Skip to content
Industry10 min read

Forged UL, FCC, and CPSC Certificates in Supplier Fraud

How suppliers fake UL listings, FCC IDs, and CPSC compliance certificates during US procurement, and how buyers verify each one before goods clear the door.

CheckFile Team
CheckFile Teamยท
Illustration for Forged UL, FCC, and CPSC Certificates in Supplier Fraud โ€” Industry

Summarize this article with

A UL mark, an FCC ID, or a CPSC Certificate of Compliance can be reproduced convincingly in a PDF editor within an hour, and unlike the EU, the US has no single mandatory mark a procurement team can check against one register. Certification splits across category-specific bodies โ€” UL Solutions and other testing labs for electrical safety, the FCC for radio-emitting devices, the CPSC for consumer goods โ€” and a supplier needs only one convincing document to clear a five-second visual review.

This article is for informational purposes only and does not constitute legal or regulatory advice. Consult qualified counsel or a compliance specialist for guidance specific to your product category and state.

This piece does not cover getting a product UL listed, FCC certified, or CPSC compliant โ€” for the supplier due-diligence process, see our know your supplier verification checklist. It also isn't about a vendor's insurance or tax paperwork, covered separately in our piece on forged Certificates of Insurance and W-9s. This one covers product-level compliance certificates: how they get faked, and what a buyer does the moment one looks wrong.

Why the US Has No Single "CE Mark" Equivalent

Buyers used to a single conformity mark are often surprised the US splits product safety oversight by category. Electrical and mechanical safety runs through OSHA's Nationally Recognized Testing Laboratory (NRTL) program, radio-emitting devices go through the FCC, consumer goods generally fall under the CPSC, and food, drugs, and medical devices sit with the FDA โ€” vehicles fall under NHTSA, with no overlap between them.

The CPSC's own May 2026 enforcement notice describes bad actors "increasingly using counterfeit certification marks to evade U.S. safety requirements, mislead consumers, undercut compliant American businesses and move hazardous products through e-commerce platforms and other trade channels" (CPSC, US Consumer Product Safety Commission Launches Crackdown on Fake Safety Labels, May 2026). The fragmentation is what forgers exploit: a team checking one register has no reason to assume a document belongs to a different agency, and most reviewers have never seen the genuine article to compare against.

How Forgers Fabricate UL, FCC, and CPSC Documents

Forgery rarely means inventing a certificate design from nothing. It is faster and less detectable to alter a real one, reuse a real one for the wrong product, or claim a mark the product never earned.

A genuine UL Listing applies to one product configuration tested by an accredited lab, not to a brand or a factory in general. Forgers commonly reuse an expired listing from a prior product generation, change the model number on an otherwise real certificate, or copy another factory's file number onto packaging for an untested unit. Because the UL mark is just a printed logo with no embedded verification, none of these tricks are visible without checking the file number against UL's own records.

FCC certification fraud hinges on a detail most buyers miss: not every device legally on the market has an FCC ID in the government database. Products approved under the Supplier's Declaration of Conformity (SDoC) procedure are self-certified by the manufacturer and never filed with the FCC, so a legitimate device can correctly show no FCC ID lookup result (FCC, Office of Engineering and Technology, Equipment Authorization). A forger relies on that ambiguity, printing a plausible FCC ID that doesn't exist or belongs to an unrelated device, betting the buyer won't distinguish "not required to be listed" from "invented."

CPSC document fraud splits along the certificate-type line the agency uses. A Children's Product Certificate (CPC) must rest on third-party testing at a CPSC-accepted lab; a General Certificate of Conformity (GCC) for non-children's products can rest on the manufacturer's own testing. Forgers exploit the CPC because reviewers rarely ask for the lab report itself, only the certificate summary โ€” a fabricated CPC referencing a test that never ran is invisible without follow-up.

Certificate Issuing/verifying authority What forgers typically fake Verification channel
UL Listing / UL Certificate UL Solutions (or another OSHA-recognized NRTL) Expired listing reused, altered model number, another factory's file number UL Product iQ file-number lookup
FCC Certification / FCC ID Federal Communications Commission (or SDoC self-certification) Invented or misapplied FCC ID, ignoring that some devices are legitimately unlisted FCC ID Search database
Children's Product Certificate (CPC) Manufacturer/importer, based on CPSC-accepted third-party lab testing Certificate referencing a lab report that was never produced Ask for the underlying test report and confirm the lab is CPSC-accepted
General Certificate of Conformity (GCC) Manufacturer/importer, self-testing permitted Certificate issued with no testing behind it at all Request the test data supporting the self-certification

Red Flags in a Forged UL Listing

The strongest signal is whether the file number resolves to the actual product, not whether the logo looks right. UL Solutions directs buyers to verify a certification mark through its Product iQ database by file number rather than trusting a logo shown in a catalog, quotation, or product photo (UL Solutions guidance, cited via industry compliance reporting). A file number returning a different product category, a different manufacturer, or no result at all is a stop-and-verify moment, not a formality to skip.

This confusion shows up outside procurement too: buyers on equipment forums regularly ask how to confirm a device's UL listing and FCC ID separately, since sellers list both marks as one certification when they come from unrelated bodies with different lookup tools. Treating "UL and FCC" as a single checkbox, rather than two verifications, is the gap forged paperwork is designed to survive.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.

Request a free pilot

Spotting a Fake FCC ID or Certification

Search the FCC ID directly in the FCC's own Equipment Authorization database before accepting a supplier's claim at face value. An FCC ID is built from a grantee code identifying the applicant followed by a product code identifying the specific device, and together they must resolve to a matching grant filing in the FCC database (FCC, FCC ID Search). A code that doesn't resolve, or resolves to a different device, is forged or misapplied โ€” but a blank result is not automatic proof of fraud, since SDoC devices are legitimately self-certified and never appear there. Confirm first whether the device category requires FCC certification at all.

CPSC Certificates of Compliance and the New Federal Crackdown

Federal law treats a false compliance certificate as more than a paperwork error. Under 16 CFR Part 1110, it is a violation to issue a Certificate of Compliance without valid supporting test results, and CPSIA penalties reach $100,000 per violation and up to $15 million for a related series, with criminal exposure of up to five years in prison (eCFR, 16 CFR Part 1110, Certificates of Compliance). CPSC opened a Request for Information on counterfeit certification markings in May 2026, comment period closing July 6, 2026, suspecting fake labels tie to broader schemes involving falsified testing and deceptive import declarations (Federal Register, RFI on Counterfeit Certification Markings, May 6, 2026) โ€” many flagged products move through e-commerce channels where a compliance file rarely gets a second look after onboarding.

A forged certificate used to secure a purchase order or clear customs can trigger federal fraud statutes independent of any CPSC action. Using a forged certification to induce a contract or payment across state lines can fall within the federal mail and wire fraud statutes, 18 U.S.C. ยงยง 1341 and 1343, each carrying a maximum sentence of 20 years' imprisonment (18 U.S.C. ยง 1343, via Cornell Law School Legal Information Institute). State forgery statutes typically stack on top. Neither the FCC nor UL Solutions penalizes a buyer for accepting a forged mark, but a company that resold uncertified product on the strength of a fake certificate stays exposed to recall costs, liability claims, and complicity questions if the falsification was foreseeable.

Building Verification Into Procurement Workflows

A one-time check at onboarding misses the more common failure mode: a supplier changes the underlying component, factory, or revision after the original certificate was issued, and nobody re-verifies before the next order. Certificates should be re-checked at each material product change, not only when a vendor is first approved โ€” UL file numbers, FCC IDs, and CPSC test-lab references are free to look up and take minutes.

Manual document review alone catches roughly 37% of occupational fraud cases, with a median detection delay of 87 days, according to the Association of Certified Fraud Examiners (ACFE, 2024 Report to the Nations), the gap platforms like CheckFile close. CheckFile's methodology applies structural, metadata and cross-document analysis to supplier compliance files, described as high detection coverage rather than a fixed percentage. For suppliers of electrical panels, wiring, and other build materials, this same model plugs into CheckFile's construction industry solution.

None of this replaces confirming a file number with UL, an FCC ID with the FCC, or a lab accreditation with the CPSC โ€” no automated layer substitutes for the issuing authority's own record. An AI-generation signal layer is deployed as a complement to structural document controls, depending on client configuration, rather than a replacement for issuer-side verification, and CheckFile's AI-generated document detection applies that layer to supplier paperwork as one more input, not a guarantee that catches every forgery. Teams evaluating a verification stack can review CheckFile's security architecture and pricing, or get in touch.

Frequently Asked Questions

Does the US have a single certification mark equivalent to CE marking?

No. US product certification is split by category: UL Solutions and other OSHA-recognized NRTLs handle electrical and mechanical safety, the FCC certifies radio-emitting devices, and the CPSC oversees most consumer goods under CPSIA, with the FDA and NHTSA covering medical devices and vehicles. No single federal mark or register covers all product types.

How do I verify a supplier's UL certificate is real?

Look up the UL file number printed on the certificate in UL Solutions' Product iQ database and confirm it resolves to the same product, model, and manufacturer named on the document. A file number returning a different product, a different company, or no result should stop onboarding until UL resolves the discrepancy directly.

Why does an FCC ID search sometimes return no results for a legitimate product?

Some device categories qualify for Supplier's Declaration of Conformity, a self-certification process never filed in the FCC's public database, so a genuine product can legitimately show no search result. Confirm whether the category requires formal FCC certification or qualifies for SDoC before treating a blank search as a red flag.

What happens if a company unknowingly sells a product with a fake CPSC certificate?

CPSIA penalties under 16 CFR Part 1110 apply to issuing a false Certificate of Compliance and can reach $100,000 per violation, up to $15 million for a related series, with criminal exposure up to five years. Buyer or reseller liability typically depends on whether the falsification was reasonably foreseeable, which is why CPSC's 2026 enforcement push emphasizes checking certificates before goods enter US commerce, not after.

Is presenting a forged product certificate to a buyer a federal crime?

It can be. Using a forged certificate to induce a purchase order or payment across state lines may fall under the federal mail and wire fraud statutes, 18 U.S.C. ยงยง 1341 and 1343, each carrying up to 20 years' imprisonment, plus any applicable CPSC penalties and state forgery statutes.


This article is for informational purposes only and does not constitute legal or regulatory advice. Consult qualified counsel or a compliance specialist for guidance specific to your product category and jurisdiction. Laws, agency guidance, and enforcement actions referenced are current as of August 27, 2026.

Stay informed

Get our compliance insights and practical guides delivered to your inbox.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.