CBP proposes heightened import disclosures: comments close December 1

U.S. Customs and Border Protection has opened a formal review that could reshape what every importer, marketplace seller, and freight intermediary must tell the government about the origins of the goods they bring into the United States. The agency published an advance notice of proposed rulemaking (ANPRM) titled “Heightened Import Disclosures for Supply Chain Visibility” in the Federal Register on September 2, 2026. It carries docket number USCBP-2026-1058 and regulatory identification number 1685-AA47, and it contemplates amendments to four parts of the customs regulations at 19 CFR parts 141, 142, 143, and 163.

The notice is not a rule. It is the stage before a rule, and CBP uses it to ask 64 numbered questions whose answers will shape whatever proposed regulation follows. Comments are due on or before December 1, 2026, submitted through the federal eRulemaking portal under the docket number. For retailers and cross-border sellers, the window between now and that deadline is the only practical chance to influence requirements that would land on their entry filings, their supplier contracts, and their landed cost models.

In short

  • What happened: CBP published an advance notice of proposed rulemaking on September 2, 2026, asking how it should require deeper disclosure of import supply chains. Docket USCBP-2026-1058, RIN 1685-AA47.
  • The deadline: Comments close December 1, 2026. CBP poses 64 questions across foreign export documents, party identification, and tracing technology.
  • The biggest ask: Importers could be required to submit or retain the documentation the foreign exporter filed with its own customs authority, including export declarations, commercial invoices, and certificates of origin.
  • The target: CBP names illegal transshipment, the routing of goods through a third country to disguise true origin, as the practice it wants to detect before goods reach the border.
  • Why it reaches e-commerce: Question 33 asks whether an online marketplace that facilitated the sale should be named to CBP on the entry, a first for platform-level identification in customs data.

What is CBP actually proposing?

The ANPRM sets out three tracks of potential requirements rather than one. The first covers foreign export documentation, meaning the paperwork a supplier or its agent files with the customs authority in the country of export before the goods leave. The second covers the identification of parties involved in manufacture, production, movement, and export. The third covers technical solutions for tracing supply chains, including artificial intelligence and tamper-resistant credentials.

Each track carries its own set of questions about scope, timing, and cost. CBP repeatedly asks whether requirements should be phased in by entry type, by commodity, by country, or by mode of transportation. It also asks whether different implementation timelines should apply to small entities, foreign importers, participants in the Customs Trade Partnership Against Terrorism (CTPAT), or high-volume filers.

That phasing language matters more than it might appear. It signals that CBP is contemplating a tiered regime rather than a single universal mandate, and it invites affected businesses to argue for their own tier. An importer that files a handful of formal entries a year has a very different case to make than a platform aggregating millions of parcels.

The agency also flags the possibility of running some of these ideas as voluntary test programs first. CBP asks directly whether any of the proposals are suited to that approach, which is the same path it used for the Global Business Identifier work and for low-value entry processing.

Proposal track What it would require Who carries the burden Question range
Foreign export documentation Submit or retain documents the exporter gave to its own customs authority Importer of record, with data pulled from foreign suppliers Q1 to Q23
Party identification Replace or supplement the manufacturer identification code with richer entity data Importer of record and licensed customs brokers at entry or entry summary Q24 to Q45
Supply chain tracing technology Use traceability tools, unique identifiers, and tamper-proof credentials visible to CBP Importers, and CTPAT partners under expanded security criteria Q46 to Q61
Economic impact Provide cost, benefit, and small business impact data to CBP All commenters Q62 to Q64

Where does the legal authority come from?

The ANPRM traces directly to Executive Order 14411, “Strengthening Customs Enforcement,” which the President signed on June 3, 2026 and which was published at 91 FR 35125 on June 10, 2026. Section 3 of that order directs the establishment of heightened import disclosure requirements. Section 3(a) instructs the Secretary of Homeland Security to require disclosure of certain foreign tax and global business identifiers alongside detailed information about supply chains and production methods.

Section 3(b) is the source of the foreign export documentation concept. It directs the Secretary to take steps to mandate submission of “any documentation or information that the foreign exporter was required to submit to the foreign customs administration prior to exporting to the United States.” The ANPRM is CBP working out how to give that instruction regulatory shape.

Underneath the executive order sits ordinary statutory authority that predates it by decades. CBP cites 19 U.S.C. 1484 and 1485 for entry documentation, 19 U.S.C. 1431 for carrier manifests, and 19 U.S.C. 1508 and 1509 for recordkeeping and audit. It also cites the broad rulemaking power at 19 U.S.C. 1624 to carry out the Tariff Act of 1930.

This is the same executive order that produced the earlier customs enforcement tranche affecting penalty mitigation, and the same enforcement push behind the decision under which CBP begins voiding importer of record numbers on September 18 for inaccurate filer data. Read together, the actions describe a single agenda: know exactly who is importing, and know exactly where the goods came from.

Why an ANPRM rather than a proposed rule

An advance notice signals that CBP has a policy direction but not a drafted regulatory text. The agency says comments received will be used, potentially, to draft a notice of proposed rulemaking that would propose the actual regulations. That means at least one more comment round before anything becomes binding.

The practical implication is timing. A December 1 close, followed by comment review, a drafted proposed rule, another comment period, and a final rule, puts realistic compliance dates well beyond 2027 for most of what is contemplated here. Businesses should treat this as a planning signal rather than an imminent operational change.

That said, the ANPRM has been designated a “significant regulatory action” under section 3(f) of Executive Order 12866 and was reviewed by the Office of Management and Budget. Significant designation at the advance notice stage indicates the agency expects material economic effects.

What foreign export documents would importers have to produce?

This is the section with the sharpest operational teeth. CBP lists six categories of foreign export documentation it is considering, and each one exists today but sits outside the importer’s normal document set. The agency’s stated reason is verification: it wants to reconcile what a supplier told its own government against what the importer told CBP.

The specific failure mode CBP names is dual invoicing, the practice of presenting one value to the export authority and a different value to the import authority. If the export declaration in the country of origin shows a higher value, a different classification, or a different quantity than the U.S. entry summary, that gap becomes an enforcement lead. The ANPRM asks in Question 11 what internal controls and reconciliation processes importers should implement to catch such discrepancies themselves.

Document type What CBP could verify with it Typical difficulty for a U.S. importer to obtain
Export declaration to foreign customs Declared value, tariff classification, and quantity at the point of export High: usually filed by the exporter or a local agent, rarely shared
Commercial invoice filed abroad Transaction value declared to the foreign authority Moderate: a version often exists in the importer’s file already
Packing list Contents, weight, and packaging of the shipment Low: commonly held by the importer
Certificate of origin Substantiation of where the goods actually originated Moderate: depends on trade agreement claims and supplier cooperation
Export license or permit Controls on restricted, controlled, or dual-use goods High: held by the exporter, often confidential
Transport documents Bill of lading or air waybill filed with the export manifest Moderate: available through the freight forwarder

Submit at entry, or retain for audit?

Question 2 asks whether foreign export documentation should be transmitted as part of an entry or entry summary filing, or whether it should be a recordkeeping requirement under 19 U.S.C. 1508. The distinction is the difference between a per-shipment data burden and a records retention burden. A transmission requirement touches every entry; a retention requirement touches only the entries CBP later examines.

CBP floats a third option in Question 3: randomized submission. Under that model the agency would demand the documents on a random subset of entries, both to test compliance with a general retention rule and to measure how widespread non-compliance actually is. Randomization is cheaper for filers in aggregate but harder to plan around, because any shipment could be selected.

Question 5 asks whether the existing duty of reasonable care is the right standard for an importer assessing the accuracy of documents it did not create. That question matters enormously. An importer can exercise reasonable care over its own classification work, but verifying that a supplier’s export declaration is genuine and unaltered is a different problem, and Question 12 asks precisely how an importer would prove a document was not modified.

The language and lead time problems

Question 17 asks how CBP should handle foreign export documentation that is not in English, and floats requiring specified data fields in English alongside the underlying foreign-language document. For sellers sourcing from Vietnam, Turkey, Bangladesh, or mainland China, that implies a translation workflow attached to every affected shipment.

Question 16 asks about current lead time to obtain these documents from foreign suppliers. In practice many suppliers treat their export filings as commercially sensitive, because those filings reveal the supplier’s own cost base and its other customers. The commercial resistance here is likely to be more binding than the technical difficulty.

Question 9 extends the reach further by asking whether foreign government agencies that perform export functions without being formal customs authorities should also be in scope. That would sweep in export promotion bodies, inspection agencies, and quality certification regimes in several sourcing markets.

Who counts as a party to your import?

The second track attacks a data field most importers barely think about. The manufacturer identification code, or MID, appears on CBP Form 7501 at entry summary and is constructed from the manufacturer or shipper name and address according to Customs Directive 3550-055, dated November 24, 1986. CBP is blunt about its limitations.

The ANPRM states the MID “provides limited identifying information and does not always identify the actual party that may be of interest to CBP for enforcement purposes.” It is also not consistently unique: because the code derives from name, address, and country of origin, the same MID can resolve to multiple entities, and a single entity’s MID can change when its address does. For an enforcement regime built on knowing exactly who made something, a 1986 formula is a weak foundation.

Questions 24 through 36 explore replacements. CBP asks whether it should collect the actual company name and physical address instead of a derived code, whether it should track the “producer” rather than the manufacturer to align with the definitions in 19 CFR part 102 and trade agreements, and whether the identifier should be required at entry, at entry summary, or on the manifest.

The marketplace question in Question 33

Buried in the party identification block is the question with the greatest reach into e-commerce. Question 33 asks whether, if an online marketplace facilitated the sale of imported merchandise to a U.S. party, that marketplace should be identified to CBP, and why.

No current entry data element names the platform through which a sale occurred. Adding one would create, for the first time, a customs dataset linking specific import shipments to specific marketplaces. The enforcement logic is straightforward: platforms aggregate seller behavior, and a platform-level view of entry data would let CBP see patterns invisible at the shipment level.

Question 34 sits alongside it, asking whether the party to which merchandise is ultimately intended to be delivered should be identified, even when that party is not the initial recipient or the consignee taking custody at arrival. Together the two questions describe an entry record that follows a good from factory to final buyer.

Global Business Identifiers and the end of the MID

CBP has been testing an alternative since 2022. The Global Business Identifier test, established under the National Customs Automation Program at 87 FR 74157 on December 2, 2022 and updated at 90 FR 38479 on August 8, 2025, lets importers and brokers transmit private-sector entity identifiers with their entry data.

Four identifiers are currently accepted in the test: the Data Universal Numbering System number (D-U-N-S), the Global Location Number (GLN), the Legal Entity Identifier (LEI), and the Altana ID. Participants may identify the manufacturer or supplier, the shipper, and the seller, and may optionally transmit identifiers for the exporter, distributor, or packager.

Questions 37 through 45 ask whether the test should become mandatory, which identifiers work best for supply chain visibility, how hard they are to obtain, and whether CBP should cross-check submitted identifier data against data other parties file. Question 41 asks specifically whether importers and brokers can realistically obtain entity-level foreign tax identifiers as well.

Attribute Manufacturer identification code (MID) Global Business Identifier (GBI)
Origin CBP formula, Customs Directive 3550-055 (1986) Private-sector issuers, tested since December 2022
Uniqueness Not guaranteed: collisions and drift are possible Designed as a unique persistent entity identifier
Data richness Derived from name, address, and country of origin only Can carry ownership, location, and supply chain role
Status Required today at entry summary Voluntary test participation
Parties covered Manufacturer or shipper, single code Manufacturer, shipper, seller, plus optional exporter, distributor, packager

How would supply chain tracing technology work?

The third track is the least defined and potentially the most consequential. CBP names illegal transshipment explicitly as the target, describing it as the practice of routing goods through a third country to obscure or misrepresent their true country of origin. The agency says it has intensified enforcement and is evaluating artificial intelligence solutions for pinpointing transshipment risk.

The stated ambition is to make decisions about transshipment risk before goods arrive at, or are released from, the U.S. border. That is a shift in posture. Origin fraud is typically detected after the fact, through audits and penalty proceedings, and a pre-arrival screening model would move the decision point upstream.

Because duty liability turns on where a good was substantially transformed rather than where it was shipped from, the accuracy of country-of-origin determination in setting your duty rate is exactly what this track is designed to police. Questions 50 and 54 ask what technology exists to verify the origin of raw materials, to bridge the visibility gap between suppliers and raw material sources, and to certify entry data elements such as country of origin.

Questions 46 through 55 ask what the private sector already uses, how accuracy is verified, how proprietary information is protected, and whether the tools scale to small businesses as well as multinationals. Question 49 asks how such technologies would integrate with the Automated Commercial Environment and partner government agency data exchanges.

The logistics platform security question

Questions 35, 36, 60, and 61 open a distinct line of inquiry about the software layer itself. CBP asks which platforms importers and their partners use to transmit shipping instructions, book freight, and manage logistics data, naming vessel sharing agreements and LOGINK as examples. It then asks what visibility importers have into those platforms’ data privacy and security practices.

Question 61 goes further, asking what costs an organization would incur if the CTPAT minimum security criteria were updated to restrict or prohibit the use of “covered logistics platforms,” described as LOGINK or other foreign-controlled systems identified as national security risks. CBP asks for detailed estimates covering capital expenditure, training, system integration, and potential supply chain delays from migrating to certified secure alternatives.

That question presumes a policy direction. Asking for migration cost estimates is what an agency does when it is weighing whether a prohibition is workable, not whether it is desirable. Importers using foreign-controlled booking platforms should read Question 61 as an early warning.

What changes for CTPAT members?

The Customs Trade Partnership Against Terrorism is a voluntary program authorized by the SAFE Port Act of 2006 and codified at 6 U.S.C. 961 and following. Members meet minimum security criteria in exchange for benefits including reduced examination rates and faster processing. CBP notes that small businesses make up approximately 70% of the membership.

Questions 56 through 61 explore turning CTPAT into the delivery vehicle for the tracing agenda. CBP asks whether all partners should be required to use enhanced supply chain tracing technologies, and if not all, what criteria should determine which tiers are covered. Question 58 asks whether partners should be required to make their tracing technology visible to CBP itself.

The trade-off is explicit in Question 59, which asks what benefits could be afforded to partners who use tracing technology and to those who share supply chain visibility with the agency. This is the classic CTPAT bargain restated for the data era: more disclosure in exchange for more facilitation.

Question 60 proposes expanding the minimum security criteria to include cybersecurity and data integrity requirements. For a program whose criteria have historically focused on physical and procedural security, adding a data integrity dimension would be a structural change, and one that reaches every member regardless of size.

What would this cost a small importer?

CBP publishes no cost estimate in the ANPRM. Instead it asks commenters to supply the numbers, requesting in Question 62 comments specific to costs and benefits for small businesses, potential effects on the availability and continuity of critical goods including medical products, and proposals to mitigate costs and supply disruption.

The agency also asks that all numerical responses include sufficient information for CBP to recreate the calculations. That is an unusually demanding evidentiary standard for a comment process, and it favors commenters with the resources to model their own compliance costs in detail.

Legal analysts reviewing the notice have flagged the structural difficulty for smaller firms. The core problem is that importers may need to obtain information from companies with which they have no direct contract, since the exporter, the manufacturer, and the seller are frequently three different entities in a sourcing chain the importer sees only partially.

Building that capability is not a software purchase. It implies new contractual rights with suppliers, supplier onboarding processes, data standards, audit procedures, and escalation protocols when a supplier will not or cannot produce a document. For a business already absorbing duty increases, this is a second, separate cost line, and it compounds the pressures described in our primer on how tariffs really work for small retailers importing goods.

The earlier filing question

Question 43 asks whether requiring entry to be filed sooner would help CBP review supply chain documentation and determine admissibility earlier. Today, 19 CFR 141.5 generally requires entry within 15 calendar days after landing or after arrival at the port of destination for in-bond cargo.

CBP notes as precedent that participants in the Entry Type 86 test, previously available to filers claiming the de minimis exemption, were required to file prior to or upon arrival of the cargo. A move toward pre-arrival filing across more entry types would compress the window in which brokers assemble data, and CBP asks directly what costs would result for affected parties.

How does this fit the wider 2026 customs agenda?

This ANPRM does not arrive in isolation. It is one component of a broader enforcement build-out running through 2026, and reading it alongside the other actions shows a consistent design. The de minimis exemption has been suspended, low-value shipments are moving to a new electronic informal entry process, importer of record data is being validated and purged, and penalty mitigation policy has been tightened.

Each of those actions closes a specific gap. Suspending de minimis removed the volume channel that carried the least data. The new postal and informal entry processes attach structured entry data to shipments that previously moved with almost none. Voiding inaccurate importer of record numbers ensures the party named on an entry is a real, reachable entity.

Heightened import disclosures address what remains: the data behind the entry, describing where a good was actually made and by whom. Origin claims are also the pressure point in forced labor enforcement, where the stakes are currently being tested in the courts, as in the forced-labor tariff litigation heading to a September 15 court test. Better origin data serves duty collection and forced labor enforcement simultaneously.

The sequencing also explains the timing. CBP is asking these questions now because the earlier structural changes are largely in place, and the remaining enforcement gap is informational rather than procedural.

What should sellers do before December 1?

The immediate action is diagnostic rather than remedial, because nothing here is yet binding. The useful work in the next 12 weeks is finding out whether your supply chain could answer these questions if it had to.

Start by testing document availability on a sample of shipments. Ask two or three suppliers for the export declaration they filed with their own customs authority on a recent shipment. The response, including a refusal, tells you more about your exposure than any internal audit.

Second, reconcile a handful of entries. Compare the value, quantity, and classification on your entry summary against the commercial documents in your file, and identify where legitimate differences arise. Question 11 asks how importers would justify such gaps, and firms that already understand their own discrepancy patterns will comment from a stronger position.

Third, map your parties. Determine whether you can name the manufacturer, shipper, seller, exporter, distributor, and packager for your top products, and whether any of them hold a D-U-N-S, GLN, or LEI identifier today. For China-sourced goods, this work overlaps with the origin diligence already required under Section 301 tariffs on China imports, so the two exercises can be run together.

Finally, consider commenting. The docket is open until December 1, 2026, and CBP has signaled it will weigh arguments about phasing, small entity treatment, and voluntary testing. The full notice is available on the Federal Register for anyone preparing a submission.

What happens next?

The comment period closes December 1, 2026. CBP will then review submissions and decide whether to issue a notice of proposed rulemaking, which would contain actual regulatory text and trigger a further comment period before any final rule.

Nothing in this ANPRM changes an importer’s obligations today. Entry requirements, recordkeeping duties under 19 U.S.C. 1508, and the MID field on Form 7501 all remain as they are. The value of the notice is forward visibility: it describes, in unusual detail, the data regime CBP wants to build.

The signature block offers a small signal of institutional weight. Commissioner Rodney S. Scott reviewed and approved the document and delegated electronic signature authority to Susan S. Thomas, Executive Assistant Commissioner of the Office of Trade. Questions on party identification and foreign export documentation route to Brandon Lord, Executive Director of Trade Programs, and Salvatore Ingrassia, Acting Executive Director of Cargo and Conveyance Security.

For retailers, the planning horizon is the important output. Requirements of this scope will not bind before a proposed rule and a final rule are issued, but supplier contracts signed in 2027 will be the instruments through which any of it becomes enforceable in practice.

Frequently asked questions

Is this a new rule that importers must comply with now?

No. It is an advance notice of proposed rulemaking, which is the stage before a proposed rule. It creates no new obligations. CBP is collecting information that may inform a future notice of proposed rulemaking, which would itself require another comment period before any final rule takes effect.

When is the comment deadline and how do I file?

Comments must be received on or before December 1, 2026. They are submitted through the Federal eRulemaking Portal at regulations.gov under docket number USCBP-2026-1058. All submissions must include the agency name and docket number, and all comments are posted publicly without change, including any personal information provided.

What is illegal transshipment and why is CBP focused on it?

Illegal transshipment is the practice of routing goods through a third country to obscure or misrepresent their true country of origin, typically to avoid tariffs tied to a specific source country. CBP states in the notice that it deprives the government of lawful revenue and threatens U.S. economic security, and that the agency is evaluating artificial intelligence driven solutions to pinpoint the risk before goods reach the border.

Would I really have to get documents from my supplier’s own customs filing?

That is one of the possibilities CBP is testing, not a settled requirement. The notice asks whether such documents should be transmitted at entry, retained as records, or demanded on a randomized basis. It also asks about lead times, language barriers, and the challenges importers face obtaining documents they did not create, which suggests CBP is aware the burden is contested.

What is the MID and why does CBP want to replace it?

The manufacturer identification code is a data element on CBP Form 7501, derived from the manufacturer or shipper name and address using a formula set out in Customs Directive 3550-055 from 1986. CBP states it provides limited identifying information, is not always unique, and can change over time, which makes it unreliable for enforcement purposes.

Could online marketplaces be named on customs entries?

Question 33 of the notice asks whether a marketplace that facilitated the sale of imported merchandise should be identified to CBP. No such data element exists today. If adopted, it would create a customs dataset linking import shipments to the platforms through which the underlying sales occurred.

How would this affect CTPAT members?

CBP asks whether CTPAT partners should be required to use enhanced supply chain tracing technologies, whether that technology should be visible to CBP, and whether the minimum security criteria should be expanded to cover cybersecurity and data integrity. It also asks about restricting the use of foreign-controlled logistics platforms. Small businesses make up roughly 70% of CTPAT membership, so any change reaches well beyond large importers.

Has CBP estimated the compliance cost?

No. The notice contains no cost estimate. CBP instead asks commenters to supply cost and benefit data, with particular attention to small businesses and to the availability of critical goods including medical products. It requests enough underlying detail to recreate any calculations submitted.

What other identifiers is CBP testing?

The Global Business Identifier test currently accepts four private-sector identifiers: the Data Universal Numbering System number (D-U-N-S), the Global Location Number (GLN), the Legal Entity Identifier (LEI), and the Altana ID. The test began in December 2022 and was updated in August 2025. The notice asks whether the test should be modified and whether identifier submission should become mandatory at entry.