CPSC eFiling in ACE requires more than obtaining an accepted entry response. Even when ACE does not issue an SX reject, importers and customs brokers must ensure that required certificate of compliance data is transmitted accurately, reviewed for agency messages, and supported by defensible product records.
Why ACE Acceptance Is Not CPSC Clearance
No SX Reject Does Not Eliminate the Filing Requirement
CPSC fully implemented its eFiling requirements for certificate of compliance data on July 8, 2026. For covered consumer products, filing the required CPSC data through the Partner Government Agency message set is mandatory even when ACE accepts an entry without that information.
This distinction is operationally significant. ACE can accept an entry that lacks a CPSC message set or contains incomplete CPSC data, provided the transmission otherwise follows the overall CATAIR PGA message set specification. In these scenarios, CBP generally will not generate an SX reject solely because the expected CPSC information is absent or incomplete.
Entry acceptance therefore confirms only that the transmission passed applicable ACE processing rules. It does not establish that the importer satisfied CPSC certification obligations, that the product is admissible, or that the agency accepted the underlying certificate data. Customs brokers and importers should treat ACE acceptance as an intermediate technical result rather than a final compliance determination.
CSMS #69382435 reinforces this separation between system processing and regulatory responsibility. The absence of an automated rejection does not create an exception from CPSC eFiling requirements and should not be interpreted as permission to release an entry workflow without further review.
CPSC Can Still Review or Reject the Data
CPSC may return an SO message indicating that data is under review or has been rejected. The agency may also take enforcement action when required eFiling data is missing, inaccurate, or unsupported. Depending on the facts, consequences can include cargo delays, examinations, requests for documentation, detention, or more serious enforcement measures.
Compliance teams should therefore evaluate CPSC-covered lines separately from the overall entry status. A successful customs response and a satisfactory CPSC response are related but distinct milestones.
Building a Defensible CPSC eFiling Workflow
Determine Applicability at the Product Level
A reliable process begins before entry transmission. Importers should determine whether each consumer product requires a Children’s Product Certificate, General Certificate of Conformity, or another applicable certification record. That analysis should consider product characteristics, intended users, testing requirements, applicable safety rules, and the importer’s role in the transaction.
HTS flagging can help identify potentially regulated merchandise, but it is not a substitute for a product-specific compliance determination. A flagged tariff classification does not always mean that a certificate is required, while an unflagged line does not necessarily establish that no CPSC obligation applies. Classification, product master data, testing records, and certification logic should be reviewed together.
Validate Certificate Data Before Transmission
CPSC eFiling workflows should capture and validate the data needed for either a Full PGA Message Set or an authorized Reference PGA Message Set. Depending on the filing method and product, relevant information may include the certifier, importer of record, manufacturer, place and date of manufacture, testing location, testing date, laboratory details, and the applicable product safety rules.
Validation should go beyond checking whether a field is populated. Systems should detect inconsistent party information, malformed identifiers, missing rule citations, invalid reference data, and mismatches between the certificate and the commercial shipment. Reusing data from an earlier entry without verifying the current product, manufacturer, or test record can introduce significant compliance risk.
Monitor Agency Messages and Exceptions
A defensible workflow should retain the transmitted payload, ACE acknowledgments, CPSC SO messages, user changes, and supporting certificate records. Exceptions should be routed to trained personnel rather than left in a general entry-processing queue.
When CPSC data is under review or rejected, the broker and importer should have a defined escalation path. That process should identify who investigates the data, who authorizes corrections, whether cargo movement should be paused, and how the final resolution is documented. Questions that cannot be resolved internally can generally be directed to CPSC’s eFiling support team at efilingsupport@cpsc.gov.
Responsibilities Across Importers, Brokers, and Software Vendors
Importers Retain Product Compliance Responsibility
Importers generally remain responsible for determining whether a product requires certification and for maintaining accurate supporting records. A broker can transmit data supplied by the importer, but brokerage services do not transfer the importer’s underlying responsibility for product compliance.
Importers should provide brokers with structured, shipment-ready data rather than certificates that require manual interpretation at the time of entry. Product master records should connect SKUs with applicable safety rules, certificate types, testing data, manufacturing details, and any valid reference identifiers. Change controls are also essential when manufacturers, laboratories, materials, or product designs change.
Brokers Need Controls Beyond Entry Acceptance
Customs brokers should identify CPSC-covered lines during intake and confirm that required data is available before transmission. Operational dashboards should distinguish among entries with complete CPSC data, entries awaiting importer information, records under agency review, and rejected data requiring correction.
Because ACE may not issue an SX reject, brokers should not rely on reject queues as the primary compliance control. A filing can appear technically successful while still containing a material CPSC deficiency. Written procedures, account instructions, exception reports, and post-entry audits can help close that gap.
Software Must Permit Compliant Submissions
Software vendors should allow users to submit CPSC data even when automated flagging does not indicate that the data is required. Hard stops based exclusively on tariff flags can prevent valid filings for products that require certification despite the absence of a system flag.
Applications should support both Full and Reference PGA Message Sets, expose agency responses clearly, and preserve line-level audit trails. Configurable warnings are generally more appropriate than rigid restrictions when flagging and product-level compliance conclusions differ.
International mail also requires attention. Effective October 22, 2026, qualifying mail shipments using CBP Entry Type 13 require the applicable Full or Reference PGA Message Set. This change makes consistent product data and filing controls increasingly important across commercial, express, and postal channels.
- CPSC eFiling of certificate of compliance data remains mandatory in ACE even without SX rejects.* On July 29, 2026, CBP issued CSMS #69382435 (update to #69177694) confirming full implementation since July 8, 2026. ACE accepts entries lacking a CPSC PGA message set or with incomplete CPSC data (if overall CATAIR PGA specs are followed); software should allow submissions regardless of flagging. CBP will not generate SX rejects in these cases, but CPSC may issue SO messages for review or data rejection and can take enforcement action (including seizures) on entries missing required eFiling data.
- CPSC extended eFiling to international mail shipments.* On September 1, 2026, CPSC posted guidance requiring Full or Reference PGA Message Sets for mail via new CBP Entry Type 13, effective October 22, 2026 (previously mail lacked ACE entry data for PGA transmission). Importers (or eligible brokers) remain responsible; this closes a prior loophole for low-value postal parcels of regulated consumer products.
- Updated HTS flagging list and supporting documents issued.* CPSC posted a revised Guidance and HTS List (September 14, 2026) identifying flagged codes, plus related citation/testing exception codes. Document library updates (through late September) include mail shipment guidance (August 31, 2026 PDF) and CATAIR implementation details. Flagging is a signal, not a substitute for determining certificate requirements.
- Industry and practitioner emphasis on ongoing risks despite no ACE reject.* Broker/law firm analyses (late July–August 2026, with some September follow-ups) and limited X discussions (e.g., September 4 on “Under Review” messages) stress that missing or incomplete CPSC data can still raise risk scores, trigger holds/exams, or lead to enforcement even without SX rejects or cargo stops. Launch glitches were limited (e.g., ignorable PGA errors if data is correct); CPSC and NCBFAA discussed messaging in mid-July. Software vendors (e.g., Shopify) added fields to support filings. Contact efilingsupport@cpsc.gov for questions.
Frequently Asked Questions
Is a CPSC Certificate Required If ACE Does Not Issue an SX Reject?
Yes, when the product is subject to CPSC certification and eFiling requirements. The absence of an SX reject means the entry passed the relevant ACE processing rules; it does not waive the requirement to submit certificate data. CPSC may still review the filing and take enforcement action when required information is missing.
What Is an SO Message From CPSC?
An SO message is an agency response associated with the CPSC data submission. It may indicate that the information is under review or that the submitted data has been rejected. Brokers and importers should monitor these messages independently of the general ACE entry status and investigate exceptions promptly.
Should Software Block CPSC Data When the HTS Code Is Not Flagged?
Generally, no. Software should allow authorized users to transmit CPSC data even when automated flagging criteria are not met. HTS flags are screening tools rather than definitive legal determinations. Product characteristics and applicable consumer product safety requirements may support filing even without a flag.
Who Is Responsible for the Accuracy of CPSC eFiling Data?
The importer generally retains responsibility for product compliance and the accuracy of supporting certification information. A customs broker may prepare and transmit the PGA message set based on importer-provided data. Both parties should establish clear responsibilities for data validation, correction, record retention, and agency response monitoring.
Can a Reference PGA Message Set Be Used Instead of Full Certificate Data?
A Reference PGA Message Set may be used when the underlying certificate data has been properly established in the applicable CPSC system and the reference remains valid for the product and shipment. Importers should confirm that the referenced record accurately reflects current manufacturing, testing, and certification facts rather than assuming that an earlier reference can be reused indefinitely.
What Records Should Be Retained?
A strong audit file typically includes the applicable certificate, test reports, product and manufacturing details, laboratory information, transmitted PGA data, ACE acknowledgments, CPSC messages, corrections, and internal approval records. Retention practices should align with applicable legal requirements and the company’s broader customs and product compliance program.
How Stable Software Can Help
Create a Controlled CPSC eFiling Process
Stable Software helps importers and customs brokers replace fragmented spreadsheets, emails, and manual checks with structured trade compliance workflows. Centralized product data, configurable validation, exception management, and line-level audit trails can help teams identify missing CPSC information before transmission and monitor agency responses after filing.
By connecting entry operations with product-level compliance records, organizations can reduce dependence on ACE rejects as a control mechanism and create a more defensible eFiling process. Customs brokers and importers seeking scalable automation for CPSC PGA filings and other trade workflows can learn more at stablesoftware.com.
Resources
| Type | Resource |
|---|---|
| CSMS #69382435 | content.govdelivery.com — 422b123 |
| CPSC eFiling / Import Surveillance | cpsc.gov — eFiling |




