CPSC eFiling Data Requirements: Complete 2026 Importer Checklist
A field-by-field, source-by-source guide for importers preparing CPSC certificate data for a Full or Reference PGA filing.
- Author:
- VelaCert Editorial Team
- Published:
- Updated:
VelaCert is not CPSC, CBP, a testing laboratory, customs broker, or law firm. This page is practical operational guidance, not legal advice or a determination that a product complies. Confirm authoritative requirements with the current CPSC, CBP, and Federal Register sources linked below.
What data do you need for CPSC eFiling?
For CPSC eFiling, prepare the finished product’s identifier and name, certificate type, applicable CPSC rule citations or testing exclusions, manufacturer identity and manufacture date/place, latest relevant test date, laboratory identity, records contact, certifying entity, and attestation. A Full PGA filing transmits the applicable certificate data with the entry. A Reference PGA filing instead sends the Certifier ID, Product ID, and Version ID for a certificate already certified in CPSC’s Product Registry. Exact fields depend on the product and filing method.
Current requirement
CPSC eFiling status in 2026
Most applicable imports
eFiling applied on July 8, 2026 for most imported consumer products subject to CPSC certification.
Foreign trade zones
For regulated products admitted into an FTZ and later entered for consumption or warehousing, the applicability date is January 8, 2027.
eFiling is the electronic submission of certificate-of-compliance data through CPSC’s PGA Message Set. CBP’s July 29, 2026 CSMS update says ACE can accept an entry when a CPSC message set is absent or some CPSC data is missing. That is an ACE processing choice, not an exemption: eFiling remains mandatory when required, and CPSC may review or reject CPSC data or take enforcement action.
Who this importer checklist is for
Use this checklist if you prepare, approve, or transmit certificate data for imported products subject to CPSC certification:
- Importer or responsible certifierThe importer of record and, where applicable, the owner, purchaser, or consignee identified as the certifying entity.
- Compliance and quality teamsTeams connecting product, supplier, testing, citation, and certificate records.
- Import operationsTeams packaging confirmed data and identifiers for a customs broker or filing system.
A broker may transmit the PGA data, but transmission alone does not create the underlying certificate records or automatically transfer certification responsibility.
Core worksheet
CPSC eFiling master data checklist
CATAIR v2.5 describes seven high-level certificate data groups. Those are not the complete list of individual Full PGA records and are not the Product Registry CSV column count. The table below consolidates the operational data an importer should locate and validate; required fields still vary by product, certificate, entity role, filing method, and conditional CATAIR rules.
| Data element | Status | What it means | Typical source | Usually provided by | Example | Common problem |
|---|---|---|---|---|---|---|
| Product identifier and type | Required | At least one supported identifier for the finished product. Current Full PGA types include GTIN, UPC, SKU, model number, serial number, registered number, and alternate identifier. | Product master / SKU record | Importer product team | Model: AC-2026 | The filing identifier does not match the product or source records. |
| Product name | Required | The name or model description of the finished product covered by the certificate. | Product master, certificate | Importer / certifier | Wooden activity cube | A shipment description is used instead of the specific certified product. |
| Certificate type | Required | Children’s Product Certificate (CPC) or General Certificate of Conformity (GCC), based on the certificate required for the product. | Compliance record | Certifier / compliance team | CPC | CPC and GCC are treated as interchangeable. |
| Applicable rule citation or testing exclusion | Required | Each applicable CPSC-enforced rule, ban, standard, or regulation being certified, or an applicable official testing-exclusion code. | Test report, regulatory assessment, CPSC code tables | Compliance team / lab | Applicable CPSC citation code | A report’s test method is copied without confirming the current CPSC citation code. |
| Manufacturer identity | Required | Manufacturer name and identifying information. Product Registry workflows may reuse an existing GLN or account-specific alternate ID. | Supplier and trade-party record | Manufacturer / supplier | Existing manufacturer alternate ID | Duplicate manufacturer records or an identifier that the importer’s Registry account does not recognize. |
| Manufacture date | Required | The manufacture month and year in Full PGA; the Registry/CSV workflow must follow its documented date format. | Production record | Manufacturer / supplier | 07/2026 | Spreadsheet software reformats the value or the date is guessed from a test report. |
| Manufacture place and contact details | Required | The manufacturing location, including the address or allowed GPS alternative and the associated contact details required by the selected workflow. | Factory profile / supplier record | Manufacturer / supplier | Factory city, country, postal code | Only a corporate headquarters address is available. |
| Laboratory type and identity | Required or conditional | Use ITL for a CPSC-accepted third-party laboratory, LAB for another laboratory, or NOL when an applicable testing exclusion means no lab testing is required. CPC Full PGA filings report ITL only. | Test report, CPSC lab listing | Lab / compliance team | ITL + four-digit CPSC Lab ID | Lab name is present but the required lab type or CPSC Lab ID is missing. |
| Latest relevant test date | Required or conditional | For laboratory testing, the latest date of testing reported for the certificate data. If multiple labs are included in Full PGA, CATAIR calls for the latest test date. | Test report | Lab / compliance team | 06/15/2026 | An old report date is carried into a newer product version. |
| Test-results records contact | Required or conditional | The party maintaining test-result records. In Full PGA, if no separate contact is sent, CPSC will contact the importer of record. | Internal responsibility matrix | Importer / certifier | Compliance operations contact | The broker is listed without confirming who can produce the records. |
| Certifying entity | Required or conditional | The entity responsible for certifying the certificate data. In Full PGA, CPSC treats the importer of record as certifier unless a different certifying entity is reported. | Certificate / importer responsibility record | Importer / responsible certifier | Owner identified as certifying entity | The filer and certifier roles are assumed to be the same without confirmation. |
| Attestation | Required | The certifying entity’s declaration that the finished product complies with the cited requirements and the certificate information is true and accurate to the best of its knowledge, information, and belief. | Certification workflow | Certifying entity | CPY declaration code in Full PGA | Operational data is prepared but no authorized certifier owns the declaration. |
| Product Registry Certifier ID, Product ID, Version ID | Required for Reference PGA | The three Certificate Identifiers that together point to the exact certified Product Registry version. | CPSC Product Registry | Registry account owner / certifier | Certifier ID + primary Product ID + Version ID | Only the Product ID is sent to the broker, or the Version ID is stale. |
| Current/new version information | Conditional | Registry updates identify the current certificate version and create a new version when certificate data changes, including new testing that requires an updated certificate. | Product Registry / change record | Compliance team | Current version mapped to new version | Multiple designs or test cycles are mixed into one version. |
| Test report ID, URL, access key, component description | Optional | CATAIR and the Product Registry support optional test-report references and a component-part description. CPSC may still request supporting records. | Document system / test report | Compliance team / lab | Report ID and controlled-access URL | A URL expires, credentials are missing, or optional fields are mistaken for a substitute for retained records. |
| Additional product details and lot dates | Optional | Additional identifiers, brand, color, style, description, lot number, and production start/end dates can improve record specificity when available. | Product and production records | Importer / manufacturer | Lot 26-071; production dates | Optional attributes conflict with the primary product version. |
On small screens, swipe the table horizontally. “Required” here means part of the applicable certificate/PGA workflow; consult current CPSC and CATAIR instructions for record-level conditions and formatting.
The seven Full PGA data groups, in plain language
- 1.Product identification
- 2.Applicable rules and/or statutory or regulatory testing exclusions
- 3.Identification of the certifier
- 4.Contact for records and optional electronic access
- 5.Manufacture date and place
- 6.Test date and place
- 7.Attestation by the certifying entity
Where each piece of CPSC eFiling data comes from
No single document or team usually owns every required data point. Assign each source before asking a broker to file.
Product and SKU records
Primary and additional product identifiers, product name, brand, model, description, color, style, lot, and production-version mapping.
Manufacturer or supplier
Manufacture date and place, manufacturer identity and contact details, production lot information, and confirmation that the shipped design matches the certified product.
Test report and laboratory
Test dates, laboratory identity, tested model, cited tests or standards, report identifiers, and sometimes manufacturer or sample details. These still need to be reconciled to CPSC citation codes and the current product version.
Internal compliance records
Certificate type, applicable-rule determination, testing exclusions, certifying entity, records contact, attestation ownership, and the decision to issue or update a certificate.
CPSC Product Registry
Certificate records and versions, reusable trade-party identifiers, and the Certifier ID, Product ID, and Version ID required for a Reference PGA filing.
Customs broker and entry workflow
Entry-line context, Full or Reference message transmission, and broker validation of the identifiers or data received. The broker should not have to reconstruct product compliance facts from scratch.
What a test report can—and cannot—give you
A test report may help identify
- • Tested product name, model, or sample identifiers
- • Tests, standards, or citations addressed
- • Test date and report date
- • Laboratory name, address, and report identifier
- • Manufacturer or applicant details, when the report includes them
It may not establish
- • The importer’s current internal Product ID
- • The responsible certifier and records contact
- • Product Registry Certifier ID, Product ID, or Version ID
- • Current manufacturer trade-party identifiers
- • Whether the shipped design matches the tested version
- • Every applicable rule or the final certification decision
A test report is an important source document, but it is not automatically a complete eFiling record.
Full PGA vs. Reference PGA
Both methods support CPSC eFiling. The main difference is where the complete certificate data is stored before the entry message is sent.
| Question | Full PGA Message Set | Reference PGA Message Set |
|---|---|---|
| Where is full certificate data prepared? | It is assembled for transmission with the entry or entry summary certified for release. | It is entered and certified in CPSC’s Product Registry before the entry. |
| What does the broker transmit? | The applicable Full PGA records containing certificate data. | The Certifier ID, Product ID, and Version ID that identify the Registry certificate. |
| Is Product Registry required? | No. CPSC says it is not required for Full PGA. | Yes, because the message references a certificate stored there. |
| Does Product Registry send to ACE automatically? | Not applicable. | No. CPSC says the Registry is stand-alone and does not communicate automatically with ACE; the identifiers must be passed into the entry workflow. |
| What changes when testing or certificate data changes? | The current certificate data must be reflected in the Full filing. | The Registry certificate/version must be updated as required, and the current identifiers must be sent to the broker. |
Before you send CPSC data to your customs broker
- Product ID, type, name, and shipped version are confirmed.
- CPC or GCC certificate type is confirmed for the product.
- Applicable CPSC citation codes or testing-exclusion codes are confirmed.
- Manufacture date, place, manufacturer identity, and contact details are available.
- Latest relevant test date and laboratory identity/type are confirmed.
- The certifying entity and test-records contact are confirmed.
- The certifier understands and owns the required attestation.
- For Reference PGA, the current Certifier ID, Product ID, and Version ID are available.
- The broker knows whether to send Full, Reference, or—only when appropriate—an optional Disclaim message.
- Source documents are retained and traceable to the product and certificate version.
Common CPSC eFiling data preparation mistakes
Sending only a Product ID for Reference PGA instead of the full set of Certifier ID, Product ID, and Version ID.
Reporting a lab name but omitting the required lab type, CPSC Lab ID for ITL, or citation/testing-exclusion records.
Treating optional test-report URL, report ID, or access key as a substitute for required certificate data or retained supporting records.
Using a model or SKU that does not match the test report, product master, certificate, and broker handoff.
Associating an older test report with a changed design, material, factory, component source, or product version without review.
Mixing multiple product versions, manufacture dates, or testing cycles in one operational record.
Asking the broker to reconstruct manufacturer, testing, citation, or certification facts from scattered files.
Practical workflow layer
How VelaCert helps organize the source data
VelaCert helps keep product, manufacturer, testing, certificate, version, and source-document information connected before filing. Teams can see missing information, trace reviewed fields to source records, and keep product versions organized for a more consistent broker handoff.
VelaCert does not determine all applicable regulations, guarantee compliance or CPSC acceptance, replace a broker or laboratory, or provide legal advice.
Official CPSC & CBP Sources
- eFiling Frequently Asked Questions— U.S. Consumer Product Safety Commission
- Certificates of Compliance guidance— U.S. Consumer Product Safety Commission
- eFiling resources for importers— U.S. Consumer Product Safety Commission
- eFiling Document Library— U.S. Consumer Product Safety Commission
- Product Registry User Guide V3— U.S. Consumer Product Safety Commission
- User Guide for CSV Upload V3— U.S. Consumer Product Safety Commission
- CPSC eFiling Implementation Guide (CATAIR v2.5)— U.S. Customs and Border Protection
- CSMS #69382435: CPSC PGA Message Set update— U.S. Customs and Border Protection
- Certificates of Compliance Final Rule, 90 FR 1800— Federal Register
- Certificates of Compliance correction, 90 FR 45917— Federal Register
- Children’s Product Certificate guidance— U.S. Consumer Product Safety Commission
- General Certificate of Conformity guidance— U.S. Consumer Product Safety Commission
Frequently asked questions
What data is required for CPSC eFiling?
The exact records depend on the filing method and product. At a high level, CPSC’s current CATAIR guide groups the certificate data into product identification; applicable rules or testing exclusions; certifier identification; records contact and optional test-record access; manufacture date and place; test date and place; and an attestation. Full PGA filings transmit the applicable certificate data with the entry, while Reference PGA filings transmit certificate identifiers that point to data already certified in the Product Registry.
What are the seven Full PGA data elements?
They are seven high-level data groups, not seven CSV columns: product identification; applicable rules and testing exclusions; certifier identification; contact for records and optional electronic access; manufacture date and place; test date and place; and attestation. Each group can require several individual fields in a Full PGA Message Set.
Do I need to use the CPSC Product Registry?
Not for every filing. CPSC says the Product Registry is used for the Reference PGA option, where full certificate data is entered and certified before entry. It is not required for a Full PGA Message Set, which transmits the certificate data with the entry. The Product Registry is separate from ACE and does not send data to ACE automatically.
What is the difference between Full PGA and Reference PGA?
A Full PGA Message Set sends the applicable certificate data as part of the entry filing. A Reference PGA Message Set sends the Certifier ID, Product ID, and Version ID that identify a certificate already certified in the Product Registry. Your broker still needs those identifiers for the reference filing.
Does my customs broker handle CPSC eFiling for me?
A broker may transmit the entry data, but transmission does not automatically shift product-certification responsibility or create the underlying records. CPSC’s importer guidance describes the importer as the importer of record eligible to make entry and explains how an owner, purchaser, or consignee may be identified as the responsible certifier in certain broker-as-IOR arrangements.
Is a test report enough for CPSC eFiling?
Usually not. A report may supply product, citation, test-date, and laboratory details, but it may not contain the certifier, current certificate version, Product Registry identifiers, records contact, internal product identifier, or complete manufacturer trade-party data. It is an important source document, not automatically a complete eFiling record.
What happens if CPSC certificate data is missing?
CBP’s July 29, 2026 update says ACE can accept an entry without a CPSC message set or with some CPSC data missing when the overall CATAIR specification is followed. That behavior is not an exemption: eFiling remains mandatory when required, CPSC may respond about or reject the CPSC data, and CPSC may take enforcement action on an entry missing required eFiling data.
When did CPSC eFiling become mandatory?
The requirement applied on July 8, 2026 for most imported consumer products subject to certification. For regulated products admitted into a foreign trade zone and later entered for consumption or warehousing, the applicability date is January 8, 2027.