP side — implementing an executive order — that closed the low-value channel and ended the entry type CPSC's text had pointed at. Two agencies, two separate actions, and the closure landed before the certificate rule it was written into ever took effect. (How the low-value channel closed, and what replaced it, is a customs-duty story we take apart separately in our brief on the end of de minimis and the new entry process. This brief stays on the safety-certificate side of it.)
What this means for you is narrower and more practical than "everything changed." If you had been counting on low-value parcels to stay outside formal filing, that plan has two independent problems now: the channel itself moved, and the certificate data requirement applies to CPSC-regulated goods regardless. So the action item isn't to read the January 2025 text as a routing instruction. It's a question for your broker: which entry type are my shipments moving under right now, and does it carry the CPSC message set? That's a question they can answer for your actual account today, which no published rule text can.
One more thing worth naming, since the same three letters appear in both stories: IOR — importer of record — carries two different responsibilities depending on which question you're asking. Under this rule, it determines who transmits the certificate data and who can be named responsible for it. In a customs refund, it determines who the money comes back to, which we covered in who gets the tariff refund. Same three letters, different consequences — don't let an answer from one context settle the other.
Filing it once instead of every time: the Product Registry and record-keeping
The rule offers two ways to submit, and the difference compounds for anyone who reorders the same product.
| Method | What you send | Best for |
|---|---|---|
| Full Message Set | All certificate data elements, with each entry | One-off or highly variable shipments |
| Reference Message Set | A reference ID pointing to certificate data already uploaded to the Product Registry | Repeat imports of the same products |
The rule's own description of the second option is the selling point: a reference ID lets you file "without having to re-enter the same certificate data elements." If you import the same catalog again and again — which describes most small consumer-product businesses — front-loading the registry work turns a recurring per-shipment task into a one-time setup. That's the single biggest lever a small importer has here, and it's available precisely because the duty can't be shrunk by being small.
The second half of this section is less pleasant and easier to forget: the paperwork has to survive longer now. Under the rule, firms supplying non-children products will have to hold certificates and supporting documentation, "such as test reports, for two additional years" — extending retention from three years to five.
Two years doesn't sound like much until you consider what typically happens in that window: you change email providers, you close a bank account, you move, a contract manufacturer goes quiet, a lab portal expires. Test reports are the exhibit that makes a certificate mean something. A five-year retention duty is really a five-year custody duty — you need to be able to put your hands on the document, at an address and in an account that still belongs to you, years after the shipment cleared.
What to do this week, in order
The order is the point. Doing step four before step one is how founders spend money on the wrong thing.
1. Determine whether your products are in scope — using the wide test, not the toy test. Ask whether your product is subject to a consumer product safety rule under the CPSA, or a similar rule, ban, standard, or regulation under any other law the Commission enforces. This is product-specific; check yours and its classification rather than reasoning from a category.
2. Find out who is currently named as responsible on your filings. One question to your broker: on our entries, whose information goes into the CPSC certificate data as the party responsible for compliance? The rule permits the broker to name the owner, purchaser, or consignee — so the answer is a fact about your account, not something you can deduce from the regulation.
3. Confirm the certificate itself exists, and that it's yours to issue. Whichever applies to your product — a Children's Product Certificate or a General Certificate of Conformity — for goods made abroad the certifier is the importer (16 CFR 1110.7(a)). You can hand off the work: §1110.15 lets a certifier rely on another party to test, to upload data to the Product Registry, even to certify "on their behalf." What you cannot hand off is the consequence — the certifier "remains legally responsible for the information in a finished product certificate, including its validity, accuracy, completeness, and availability." If nobody in your supply chain can point you to the actual certificate and the testing behind it, that gap is the real problem, and it's upstream of anything to do with eFiling.
4. Ask which entry type your shipments are moving under now. Entry Type 86 has been unusable since August 2025, and for non-postal modes CBP has named Entry Type 11 as the main informal entry method. The routing question for your specific goods belongs to your broker and your current entries, not to a rule text written in January 2025.
5. If anything comes by international mail, load the Product Registry before it ships. The obligation runs to arrival, so treat it as part of placing the order, not part of clearing it.
6. Set up the Reference Message Set if you reorder the same products. Upload once, reference by ID, stop re-entering the same data on every shipment.
7. Fix your retention now, while it's cheap. Certificates plus supporting documentation — test reports included — for five years on non-children's products. Store them somewhere that isn't a personal inbox or a laptop, and make sure the business address on the records is one you'll still be reading mail at in 2031.
That last point is where this rule quietly connects to something duller than product safety. Everything above assumes there's a stable, findable business behind the certificate: a party a broker can name, a party that can produce a test report five years later, a party whose correspondence doesn't bounce. Nothing in this rule is about your address, and a business address doesn't issue a certificate, doesn't test a product, and doesn't make you compliant. What it does is keep the records, notices, and lab correspondence reaching the same place while the rules keep moving — and for a non-resident founder importing into the US, that's usually the weakest link in the chain, not the certification itself. On the US side, our partner SaveOffice handles that address layer — Auteur doesn't operate the US service directly — and you can see how it works on the US virtual office page.
This is general information about a US import compliance development for founders, not legal, customs, or product-safety advice. Confirm how these requirements apply to your specific products and shipments with CPSC, a licensed customs broker, or a qualified testing lab before you rely on it.
FAQ
Is CPSC eFiling mandatory? Yes. The Final Rule is "effective on July 8, 2026," and from that date certificate data for CPSC-regulated consumer products is filed electronically with the customs entry as part of CPSC's PGA Message Set. A separate, later date — "effective on January 8, 2027" — applies only to products "imported into a foreign trade zone (FTZ) and subsequently entered for consumption or warehousing." Both halves of that carve-out require an FTZ; goods entered for warehousing without passing through one are on the July 8, 2026 date. There is no small-business carve-out: "The CPSA does not exclude small businesses from certification requirements."
What products are subject to CPSC eFiling? The rule "applies to importers, domestic manufacturers, and private labelers who are required to issue certificates for consumer products and substances regulated by CPSC that are imported for consumption or warehousing into the United States or are distributed in commerce in the United States." For goods manufactured outside the United States, 16 CFR 1110.7(a) puts the certifier role on the importer. The certification net is wider than children's products: it covers goods subject to a consumer product safety rule under the CPSA "or a similar rule, ban, standard, or regulation under any other law enforced by the Commission." Two certificate types exist — the Children's Product Certificate (CPC) and the General Certificate of Conformity (GCC). Whether either applies to your item depends on the specific product and its classification, so verify yours rather than reasoning from a product category.
Can my customs broker handle CPSC eFiling for me? A broker can transmit the data, and if the broker is the importer of record it "may identify the owner, purchaser, or consignee … as the party responsible for compliance with CPSC certificate requirements" in the data it files. That's a permission the rule grants, not a guarantee about your account. And it doesn't shift the underlying duty: the rule applies to importers, domestic manufacturers, and private labelers "who are required to issue certificates" — a duty that exists independently of who presses send. The Commission's own reasoning is that a broker "may not have sufficient knowledge of the consumer products to be held responsible for testing and certification," while the owner, purchaser, or consignee is "the party that CPSC would expect to have sufficient knowledge of the products." Ask your broker who is named on your entries, and treat the certificate itself as yours.
Bottom line
Transmission and certification are two jobs. Since July 8, 2026, the first one has to happen electronically with the entry, and someone else can do it for you. The second one is delegable only in appearance: §1110.15 lets a certifier rely on another party to test, to upload the data, even to certify "on their behalf" — and then says that certifier "remains legally responsible for the information in a finished product certificate." Someone else can do the work. Nobody else absorbs the consequence. That is also why the rule bothered to build a field where a broker may name the owner, purchaser, or consignee as the responsible party: the Commission expects the person who knows the product to answer for it.
So the check isn't "has my broker got this handled." It's three shorter questions, in order: is my product in scope (using the wide test, not the toy test), who is named as responsible on my entries, and does the certificate they're pointing at actually exist. Add a fourth if anything arrives by post, because that path runs against arrival through the Product Registry instead of through an entry filing.
And be careful reading the rule as a routing map. Its January 2025 text sends low-value shipments to Entry Type 86 — a route that stopped being usable on August 29, 2025, when CBP, implementing Executive Order 14324, stated that "type 86 entries may no longer be utilized." The certificate rule then took effect in July 2026 still naming it. Two agencies, two decisions, ten months of gap in between. Where that leaves your shipments is a question for your broker about your current entries, not a question the rule text can answer.
Then do the boring durable part: get onto the Reference Message Set so you're not re-keying the same data forever, and keep the certificates and test reports for five years somewhere they'll still reach you. A certificate is only worth what you can produce years later, at an address that still works.



