The short answer
For an ordinary cosmetic sold in the United States, MoCRA requires the responsible person to ensure adequate safety substantiation and maintain supporting records. Where applicable, facility registration and product listing are separate obligations. A useful evidence file connects the marketed product to relevant information and the reasoning behind the safety conclusion; a folder of unrelated certificates does not establish that connection.
Start with the product and the responsible person
This guide addresses the organization of evidence for ordinary US cosmetics. It is an operational framework, not a substitute for a product-specific regulatory or scientific assessment. Classification comes first: intended use can make a beauty product a drug, or both a drug and a cosmetic. An acne-treatment cleanser, for example, does not follow the same regulatory path as an ordinary cleanser. FDA explains the distinction.
Name the entity responsible for the product before dividing the work among suppliers. MoCRA defines the responsible person through the manufacturer, packer or distributor named on the label. Outsourcing formulation, manufacturing or testing does not make an evidence request disappear. Assign an internal owner who can coordinate those parties and bring unresolved questions to the appropriate reviewer. FDA’s MoCRA overview.
Our recommended starting record is deliberately concrete: commercial product name, internal product identifier, market, intended use, formula reference, current packaging and labeling, responsible entity, and the person coordinating the file. Distinguish what is confirmed from what is still awaiting a supplier answer. A familiar product name is not sufficient when several versions are circulating.
What safety substantiation actually requires
The statutory duty concerns both adequate substantiation and the records supporting it. The standard looks to evidence sufficient for appropriately qualified experts to support a reasonable certainty of safety under labeled or customary use. The law also contains a specific provision for certain coal-tar hair dyes. Read 21 USC 364d.
That makes the practical question more precise than “Do we have a safety document?” Ask what conclusion the information supports, for which product, and on what basis. A reviewer may need to examine the relevance of existing information, identify gaps, and explain how those gaps are addressed. The work cannot be reduced to counting attachments.
FDA states that there is no prescribed list of tests for every individual cosmetic product or ingredient. Scientifically robust existing evidence may contribute to substantiation. That flexibility does not establish that any particular supplier package is sufficient. FDA’s safety-substantiation explanation.
Keep registration, safety and commercial requests separate
FDA explicitly states that facility registration and product listing are not an approval program, and that it does not issue registration or listing certificates. Treat confirmation of a submission as evidence of the submission, rather than evidence that FDA reviewed the product’s safety. FDA’s registration and listing page.
For your own workflow, create separate record groups for administrative submissions, scientific safety support, manufacturing or lot information, and buyer-specific requests. These groups may reference one another without becoming interchangeable. This is an organizational recommendation; it is not a claim that MoCRA prescribes this file structure.
A retailer might ask for a report in a particular format, while a scientific reviewer needs additional information that the retailer template never mentions. Record the reason for each request. “Required by this buyer” and “needed to resolve this safety question” lead to different follow-ups, different reviewers and potentially different disclosure permissions.
Build an evidence index before chasing more PDFs
We recommend using an index with one entry per evidence item or unresolved question. The index should tell a new colleague what exists, who holds it, what it applies to and what remains to be decided. It can start in a structured spreadsheet. The important discipline is preserving the relationships when documents change.
For each received file, record the original issuer, report identifier, issue date, revision, sample identity and intended use in the file. Where applicable, connect it to the formula, package or lot. If an identifier is absent, preserve that fact instead of filling the gap from memory. The next request can then ask for a precise correction.
An evidence index should also distinguish a scientific decision from a collection status. “Received” means the file arrived. “Reviewed” means someone assessed it for a stated purpose. “Correction requested” means the original remains available while the identified problem is addressed. Avoid a single green check that collapses all three.
- Identity: Which marketed product and version does this item concern?
- Provenance: Who issued it, and where did this exact copy come from?
- Scope: What question can it help answer, and what falls outside it?
- Review: Who evaluated it, when, and for what request or decision?
- Open work: What is missing, who is responsible, and what happens next?
A hypothetical moisturizer file with a hidden mismatch
Imagine a brand collecting evidence for a new moisturizer. The manufacturer sends a registration confirmation, an ingredient statement and a stability summary. The commercial product name appears on all three, so the file initially looks coherent. This is a hypothetical example, not a customer case or an account of an FDA decision.
When the coordinator checks the references, the ingredient statement identifies Formula C, while the stability summary identifies Formula B. The team should preserve both files and ask the manufacturer to explain the relationship. It should not change the formula identifier in the report or describe the study as covering Formula C without support.
The follow-up becomes specific: identify the tested composition, explain the change between B and C, provide the relevant study materials, and ask the qualified reviewer what can support the current product. The outcome could be a documented justification for using some earlier evidence, a request for additional work, or a decision that the evidence is insufficient. The index records the actual conclusion, including its limits.
This is also a useful way to coordinate with a supplier that has several departments. Regulatory staff may hold the ingredient statement, R&D may know the formula change, and quality may hold the study reference. One vague request for “all compliance documents” leaves those dependencies invisible.
A small-business exemption is not a blanket exemption
The statutory small-business provision exempts qualifying entities from the sections governing cosmetic GMP and registration/listing; it does not exempt them from the safety-substantiation section. Eligibility also has product-category exclusions and an inflation-adjusted sales test. Confirm applicability for the particular business instead of assuming “small brand” settles it. 21 USC 364h.
In an operational record, retain the basis for the exemption determination separately from the product evidence. Give the determination an owner and identify what changes would require another look. A change in product category or business circumstances should reach that owner rather than remain buried in a sales discussion.
Set retention rules by record type
MoCRA’s adverse-event provision generally requires retention of the related records for six years, with a three-year period for qualifying small businesses described in the provision. Do not turn those periods into a universal retention rule for every cosmetic document. 21 USC 364a(e).
FDA’s January 2026 records-access announcement distinguishes access to adverse-event records during inspection from broader access under the serious-health-risk conditions in section 610. The accompanying guidance is identified as draft guidance. It should not be presented as a new blanket requirement to submit every product file. FDA’s draft-guidance announcement.
For the wider evidence library, establish a documented retention approach with the people responsible for legal, quality and operational requirements. Preserve earlier versions needed to explain past products and decisions. Also decide how you will retrieve records held by an external party if a contact changes, a supplier relationship ends or a shared link stops working.
Make the file usable before the next request arrives
Try a small retrieval exercise. Choose one marketed product and ask a colleague who did not collect its documents to identify the applicable formula, find the supporting evidence, explain the last review decision and list the open questions. Record where they get stuck. This is a suggested internal exercise, not an FDA inspection standard.
Fix broken references before commissioning more studies or buying a new tool. Agree with suppliers on the identifiers they should include, set a clear correction process, and keep a record of what was disclosed for each external request. These habits make a file understandable even when the people handling it change.
BeautyAssured supports this evidence workflow by helping beauty brands collect documents, resolve supplier gaps and retain review context. Scientific and regulatory conclusions remain with the people responsible for making them. The useful outcome is a clear record of the product, its evidence and its unresolved questions.
Common questions
Does a MoCRA registration prove that my cosmetic is safe?
No. FDA says cosmetic registration and listing are not an approval program. Keep submission confirmations separate from the evidence and reasoning used to support product safety.
Does MoCRA prescribe one testing checklist for all cosmetics?
No. FDA does not prescribe a universal test list for individual cosmetics or ingredients. The evidence must be scientifically appropriate to the product; a qualified reviewer should resolve product-specific gaps.
Can a small brand ignore safety substantiation?
The small-business exemption in 21 USC 364h does not remove the safety-substantiation obligation. Eligibility for its other exemptions depends on the statutory criteria and product exclusions.
Should every cosmetic document be kept for six years?
Do not use that as a blanket rule. The six-year period, with a limited three-year exception, concerns adverse-event records. Set retention rules for other records according to their applicable obligations and purpose.
Sources & further reading
Primary sources consulted for this guide. Requirements and guidance can change; follow the linked source for its current wording.
- 21 USC 364d: Safety substantiationU.S. House of Representatives, Office of the Law Revision Counsel
- MoCRA: FDA overviewU.S. Food and Drug Administration
- Registration and listing of cosmetic facilities and productsU.S. Food and Drug Administration
- 21 USC 364h: Small businessesU.S. House of Representatives, Office of the Law Revision Counsel
- 21 USC 364a: Adverse eventsU.S. House of Representatives, Office of the Law Revision Counsel
- FDA draft guidance announcement: Cosmetics records accessU.S. Food and Drug Administration
- How can I tell if my product is a cosmetic, a drug, or both?U.S. Food and Drug Administration
Published by BeautyAssured, a product of Kite Labs, Inc. These guides combine source research with practical workflow recommendations and AI-assisted drafting. They do not imply review by a regulator or independent subject-matter expert. Read our editorial approach.
Put the record in context.
Bring one product document request. See how BeautyAssured connects the evidence, its versions, and the people involved.
Discuss a pilot