European Union (CPNP)

Setting Up an EU Login Account to Access the CPNP

A walkthrough of the EU Login and SAAS access steps you need before you can even open a CPNP notification screen.

The Compliance Desk4 min read

The part nobody warns you about with CPNP is that you don't just show up and start typing in ingredients. There's a login layer sitting in front of it, and if you've never touched an EU Commission system before, it can eat an afternoon before you've entered a single product.

Here's what that layer actually is and how to get through it without guessing.

EU Login is not the CPNP itself

EU Login (some older documentation still calls it ECAS, the European Commission Authentication Service) is the Commission's shared identity system. It's the same login used across a bunch of unrelated EU portals, not something built specifically for cosmetics. Think of it as the front door to an office building with many different tenants. CPNP is one of the tenants.

You create the EU Login account first, separately, before CPNP will mean anything to you. That means:

  • Go to the EU Login registration page and create an account with a real email you control.
  • Verify the email. There's a confirmation step, and the account is not usable until you click through it.
  • Set a password that meets their complexity rules, and consider enabling two-factor if it's offered. Some Commission systems have started requiring it.

Then you need SAAS access specifically

Once your EU Login exists, it doesn't automatically know you want CPNP. You have to request access to the specific application, which historically has been handled through what's called SAAS (Systeme d'Authorisation d'Acces Sécurisé), the access-request mechanism sitting between EU Login and the actual CPNP tool.

Practically, this means:

  • After logging in with your new EU Login credentials, you'll be prompted to request a role or access right for the CPNP application.
  • You typically request access as either a Responsible Person or as someone acting on behalf of one (an agent, a consultant, a filer).
  • There can be a short approval delay. It's not always instant, so don't leave this until the day before you plan to sell.

This distinction, EU Login versus CPNP access, trips people up because the error messages you get when it goes wrong are vague. "Access denied" or a blank dashboard usually means the identity layer worked but the application-level permission didn't get granted yet, not that your account itself is broken.

Company structure matters here

If you're a small operation, one person can hold the EU Login account and the CPNP access role, filing everything themselves. If you're bigger, or you use a consultant, you may have multiple people needing access under the same Responsible Person entity. CPNP supports that, but it means someone has to think through:

Role What they need
Responsible Person (legal entity) Established in the EU, ultimately accountable for the notification
Person filing on the RP's behalf Their own EU Login, granted delegated access to file under that RP
Safety assessor Not necessarily a CPNP user at all, but their signed CPSR has to exist before notification

Have your Responsible Person details sorted before you start

The account setup itself is just plumbing. The actual notification, once you're in, asks for details tied to your Responsible Person: their EU address, contact details, and the product information that ultimately lives in the Product Information File. If you rush the account setup and then sit there without a PIF or a signed Cosmetic Product Safety Report ready, you've just moved the delay downstream instead of removing it.

A reasonable order of operations:

  1. Register the EU Login account and verify the email.
  2. Request CPNP-specific access under the correct Responsible Person.
  3. While waiting on approval, get your Product Information File and CPSR assembled with your safety assessor.
  4. Once access clears, do a test entry with one product to get familiar with the interface before you notify anything for real.

A note on keeping this from becoming a recurring headache

None of this is hard once you've done it, but doing it for the first time under a launch deadline is where people get stressed. If you're coordinating a Responsible Person, a safety assessor, and a growing product line, the account setup is a one-time cost, but keeping the underlying ingredient data straight (INCI mapping, restricted substance checks, PIF documentation) is ongoing. Cosmetic Comply is built around the ingredient side of that problem for the markets it supports, matching ingredients to INCI and CAS and flagging restricted substances before a filing goes out, which is worth knowing about even if your first hurdle right now is just getting logged in.

READY TO FILE?

Send your ingredients and we take it from here

A short intake form is all it takes to start. Every ingredient gets checked against your market's prohibited and restricted lists, then we file your notification and hand you a number you can track.

Start a filing

Keep reading