By the Digital Empire Regulatory Research Team (EntryProof Analysis Team) · Reviewed by Andy Gaber, Founder, Digital Empire Holdings LLC · Published August 23, 2026 · Last updated August 23, 2026
The single most common conceptual error in CPSC compliance is treating the third-party testing laboratory as the certifying body for a Children's Product Certificate or General Certificate of Conformity. Under Section 14 of the Consumer Product Safety Act, at 15 USC 2063, the certifying party is always the manufacturer of the product (for domestically-made goods) or the importer of record (for foreign-made goods). It is never the testing lab. The testing lab performs the physical, chemical, or mechanical testing required by the applicable children's product safety rule, issues a test report documenting the results, and appears in the CPSC Product Registry as the accepted testing laboratory associated with the manufacturer's certification, but the certification signature itself is the manufacturer's or importer's. This guide walks the statutory allocation, the CPSC-accepted laboratory program at 16 CFR Part 1112, the firewalled-lab requirements for children's products, the operational split between the CPC and the GCC, and how the certifying-body identification flows into the Jul 8 2026 CPSC eFiling mandate through the ACE Partner Government Agency message set. Where EntryProof fits: as a pre-filing readiness check that surfaces certifying-body vs testing-lab identification errors before they reach the CPSC Product Registry validation layer.
Section 14(a) of the CPSA, at 15 USC 2063(a), establishes two distinct certification obligations. Paragraph (1) covers general-conformity certification for non-children's consumer products that are subject to a specific CPSA rule (cigarette lighters, bicycle helmets, portable generators, and so on). Paragraph (2) covers children's-product certification for products designed or intended primarily for children 12 years of age or younger. Both paragraphs place the certification obligation on the manufacturer of the product, or the importer of record for foreign-manufactured products. Neither paragraph places the certification obligation on the testing lab. The testing lab's role is defined separately in paragraph (2) as the third-party independent verifier of the underlying test results for children's products.
Why does this matter operationally? Because the CPSC Product Registry filing (the source system for post-Jul-8-2026 eFiling data) contains distinct fields for the certifying party and the accepted testing laboratory. Populating the accepted-lab field with the manufacturer's name, or populating the certifying-party field with the lab's name, is a validation failure. On the pre-Jul-8-2026 paper-and-optional-electronic regime, this kind of field-swap error was corrected at CBP release; on the post-Jul-8-2026 mandatory eFiling regime, it holds the shipment at the port until corrected in the Registry and re-transmitted through the ACE PGA message.
A CPSC-accepted third-party testing laboratory is a laboratory that has completed the CPSC acceptance process under 16 CFR Part 1112 for a specific scope of test methods. Acceptance is scope-granular; a lab accepted for lead-content testing under 16 CFR 1500.87 is not automatically accepted for phthalate content testing under 16 CFR 1307, or for small-parts mechanical testing under 16 CFR 1501, or for children's sleepwear flammability under 16 CFR 1615 and 16 CFR 1616. Each accepted scope is separately listed for the lab in the CPSC public registry at cpsc.gov/labsearch.
The acceptance criteria under 16 CFR 1112.13 through 1112.19 include: accreditation to ISO/IEC 17025 (the international general-competence standard for testing laboratories) by an accreditation body that is a signatory to the ILAC Mutual Recognition Arrangement; accreditation scope explicitly covering the specific CPSC test method the lab wants to be accepted for; a completed CPSC Form 223 acceptance application; and, where applicable under Subpart C, firewalling or governmental-lab documentation. CPSC reviews the acceptance application, verifies the underlying ISO/IEC 17025 accreditation with the accreditation body, and issues an acceptance letter that lists the lab and its accepted scopes in the public registry. Acceptance is not a one-time event; the lab must maintain the underlying ISO/IEC 17025 accreditation, must undergo periodic reassessment by the accreditation body, and must notify CPSC of any material change in the scope of its accreditation.
For children's products, the general expectation under 15 USC 2063(a)(2) is that the testing lab is independent of the manufacturer, defined as not owned, controlled, or under common control with the manufacturer. Independent labs are the standard model and represent the vast majority of CPSC-accepted labs in the public registry.
The exception is the firewalled lab model at 16 CFR 1112.31 through 1112.42. A manufacturer that owns, controls, or is under common control with a testing lab can use that lab for CPSC-required testing of the manufacturer's own children's products, but only if the lab meets the firewalled-lab requirements: physical separation of the lab operations from the manufacturer's design and production functions; independent lab personnel who do not report to manufacturer product-line management; a documented allegation-of-inappropriate-influence procedure that captures any attempted or actual influence on lab test results; periodic reporting to CPSC on allegations received; and an explicit "firewalled" designation on the lab's registry entry.
The firewalled-lab overhead is substantial, and in practice only the largest manufacturers with meaningful in-house testing capacity operate firewalled labs. Most manufacturers simply use an independent third-party lab from the public registry, which sidesteps the firewalling documentation burden entirely. The governmental lab variant at 16 CFR 1112.51 covers testing labs owned by federal, state, or local governmental entities; the governmental-lab framework is a niche pathway used mainly for specialty testing methods that only a national or state lab performs.
The operational sequence for a children's product certification, from a compliance-workflow perspective, is: (1) the manufacturer or importer identifies the applicable children's product safety rules for the specific product SKU; (2) the manufacturer sends a representative production sample to a CPSC-accepted lab whose accepted scope covers those rules; (3) the lab performs the required testing and issues a test report; (4) the manufacturer reviews the test report to confirm pass status on every applicable rule; (5) the manufacturer drafts the Children's Product Certificate identifying itself as the certifying party, listing the CPSC-accepted lab and the lab's CPSC-issued laboratory number, and referencing the specific test report identifier; (6) the manufacturer signs and dates the CPC; (7) the CPC is maintained in the manufacturer's records and made available on request to CBP, CPSC, retailers, and distributors; and (8) since Jul 8 2026, the underlying certification data is transmitted through the ACE PGA message set into the CPSC Product Registry at entry.
The signature block on the certificate identifies the certifying party (manufacturer or importer) with company name, address, contact person, and date. It does not identify the testing lab as the certifying party. It does list the testing lab and the lab's CPSC-issued number as a mandatory data element separate from the certifying party. Confusing these two fields on the certificate document, or transposing them in the CPSC Product Registry filing, produces the certifying-body-vs-testing-lab validation failure that is the most common eFiling hold reason at the port.
Since 2026-07-08, CPSC-regulated consumer product imports have been required to file the underlying certification data electronically at entry through the CPSC Product Registry via the ACE PGA message set. The specific data elements required in the eFiling transmission include: the identity of the certifying party (with the company's IOR number or manufacturer identifier), the identity of the CPSC-accepted testing lab (with the lab's CPSC-issued laboratory number), the specific test report identifier(s) supporting the certification, the applicable children's product safety rules the product was tested against, and the specific manufacturing production lot the certificate covers.
Validation failures at the CPSC Product Registry surface as ACE PGA rejects, which flow back to the importer's customs broker as a shipment hold at the port of entry. Common validation failures in the certifying-body-vs-testing-lab space include: (1) the lab identifier populated in the certifying-party field; (2) the manufacturer identifier populated in the accepted-lab field; (3) an accepted-lab number that does not appear in the current CPSC public registry (either a typo or a lab whose acceptance was suspended or withdrawn since the certificate was signed); (4) an accepted-lab scope that does not cover the specific children's product safety rule being certified against; (5) a certificate signed by a party (a consultant, a testing-lab affiliate, an unauthorized signatory) other than the manufacturer or importer of record.
EntryProof's readiness checker at /cpsc-efile/checker is designed specifically to catch these five failure modes before the eFiling submission reaches the CPSC Product Registry validation layer. The checker reads the intended certifying party, the intended accepted lab identifier, and the intended tested-against rule set, and returns a pre-filing readiness status that flags each of the common validation-failure patterns.
The Children's Product Certificate at 15 USC 2063(a)(2) and the General Certificate of Conformity at 15 USC 2063(a)(1) share the same certifying-party structure (manufacturer or importer) but differ substantially on the underlying testing regime. The CPC requires third-party CPSC-accepted lab testing against every applicable children's product safety rule. The GCC requires only a "reasonable testing program," which does not require third-party CPSC-accepted lab testing; a first-party or non-accredited-third-party testing program can satisfy the "reasonable" standard if the manufacturer documents the program adequately.
The eFiling regime treats both CPC and GCC data elements as required for the covered product categories, but the accepted-lab identifier is only required for CPC certifications (children's products). GCC certifications for non-children's products do not populate the accepted-lab field, because there is no accepted-lab requirement for GCCs. This is a common source of eFiling filing errors: a broker or importer that treats every certificate the same way and populates the accepted-lab field on a GCC will get a validation failure telling them the field is not applicable to the underlying certificate type.
The certifying-body statutory obligation cannot be delegated. What can be delegated, and typically is delegated, is the operational drafting of the certificate document, the maintenance of the underlying record-set, the filing of the ACE PGA message, and the management of the CPSC Product Registry account. Three different service providers commonly appear in the supporting cast:
The compliance consultant or the testing lab's regulatory-services arm typically drafts the CPC or GCC document, identifies the applicable children's product safety rules for a new SKU, and maintains the manufacturer's Registry account. This is a professional services engagement, not a certifying-body delegation; the signature block on the certificate still names the manufacturer or importer.
The customs broker transmits the ACE PGA message set at entry, pulling the certifying-party and accepted-lab data from the manufacturer's or importer's Registry account. The broker is the licensed customs professional the manufacturer or importer relies on to actually clear the entry through CBP and the CPSC Product Registry; the broker's job is transmission integrity, not certification substance.
The testing lab performs the underlying testing and issues the test report the manufacturer relies on to sign the certificate. Some testing labs also offer regulatory-services support (drafting CPCs on the manufacturer's behalf, maintaining Registry accounts), but the certifying-party signature always belongs to the manufacturer or importer, regardless of whether the drafting was done in-house, by a consultant, or by the lab.
EntryProof is a data preparation and readiness-assessment tool for the CPSC Product Registry. EntryProof is NOT a customs broker, NOT a testing laboratory, and NOT a legal-advice service. Compliance decisions remain the responsibility of the importer. EntryProof does not guarantee that any classification, packet, or filing will be accepted by CPSC or CBP.
EntryProof is not affiliated with the U.S. Consumer Product Safety Commission (CPSC), U.S. Customs and Border Protection (CBP), Amazon, Shein, Temu, or TikTok Shop.
The party that issues the certificate (Children's Product Certificate or General Certificate of Conformity) is the manufacturer of the product, or the importer of record if the product is foreign-manufactured. Under 15 USC 2063(a)(1) for general-conformity certificates and 15 USC 2063(a)(2) for children's product certificates, the statute puts the certification obligation on the manufacturer or importer. It is NEVER the testing laboratory that certifies the product. The testing lab performs the testing and issues a test report; the manufacturer or importer relies on that test report to sign the certificate.
A CPSC-accepted third-party testing laboratory performs the physical, chemical, or mechanical testing required by the applicable children's product safety rule and issues a test report documenting the results. For children's products under 15 USC 2063(a)(2), that test report must be issued by a laboratory listed on the CPSC-accepted laboratory registry at cpsc.gov/labsearch, must have been accepted by CPSC for the specific scope of the required test, and must be firewalled and independent from the manufacturer if the underlying product falls within the "firewalled lab" or "governmental lab" exception categories at 16 CFR Part 1112.
The regulations at 16 CFR Part 1112 govern the process by which CPSC accepts a third-party testing laboratory to perform testing under Section 14 of the CPSA. The lab must be accredited to ISO/IEC 17025 by an accreditation body that is a signatory to the ILAC MRA, must be accredited for the specific scope of the CPSC test method it will perform (each scope is granular; a lab accepted for lead-content testing under 16 CFR 1500.87 is not automatically accepted for phthalate testing under 16 CFR 1307), and must file the CPSC Form 223 acceptance application. Once accepted, the lab appears in the public registry with its accepted scopes.
For children's products where the manufacturer chooses to use a laboratory that the manufacturer owns, controls, or is under common control with, that laboratory must be "firewalled" from the manufacturer under 16 CFR Part 1112 Subpart C. The firewalling requirements include: physical separation of the lab operations from the manufacturer's design and production functions; independent lab personnel who do not report to manufacturer product-line management; a documented allegation-of-inappropriate-influence procedure; and periodic reporting to CPSC on any allegation received. Most manufacturers avoid the firewalled-lab overhead entirely by using an independent third-party CPSC-accepted lab; the firewalled-lab regime is primarily used by very large manufacturers with in-house testing capacity they want to leverage.
Since 2026-07-08, CPSC-regulated consumer product imports must file the underlying certification data electronically at entry through the CPSC Product Registry via the ACE Partner Government Agency (PGA) message set. The eFiled data includes the identity of the certifying party (manufacturer or importer), the identity of the CPSC-accepted testing lab, the CPSC-issued laboratory number, and the specific test report identifier. Filing the testing lab as the certifying party (a common error) will surface as a CPSC eFiling validation failure and hold the shipment at the port until corrected. EntryProof's readiness checker at /cpsc-efile/checker flags this specific mismatch on any hypothetical filing before it is submitted.
Yes for children's products, and yes for most non-children's consumer products that fall within an applicable general-conformity certificate rule. The Section 321 de minimis entry procedure (for shipments valued at $800 or less) does not exempt the underlying product from the CPSA certification requirement; it only simplifies the customs entry paperwork. The Jul 8 2026 CPSC eFiling mandate specifically covers Section 321 entries as well as formal entries, and the same certifying-body identification requirements apply. The specific de minimis compliance posture for the July 2026 mandate is documented in the CPSC eFiling FAQ at cpsc.gov/eFiling.
A CPC is issued for products designed or intended primarily for children 12 years of age or younger under 15 USC 2063(a)(2). CPC requires third-party CPSC-accepted lab testing against every applicable children's product safety rule. A GCC is issued for non-children's consumer products under 15 USC 2063(a)(1) that are subject to a specific CPSA rule (for example, cigarette lighters under 16 CFR 1210, or bicycle helmets under 16 CFR 1203). GCC requires "a reasonable testing program" but does NOT require third-party CPSC-accepted lab testing (that is the key statutory distinction). The certifying party is the same in both cases: the manufacturer, or the importer of record for foreign-made products.
No. The certification signature is a binding statement by the manufacturer or importer of record. Some manufacturers engage compliance consultants or their testing lab's regulatory-services arm to draft the certificate document and manage the CPSC Product Registry filing on the manufacturer's behalf, but the legal certifying party remains the manufacturer or importer. This is the same rule that governs any regulated-industry certification (medical-device 510(k) submissions, EPA Toxic Substances Control Act notifications, and so on): the operational drafting can be delegated, the legal certification cannot. EntryProof does not sign certificates on behalf of any manufacturer.
EntryProof runs pre-submission readiness checks against the CPSC eFiling validation layer — free checker, paid tier for continuous monitoring of accepted-lab registry changes.