Setting Up an EU Login Account to Access the CPNP
A walkthrough of the EU Login and SAAS access steps you need before you can even open a CPNP notification screen.
The part nobody warns you about with CPNP is that you don't just show up and start typing in ingredients. There's a login layer sitting in front of it, and if you've never touched an EU Commission system before, it can eat an afternoon before you've entered a single product.
Here's what that layer actually is and how to get through it without guessing.
EU Login is not the CPNP itself
EU Login (some older documentation still calls it ECAS, the European Commission Authentication Service) is the Commission's shared identity system. It's the same login used across a bunch of unrelated EU portals, not something built specifically for cosmetics. Think of it as the front door to an office building with many different tenants. CPNP is one of the tenants.
You create the EU Login account first, separately, before CPNP will mean anything to you. That means:
- Go to the EU Login registration page and create an account with a real email you control.
- Verify the email. There's a confirmation step, and the account is not usable until you click through it.
- Set a password that meets their complexity rules, and consider enabling two-factor if it's offered. Some Commission systems have started requiring it.
Then you need SAAS access specifically
Once your EU Login exists, it doesn't automatically know you want CPNP. You have to request access to the specific application, which historically has been handled through what's called SAAS (Systeme d'Authorisation d'Acces Sécurisé), the access-request mechanism sitting between EU Login and the actual CPNP tool.
Practically, this means:
- After logging in with your new EU Login credentials, you'll be prompted to request a role or access right for the CPNP application.
- You typically request access as either a Responsible Person or as someone acting on behalf of one (an agent, a consultant, a filer).
- There can be a short approval delay. It's not always instant, so don't leave this until the day before you plan to sell.
This distinction, EU Login versus CPNP access, trips people up because the error messages you get when it goes wrong are vague. "Access denied" or a blank dashboard usually means the identity layer worked but the application-level permission didn't get granted yet, not that your account itself is broken.
Company structure matters here
If you're a small operation, one person can hold the EU Login account and the CPNP access role, filing everything themselves. If you're bigger, or you use a consultant, you may have multiple people needing access under the same Responsible Person entity. CPNP supports that, but it means someone has to think through:
| Role | What they need |
|---|---|
| Responsible Person (legal entity) | Established in the EU, ultimately accountable for the notification |
| Person filing on the RP's behalf | Their own EU Login, granted delegated access to file under that RP |
| Safety assessor | Not necessarily a CPNP user at all, but their signed CPSR has to exist before notification |
Have your Responsible Person details sorted before you start
The account setup itself is just plumbing. The actual notification, once you're in, asks for details tied to your Responsible Person: their EU address, contact details, and the product information that ultimately lives in the Product Information File. If you rush the account setup and then sit there without a PIF or a signed Cosmetic Product Safety Report ready, you've just moved the delay downstream instead of removing it.
A reasonable order of operations:
- Register the EU Login account and verify the email.
- Request CPNP-specific access under the correct Responsible Person.
- While waiting on approval, get your Product Information File and CPSR assembled with your safety assessor.
- Once access clears, do a test entry with one product to get familiar with the interface before you notify anything for real.
A note on keeping this from becoming a recurring headache
None of this is hard once you've done it, but doing it for the first time under a launch deadline is where people get stressed. If you're coordinating a Responsible Person, a safety assessor, and a growing product line, the account setup is a one-time cost, but keeping the underlying ingredient data straight (INCI mapping, restricted substance checks, PIF documentation) is ongoing. Cosmetic Comply is built around the ingredient side of that problem for the markets it supports, matching ingredients to INCI and CAS and flagging restricted substances before a filing goes out, which is worth knowing about even if your first hurdle right now is just getting logged in.
Send your ingredients and we take it from here
A short intake form is all it takes to start. Every ingredient gets checked against your market's prohibited and restricted lists, then we file your notification and hand you a number you can track.
Start a filingKeep reading
Reporting Serious Undesirable Effects Through the CPNP
A customer complaint about a burning rash is not just feedback, it may be a serious undesirable effect you are obligated to report.
Minimum Durability Dates on EU Cosmetic Labels
How the EU hourglass symbol differs from PAO, and what stability data actually has to back up each one on your label.
Stating the Function on an EU Label When It Is Not Obvious
When EU Regulation 1223/2009 requires a stated product function on the label, with soap and serum examples showing where it applies.
Can You Sell a CBD Cosmetic in the EU CPNP
The CosIng entry situation for cannabidiol, and why THC content and narcotic status constrain whether a CBD cosmetic can be notified in the EU at all.