CPSC eFiling Data Requirements: Complete 2026 Importer Checklist

A field-by-field, source-by-source guide for importers preparing CPSC certificate data for a Full or Reference PGA filing.

Author:
VelaCert Editorial Team
Published:
Updated:

VelaCert is not CPSC, CBP, a testing laboratory, customs broker, or law firm. This page is practical operational guidance, not legal advice or a determination that a product complies. Confirm authoritative requirements with the current CPSC, CBP, and Federal Register sources linked below.

What data do you need for CPSC eFiling?

For CPSC eFiling, prepare the finished product’s identifier and name, certificate type, applicable CPSC rule citations or testing exclusions, manufacturer identity and manufacture date/place, latest relevant test date, laboratory identity, records contact, certifying entity, and attestation. A Full PGA filing transmits the applicable certificate data with the entry. A Reference PGA filing instead sends the Certifier ID, Product ID, and Version ID for a certificate already certified in CPSC’s Product Registry. Exact fields depend on the product and filing method.

Current requirement

CPSC eFiling status in 2026

Most applicable imports

eFiling applied on July 8, 2026 for most imported consumer products subject to CPSC certification.

Foreign trade zones

For regulated products admitted into an FTZ and later entered for consumption or warehousing, the applicability date is January 8, 2027.

eFiling is the electronic submission of certificate-of-compliance data through CPSC’s PGA Message Set. CBP’s July 29, 2026 CSMS update says ACE can accept an entry when a CPSC message set is absent or some CPSC data is missing. That is an ACE processing choice, not an exemption: eFiling remains mandatory when required, and CPSC may review or reject CPSC data or take enforcement action.

Who this importer checklist is for

Use this checklist if you prepare, approve, or transmit certificate data for imported products subject to CPSC certification:

  • Importer or responsible certifierThe importer of record and, where applicable, the owner, purchaser, or consignee identified as the certifying entity.
  • Compliance and quality teamsTeams connecting product, supplier, testing, citation, and certificate records.
  • Import operationsTeams packaging confirmed data and identifiers for a customs broker or filing system.

A broker may transmit the PGA data, but transmission alone does not create the underlying certificate records or automatically transfer certification responsibility.

Core worksheet

CPSC eFiling master data checklist

CATAIR v2.5 describes seven high-level certificate data groups. Those are not the complete list of individual Full PGA records and are not the Product Registry CSV column count. The table below consolidates the operational data an importer should locate and validate; required fields still vary by product, certificate, entity role, filing method, and conditional CATAIR rules.

CPSC eFiling data elements, status, meaning, source, provider, example, and common problem
Data elementStatusWhat it meansTypical sourceUsually provided byExampleCommon problem
Product identifier and typeRequiredAt least one supported identifier for the finished product. Current Full PGA types include GTIN, UPC, SKU, model number, serial number, registered number, and alternate identifier.Product master / SKU recordImporter product teamModel: AC-2026The filing identifier does not match the product or source records.
Product nameRequiredThe name or model description of the finished product covered by the certificate.Product master, certificateImporter / certifierWooden activity cubeA shipment description is used instead of the specific certified product.
Certificate typeRequiredChildren’s Product Certificate (CPC) or General Certificate of Conformity (GCC), based on the certificate required for the product.Compliance recordCertifier / compliance teamCPCCPC and GCC are treated as interchangeable.
Applicable rule citation or testing exclusionRequiredEach applicable CPSC-enforced rule, ban, standard, or regulation being certified, or an applicable official testing-exclusion code.Test report, regulatory assessment, CPSC code tablesCompliance team / labApplicable CPSC citation codeA report’s test method is copied without confirming the current CPSC citation code.
Manufacturer identityRequiredManufacturer name and identifying information. Product Registry workflows may reuse an existing GLN or account-specific alternate ID.Supplier and trade-party recordManufacturer / supplierExisting manufacturer alternate IDDuplicate manufacturer records or an identifier that the importer’s Registry account does not recognize.
Manufacture dateRequiredThe manufacture month and year in Full PGA; the Registry/CSV workflow must follow its documented date format.Production recordManufacturer / supplier07/2026Spreadsheet software reformats the value or the date is guessed from a test report.
Manufacture place and contact detailsRequiredThe manufacturing location, including the address or allowed GPS alternative and the associated contact details required by the selected workflow.Factory profile / supplier recordManufacturer / supplierFactory city, country, postal codeOnly a corporate headquarters address is available.
Laboratory type and identityRequired or conditionalUse ITL for a CPSC-accepted third-party laboratory, LAB for another laboratory, or NOL when an applicable testing exclusion means no lab testing is required. CPC Full PGA filings report ITL only.Test report, CPSC lab listingLab / compliance teamITL + four-digit CPSC Lab IDLab name is present but the required lab type or CPSC Lab ID is missing.
Latest relevant test dateRequired or conditionalFor laboratory testing, the latest date of testing reported for the certificate data. If multiple labs are included in Full PGA, CATAIR calls for the latest test date.Test reportLab / compliance team06/15/2026An old report date is carried into a newer product version.
Test-results records contactRequired or conditionalThe party maintaining test-result records. In Full PGA, if no separate contact is sent, CPSC will contact the importer of record.Internal responsibility matrixImporter / certifierCompliance operations contactThe broker is listed without confirming who can produce the records.
Certifying entityRequired or conditionalThe entity responsible for certifying the certificate data. In Full PGA, CPSC treats the importer of record as certifier unless a different certifying entity is reported.Certificate / importer responsibility recordImporter / responsible certifierOwner identified as certifying entityThe filer and certifier roles are assumed to be the same without confirmation.
AttestationRequiredThe certifying entity’s declaration that the finished product complies with the cited requirements and the certificate information is true and accurate to the best of its knowledge, information, and belief.Certification workflowCertifying entityCPY declaration code in Full PGAOperational data is prepared but no authorized certifier owns the declaration.
Product Registry Certifier ID, Product ID, Version IDRequired for Reference PGAThe three Certificate Identifiers that together point to the exact certified Product Registry version.CPSC Product RegistryRegistry account owner / certifierCertifier ID + primary Product ID + Version IDOnly the Product ID is sent to the broker, or the Version ID is stale.
Current/new version informationConditionalRegistry updates identify the current certificate version and create a new version when certificate data changes, including new testing that requires an updated certificate.Product Registry / change recordCompliance teamCurrent version mapped to new versionMultiple designs or test cycles are mixed into one version.
Test report ID, URL, access key, component descriptionOptionalCATAIR and the Product Registry support optional test-report references and a component-part description. CPSC may still request supporting records.Document system / test reportCompliance team / labReport ID and controlled-access URLA URL expires, credentials are missing, or optional fields are mistaken for a substitute for retained records.
Additional product details and lot datesOptionalAdditional identifiers, brand, color, style, description, lot number, and production start/end dates can improve record specificity when available.Product and production recordsImporter / manufacturerLot 26-071; production datesOptional attributes conflict with the primary product version.

On small screens, swipe the table horizontally. “Required” here means part of the applicable certificate/PGA workflow; consult current CPSC and CATAIR instructions for record-level conditions and formatting.

The seven Full PGA data groups, in plain language

  1. 1.Product identification
  2. 2.Applicable rules and/or statutory or regulatory testing exclusions
  3. 3.Identification of the certifier
  4. 4.Contact for records and optional electronic access
  5. 5.Manufacture date and place
  6. 6.Test date and place
  7. 7.Attestation by the certifying entity

Where each piece of CPSC eFiling data comes from

No single document or team usually owns every required data point. Assign each source before asking a broker to file.

Product and SKU records

Primary and additional product identifiers, product name, brand, model, description, color, style, lot, and production-version mapping.

Manufacturer or supplier

Manufacture date and place, manufacturer identity and contact details, production lot information, and confirmation that the shipped design matches the certified product.

Test report and laboratory

Test dates, laboratory identity, tested model, cited tests or standards, report identifiers, and sometimes manufacturer or sample details. These still need to be reconciled to CPSC citation codes and the current product version.

Internal compliance records

Certificate type, applicable-rule determination, testing exclusions, certifying entity, records contact, attestation ownership, and the decision to issue or update a certificate.

CPSC Product Registry

Certificate records and versions, reusable trade-party identifiers, and the Certifier ID, Product ID, and Version ID required for a Reference PGA filing.

Customs broker and entry workflow

Entry-line context, Full or Reference message transmission, and broker validation of the identifiers or data received. The broker should not have to reconstruct product compliance facts from scratch.

What a test report can—and cannot—give you

A test report may help identify

  • • Tested product name, model, or sample identifiers
  • • Tests, standards, or citations addressed
  • • Test date and report date
  • • Laboratory name, address, and report identifier
  • • Manufacturer or applicant details, when the report includes them

It may not establish

  • • The importer’s current internal Product ID
  • • The responsible certifier and records contact
  • • Product Registry Certifier ID, Product ID, or Version ID
  • • Current manufacturer trade-party identifiers
  • • Whether the shipped design matches the tested version
  • • Every applicable rule or the final certification decision

A test report is an important source document, but it is not automatically a complete eFiling record.

Full PGA vs. Reference PGA

Both methods support CPSC eFiling. The main difference is where the complete certificate data is stored before the entry message is sent.

QuestionFull PGA Message SetReference PGA Message Set
Where is full certificate data prepared?It is assembled for transmission with the entry or entry summary certified for release.It is entered and certified in CPSC’s Product Registry before the entry.
What does the broker transmit?The applicable Full PGA records containing certificate data.The Certifier ID, Product ID, and Version ID that identify the Registry certificate.
Is Product Registry required?No. CPSC says it is not required for Full PGA.Yes, because the message references a certificate stored there.
Does Product Registry send to ACE automatically?Not applicable.No. CPSC says the Registry is stand-alone and does not communicate automatically with ACE; the identifiers must be passed into the entry workflow.
What changes when testing or certificate data changes?The current certificate data must be reflected in the Full filing.The Registry certificate/version must be updated as required, and the current identifiers must be sent to the broker.

Before you send CPSC data to your customs broker

  • Product ID, type, name, and shipped version are confirmed.
  • CPC or GCC certificate type is confirmed for the product.
  • Applicable CPSC citation codes or testing-exclusion codes are confirmed.
  • Manufacture date, place, manufacturer identity, and contact details are available.
  • Latest relevant test date and laboratory identity/type are confirmed.
  • The certifying entity and test-records contact are confirmed.
  • The certifier understands and owns the required attestation.
  • For Reference PGA, the current Certifier ID, Product ID, and Version ID are available.
  • The broker knows whether to send Full, Reference, or—only when appropriate—an optional Disclaim message.
  • Source documents are retained and traceable to the product and certificate version.

Common CPSC eFiling data preparation mistakes

CPSC / CATAIR condition

Sending only a Product ID for Reference PGA instead of the full set of Certifier ID, Product ID, and Version ID.

CPSC / CATAIR condition

Reporting a lab name but omitting the required lab type, CPSC Lab ID for ITL, or citation/testing-exclusion records.

CPSC / CATAIR condition

Treating optional test-report URL, report ID, or access key as a substitute for required certificate data or retained supporting records.

VelaCert workflow recommendation

Using a model or SKU that does not match the test report, product master, certificate, and broker handoff.

VelaCert workflow recommendation

Associating an older test report with a changed design, material, factory, component source, or product version without review.

VelaCert workflow recommendation

Mixing multiple product versions, manufacture dates, or testing cycles in one operational record.

VelaCert workflow recommendation

Asking the broker to reconstruct manufacturer, testing, citation, or certification facts from scattered files.

Practical workflow layer

How VelaCert helps organize the source data

VelaCert helps keep product, manufacturer, testing, certificate, version, and source-document information connected before filing. Teams can see missing information, trace reviewed fields to source records, and keep product versions organized for a more consistent broker handoff.

VelaCert does not determine all applicable regulations, guarantee compliance or CPSC acceptance, replace a broker or laboratory, or provide legal advice.

Official CPSC & CBP Sources

Frequently asked questions

What data is required for CPSC eFiling?

The exact records depend on the filing method and product. At a high level, CPSC’s current CATAIR guide groups the certificate data into product identification; applicable rules or testing exclusions; certifier identification; records contact and optional test-record access; manufacture date and place; test date and place; and an attestation. Full PGA filings transmit the applicable certificate data with the entry, while Reference PGA filings transmit certificate identifiers that point to data already certified in the Product Registry.

What are the seven Full PGA data elements?

They are seven high-level data groups, not seven CSV columns: product identification; applicable rules and testing exclusions; certifier identification; contact for records and optional electronic access; manufacture date and place; test date and place; and attestation. Each group can require several individual fields in a Full PGA Message Set.

Do I need to use the CPSC Product Registry?

Not for every filing. CPSC says the Product Registry is used for the Reference PGA option, where full certificate data is entered and certified before entry. It is not required for a Full PGA Message Set, which transmits the certificate data with the entry. The Product Registry is separate from ACE and does not send data to ACE automatically.

What is the difference between Full PGA and Reference PGA?

A Full PGA Message Set sends the applicable certificate data as part of the entry filing. A Reference PGA Message Set sends the Certifier ID, Product ID, and Version ID that identify a certificate already certified in the Product Registry. Your broker still needs those identifiers for the reference filing.

Does my customs broker handle CPSC eFiling for me?

A broker may transmit the entry data, but transmission does not automatically shift product-certification responsibility or create the underlying records. CPSC’s importer guidance describes the importer as the importer of record eligible to make entry and explains how an owner, purchaser, or consignee may be identified as the responsible certifier in certain broker-as-IOR arrangements.

Is a test report enough for CPSC eFiling?

Usually not. A report may supply product, citation, test-date, and laboratory details, but it may not contain the certifier, current certificate version, Product Registry identifiers, records contact, internal product identifier, or complete manufacturer trade-party data. It is an important source document, not automatically a complete eFiling record.

What happens if CPSC certificate data is missing?

CBP’s July 29, 2026 update says ACE can accept an entry without a CPSC message set or with some CPSC data missing when the overall CATAIR specification is followed. That behavior is not an exemption: eFiling remains mandatory when required, CPSC may respond about or reject the CPSC data, and CPSC may take enforcement action on an entry missing required eFiling data.

When did CPSC eFiling become mandatory?

The requirement applied on July 8, 2026 for most imported consumer products subject to certification. For regulated products admitted into a foreign trade zone and later entered for consumption or warehousing, the applicability date is January 8, 2027.