By Andy Gaber · Published August 24, 2026 · Last updated August 24, 2026
Key stat: CPSC's eFiling rule (16 CFR Part 1110) requires the importer of record to file certificate data with CBP at or before entry — for children's products, filing after entry is not a permitted late-cure; the entry can be refused admission under 15 U.S.C. § 2066.

Your freight forwarder didn't ask for your lab report. They asked for something you've never heard of — and your container isn't moving until you get it right.
Your freight forwarder emailed. Subject line: "Need certificate data for CPSC eFiling before we can submit entry."
You sent them the PDF. The lab report. The one you paid $800 for eight months ago when you launched the toy. Test passed, nice little logo on it, everyone was happy.
They emailed back. That's not it.
Now you're on hold with your broker, googling "CPSC Product Registry" from your phone in a Costco parking lot, and your container is sitting at the port racking up per-diem while you figure out what a "PGA message set" is. Nobody told you this was coming. Or someone did, in a newsletter you skimmed in 2024, and you filed it under "not my problem" because you're not the one filling out customs forms — your broker is.
Except it turns out you are the problem. You're the importer of record. The broker just types what you give them.
And here's the part that makes it worse: this has nothing to do with the compliance documents Amazon already makes you upload to Seller Central. You can be fully squared away with Amazon's ASIN-level compliance checks and still get your container held at the port, because CPSC eFiling and Amazon's internal compliance review are two completely separate systems run by two completely different organizations, and passing one tells you nothing about the other.
This guide is the thing that email should have linked to. Let's fix your shipment, then let's fix your system so this never happens again.
One honest note before we start: I'm not a lawyer, and this isn't legal advice. It's a practitioner's field guide written for sellers who need to move a container this month. For anything ambiguous or high-stakes, get a customs broker or import compliance attorney to sign off before you ship.
Strip away the acronyms and it's a simple idea: instead of a certificate of compliance sitting in a folder on your laptop that nobody at the border ever sees, the underlying certificate data now has to be transmitted electronically to U.S. Customs and Border Protection at the moment of entry, so CPSC can see it too.
For most of CPSIA's history, the rule was that you had to have a valid certificate — General Certificate of Conformity (GCC) or Children's Product Certificate (CPC) — and it had to "accompany" the shipment or be available on request. In practice, that meant a PDF nobody checked unless something went wrong. CPSC couldn't screen incoming cargo for compliance data the way CBP screens for tariff classification, because the certificate wasn't part of the electronic entry.
CPSC finalized a rule in late 2024 that closes that gap. It requires the data elements from your GCC or CPC to be filed electronically with the entry, using the existing infrastructure CBP already runs for other regulatory agencies: the Automated Commercial Environment (ACE) and its Partner Government Agency (PGA) message set. CPSC becomes one more agency whose data rides along inside the same electronic entry your broker already files for tariff and country-of-origin purposes. Practically, that means the certificate stops being a document you produce if asked and becomes a data feed that has to exist before your goods clear.
The rollout has been phased rather than a single flip-the-switch date. There was a voluntary/pilot period where filers could test the PGA message set without being required to, followed by a period where CPSC and CBP began actively expecting the data on applicable entries, moving toward the full enforcement posture that's now in effect through 2026. If you've heard conflicting things about "the deadline," that's why — there wasn't one deadline, there was a runway, and different parts of the trade (brokers, filers, specific product categories) got onto it at different points. What matters for you right now, in 2026, is where enforcement actually sits: eFiling is live, brokers are asking for the data because they need it to file, and entries lacking it are getting held.
If your broker is asking you for this today, treat it as current, not early. The phase-in language you might have seen a year or two ago describing this as a future requirement has expired. It's the present.
The legal foundation underneath all of this is still the Consumer Product Safety Improvement Act (CPSIA) of 2008, which is what created the certification requirement in the first place. eFiling doesn't create a new substantive obligation to certify your products — you've technically owed that since 2008 or since your product came into scope. What eFiling does is make the government able to actually verify it at the border, in real time, instead of trusting the honor system.
This is the question that trips up more FBA sellers than any regulatory nuance in the certificate itself, because Amazon's whole platform is designed to make you feel like a marketplace vendor rather than an importer. You list a product, Amazon boxes it, Amazon ships it, Amazon handles the customer. It's easy to conclude Amazon is somewhere upstream of you handling the boring compliance stuff too.
It isn't. Not for direct-import FBA shipments where you're the one arranging freight from your factory in Shenzhen or Ho Chi Minh City to a U.S. port and then on to an Amazon fulfillment center. In that flow, you — or your LLC, if you've set one up, which you should have — are the Importer of Record (IOR). The IOR is the party legally responsible for the accuracy of the entry, for paying duties, and for compliance with every regulation that applies to what's in the container. That includes CPSC certification and, now, eFiling.
Amazon is not your customs broker. Amazon is not your IOR. Amazon does not see your entry data, does not file it, and does not know whether your GCC data ever made it into the Product Registry. Amazon's own compliance requests inside Seller Central (more on that in Section 6) are a completely separate check that Amazon runs for Amazon's own reasons — protecting itself from liability and from regulatory pressure on its marketplace. They do not touch CBP's ACE system at all.
Your customs broker executes the eFiling — they're the one physically transmitting the PGA message set as part of your entry. But a broker can only file what you give them. They don't test your product, they don't know your product's CPSIA rule set, and they legally cannot manufacture a certificate on your behalf. If you show up without certificate data, the best a broker can do is hold the entry and wait, because filing without it (or filing with wrong data) exposes both of you.
A few situational wrinkles worth naming plainly:
Two certificate types exist under CPSIA, and picking the wrong one is one of the most common — and most avoidable — mistakes sellers make.
General Certificate of Conformity (GCC) applies to products subject to a consumer product safety rule enforced by CPSC that are not children's products. Think: certain electronics, household goods, some furniture, general-use items that fall under a specific safety standard (flammability rules, for instance) but aren't marketed to or primarily used by kids 12 and under. A GCC can be based on your own reasonable testing program — it does not always require third-party lab testing, depending on the specific rule involved.
Children's Product Certificate (CPC) applies to any product designed or intended primarily for children age 12 or younger. This is the stricter path. A CPC must be based on testing conducted by a CPSC-accepted third-party laboratory — no self-certification allowed. If you sell toys, kids' furniture, juvenile products, children's jewelry, or apparel/accessories aimed at kids, you're almost certainly in CPC territory, and that means accredited lab testing is not optional.
Both certificate types, regardless of which one applies, need to contain the same broad categories of data under 16 CFR Part 1110 (the regulation governing certificate content):
| Data element | What it actually means | |---|---| | Product identification | SKU, model/style number, description specific enough to tie the certificate to the exact item | | Applicable rules/standards | Which CPSIA rule(s) the product is being certified against — e.g., 16 CFR 1303 (lead paint), 16 CFR 1501 (small parts/choking hazard for under-3s), 16 CFR 1250 (infant sleep product safety) | | Testing basis | Date(s) of testing, and for CPCs, the name and accreditation of the third-party lab that ran it | | Manufacturer information | Name and address of the manufacturer (and, where applicable, the private labeler) | | Importer information | Your name/entity and address — this is where your IOR status shows up on paper | | Date and place of manufacture | Which factory, which country, and roughly when the specific production run happened |
Here's the distinction that catches sellers out: a certificate is not a lab report, and a lab report is not a certificate. Your lab report is the underlying test data — pass/fail results against specific standards, run by a technician, stamped by the lab. Your certificate is a separate document (or now, a separate data record) that you generate, citing the lab report as its evidentiary basis, but structured according to 16 CFR 1110's specific data requirements. When your forwarder asked for "certificate data" and you sent the lab PDF, you gave them the raw ingredient, not the finished dish. The certificate is what pulls the lab result together with your product ID, your rule citations, your manufacturer info, and your importer info into the exact shape CPSC's system expects.
If you've never actually issued a formal GCC or CPC for a SKU — if all you have is a stack of lab PDFs from your sourcing agent — that's the gap you need to close first, before eFiling even enters the picture.
The Product Registry is CPSC's portal where certificate records live. Instead of your broker trying to transmit an entire certificate's worth of data fields inline with every single customs entry, you (or whoever owns compliance in your operation) create the certificate record once, in the Registry, and that record gets you a reference identifier. That reference is what actually flows through to the entry via the PGA message set — a pointer to a record CPSC already has, rather than the whole document re-transmitted every time.
There are effectively two ways the data can move at entry: a full-record filing, where the complete certificate data set is transmitted with that specific entry, and a reference filing, where you cite the existing Registry record by its reference number and CPSC/CBP pull the underlying detail from what's already on file. For a seller who reorders the same SKU repeatedly — which is most FBA sellers, since you're not inventing a new toy every container — reference filing is the workflow you want. Create the certificate once per product (and per material/testing change), then reuse the reference on every subsequent shipment of that same SKU until something changes that requires a recertification.
Who should own the Registry account? Not your freight forwarder, and not your broker, even though they're the ones who'll be asking you for the reference number on every shipment. The account holder is making legal representations about product compliance — that's an importer function, not a logistics function. In practice, for most small-to-mid FBA operations, that's either you personally as the business owner, or a designated compliance/ops lead who reports to you and who you trust to not fat-finger a rule citation. If you use a compliance consultant or a third-party service to manage this, make sure there's clarity on who has login access, who actually presses "create record," and who's accountable if a record is wrong — because the legal exposure sits with the importer regardless of who typed it in.
One practical habit worth building immediately: treat your Registry account the way you treat your Seller Central account. Don't share the login casually, keep a record of every certificate ID mapped to your SKUs somewhere your team can see (we'll build that exact matrix in Section 10), and revisit each record any time something about the product, the factory, or the testing changes.
Here's the full path from product idea to inventory sitting in an FBA warehouse, with who's responsible for each step.
The single most common failure point in this chain isn't the testing — sellers generally get that part right because a lab won't ship results without running the test. It's steps 4 and 5: assuming a lab report is the certificate, and never creating the Registry record at all until a broker forces the issue mid-shipment.
Amazon runs its own, entirely separate compliance apparatus inside Seller Central. If you sell toys, electronics, or other regulated categories, you've likely already been asked to upload documents — sometimes labeled as "safety test reports," sometimes as certificates, sometimes through category-specific enrollment flows before you're even allowed to list. Amazon can suspend individual ASINs, freeze inventory, or restrict your account based on its own review of what you upload, and it can do this independent of anything happening at the border.
Here's the collision: Amazon's compliance check and CPSC eFiling are unrelated systems that happen to ask for overlapping information. Passing one tells you nothing about the other.
You can have a spotless Seller Central compliance record — every document Amazon asked for, uploaded, approved, green checkmark — and still have your container held at the port because your broker never got a valid Product Registry reference. Amazon's document upload doesn't transmit anything to CBP. It's an internal Amazon risk-management tool, reviewed by Amazon's team (or their automated systems) against Amazon's own policies, which are informed by but not identical to CPSIA requirements.
Conversely, you can be perfectly eFiling-compliant — clean Registry records, broker files without a hitch, goods clear customs without incident — and still get an ASIN suspended because Amazon's compliance team wants a specific document format, or flagged your listing for a keyword that triggered an automated review, or wants proof tied to a program requirement (like Amazon's own toy safety enrollment) that has nothing to do with what CBP requires at entry.
The practical implication: you need to maintain compliance documentation twice, in two different systems, satisfying two different reviewers, and you cannot assume clearing one gate means the other is open. If your ops process only checks "did Amazon approve this ASIN," you have a blind spot at the border. If your ops process only checks "did the shipment clear customs," you have a blind spot on the listing side, and an ASIN suspension can freeze inventory that already cleared and is sitting in an FBA warehouse.
Build your compliance checklist to explicitly separate these two lanes: "Amazon Seller Central requirements" and "CPSC eFiling requirements," each with their own document set, their own point of contact, and their own verification step before a shipment or a listing goes live.
For years, a meaningful chunk of smaller FBA sellers — particularly those testing new SKUs, running low-volume imports, or using fulfillment models that split larger orders into smaller parcel-level shipments — could route goods under Section 321 de minimis treatment, which allowed shipments valued under a set threshold (historically $800 per person per day) to enter with minimal formal entry paperwork and largely skip the kind of formal-entry scrutiny that triggers PGA data requirements.
That door has been closing. Executive and regulatory actions during 2025 moved to eliminate or sharply restrict de minimis treatment, particularly for shipments originating from China and, more broadly, for low-value parcel imports generally. I'll be honest about the limits of what I can promise you here: the exact scope, effective dates, and country-by-country carve-outs shifted multiple times through 2025, and if you're relying on de minimis treatment for any part of your supply chain, you need to verify the current rule with your broker or a trade compliance source before you plan your next shipment around it — don't take a blog post's word for where that line sits today.
What matters practically, regardless of the exact current boundary, is the direction of travel: sellers who used to structure shipments to stay under the de minimis threshold — smaller, more frequent parcels, sometimes fulfilled through parcel-based cross-border programs rather than bulk container freight — are increasingly finding those shipments pushed into formal entry. And formal entry is exactly where CPSC eFiling requirements bite. A shipment that used to glide through with a commercial invoice and a customs declaration now needs the full entry treatment: tariff classification, country-of-origin documentation, and — if the product is CPSC-regulated — the PGA message set with your certificate reference.
If your business model included any meaningful volume that used to ride de minimis — drop-shipped test SKUs, low-MOQ trial runs shipped direct-to-consumer rather than through bulk FBA inbound, or parcel consolidators marketed as "duty-free under $800" — treat that volume as now exposed. Practically, that means: get Registry records created for those SKUs before you assume you can keep shipping them the old way, and have a conversation with whoever handles your parcel/de minimis logistics about whether their model still qualifies under current rules. Don't assume last year's shipping method still avoids formal entry just because it did in 2024.
The failure modes stack, and they compound each other, which is what makes a paperwork gap this expensive relative to how boring it looks on paper.
Entry rejection or hold at port. If your broker can't provide valid certificate data — no Registry reference, a reference that doesn't match the product description, or a rule citation that doesn't match the HTS classification — CBP can hold the entry rather than release it. Your container doesn't move. Your goods sit in a bonded facility while the paperwork gets sorted out.
CPSC sample requests. Beyond a paperwork hold, CPSC has authority to request physical samples for examination when something about an entry looks off — a new importer, a rule mismatch, a product category with a history of issues. This adds real time on top of the paperwork delay, and it's not something your broker can expedite; it's on CPSC's schedule, not yours.
Storage and demurrage bleed. Every day your container sits at port past its free time, you're paying per-diem storage and demurrage charges to the terminal and the carrier. These are not small numbers on a full container, and they accumulate daily while you're on the phone trying to figure out what data your broker needs. A one-week hold can turn into a bill that dwarfs what the compliance work would have cost if done in advance.
Repeated-violator targeting. CBP and CPSC both have discretion to increase scrutiny on importers with a history of entry problems. One missed filing might get resolved with a hold and a scramble. A pattern of missed or incorrect filings can get your future shipments flagged for closer review by default, which means every subsequent container — including ones that are perfectly compliant — moves slower.
The Amazon stockout cascade. This is the one sellers underweight until it happens to them. A held container means inventory doesn't arrive on schedule. FBA inventory runs out. You lose the Buy Box on the ASIN — sometimes within days of going out of stock, and it doesn't snap back the moment you restock. Amazon's ranking algorithm treats the stockout as a signal, and organic rank drops with it. You can spend months rebuilding a listing's velocity and rank after a stockout that a compliance-data gap caused. The dollar cost of a customs hold is almost never the demurrage bill — it's the weeks of suppressed sales and rank recovery that follow a stockout, which for an established ASIN can run into real five-figure territory depending on your sales velocity, and there's no fine or fee schedule anywhere that captures that number, because Amazon doesn't publish it and it depends entirely on your specific listing's history.
None of this requires bad intent. Most sellers who get caught by this are not trying to cut corners — they simply didn't know the lab report wasn't the certificate, or didn't know they needed a Registry record, or assumed their sourcing agent had it handled. The system doesn't distinguish between willful noncompliance and an honest gap in understanding. The hold happens either way.
Rough, honest numbers — treat everything here as an approximation to plan around, not a quote, because actual costs vary by lab, product complexity, and region.
Third-party lab testing, for a typical CPC-eligible product (a simple toy, for instance), tends to run roughly in the low-to-mid hundreds of dollars per SKU for a baseline test package covering the core requirements — lead content, phthalates where applicable, small parts/choking hazard, mechanical safety basics. More complex products — anything with batteries, electronics, textiles with additional flammability testing, or multiple material components — can push well into four figures per SKU once you're covering every applicable standard. If your product has electronic components, budget meaningfully more; electrical safety and EMC-adjacent testing (even where not CPSC-specific) adds real cost and real lead time, often several weeks on top of standard testing turnaround.
Registry setup time is mostly a one-time organizational cost rather than a per-shipment cost: getting the account created, understanding the interface, and building your first handful of certificate records typically takes a focused afternoon to a few days for someone doing it the first time, depending on how many SKUs you're onboarding at once. After that, adding a new certificate record for a new SKU (once you already have the lab data and the certificate document assembled) is a much faster task — closer to an hour than a day, per SKU, once you know the workflow.
Broker fees for handling PGA-inclusive entries vary by brokerage, by entry complexity, and by your existing relationship and volume. Some brokers fold this into their standard entry fee since it's now routine; others charge a modest incremental fee per entry for PGA data handling. Ask your broker directly what their current fee structure looks like for CPSC-regulated entries — this is not something to guess at, since it varies enough between brokers that a number here would mislead you either direction.
The timeline question that actually matters: how far ahead of a shipment should you start this? The honest answer is before the purchase order, not before the shipment. Lab testing takes real time — often two to four weeks depending on the lab's queue and the test package — and if you're waiting until goods are produced and ready to ship to start testing, you're already looking at a delay on that specific shipment. The sellers who never end up stuck in a parking lot arguing with a forwarder are the ones who treat "confirm the certificate and Registry record exist" as a gate before placing the PO, the same way they'd confirm pricing and MOQ. If a SKU doesn't have a valid, current certificate, don't place the reorder until it does.
One-off fixes get you through this shipment. What gets you through every future shipment without a parking-lot phone call is a system — specifically, a SKU-level compliance matrix that your whole team (or just you, if it's still just you) can check before any PO goes out and before any shipment gets booked.
Here's the shape of it:
| SKU | Product type | Applicable rule(s) | Test report ref. | Certificate type | Certificate/Registry ID | Cert. date | Expiry / retest trigger | |---|---|---|---|---|---|---|---| | TOY-1042-BLU | Stacking toy, ages 2+ | 16 CFR 1303, 1501 | LAB-REPORT-2291 | CPC | REG-88213 | 2026-01-14 | Material or factory change | | ELEC-3300-WHT | USB night light | 16 CFR 1500 (general) | LAB-REPORT-2305 | GCC | REG-88214 | 2026-02-02 | Component supplier change | | INF-0091-GRY | Infant sleep positioner | 16 CFR 1250 | LAB-REPORT-2318 | CPC | REG-88220 | 2026-02-19 | Annual retest recommended |
Build this as a living spreadsheet or, better, inside whatever inventory/PO tool you already use, so it's not a document that gets forgotten between shipments. The columns that matter most for staying out of trouble:
Retest triggers worth hard-coding into your process:
Supplier-change discipline is the unglamorous habit that prevents most of this. Put a clause in your supplier agreements or POs requiring notification before any material, component supplier, or subcontracted factory change. Suppliers change vendors to save two cents a unit constantly, and they usually don't think of it as something that affects your compliance status — because from their side, it doesn't. From your side, as the certificate holder, it can invalidate the whole basis of what you filed. A five-minute notification clause in your PO template is cheaper than any retest, let alone a held container.
Runnable this week. Work through it SKU by SKU for anything you're planning to ship in the next 60-90 days.
Does Amazon file CPSC certificates for me? No. Amazon is not your customs broker or your Importer of Record for direct-import FBA shipments, and it does not transmit anything to CBP's ACE system on your behalf. Amazon's Seller Central compliance document requests are a separate, internal Amazon process. You (or your customs broker, acting on the data you provide) are responsible for CPSC eFiling.
Do I need eFiling for products made in the USA? eFiling is tied to import entries — it applies at the point goods cross the border and get filed with CBP. If your product is manufactured domestically and never goes through an import entry, eFiling doesn't apply to that shipment leg. You still need a valid GCC or CPC to distribute the product in U.S. commerce, but there's no PGA data transmission involved since there's no customs entry happening.
Is my lab report enough? No, and this is the single most common mix-up. A lab report is the underlying test data. A certificate (GCC or CPC) is a separate record you generate that cites the lab report but also includes product identification, applicable rule citations, manufacturer and importer information, and date/place of manufacture per 16 CFR 1110. Your broker needs the certificate data — specifically, your Product Registry reference — not the raw lab PDF.
What if I sell only via sea freight to a 3PL, which then ships to FBA? The import entry still happens at the point your goods clear customs into the U.S., regardless of whether they go straight to an Amazon fulfillment center or first to a 3PL warehouse for prep. You're still the Importer of Record at that entry, and eFiling still applies the same way. The extra hop to a 3PL doesn't change your customs obligations — it's just a domestic logistics step that happens after entry.
Do general-use (non-children's) products need this too? Yes, if they're subject to a CPSC-enforced consumer product safety rule — that's exactly what a GCC covers. eFiling isn't limited to children's products; it applies to any CPSC-regulated product requiring a certificate, GCC or CPC alike. Don't assume you're exempt just because you don't sell toys.
What's a "reference filing" versus a "full-record filing"? A full-record filing transmits the complete certificate data set with that specific entry. A reference filing cites an existing Product Registry record by its reference ID, letting CBP/CPSC pull details from the record already on file. For sellers reordering the same SKU repeatedly, reference filing means creating the certificate once and reusing the reference across shipments, rather than resubmitting full data every time.
How do I know if my product needs a CPC instead of a GCC? Ask whether the product is designed or intended primarily for children 12 and under. If yes, it's a children's product and needs a CPC, which requires third-party lab testing — self-certification isn't allowed. If it's a general consumer product under a specific CPSC safety rule but not marketed to kids, a GCC applies, and depending on the specific rule, third-party testing may or may not be required.
Who should physically create the Product Registry records — me, my broker, or my sourcing agent? The account and the records should be owned by someone on the importer side — you or a designated compliance lead — because creating a certificate record is a legal representation about the product, and that liability sits with the importer, not the logistics chain. Your broker needs the reference number to file; they shouldn't be the one generating the underlying certificate.
What happens to my existing inventory already sitting in FBA — does it need to be pulled if I'm not eFiling-compliant? eFiling requirements attach at the point of import entry, not retroactively to inventory already cleared and warehoused. Goods that already cleared customs under the rules in effect at the time aren't typically subject to being pulled from FBA over a subsequent compliance gap discovered later — but any future reorder of that SKU needs a valid certificate and Registry record before its next entry. Don't extrapolate a compliance gap on your next shipment into a claim about existing inventory; if you're unsure, this is a case for a compliance attorney rather than guesswork.
Is there a grace period if I mess this up on my next shipment? Don't count on one. Enforcement in 2026 reflects the end of the phase-in runway, not the beginning of it. Treat any hold or rejection as a real, current-consequence event, not a warning shot — because by this point in the rollout, brokers and CBP are largely past the "we'll let it slide" phase that existed earlier in the transition.
Where do I even start if I've never touched any of this? Start with Section 11's checklist, and start with your highest-volume SKU, not your newest one. Get one SKU fully squared away — tested, certified, in the Registry, reference number in your broker's hands — as a proof of process, then replicate it across the rest of your catalog. Trying to fix everything simultaneously is how sellers end up doing none of it well before the next PO ships.