Nothing about your products became regulated in July. What changed is that someone now checks at the border, automatically, on every entry.
Compliance obligations that are never verified behave, in practice, like optional ones. Certificates of compliance have been required for regulated consumer products since 2008, and for most of that period the enforcement mechanism was that Customs or CPSC could ask to see one. Many never asked.
Electronic filing removes the asking. Certificate data now travels with the entry, which means the question is answered on every shipment rather than on the rare occasions somebody raised it.
This is written for ecommerce operators trying to understand what changed and why. It is not legal or customs advice. Product classification drives everything downstream here and is genuinely specialist work, so verify against CPSC's own guidance and work with a qualified customs broker rather than relying on any article, including this one.
What Actually Changed
The Consumer Product Safety Commission approved a final rule in December 2024, published in the Federal Register on 8 January 2025, amending 16 CFR Part 1110. A correction was published in September 2025, which is worth knowing exists if you are working from an early copy of the rule.
The mechanism is straightforward. Certificate data is transmitted through the CPSC participating government agency message set within CBP's Automated Commercial Environment at the time of entry, alongside the customs filing. This brings CPSC into line with other agencies that already collect data at entry.
| Aspect | Before | Since 8 July 2026 |
|---|---|---|
| Certificate required? | Yes, since 2008 | Yes. Unchanged. |
| Which products? | Those subject to a CPSC rule, ban or standard | Identical. No scope change. |
| When submitted | On request, after the fact | Proactively, at entry. |
| How submitted | Paper or document accompanying goods | Electronically via ACE. |
| Visibility to CPSC | Occasional and sampled | Every regulated entry. |
Read that table across and the nature of the change is clear. Every row about obligation is unchanged. Every row about visibility is different. That distinction is the whole article.
Why This Exposed Rather Than Created
The framing matters because it determines what a brand should conclude about its own position.
If eFiling were a new obligation, a brand without certificates would be a brand facing a new requirement, with a reasonable grievance about compliance burden. Since it is a filing change, a brand without certificates has been non-compliant for as long as it has been importing regulated goods, and the rule simply made that legible.
The rule imposes new requirements for how importers manage certificate data, not which products require a certificate. If you did not have one before, the problem is not the new rule.
That is uncomfortable and it is more useful than the alternative reading. A brand that concludes it now needs certificates will obtain them and move on. A brand that concludes it has been shipping uncertified regulated products for years will also ask what testing was never done, which is the more important question.
The corollary is that fixing the filing does not fix the underlying position. Filing certificate data requires having a certificate, and a valid certificate requires testing that actually happened. There is no route through this that skips the testing, which is why section eleven exists.
Domestic Manufacturers Too
Nearly all coverage of this rule addresses importers, and that framing is incomplete in a way that matters.
CPSC's own published effective-date table lists domestically manufactured products alongside imported general products, both taking effect 8 July 2026, with only Foreign Trade Zone entries deferred. The rule revises certificate requirements for products manufactured in the United States as well as those brought into it.
The eFiling component naturally attaches to import entry, since that is where customs filing occurs. The revised certificate content requirements are broader than the filing mechanism, and a US manufacturer reading importer-focused coverage may reasonably but wrongly conclude none of it applies.
Reporting indicates the rule reaches importers, domestic manufacturers, and private labelers of CPSC-regulated consumer products. Private labeler is the category ecommerce brands most often occupy without recognizing the term: if your name is on a product somebody else manufactured, you are likely a private labeler rather than a bystander.
Reporting also indicates the requirements extend to resold and overstock products, which catches brands buying closeout inventory and assuming certification travelled with it. Certification obligations attach to the product being distributed in commerce rather than to whether you were the first party to sell it.
Low-Value Shipments Are Included
The assumption most likely to catch a direct-to-consumer brand, and it is stated plainly in the reporting.
CPSC electronic filing requirements apply regardless of shipment value, including low-value and direct-to-consumer shipments. There is no small-parcel carve-out and no value threshold below which the certificate data requirement disappears.
That matters for a specific and increasingly common model: brands shipping individual orders direct from an overseas factory or fulfillment partner to US customers, bypassing domestic inventory entirely. Each of those parcels is an entry, and if the product is CPSC-regulated the certificate data requirement attaches.
Brands operating that way should have a direct conversation with their logistics partner about how certificate data is being transmitted on their behalf, because the answer determines whether shipments flow or accumulate at the border. If nobody can describe the mechanism, it is probably not happening.
This is also worth factoring into fulfillment model decisions rather than treating as an afterthought. Direct-from-factory shipping carries compliance overhead that domestic inventory does not, and our comparison of fulfillment models covers the wider trade-offs that sits inside.
Which Certificate You Need
Two document types, and which applies depends on who the product is for.
For products designed or intended primarily for children 12 and under. Requires testing by a CPSC-accepted third-party laboratory, which is the significant cost and lead-time item.
For general-use products subject to a CPSC rule, ban, standard or regulation. Based on a test or a reasonable testing program rather than mandatory third-party testing.
Certificates are required for products subject to a CPSC rule, ban or standard. Determining that is a classification exercise and the answer is frequently yes for ordinary consumer goods.
Certificates are issued for finished products, and testing supporting the affirmation must be recorded on the certificate even where it was performed on component parts.
The classification question is the one to spend time on. Sellers routinely assume regulation applies to obviously hazardous categories and not to ordinary household goods, when in practice a wide range of everyday products fall under a CPSC rule, ban or standard.
Children's products carry the heaviest burden because third-party testing at an accepted laboratory is mandatory rather than optional. If you sell anything designed or intended primarily for children twelve and under, treat testing lead time as a fixed input to your launch schedule rather than a step you compress.
What The Certificate Must State
The content requirements are more specific than sellers expect, and a certificate missing elements is not a valid certificate.
Per CPSC's guidance, certificates must state all applicable rules, bans, standards and regulations; the most recent date of testing; and identify each testing laboratory that conducted the testing. Certificates should associate each laboratory with the specific rules and standards for which it tested, whether that testing was performed on the finished product or on a component part.
That last requirement is the one that breaks supplier-provided documents. A factory certificate frequently asserts compliance in general terms without naming which laboratory tested against which standard, and a document that cannot map laboratory to standard does not satisfy the requirement however genuine the underlying testing was.
Take one certificate your supplier has provided and check it against those elements: every applicable rule named, most recent testing date present, each laboratory identified, and each laboratory mapped to what it tested against. If any element is missing, the certificate needs reissuing, and you would rather discover that now than through a held shipment.
The practical consequence is that certificate quality becomes a supplier selection criterion. A factory that produces properly constituted certificates without argument is meaningfully easier to work with than one that supplies a document and resists questions about it.
Two Ways To File
The rule permits two mechanisms, and the choice affects your operational load rather than your compliance position.
Full message set. You provide your broker with the complete product certificate and the broker files the full data in the CPSC message set with each entry. Simpler to start, and it means transmitting the same data repeatedly for repeat shipments.
Reference message set. You pre-enter certificate data into the CPSC Product Registry, receive identifiers, and provide those identifiers to your broker for filing. More setup, considerably less repetition afterwards.
Reporting indicates the Product Registry is optional but encouraged for frequent importers, that registration can take time to complete, and that a privacy setting exists allowing account administrators to restrict visibility of trade party data, meaning the manufacturers, laboratories and contacts identified on certificates.
The sensible split follows shipment frequency. A brand importing occasionally can reasonably file full data each time. A brand importing regularly across a stable catalog will find the registry route removes recurring work, and the setup cost is paid once.
Either way the broker is central to execution, which makes this a conversation to have with them rather than a system to configure alone. They file it; you supply accurate data and correct classification.
The January 2027 Date
One deadline in this rule has not yet arrived, and it is roughly three months out as this publishes.
Consumer products imported into a Foreign Trade Zone and subsequently entered for consumption or warehousing become subject to the requirements on 8 January 2027, six months after the general date.
If you use a Foreign Trade Zone, that deferral has given you additional runway and it is running out. The preparation is identical to what other importers completed for July: confirm which products are regulated, confirm certificates exist and contain the required elements, decide your filing route, and make sure your broker has what they need.
Everyone else already did this in July, which means the mistakes are documented, brokers have processed several months of live filings, and the practical questions have known answers. Preparing now is considerably easier than preparing in June was, provided you start before December rather than during it.
The risk in a deferred deadline is that it stops feeling like a deadline. Six months of additional time is useful only if some of it is spent, and Foreign Trade Zone operators who have not begun should treat the remaining window as short rather than comfortable.
The Ecom Profit Box
Our collection of ecommerce growth resources, including the sourcing and cost frameworks this belongs inside.
Get It FreeSourcing A New Product?
We are not customs brokers. We can help you build testing and certification into a launch timeline before it becomes urgent.
Book A CallWarnings Are Not Amnesty
A nuance in how the rollout has operated that is easy to misread in a convenient direction.
Reporting indicates that during rollout, the system issues warning messages rather than rejecting entries for missing data. A brand filing incomplete data may therefore see goods released with a warning rather than held.
The wrong conclusion is that the requirement is not being enforced. Reporting is explicit that CPSC continues to enforce certificate requirements and can seek seizure of non-compliant products, and non-compliant importers may face delays in release and increased scrutiny at the port of entry.
The distinction worth holding is between the filing mechanism and the underlying obligation. A lenient filing system is not a lenient safety regime. Warnings relate to the transmission of data; seizure relates to whether the product complies, and those are separate questions with different consequences.
Treating a warning as a pass also misses the trajectory. Rollout leniency is temporary by design, and a brand relying on it is relying on a condition that exists specifically to be withdrawn once filers have adapted.
Where This Meets Your Other Obligations
Certification does not sit alone, and the connections are worth seeing because the same underlying work serves several purposes.
Testing supports more than the certificate. The laboratory reports behind a certificate are the same evidence you would rely on if a product's safety were questioned, so the file has value beyond satisfying a filing requirement.
Marketplace category approval frequently requires certificates. Children's product certificates are commonly requested when seeking approval to sell in restricted categories, so certification work done for import purposes is reusable.
Insurance and certification interact. Demonstrating that a product was tested against applicable standards is relevant to how a liability claim proceeds, and continuing to sell after learning of a hazard is a different situation entirely from an unforeseen defect.
Cost belongs in unit economics. Third-party testing for children's products in particular is a real per-product cost with real lead time, and it should sit in your landed cost model rather than appearing as an unpleasant surprise before a launch. Our landed cost guide covers where to put it.
The unifying point is that a brand with proper testing documentation is in a better position across several unrelated scenarios at once, which makes the spend easier to justify than viewing it purely as a customs requirement.
If You Have Never Held A Certificate
Written for the situation section two describes, because it is more common than the compliance literature acknowledges and the honest advice differs from the general advice.
- Establish whether your products are actually regulated. Not every consumer product is. This is a classification question and it is worth getting right before assuming the worst or the best.
- Do this before your next order, not before your next shipment. If testing is needed, it has lead time, and discovering that with goods already in production is worse than discovering it now.
- Ask your supplier what testing exists. Sometimes testing was performed and documentation was simply never passed on, which is a paperwork exercise rather than a testing program.
- Where testing does not exist, arrange it. There is no filing route that substitutes for it, and a certificate asserting untested compliance is a worse position than no certificate.
- Get advice on historic exposure. If you have been distributing regulated products without certification, that is a question for a lawyer rather than for a blog post, and the answer depends on specifics.
- Fix forward first. Get the next order right while you work out the rest. Compliance from here is achievable immediately; the past is a separate conversation.
The reason to be direct about this is that the alternative is worse. A brand that quietly obtains a certificate without asking whether testing happened has documentation asserting something nobody verified, which converts a compliance gap into a false attestation.
What To Do Now
Practical sequence, whichever position you are in.
- Confirm classification. Which products are subject to a CPSC rule, ban or standard, and which are genuinely outside it. Accurate HTS codes and product descriptions drive everything downstream.
- Audit existing certificates against the content requirements in section six. Named rules, testing date, laboratories identified and mapped.
- Confirm who files. Your broker transmits the data; you supply it. Make sure both parties agree on which.
- Choose full or reference filing based on shipment frequency, and start Product Registry setup early if you choose the reference route.
- Check direct-shipping arrangements if you fulfil from overseas, since low value does not exempt anything.
- Diarise January 2027 if you use a Foreign Trade Zone.
- Build testing into product development so certification is a scheduled step rather than a pre-launch emergency.
The Underlying Point
This rule is unusual among 2026 compliance changes in that it asks for nothing new substantively. No product became regulated, no standard tightened, no threshold moved. A brand that was doing this properly experienced an administrative change and nothing more.
Which makes it a reasonable proxy for the health of your compliance generally. If July was uneventful, your documentation was in order. If it caused difficulty, the difficulty was already present and merely unobserved, and the useful response is to ask what else is in that category rather than to treat the filing as the problem that was solved.
What To Remember
- The rule changed how and when certificate data is submitted, not which products need certificates. Those have been required since 2008, so a brand without them was already non-compliant.
- Mandatory eFiling began 8 July 2026 for most imported products and for domestically manufactured ones, with Foreign Trade Zone entries following on 8 January 2027.
- It is not only an importer rule. CPSC's effective-date table covers domestically manufactured products, and reporting indicates the rule reaches importers, domestic manufacturers, and private labelers.
- There is no value threshold. Requirements apply regardless of shipment value, including low-value and direct-to-consumer parcels shipped from overseas.
- Certificates must name every applicable rule, the most recent testing date, and each laboratory, mapped to what it tested, which is where supplier-provided documents commonly fail.
- Warnings during rollout are not amnesty. A lenient filing system is not a lenient safety regime, and CPSC can still seek seizure of non-compliant products.
- Filing cannot substitute for testing. A certificate asserting untested compliance is a worse position than having no certificate at all.
Where This Came From
- Consumer Product Safety Commission, Certificates of Compliance final rule, published in the Federal Register on 8 January 2025, and the subsequent correction published 24 September 2025.
- Certificate requirements at 16 CFR Part 1110, via the Electronic Code of Federal Regulations.
- US Customs and Border Protection, Automated Commercial Environment, the system through which participating government agency message sets are transmitted.
- CPSC's published business guidance on certificates and its eFiling frequently asked questions, including the effective-date table covering domestically manufactured, imported general, and Foreign Trade Zone scenarios, and the certificate content requirements regarding applicable rules, testing dates, and laboratory identification. Cited by description because cpsc.gov refuses automated requests and could not be linked or verified programmatically.
- Customs brokerage, law firm, and carrier reporting on the two filing routes, the optional Product Registry and its trade party privacy setting, the application of requirements regardless of shipment value including low-value and direct-to-consumer shipments, the extension to resold and overstock products, and the issuance of warning messages rather than entry rejections during rollout alongside continued enforcement and possible seizure.

