Executive summary
The General Certificate of Conformity is the certificate a manufacturer or importer of a non-childrens consumer product issues to attest that the product complies with each applicable consumer product safety rule under 15 U.S.C. § 2063. Every non-childrens consumer product subject to any CPSC rule requires a GCC. Every childrens product subject to any CPSC rule requires a Childrens Product Certificate (CPC) instead, and a CPC has the additional third-party-testing requirement.
The seven required GCC data elements are set at 16 CFR § 1110.11. The GCC must accompany the product to each distributor or retailer, must be furnished to CBP on request, and (under the CPSC eFiling regime effective July 8, 2026) has specific data elements transmitted to CBP through the Automated Commercial Environment (ACE) at entry filing time.
A missing, incomplete, or defective GCC on a covered product is a prohibited act under 15 U.S.C. § 2068 and creates civil-penalty exposure at 15 U.S.C. § 2069 with caps at $120,000 per violation and $17,150,000 per related series. Missing-GCC or bad- data shipments are held at port pending resolution — the industry-observed dwell- time cost runs $500 to $5,000 per day per container.
Statutory basis: 15 U.S.C. Section 2063
The certificate requirement is at 15 U.S.C. § 2063, Section 14 of the Consumer Product Safety Act. Subsection 14(a)(1) requires every manufacturer of a product subject to a consumer product safety rule or a similar rule, ban, standard, or regulation to issue a certificate that the product complies with the rule. Subsection 14(a)(2) requires the certificate to be based on a test of each product or on a reasonable testing program.
Subsection 14(a)(4) enumerates the categories that require third-party testing (children products fall under a separate CPC regime installed by the Consumer Product Safety Improvement Act of 2008 and codified at 15 U.S.C. § 2063(a)(2)). For most non- childrens products, first-party testing under a documented reasonable-testing program is the operative compliance basis.
The implementing regulations are in 16 CFR Part 1110. Section 1110.11 specifies the required content of every certificate. Section 1110.13 addresses language requirements. Section 1110.15 addresses the electronic-format certificate option. Section 1110.17 addresses record retention.
GCC vs. CPC: which certificate applies to which product
The GCC-CPC distinction is the first fork every certificate-issuing entity encounters. The distinction turns on whether the product is a childrens product as defined at 15 U.S.C. § 2052(a)(2). A childrens product is a consumer product designed or intended primarily for children 12 years of age or younger, evaluated based on the manufacturer's statement of intent, the labeling on the product, the age-appropriateness of the product in fact, and the four-factor guidance CPSC has published in 16 CFR Part 1200.
If the product is a childrens product, a Childrens Product Certificate is required and third-party testing by a CPSC-accepted laboratory under 16 CFR Part 1107 is mandatory. The CPC has an additional two required data elements beyond the GCC's seven: the identification of the CPSC-accepted third-party laboratory that conducted the testing, and the date and place of the third-party testing.
If the product is not a childrens product but is subject to any consumer product safety rule, a General Certificate of Conformity is required. First-party testing under a reasonable testing program is acceptable unless the specific rule category is one of the enumerated third-party-testing categories at 16 CFR § 1107.2 (fireworks under 16 CFR Parts 1500 and 1507, cigarette lighters under 16 CFR Part 1210, and others).
A product that is subject to no consumer product safety rule requires no certificate at all — there is nothing to certify compliance with. Determining the applicable-rule set for a given product is the first analytical step every certificate program starts with; the EntryProof rule engine cross-references HTS classification against 40 CPSC- regulated categories to identify applicable rules, and the free EntryProof readiness checker produces the applicable-rule list per SKU.
The seven required data elements
Under 16 CFR § 1110.11, every General Certificate of Conformity must include the following seven data elements. Missing any one of the seven renders the certificate defective:
- Product identification. Sufficient description of the product covered by the certificate to uniquely identify what is being certified. In practice this includes the product name, model number, SKU, and a brief description that identifies the specific configuration.
- Citation to each consumer product safety rule. Every rule the product is being certified to comply with must be cited by its regulatory reference, typically the 16 CFR section number. If the product complies with three rules, all three must be cited.
- Identification of the U.S. importer or domestic manufacturer. The legal-entity name of the issuer, along with a full physical U.S. mailing address and a direct telephone number. P.O. boxes are not acceptable. A generic customer-service phone number is defensible but a direct contact is preferred.
- Contact information for the records-maintenance individual. The name, full mailing address, e-mail address, and telephone of the specific individual who maintains the underlying test records. This person is the operational contact CPSC would reach if it audits the testing basis of the certificate.
- Date and place of manufacture. The month and year the product was manufactured, and the city and country of manufacture. If the product was manufactured at multiple facilities under the same GCC, each facility must be identifiable, though grouping by country is acceptable when the fact set supports it.
- Date and place of testing. The month and year the product was tested for compliance with each cited rule, and the city and country of testing. If different rules were tested at different times or places, each is separately identifiable on the certificate.
- Third-party laboratory identification (if applicable). If the certification depends on testing conducted by a third-party laboratory, the laboratory's name, full mailing address, and telephone. Where first-party testing under a reasonable testing program is the basis, this element may state that internal testing was performed and identify the internal testing group, but must not be omitted entirely.
Who is required to issue the GCC
Under 15 U.S.C. § 2063(a)(1), the domestic manufacturer of a covered non-childrens product is required to issue the GCC. For an imported product, the importer of record is the required issuer and is treated as the manufacturer for GCC purposes. The importer cannot delegate the issuance duty to the foreign manufacturer, though the importer typically works from documentation the foreign manufacturer provides.
The reason the importer is the required issuer, not the foreign manufacturer, is jurisdictional. The certification carries U.S. legal liability under 15 U.S.C. § 2069 and 15 U.S.C. § 2070. A foreign entity outside U.S. jurisdiction cannot be the bearer of that liability. The importer, subject to U.S. law, is the required certifier.
For products manufactured domestically for domestic sale, the manufacturer is the issuer. For products manufactured domestically for export and re-import, the practical answer is that the re-importer is the required issuer at the moment of re-importation, on the same importer-as-manufacturer principle. For products drop-shipped through a U.S.-address distributor from a foreign origin, the entity acting as importer of record on the customs entry is the required issuer.
The reasonable-testing-program requirement
For most non-childrens products, the GCC is based on a reasonable testing program under 15 U.S.C. § 2063(a)(2). The reasonable-testing-program requirements are elaborated at 16 CFR § 1107.10. A reasonable testing program provides a high degree of assurance that products comply with each applicable rule, and is documented in a written testing plan retained with the testing records.
The written testing plan must identify the specific tests to be performed, the sampling method, the acceptance criteria, the frequency of testing, and the procedures for responding to test failures. The plan is not a one-page document; it is a working quality-assurance procedure that a CPSC investigator can read and follow to reproduce the compliance basis of the certification.
Third-party testing at a CPSC-accepted laboratory under 16 CFR Part 1107 is mandatory for the enumerated third-party-testing categories at 16 CFR § 1107.2. For every other non-childrens category, first-party testing under a documented reasonable testing program is acceptable. Testing through a third-party laboratory is often the operationally simpler choice at any scale, because it produces an independent testing record that a later audit reads as authoritative without a reconstruct-the-internal-testing-program exercise.
How the GCC feeds CPSC eFiling
The mandatory CPSC eFiling of Certificates of Compliance regime became effective July 8, 2026 under the rule published at 89 FR 60070 (July 24, 2024). Every covered import entry must transmit specific certificate data elements to CBP through the Automated Commercial Environment (ACE) at entry-filing time. See the CPSC eFiling program page for the current PGA message set specification.
The eFiling data set includes the certificate identifier (a unique reference to the issued GCC or CPC), the product identifier, the applicable rule citations, the manufacturer or importer identification, and the third-party laboratory identification where applicable. These elements map directly to a subset of the seven required GCC data elements at 16 CFR § 1110.11. The full GCC is not transmitted at entry time but must be available for CPSC or CBP inspection on request.
The operational consequence for importers is that GCC issuance is now on the critical path for every covered import entry. A shipment cannot clear without a compliant PGA message, and a compliant PGA message requires a valid certificate identifier that references a properly-issued GCC. Missing-data holds at port are the first-order cost of a broken GCC program; Section 15 civil-penalty exposure is the second-order cost when a non-compliant product later triggers a reportable event.
EntryProof's free readiness checker at /cpsc-efile maps HTS classification to the applicable CPSC rule set and identifies the specific data elements the eFiling manifest will require. Running the checker before the container ships is the recommended pre-import workflow.
Common GCC mistakes and how to avoid them
The five most common GCC errors CPSC and CBP see in practice:
- Wrong certificate type. Issuing a GCC for a childrens product that requires a CPC (or the reverse) is a defective-certificate finding that requires re-issuance and, on childrens products, a third-party testing cycle the importer may not have completed. Always confirm childrens-product status against the 16 CFR Part 1200 four-factor test before issuing.
- Missing rule citations. Certifying compliance with a subset of the applicable rules while a rule that also applies to the product goes uncited is a per-rule certification failure. Map the applicable-rule set to the product before drafting the GCC; running the EntryProof rule-engine check against the HTS classification is the recommended pre-drafting step.
- Wrong records-contact. Naming a records-maintenance individual who has since left the company or does not in fact maintain the underlying records renders the certificate defective. Review and update the records contact on every certificate issuance and quarterly on all live certificates.
- Vague date-of-testing. Providing a testing date so broad (a year, or approximate) that it does not correspond to a specific testing event is a common audit-finding basis. Specify the month and year the actual testing was performed and retain the underlying test report with the testing date on it.
- No third-party lab identification when required. On the enumerated third-party-testing categories at 16 CFR § 1107.2, omitting the CPSC-accepted laboratory identification renders the certificate defective. Confirm both that third-party testing was in fact performed and that the laboratory is CPSC-accepted by checking the current CPSC accepted-laboratory search.
Records retention
The CPSC recommends and enforcement practice supports retaining the GCC and the underlying testing records for a minimum of five years from the last date of manufacture or importation of the product covered by the certificate. There is no shorter statutory retention requirement; the five-year floor accommodates the typical enforcement lookback and provides the record base needed to respond to a CBP or CPSC records request.
Retention scope covers the certificate itself, the written testing plan, the test reports, the third-party laboratory records where applicable, and any records documenting the reasonable-testing-program compliance basis. Electronic retention is acceptable under 16 CFR § 1110.15. The records must be producible on reasonable notice; a records-request response cycle of one to two weeks is defensible.
Retention beyond five years is a defensible extra-safety practice on products with a long field life. A hardware product with a 15-year expected service life is one for which retaining certificate and testing records for the product's field life plus two years is the safer operational default. The additional storage cost is minimal relative to the reconstruction cost of a Section 15 reporting question ten years after the last import.
Frequently asked questions
What is the difference between a GCC and a CPC?
A General Certificate of Conformity (GCC) covers non-childrens products subject to a consumer product safety rule. A Childrens Product Certificate (CPC) covers products designed or intended primarily for children 12 years of age or younger and requires third-party testing by a CPSC-accepted laboratory under 16 CFR Part 1107. Both are certificates of conformity under 15 U.S.C. Section 2063; the difference is in the underlying testing requirement (self-attestation acceptable for GCC on many rules, third-party testing mandatory for CPC).
Who is legally required to issue a GCC?
The domestic manufacturer of a covered non-childrens product is required to issue a GCC. For imported products, the importer is required to issue the GCC and is generally treated as the manufacturer for GCC purposes under 15 U.S.C. Section 2063(a)(1). Foreign manufacturers are not required to issue a GCC (they cannot; the issuer must be subject to U.S. jurisdiction), but they typically prepare the underlying documentation the importer uses to issue.
What are the seven required data elements on a GCC?
Under 16 CFR Section 1110.11, every GCC must include: (1) identification of the product covered; (2) citation to each consumer product safety rule the product complies with; (3) identification of the U.S. importer or domestic manufacturer certifying compliance, including address and telephone; (4) contact information for the individual maintaining records of test results, including full mailing address and telephone; (5) date and place where the product was manufactured; (6) date and place where the product was tested for compliance with each cited rule; and (7) identification of any third-party laboratory on whose testing the certificate depends, including name, full mailing address, and telephone.
Does a GCC require third-party testing?
Not automatically. GCC compliance can be certified based on a reasonable testing program that produces evidence the product complies with each cited rule. Third-party testing is required by rule on specific product categories (fireworks, cigarette lighters, and others enumerated in 16 CFR Section 1107.2) and on all childrens products (which trigger CPC not GCC). For non-childrens products outside the enumerated third-party categories, first-party testing by the manufacturer or importer under a documented reasonable-testing program is acceptable. Reasonable-testing-program requirements are at 16 CFR Section 1107.10.
How is the GCC delivered to CBP and to distributors?
The GCC must accompany the product or its shipment to each distributor or retailer of the product, and must be furnished to CBP on request. In practice, importers make the GCC available electronically to distributors and warehouse the underlying testing records for CBP inspection. Under the mandatory CPSC eFiling regime effective July 8, 2026, specific GCC data elements (product identification, applicable rules, certificate identifier) are transmitted to CBP through ACE at entry filing time, and the full GCC is available on CPSC or CBP request.
What happens if a shipment arrives with a defective or missing GCC?
A shipment arriving without a required GCC, or with a GCC missing required data elements or citing rules the product does not actually comply with, is subject to CBP hold under 19 CFR Part 141 pending resolution. The importer must produce a compliant GCC or arrange for the shipment to be re-exported or destroyed. Distribution or sale of a covered product without a valid GCC is a prohibited act under 15 U.S.C. Section 2068 and triggers Section 15 civil-penalty exposure at 15 U.S.C. Section 2069.
How long must GCC and testing records be retained?
The CPSC recommends and enforcement practice supports retaining the GCC and underlying testing records for a minimum of five years from the last date of manufacture or importation of the product covered by the certificate. There is no shorter statutory retention requirement; the five-year floor accommodates the typical enforcement lookback and gives the importer or manufacturer the records needed to respond to a CBP or CPSC records request. Retention beyond five years is a defensible extra-safety practice on products with a long field life.
Can one GCC cover multiple SKUs or product variants?
Yes, provided every SKU covered is subject to the same set of applicable rules and every SKU was tested under a testing program that supports the certification. In practice, importers issue one GCC per product line or SKU family where the products are meaningfully identical from a safety-rule compliance perspective, and separate GCCs for products with different applicable-rule sets. Broad multi-SKU GCCs are more efficient to administer but create a shared-fate risk if one SKU is later found non-compliant — the certification for the group is called into question.
References and primary sources
- Certificate-of-conformity requirement at 15 U.S.C. § 2063.
- Consumer Product Safety Act definitions, including childrens-product definition, at 15 U.S.C. § 2052.
- Certificates of conformity, general requirements at 16 CFR Part 1110, including the seven required data elements at § 1110.11.
- Third-party testing categories and reasonable-testing-program requirements at 16 CFR Part 1107, especially § 1107.2 and § 1107.10.
- Childrens-product-determination four-factor guidance at 16 CFR Part 1200.
- Prohibited-acts statute and civil-penalty framework at 15 U.S.C. § 2068 and 15 U.S.C. § 2069.
- Mandatory CPSC eFiling of Certificates of Compliance program page at cpsc.gov/eFiling.
- Third-party CPSC-accepted laboratory search at cpsc.gov/cgi-bin/labsearch.
- CPSC business guidance on testing and certification at cpsc.gov/Business--Manufacturing/Testing-Certification.
- CBP entry regulations at 19 CFR Part 141.
Related EntryProof resources
- EntryProof readiness checker — free CPSC filing-data readiness check. Enter your product URL and HTS code to get the applicable-rule list and the gap list for eFiling.
- CPSC Section 15 penalties explained — the civil-penalty exposure a defective or missing GCC creates.
- EntryProof methodology — the 40 product-category rule engine that maps HTS to applicable CPSC rules.
- Glossary — definitions for CPC, GCC, ASTM F963, CPSIA, and the other acronyms this page uses.
- CPSC penalty calculator — interactive per-SKU and per-series exposure estimator.
- CPSC compliance calendar — upcoming CPSC deadlines and rulemakings.
- Best CPSC eFiling tools 2026 — ranked list of CPSC eFiling and adjacent compliance tools.
Author
Andy Gaber is the founder of Digital Empire Holdings LLC and the author of the EntryProof, TariffWatch, and PixelProof compliance-intelligence tools. He writes the EntryProof long-form regulatory reference material from primary-source review of the Consumer Product Safety Act, implementing 16 CFR regulations, and published CPSC guidance. See the founder's /about page for background.
Editorial and corrections policy
This guide is maintained by the Digital Empire Regulatory Research Team, published by Digital Empire Holdings LLC, and covers the current General Certificate of Conformity framework under 15 U.S.C. § 2063 and 16 CFR Part 1110. Non-U.S. consumer-safety certification frameworks and state consumer-protection channels are out of scope. Every claim is cited to a primary source. Corrections are posted to /corrections within one business day of confirmation. Editorial standards are at /editorial-policy.
Nothing on this page is legal advice or customs classification advice under 19 CFR Part 111. EntryProof is a data preparation and readiness-assessment tool, not a customs broker, not a testing laboratory, and not a legal-advice service. Consult your customs broker or a licensed attorney experienced in Consumer Product Safety Act compliance before issuing a GCC on a specific product line or responding to a CPSC records request. Attorney review of the specific analysis in this guide is pending as of publication; this guide is a v0 disclosure.