How to Submit Your E2B(R3) ICSR File to the FDA: A Step-by-Step Guide
You have already generated the E2B(R3) XML file — whether with AdverseEvent.ai or on your own. Now let's submit it to the FDA's FAERS database.
If you've never sent a safety report to the FDA electronically before, this can feel intimidating — there are gateways, acknowledgments, certificates, and a lot of acronyms. The good news: for most small and mid-size companies, the simplest path is a web portal where you log in and upload your file, much like attaching a document to an email. This guide walks you through that path, called the Unified Submission Portal (USP), from start to finish.
The big picture: a one-time setup, then a quick routine
There are two phases, and it helps to keep them separate in your mind.
Phase 1 is a one-time setup. This is a one-time onboarding with the FDA. It helps to separate two very different kinds of time here, because they get blurred together and make the setup sound bigger than it is:
- Your active time is small — on the order of a couple of hours total, spread across a few short tasks: registering your account, completing a one-page letter, and running a single test submission.
- The rest is the FDA's processing time, not your work. After you register, an FDA reviewer approves your account (often quickly — some applicants within a day, even over a weekend). Later you run test submissions, which the FDA reviews before switching you on for production; for a first-time submitter this review can involve a few rounds of back-and-forth over several days. Most of the calendar time is you waiting on the FDA, not working.
You only go through Phase 1 once. After that, every real submission is the quick routine in Phase 2.
Phase 2 is the routine. Once you're set up, each future report is a short process: check the file, log in, upload, and save your receipts. This is the part you'll repeat for every case, and it's genuinely quick.
The USP is the web-based option. You don't need to write any code, run any servers, or set up a system-to-system connection. You just need a browser. (There are two other, more technical routes — AS2 and an API — but those are for high-volume automation and aren't necessary here.)
Phase 1: One-time FDA gateway setup
Important: these setup steps are the FDA's requirements, not ours. Every organization that submits adverse event reports to the FDA electronically must complete this same onboarding — an FDA gateway account, a DUNS number, a Non-Repudiation Letter, and (for first-time submitters) a one-time test submission. This is true regardless of which software produced the report or which submission method you use. A company running a large, established commercial safety system must satisfy the very same FDA prerequisites before it can transmit a single report; the only thing that differs is how the finished file reaches the gateway. AdverseEvent.ai adds no requirements on top of the FDA's — we simply produce the file you submit. And don't let "test submission" worry you: it's a one-time FDA requirement, and Step 3 walks you through it — and if you use AdverseEvent.ai, the test file itself is created for you.
Step 1 — Have your DUNS number ready
Your company needs a DUNS number — a free, nine-digit business ID issued by Dun & Bradstreet (D&B), not the FDA. It identifies your company on every report and is required on each submission. Most established businesses already have one; if yours doesn't, you can apply free at https://www.dnb.com/en-us/smb/duns/get-a-duns.html — allow a little lead time, since issuance isn't instant.
Step 2 — Register for an ESG NextGen account (and Non-Repudiation Letter)
The FDA's front door for electronic submissions is called ESG NextGen (Electronic Submissions Gateway, Next Generation). The USP lives inside it.
Go to the FDA's ESG NextGen page — https://www.fda.gov/industry/electronic-submissions-gateway-next-generation-esg-nextgen — and use the Industry USP Login link there to register or create an account. A few things to know before you start:
- Use a business email address. Personal email services like Gmail or Yahoo are not accepted. Use your company domain (for example, your-name@yourcompany.com).
- You'll use multi-factor authentication (MFA) — but there's no app to install. This is the same extra security many banks use: after your password, the FDA emails you a short one-time verification code, and you enter it to finish logging in. No Google Authenticator or other authenticator app is required.
- The first person to register for your company becomes the "Power User." This person can manage other users and handle the company's paperwork later. If you're the one setting this up, that's you.
You'll also complete your Non-Repudiation Letter (NRL) here — it's a required part of finishing registration, not a later step. The NRL is a short statement that electronic signatures made under your account are genuine and binding, so a submission can't later be disowned (it satisfies an FDA electronic-records rule, 21 CFR 11.100). The wizard reaches the NRL step before it will let you submit, and you don't mail anything. You have two ways to handle it:
- Create it digitally (the easy path): the wizard generates the letter for you and you sign it electronically right on the screen. Nothing to write, nothing to attach.
- Upload your own signed copy: put the letter on company letterhead, have an authorized person sign it by hand, and upload it as a PDF during the wizard. If you go this route, have the PDF ready before you start. The FDA gives you a fill-in-the-blank sample to copy — see Letters of Non-Repudiation Agreement.
A single company-wide letter can cover everyone at your company, or you can file an individual one just for yourself — either way it's one-time, and no paper copy needs to be mailed to the FDA.
Once you submit your registration, an FDA administrator reviews it and emails you when your account is approved — often quickly; some applicants are approved within a day.
Helpful link: The FDA's Getting Started with ESG NextGen page has the official user guides and short training videos that walk through registration screen by screen.
Step 3 — Do a test submission
Before the FDA turns on your ability to send real reports, first-time submitters complete a test submission — a practice run in a separate test environment that proves your file is well-formed and that acknowledgments come back properly. Nothing in the test reaches the real safety database.
Good news: you can start testing on your own — you don't need to email the FDA or wait for permission to begin. Run the test yourself; for a first-time submitter, the FDA then reviews your test submissions before switching you on for production (more on that below). Here's the sequence:
- Generate a test version of your file. A test file is identical to a real report except it carries the FDA's test routing, which sends it to the test environment instead of the live database: the batch receiver identifier is
ZZFDATSTrather than the production valueZZFDA(the message receiver — your product's reviewing Center,CDERorCBER— is set by the product, not by the test/production choice). If you build your own XML, set that test value yourself; if you use AdverseEvent.ai to generate the file, just pick "Postmarket - Test (FDA pre-production)" in Field F0 (Submission Type) and the test routing is stamped in for you. - Upload that file through the USP portal, using the same steps as a real report (the Phase 2 routine below). The file always goes through the portal — never by email.
- Wait for your acknowledgments. ESG NextGen returns several acknowledgments as your file moves through the system; the decisive one is the Center's response — ACK3 (and ACK4, if applicable) — saying whether FAERS accepted or rejected your report (the full set is explained in Phase 2 below). A positive Center response means the system accepted your test file — a good sign, though for a first-time submitter it may not be the final word (see below).
A positive ACK3 clears the technical bar, but first-time submitters usually aren't switched on for production automatically. The FDA reviews your test submissions and often follows up by email — asking for additional test files that exercise more fields and scenarios — and you may exchange a few rounds over several days before it grants final production approval. Once the FDA confirms you're approved, you can start sending real reports; from then on you skip the test and use the routine in Phase 2.
You don't need to notify the FDA to start testing, but expect the FAERS submission coordinator (faersesub@fda.hhs.gov) to be your point of contact through this review — and later, too, if you make a major change to your reporting system that calls for a re-test.
That's it for setup. Everything below is the part you repeat.
Phase 2: Submitting your E2B(R3) report through the USP (the routine)
Step a — Validate the file
Before you upload, run your XML through the FDA's free E2B(R3) Validator at https://faers-validator.fda.gov/LSMV/Validator — a web page where you upload the file and it instantly tells you whether it meets the FDA's rules, no account required. Fix any errors before submitting.
The validator flags both hard errors (which would cause the FDA to reject the report) and warnings (which won't block it but are worth reviewing). Catching a hard error here — in about thirty seconds — saves you a rejected submission later. If you use AdverseEvent.ai, these issues would already have been flagged on your report as you built it, but running the validator anyway is a free safety net that's always worth it.
Step b — Log in to the USP
Go to the USP login page and sign in with your email and password, then enter the one-time code the FDA emails you. The first time you log in, you'll review a short confirmation screen and click through to activate your portal.
Step c — Start a new submission and upload your file
Choose to create a new submission. The first time you upload, the portal will prompt you to install a small helper tool (the FileCatalyst Transfer Agent) that handles the file transfer securely and quickly. Install it once; it's reused after that.
You'll then:
- Select the FDA Center that reviews your product — this is assigned per product, not a drug-vs-biologic guess (see the note just below). (If you use AdverseEvent.ai, the file already carries your product's Center — pick the same one here.)
- Select the submission type — for postmarket drug ICSRs under CDER this is AERS (FDA's Adverse Event Reporting System, i.e., FAERS). Under CBER, choose that Center's corresponding adverse-event reporting type. Either way, avoid the premarket (IND) variant such as AERS_PREMKT_CDER. (File attachments are sent separately under the matching Attachments type.)
- Choose your XML file and add it to the upload queue.
Not sure which Center? Every approved product has an assigned reviewing Center, named in its approval letter and listed in Drugs@FDA and the Purple Book — so look it up rather than guess. A quick shortcut from the application number: an NDA or ANDA means CDER; a BLA usually means CDER too, since most therapeutic biologics (monoclonal antibodies, insulins, enzymes) moved to CDER in 2003. CBER covers vaccines, blood products, allergenics, and gene and cell therapies.
These selections happen in the portal at upload time and aren't part of the file itself — they're separate from the routing codes already inside your XML.
One identifier in the file is specific to your company: the sender identifier, which is your DUNS number from Step 1. Make sure it's the correct DUNS for your registered account — the FDA checks it, and a missing or wrong one gets the report rejected. (If you use AdverseEvent.ai, you just enter your DUNS in the report form and it's written into the file for you.)
Step d — Sign, submit, and collect your acknowledgments
There's a reference field where you can note something for your own records (it's just for you). Then you electronically sign the submission by drawing your signature in the box with your mouse, finger, or stylus. If you need to change anything after signing, clear the signature, make your edits, and sign again. When everything looks right, submit.
After you submit, the FDA sends back a series of acknowledgments as your file moves through the system. You'll receive them by email, and you can also view and download them anytime from the Submission History inside the portal.
- ACK1 (uploaded): confirms your file was received and uploaded into the ESG NextGen gateway.
- ACK2 (routed to the Center, if applicable): confirms your submission was transmitted on to the Center (CDER or CBER).
- ACK3 — and ACK4, if applicable — (the Center's response): FAERS's verdict on whether your report was accepted or rejected. This is the one that tells you pass or fail; a rejection carries error codes showing what to fix.
How long to wait: the earlier acknowledgments (ACK1, ACK2) typically arrive within minutes to a few hours. The decisive Center response — ACK3 (and ACK4, if applicable) — should follow within 24 hours, often much sooner. If it hasn't arrived 24 hours after the earlier acknowledgments, check the FDA's ESG status page before assuming your file is the problem. A rejection comes as a negative Center response with error codes; fix the file and resubmit with a new batch identifier.
These messages are your proof of submission. Save them — they're part of your regulatory records, and you'll want them on file.
The portal also has a Status Tracker that gives you an at-a-glance view of your recent submissions, and a search box to look up a specific submission by its Core ID (a tracking number the FDA assigns to each submission).
What to do if a report is rejected
If the Center's response (your ACK3, or ACK4) comes back as a rejection, don't panic — the report simply didn't enter the database, so there's nothing to undo. Read the error codes in it, correct the issue in the XML, run it through the validator again, and resubmit with a new batch identifier. The acknowledgment will point you to what went wrong.
This is exactly why Step a matters: validating first means rejections at this stage should be rare.
How to file a follow-up report
When you send updated information about a case you've already reported (a "follow-up"), the FDA needs to recognize it as the same case so the new details attach to the original instead of creating a duplicate. In E2B(R3), every case carries a unique case identifier that stays constant for its entire lifecycle, and a follow-up reuses that same identifier. That identifier is built from your organization's identity and your own internal case number — so whatever tool you use, the rule is the same: keep the case identifier and your internal case number identical to the original, and update the "date of most recent information" to the date of the new update.
If you use AdverseEvent.ai, you never type the case ID at all — it's generated automatically from two fields, and you control a follow-up by matching them to the original report:
- Manufacturer Name (G1) — same as the initial report.
- Manufacturer Report Number (G8) — same as the initial report.
- Date of This Report (B4) — same as the initial report. This is the date your company first learned of the case, so it doesn't change on follow-ups.
- Date of Most Recent Information (F16) — set this to the date you last updated the case (usually today).
Leave F17 (Worldwide Unique Case ID) blank — it auto-generates from the fields above, so there's nothing to enter there.
Keeping your account active
One small thing to remember: USP accounts go inactive after 60 days without a login. If you submit infrequently, log in occasionally so your account stays active.
Where AdverseEvent.ai fits
Your job in this whole process is the last mile: getting a correct, validated XML file into the portal and saving the acknowledgments. AdverseEvent.ai handles the hard part that comes before that — turning your case data into a clean, rules-compliant E2B(R3) file with the right structure, routing, and identifiers, so that when you upload it, it sails through validation.
Generate the file with AdverseEvent.ai, validate it, upload it, save your acknowledgments. That's the whole journey.
Further reading:
- How to Generate Valid E2B(R3) XML — building the ICSR file you submit here, field by field
- How to Fill Out FDA Form 3500A — the underlying MedWatch case data behind every ICSR
- Drug adverse event reporting workflow — generate a submission-ready E2B(R3) report from your case
- FDA — Getting Started with ESG NextGen — official registration steps and user guides
- FDA — E2B(R3) Validator — check your file before you submit
This guide is for general educational purposes and reflects the FDA's electronic submission process at the time of writing. The FDA periodically updates its portal and requirements, so check the official FDA ESG NextGen pages and user guides for the latest steps. This article is not legal or regulatory advice.