Skip to content

Product Safety

US GCC Guide: CPSC Certificate of Conformity

In 2023, the US Consumer Product Safety Commission levied over $45 million in civil penalties across multiple enforcement actions — and a recurring finding in compliance investigations is that the General Certificate of Conformity either did not exist, was incomplete, or cited the wrong safety standard. When a GCC is missing or inaccurate, the product is legally non-compliant regardless of how safe it actually is. Amazon has increasingly codified this into its own enforcement: in categories like children's furniture, apparel, and electronics, sellers must upload a valid GCC directly to Seller Central or face listing suppression.

The US General Certificate of Conformity (GCC) is a mandatory document under the Consumer Product Safety Improvement Act (CPSIA) Section 14. It certifies that your consumer product has been tested and complies with all applicable CPSC safety rules. On the Sustalium platform, the most common GCC error we see is not a missing certificate — it's a certificate that lists one or two applicable standards while omitting others that apply to the same product.

EU Cyber Resilience Act (CRA) Guide

Here's a problem you might not have thought about: before the Cyber Resilience Act, most hardware and software products had no mandatory cybersecurity requirements at all. A smart camera, a connected thermostat, a SaaS platform — none of them needed to meet any baseline security standard to be sold in the EU. The CRA (Regulation 2024/2847) changes that, and it's going to affect every company that makes or sells products with digital elements.

The Act entered into force in 2024, with obligations phasing in through 2027. If you make connected devices, operating systems, or even mobile apps sold in the EU, you're in scope.

GPSR Software: Meet EU Product Safety Requirements

The EU General Product Safety Regulation (GPSR, Regulation 2023/988) has been in effect since December 2024, replacing the old GPS Directive. It requires every product sold in the EU to have an accountable EU Responsible Person, accessible safety documentation, and a traceability system — regardless of whether the product is covered by sector-specific legislation like CE marking.

GPSR compliance software automates responsible person appointment, safety document management, incident reporting, and marketplace compliance — keeping your products selling on Amazon, eBay, and other EU marketplaces.

Toy Safety: EU vs. US Requirements

Toys are one of the most heavily regulated consumer product categories in the world — and for good reason. A defective toy can cause choking, lacerations, chemical poisoning, or strangulation in a matter of seconds. Because the end-user is a child, regulators apply a zero-tolerance approach to non-compliance.

If you manufacture, import, or sell toys in the European Union or the United States, you must navigate two distinct but equally demanding regulatory regimes: the EU Toy Safety Directive (2009/48/EC) and the US Consumer Product Safety Act (CPSIA), which mandates a Children's Product Certificate (CPC). Understanding the differences — and producing compliant documentation for both markets — is essential for uninterrupted market access.

EU AI Act Compliance for Product Manufacturers

If your products contain software that makes decisions, recognizes patterns, generates outputs, or interacts with users — even basic features like predictive text, smart sensors, or automated quality grading — you are now regulated under the EU Artificial Intelligence Act (Regulation [EU] 2024/1689).

This is not a law for Silicon Valley alone. The EU AI Act applies to every manufacturer, importer, and distributor placing AI-enabled products on the European market. And because the Act is integrated with the New Legislative Framework (NLF), AI compliance is now directly tied to your CE Mark. If your AI system does not meet the Act's requirements, your product cannot legally carry the CE Mark — and cannot be sold in the European Union.

How to Build a RoHS Compliance System

Manufacturing electronic and electrical equipment (EEE) involves complex global supply chains, often requiring thousands of individual components to build a single finished product. If just one of those components—down to the smallest resistor, capacitor, or plastic casing—contains a restricted hazardous substance above the legal threshold, your entire product is barred from entering the European Union.

This is the reality of the Restriction of Hazardous Substances (RoHS) Directive (2011/65/EU), commonly referred to as RoHS 2 (and updated by RoHS 3). Ensuring that your products are compliant is not a one-time event; it requires a continuous, dynamic RoHS Compliance Management System (CMS).

In this guide, we will break down the exact technical steps required to build a system that satisfies market surveillance authorities and ensures uninterrupted market access.

RoHS vs. REACH: Supplier Requirements

One of the most common causes of supply chain friction in European manufacturing is the conflation of REACH and RoHS.

It happens every day: A procurement manager emails a supplier asking for a "REACH/RoHS Certificate." The supplier, based outside the EU and confused by the acronyms, replies with a generic letter stating their product is "safe and compliant." The procurement manager files it away. A year later, a market surveillance authority audits the manufacturer, deems the generic letter invalid, and forces a product recall.

While both REACH and RoHS are European regulations designed to protect human health and the environment from hazardous chemicals, their scopes, thresholds, and reporting mechanics are completely different. To secure your supply chain, you must know exactly what to ask for.

Preparing for the EU CRA: SBOM Requirements

If you manufacture hardware, connected consumer electronics, IoT devices, or develop commercial software sold in the European Union, a massive regulatory wave is about to hit your engineering team.

The EU Cyber Resilience Act (CRA) represents the most sweeping cybersecurity law for physical and digital products in the world.

Under the CRA, cybersecurity is no longer treated as a post-launch software update or a marketing feature. It has become a mandatory condition for CE Marking.

If your "product with digital elements" does not meet the CRA's strict security-by-design standards, you cannot legally affix the CE Mark, and your product is banned from entering the European market. Penalties for non-compliance are severe, reaching up to €15 million or 2.5% of global turnover.

To maintain EU market access, software and hardware product teams must master the CRA's core technical requirement: the Software Bill of Materials (SBOM).

PFAS-Free Declarations for Retail Buyers

If you supply consumer goods, apparel, cosmetics, or electronics to major retailers or online marketplaces, you have likely received a sudden, urgent request for a PFAS-Free Declaration.

Per- and polyfluoroalkyl substances (PFAS)—commonly dubbed "forever chemicals" due to their extreme persistence in the human body and environment—are facing an unprecedented wave of global regulation. In the United States, several states (including California, Maine, and Vermont) have enacted strict bans on intentionally added PFAS in consumer products.

Meanwhile, the European Union is evaluating a blanket restriction under REACH.

To protect themselves from immense liability and potential class-action lawsuits, retail giants (such as Amazon, Target, and Costco) are enforcing strict "flow-down" policies. If you cannot provide a valid, verifiable chemical compliance statement proving your products contain no intentionally added PFAS, your inventory will be immediately rejected and your vendor status terminated.

Here is how to audit your supply chain and draft a legally compliant PFAS-free declaration.

California Proposition 65 Compliance

If your business ships physical products to California, list items on Amazon US, or sells through major retail distributors, you are subject to one of the most litigious consumer laws in the United States: California Proposition 65 (Prop 65).

Officially known as the Safe Drinking Water and Toxic Enforcement Act of 1986, Prop 65 requires businesses to provide a "clear and reasonable" warning to California consumers before exposing them to any of over 900 naturally occurring or synthetic chemicals known to cause cancer, birth defects, or other reproductive harm.

What makes Prop 65 uniquely dangerous is its enforcement mechanism. Unlike most laws enforced by government agencies, Prop 65 allows private citizens and advocacy groups to sue businesses on behalf of the public—creating a lucrative industry for plaintiff attorneys operating on contingency fees.

In 2024 alone, businesses paid over $30 million in settlements to resolve private Prop 65 lawsuits. To protect your business from these "bounty-hunter" lawsuits, you must understand how to audit your products and apply compliant safe harbor warnings.