The Deadline Is Behind You, Not Ahead of You
On July 8, 2026, the CPSC eFiling mandate took effect. Not “will take effect.” Took effect. If you import CPSC-regulated consumer products, the way you certify them has changed already.
Here is what that means in practice. Certificate of Compliance data now moves electronically, at the time of entry. Not on request. Not after the fact. At entry, every single time.
This is not a paperwork tweak. It rewires where your compliance data lives and when it has to exist.
Toys. Furniture. Mattresses. Button cell batteries. If any of that sits in your catalog, this is your problem now.
So what actually changed, what do you have to send, and what happens if you are still filing the old way? Let’s break it down in practical terms.
From Documents on File to Active Submission
For almost twenty years the model was simple. You kept certificates. Somebody asked. You produced them.
CPSC called that “Documents on File.” That era is over.
The new model is Active Submission. Certificate data travels with the entry as structured electronic information, transmitted through the CPSC PGA Message Set in ACE. Nobody has to ask for it. The data goes up front.
One point worth being precise about: the Final Rule changed how certificate data is filed, not which products need a certificate. Certification has been required since 2008 under Section 14 of the Consumer Product Safety Act. If your product needed a Children’s Product Certificate (CPC) or a General Certificate of Conformity (GCC) in June, it still does. What changed is that CBP now sees the data at entry.
You have two ways to send it:
- Full PGA Message Set. All seven certificate data elements go with every shipment. Best if you import a limited number of regulated products or rarely repeat the same item.
- Reference PGA Message Set. You pre-load certificate data into the CPSC Product Registry, then transmit three Certificate Identifiers at entry: Certifier ID, Product ID, and Version ID. Best if you import the same regulated products over and over.
The Product Registry is optional. The electronic submission is not.
And here is a detail that catches people. The Product Registry does not talk to ACE on its own. You enter data in the Registry, then hand the identifiers to your broker, who files them in ACE. Two systems, one manual handoff, one more place for things to break.
What Is Actually Covered
The mandate applies to imported finished consumer products that require a Certificate of Compliance under 16 CFR Part 1110.
The word “finished” is doing real work there. A component part is not, by definition, a finished product. It only requires certification if it is packaged, sold, or held for sale to consumers on its own, is specifically regulated by CPSC, and is imported for consumption or warehousing. Replacement parts sold directly to consumers usually clear that bar.
Check your catalog against these categories:
- Children’s products. Toys, games, cribs, bassinets, strollers, carriers, highchairs, children’s clothing and sleepwear.
- GCC products. Any general-use product subject to a CPSC rule, ban, or standard.
- Flammability items. Mattresses, rugs, carpets, and window coverings.
- Furniture. Upholstered furniture, dressers, bunk beds.
- Lighters and fireworks.
- Button cell and coin batteries (Reese’s Law), plus consumer products that contain them.
- Bicycles and ATVs.
That list is not exhaustive. Power adapters, portable lighting, small appliances, ladders, step stools, candles, and portable fuel containers also fall inside CPSC jurisdiction.
Roughly 600 HTS numbers are flagged in ACE for possible eFiling, but that list does not capture every regulated product. HTS flags are a trigger, not a definition. If you are not sure, run the product through CPSC’s Regulatory Robot before you file, or check the CPSC eFiling resources.
The Seven Data Elements
A Full PGA Message Set needs seven elements. They are the same fields your CPC or GCC already contains, so this is a data-plumbing problem, not a testing problem.
- Product ID. One of seven accepted types: GTIN, SKU, UPC, Model Number, Serial Number, Registered Number, or Alternate ID. Pick one that also appears on the packaging, packing list, or invoice so CPSC staff can match it fast.
- CPSC citations. Every applicable rule, ban, or standard the product is certified against. List each one separately. As of July 8, 2026, you must also identify any testing exclusions you rely on.
- Certifier identity. Name, full mailing address, and phone number for the party certifying the finished product.
- Records contact. Who holds the test records, and how CPSC reaches them.
- Manufacture date and place. Month and year at minimum, plus city and country.
- Test date and place. The most recent compliance test, plus the testing laboratory. If component part testing supports your certification, name that lab too.
- Attestation. Your affirmation that the product was tested to all applicable CPSC regulations and complies.
Going the Reference route instead? You send three identifiers, and the full data sits in your Registry account.
Here is a trap worth naming. A testing exclusion does not eliminate the certificate. If your product qualifies for an exclusion, you still issue a certificate, still cite the applicable rule, and still transmit the testing exclusion code. “Exempt from testing” is not “exempt from filing.” Importers get this backwards, and it surfaces at entry.
What Actually Happens If You Are Not Filing
This is where a lot of the commentary overshoots, so let’s be precise about what CPSC has actually said.
At launch, CPSC does not intend to ask CBP to deny entry solely because you failed to eFile certificate data. Per CPSC’s own eFiling FAQ, ACE sends warning messages for missing PGA data, not reject messages. Your container is not automatically stopped because a message set came through blank.
That is the good news. Now the part importers keep missing.
“Warning, not reject” is not the same as “no consequence.” CPSC built eFiling to sharpen its risk targeting. The agency has stated plainly that it will adjust an entry line’s risk score based on the certificate data you provide. Clean, complete filings pull your score down and reduce holds and examinations. Missing or sloppy data pushes it up and concentrates CPSC’s attention squarely on you.
And the underlying certificate obligation has teeth that predate eFiling entirely. CPSC continues to enforce certificate requirements and can request that CBP seize non-compliant products. Failing to furnish a certificate, or issuing a false one, is a violation of the Consumer Product Safety Act. That can carry civil penalties, criminal penalties in serious cases, and asset forfeiture.
So the honest picture looks like this. Nothing dramatic lands on you on day one for a missing message set. But every incomplete filing is a data point feeding a targeting algorithm, and over the coming months that algorithm decides whose containers get opened.
Treating July 8 as a soft suggestion because nothing bounced is exactly how a manageable compliance update turns into a chronic hold problem.
Your Catch-Up Checklist
The deadline passed. That does not mean you are out of options. It means the work moved from optional to urgent.
- Own it. Assign one person accountability for CPSC eFiling. Not a committee.
- Audit the catalog. Identify every product you import that requires CPSC certification. Confirm the HTS classifications. Run anything uncertain through the Regulatory Robot.
- Validate the data. Pull the seven elements for each regulated product. Confirm certificates are complete, current, and internally consistent. Watch for mismatches between the certificate, the invoice, and the packaging.
- Fix the exclusions. If you rely on a testing exclusion anywhere, confirm you have a certificate that cites the rule and names the exclusion code.
- Decide your route. Full Message Set or Product Registry. If you import the same SKUs repeatedly, register and bulk upload by CSV or API, then store your Certificate Identifiers.
- Close the loop with your broker. Agree explicitly on how certificate data or identifiers reach them before each entry. Then run filings together and read the ACE responses.
- Keep the records. Maintain certificates and supporting test records for at least five years from the certificate date.
Where CustomsCity Fits
Whatever route you take to CBP, you need a system that can actually transmit it.
CustomsCity supports the full range of CPSC PGA Message Sets in ACE, so your filing method is a business decision, not a software limitation.
- Full Message Set. Transmit all seven certificate data elements with the entry.
- Reference Message Set. Pre-load in the Product Registry and send the three Certificate Identifiers at entry.
- Disclaim Message Set. Signal when a line is not subject to CPSC requirements. Not mandatory, but CPSC encourages it, and it can help your risk score.
Ten entries a month or ten thousand, the objective is the same: get accurate certificate data to CBP the way that fits your operation, keep cargo moving, and keep your compliance record clean. Filing through the CustomsCity ABI platform means the CPSC message set lives in the same system as the rest of your entry.
The mandate is live. Do not wait for your first hold to find out where your process leaks. Request a demo and see how CustomsCity supports your CPSC eFiling.
Frequently Asked Questions
Yes. It took effect on July 8, 2026 for most imported regulated consumer products. Goods entered from a Foreign Trade Zone for consumption or warehousing get until January 8, 2027.
No. Certification has been required since 2008. The rule changed how the data reaches CBP: electronically, at entry, through the CPSC PGA Message Set in ACE.
No. There is no Section 321 or de minimis exemption. If the product requires certification, the certificate data must be eFiled regardless of shipment value.
Not for that reason alone, at least for now. CPSC has said it does not intend to request denial of entry based solely on a failure to eFile, and ACE sends warnings rather than rejects for missing PGA data. But CPSC still enforces certificate requirements, can request seizure of non-compliant products, and adjusts your risk score based on what you file. Nothing bouncing is not the same as nothing happening.
Yes. A testing exclusion does not remove the certificate obligation. You still issue the certificate, cite the applicable rule, and transmit the testing exclusion code.
Start with the catalog audit and your broker conversation, in that order. You cannot fix filings you have not mapped, and your broker cannot transmit data you have not sent them.



