Certificate of Analysis vs Certificate of Conformance: What QA Needs to Know
![]()
A Certificate of Analysis (COA) is a batch-specific lab report showing measured test results against specification limits. A Certificate of Conformance (CoC) is a supplier’s declaration that a product meets defined requirements, typically without presenting numeric test data. Knowing which document to request, and how to verify it, is one of the most practical skills in quality assurance.
Quick usage rules:
- Require a COA when receiving regulated goods (pharmaceuticals, dietary supplements, food ingredients, research peptides), critical raw materials, or any lot where batch-specific data is needed for release decisions or traceability.
- A CoC may suffice for low-risk commodity items, standard mechanical components, or non-regulated goods where a supplier’s blanket declaration against a drawing or specification is contractually acceptable.
- Both documents together are common in regulated shipments where a CoC covers contractual conformity and a COA provides the evidentiary test data.
Key Takeaways
A COA provides batch-specific, numeric test evidence for a lot; a CoC provides a supplier’s conformance declaration, and regulated goods typically require the COA.
| Point | Details |
|---|---|
| COA vs CoC core difference | A COA shows measured numeric results per lot; a CoC declares conformity without necessarily presenting test data. |
| When to require a COA | FDA-regulated goods, research peptides, dietary supplements, and any critical material where batch data is needed for release. |
| Lab accreditation matters | ISO/IEC 17025 accreditation from the issuing lab confirms the test methods and scope are independently validated. |
| Lot number is non-negotiable | A COA without a lot number that matches your PO and packing list provides no meaningful traceability for audits or recalls. |
| Peppy&Me’s COA practice | Peppy&Me publishes lot-linked third-party COAs with raw data in its COA Vault, covering purity, identity, endotoxins, sterility, and heavy metals. |
Table of Contents
- What is a Certificate of Analysis, and what fields should you expect?
- What a Certificate of Conformance actually says, and what it leaves out
- How COA and CoC compare across the dimensions QA teams care about
- When should QA require a COA, and when is a CoC enough?
- How to read and verify a COA or CoC step by step
- How COAs and CoCs function within US regulatory and traceability frameworks
- Questions QA should ask suppliers when receiving a COA or CoC
- How Peppy&Me handles lot-specific COAs and supports QA verification
- Peppy&Me’s perspective on setting internal COA/CoC policy
- Peppy&Me supports COA-based traceability for research professionals
- Sources
- FAQ
What is a Certificate of Analysis, and what fields should you expect?
A Certificate of Analysis is a batch-specific document that records measured test results against pre-defined specification limits for a specific production lot. It is typically issued by a manufacturer’s QA/QC laboratory or by an independent, accredited testing laboratory. In regulated industries, the COA is the primary evidentiary record that a lot was tested, what the results were, and whether it passed.
Standard COA fields a QA professional should verify:
- Product name and description (including grade, form, and catalog number)
- Lot or batch number (the single most critical traceability field)
- Manufacture date, expiry date, and/or retest date
- Tested parameters (identity, purity, potency, appearance, pH, moisture, contaminants)
- Numeric test results with units (e.g., HPLC purity ≥98.5%, measured at 99.1%)
- Specification limits (the pass/fail threshold for each parameter)
- Test methods (e.g., USP <621>, HPLC, ICP-MS, LAL endotoxin assay)
- Analyst name and laboratory name
- Laboratory accreditation (ISO/IEC 17025 or equivalent)
- Authorized signature and date
- Attachments (chromatograms, mass spectra, raw instrument data)
| COA Field | What to Check |
|---|---|
| Lot/batch number | Matches your purchase order and packing list exactly |
| Test results | Numeric values, not just “pass” or “complies” |
| Specification limits | Stated alongside results so pass/fail is verifiable |
| Test methods | Named method (USP, AOAC, in-house SOP with version) |
| Lab name and accreditation | ISO/IEC 17025 scope covers the tests listed |
| Authorized signature | Dated, named, and traceable to a responsible person |
| Attachments | Chromatograms or raw data linked or appended |
Who issues a COA matters. A manufacturer’s internal QA lab can produce a COA, but an independent, third-party accredited laboratory adds a layer of independence that internal documents cannot. For research peptides and other high-purity compounds, third-party testing is the standard that serious QA programs expect.
What a Certificate of Conformance actually says, and what it leaves out
A Certificate of Conformance (also called a Certificate of Compliance, or CoC) is a written declaration from a supplier or manufacturer stating that a product, batch, or shipment meets specified requirements. Those requirements may be a drawing number, a purchase order specification, an industry standard (such as ASTM or MIL-SPEC), or a contractual quality clause. The key distinction from a COA is that a CoC does not necessarily include numeric test data; it asserts conformity rather than demonstrating it through measured results.
Typical CoC content:
- Supplier name, address, and authorized representative
- Customer name and purchase order reference
- Product description, part number, and quantity
- Referenced specification, standard, or drawing number
- Statement of conformance (e.g., “This product conforms to ASTM B211 and purchase order #12345”)
- Authorized signature and date
CoCs are common in electronics, aerospace fasteners, automotive components, and construction materials, where a supplier certifies that parts were manufactured to a drawing and that materials meet a referenced alloy or grade specification. In those contexts, the conformance declaration is often backed by internal testing records that the buyer does not receive unless specifically requested.
The limitation is straightforward: a CoC tells you the supplier believes the product conforms. It does not show you the data that supports that belief. For regulated goods, that gap matters significantly.
How COA and CoC compare across the dimensions QA teams care about
The practical difference between a COA and a CoC comes down to evidence versus declaration. A COA shows you the numbers; a CoC tells you the supplier is confident the numbers are acceptable. Both have legitimate roles, and many regulated shipments require both.

| Dimension | Certificate of Analysis (COA) | Certificate of Conformance (CoC) |
|---|---|---|
| Issuer | Manufacturer QA/QC lab or independent accredited lab | Supplier or manufacturer (self-declaration) |
| Purpose | Documents measured test results for a specific lot | Declares that a product meets specified requirements |
| Level of detail | Numeric results, methods, limits, and accreditation | Pass/fail or conformance statement; rarely numeric |
| Lot specificity | Always lot-specific | May cover a batch, a shipment, or a blanket period |
| Typical fields | Lot number, parameters, results, limits, methods, signatures, attachments | PO reference, spec reference, authorized signature |
| Use cases | Drug release, supplement QC, food safety, R&D materials, incoming inspection of critical inputs | Industrial parts, electronics, non-regulated components, commodity materials |
| Regulatory/legal weight | Primary evidentiary document for FDA-regulated goods | Sufficient for CPSC general conformity; limited in FDA contexts |
| How to verify | Match lot number to PO; check lab accreditation; request raw data attachments | Confirm spec references are current; request supporting test records if risk warrants it |
Micro-scenarios:
- Incoming peptide lot for research: A COA is required. The document should include lot number, HPLC purity with chromatogram, mass spectrometry identity confirmation, endotoxin result, and sterility data. A CoC alone is insufficient.
- Metal fasteners for an assembly run: A CoC referencing the applicable ASTM material specification and heat/lot number is typically acceptable. The buyer may request mill certifications (a form of COA) for safety-critical applications.
When should QA require a COA, and when is a CoC enough?
The decision follows risk. The higher the consequence of a non-conforming lot reaching end use, the more evidence you need, and evidence means a COA with numeric data.
Scenarios that require a COA:
- Pharmaceutical active ingredients and excipients (FDA cGMP expectation)
- Dietary supplements and food ingredients (FDA 21 CFR Part 111 and Part 117)
- Research peptides and laboratory reagents where identity and purity directly affect experimental validity
- Any material where a contaminant (heavy metals, endotoxins, microbial) could cause harm
- Incoming inspection of critical raw materials before production release
Scenarios where a CoC may be acceptable:
- Standard commercial hardware (screws, brackets) purchased to a published ASTM or ISO specification
- Packaging materials with no direct product contact
- Low-risk commodity items with a long, documented supplier history and no regulatory requirement for batch data
- Non-regulated consumer goods where a general conformity certificate satisfies the applicable standard
Rules of thumb for procurement and inspection policy:
- If the material is regulated by FDA, USDA, or EPA, default to requiring a COA.
- If a non-conforming lot could cause patient harm, research error, or product recall, require a COA.
- If the supplier has a strong audit history and the material is low-risk, a CoC with a right-to-audit clause may be contractually sufficient.
- For new suppliers, always start with a COA requirement regardless of product risk level.
- For R&D materials, require a COA with identity confirmation; a purity percentage alone is not sufficient evidence of what the compound actually is.
How to read and verify a COA or CoC step by step
Receiving a document is not the same as verifying it. A COA that looks complete can still be unreliable if the lot number does not match, the lab is unverifiable, or the test methods are vague. Work through these steps before accepting any lot.
- Match the lot number. Compare the lot or batch number on the COA to the number on your purchase order, packing list, and physical label. A mismatch is an immediate hold.
- Confirm product identity. The product name, grade, and catalog number should match your specification exactly. For peptides and similar compounds, identity confirmation via mass spectrometry is the standard, not just a purity percentage.
- Check specification limits against results. Every tested parameter should show both the specification limit and the measured result. A COA that lists only “pass” without numeric values gives you no ability to assess how close the lot came to the limit.
- Verify test methods. Methods should be named and versioned (e.g., “USP <85> Bacterial Endotoxins Test” or “HPLC per in-house method SOP-QC-012 Rev. 3”). Vague entries like “by standard methods” are a red flag.
- Validate lab credentials. Look up the issuing laboratory’s ISO/IEC 17025 accreditation. Most accredited labs are listed in the ILAC MRA directory or on their national accreditation body’s website. Confirm the scope of accreditation covers the tests listed on the COA.
- Request attachments. A credible COA for a research compound or pharmaceutical material should include or link to chromatograms, mass spectra, or other raw instrument data. A summary sheet without supporting data is incomplete.
- Check the signature and date. The COA should be signed by an authorized representative, dated, and version-controlled. An undated or unsigned document has no chain-of-custody integrity.
Red flags that should prompt a hold and supplier inquiry:
- No lot number, or a lot number that does not match the shipment
- Results listed only as “pass” or “complies” with no numeric values
- Test methods described vaguely or not at all
- Lab name is unverifiable or has no listed accreditation
- Identical COAs reused across multiple lots (same document, different lot number typed in)
- Dates that precede the manufacture date or fall outside the retest window
Pro Tip: When requesting a third-party COA, ask the lab directly for their ISO/IEC 17025 accreditation certificate and the scope document. The scope should list the specific test methods and matrices the lab is accredited for. If the tests on your COA fall outside that scope, the accreditation does not cover them.
How COAs and CoCs function within US regulatory and traceability frameworks
In the United States, the regulatory weight of each document depends heavily on the product category and the agency overseeing it.
FDA-regulated products (drugs, dietary supplements, food ingredients, biologics) operate under current Good Manufacturing Practice (cGMP) regulations. For these categories, a COA is the expected evidentiary record for lot release. FDA’s guidance for dietary supplements under 21 CFR Part 111 specifies that manufacturers must test incoming components and finished products, with results documented in batch records. A CoC from a supplier does not satisfy this requirement on its own; the receiving manufacturer must verify identity and may rely on supplier COAs only under specific conditions with supplier qualification on file.
CPSC-regulated consumer products use a different framework. The Consumer Product Safety Improvement Act (CPSIA) requires a General Certificate of Conformity (GCC) for many children’s products, certifying compliance with applicable safety rules. This is a conformance declaration, not a detailed test report, though it must be based on testing by a CPSC-accepted laboratory.
Traceability and recall readiness depend directly on lot numbers. When FDA issues a recall or requests records, the lot number on the COA is the link between the physical product, the test data, and the supply chain. A COA without a lot number, or one where the lot number cannot be traced back to a specific production run, provides no meaningful traceability. Lot-specific COAs with attached raw data are the standard auditors expect in FDA-regulated environments.
What auditors look for:
- Lot numbers that match batch records and distribution records
- Test method references that correspond to validated or compendial methods
- Signatures from qualified personnel with documented authority
- Attachments or links to full test reports, not just summary sheets
- Evidence of lab accreditation, particularly ISO/IEC 17025 for analytical testing
Questions QA should ask suppliers when receiving a COA or CoC
Receiving documentation is the start of the verification process, not the end. These questions help QA teams close gaps before a lot is released.
Priority questions before release:
- Does the lot number on this document match the lot number on the physical shipment and the purchase order?
- Which accredited laboratory performed the testing, and can you provide their ISO/IEC 17025 accreditation certificate?
- Are chromatograms, mass spectra, or other raw instrument data available for this lot?
- What test method was used for identity confirmation, and is it compendial or in-house?
- What are the endotoxin and sterility results for this lot? (Required for injectable-grade or research-grade peptides and biologics.)
- What is the retest date or expiry date, and has the lot been stored under the specified conditions since manufacture?
- If this is a manufacturer’s COA, has the material also been tested by an independent third-party laboratory?
Email template for requesting a lot-specific COA or full test report:
Subject: COA Request — [Product Name], Lot [Lot Number], PO [PO Number]
Dear [Supplier QA Contact],
We are conducting incoming inspection for the above-referenced shipment. Please provide the following for Lot [Lot Number]:
- Lot-specific Certificate of Analysis including all tested parameters, numeric results, specification limits, and test methods.
- ISO/IEC 17025 accreditation certificate for the issuing laboratory, including the scope of accreditation.
- Supporting raw data: chromatograms (HPLC), mass spectra (MS), and endotoxin/sterility test reports where applicable.
- Confirmation that the lot number on the COA matches the lot number on the packing list and physical label.
Please respond within [X] business days. The lot will remain on hold pending receipt and review of the above documentation.
Thank you,
[Your Name, Title, Company]
How Peppy&Me handles lot-specific COAs and supports QA verification
Peppy&Me’s approach to COA documentation reflects the standard that regulated research environments expect. Every lot received goes through third-party testing before it is made available to researchers, covering purity (HPLC), mass accuracy (mass spectrometry), endotoxins, sterility, and heavy metals. The results are not summarized internally; they are published as lot-linked documents in the COA Vault, where authorized members can download the full COA and supporting raw data for any lot they have ordered.
What Peppy&Me’s COA workflow covers:
- Lot reception and assignment of a traceable lot number from manufacturer to warehouse
- Third-party laboratory testing for purity, identity, endotoxins, sterility, and heavy metals
- COA upload to the secure member portal, linked directly to the lot number
- Downloadable raw data (chromatograms, spectra) available alongside the summary COA
- Same-day shipping for orders placed before 2 PM, with lot information carried through to the shipping documentation
This workflow addresses the most common COA gaps: missing lot numbers, absent raw data, and unverifiable lab credentials. Researchers accessing the COA Vault guide can see exactly how lot numbers map to test results and how to interpret each parameter.
Pro Tip: When evaluating any peptide supplier’s COA, check whether the issuing lab is independent of the supplier. A manufacturer’s in-house COA and a third-party accredited lab COA are not equivalent. Third-party testing removes the conflict of interest and adds a layer of verification that internal documents cannot provide.

Peppy&Me’s perspective on setting internal COA/CoC policy
The most common mistake QA teams make is treating document type as a binary choice rather than a risk-calibrated decision. A CoC is not a lesser document; it is the right document for the right context. The error is accepting a CoC for a context that requires a COA, usually because the COA was not immediately available and the pressure to release was high.
A defensible policy defaults to COA for any regulated, critical, or novel input and accepts a CoC only under three defined conditions: the material is low-risk, the supplier has a qualified audit history, and the contract explicitly defines what “conformance” means with reference to a specific, current specification. Conditional acceptance with a block-release hold, pending receipt of the full COA, is a reasonable middle ground when a supplier needs time to provide documentation. What is not reasonable is releasing a lot on the strength of a declaration alone when the regulatory or research context demands measured data.
Peppy&Me supports COA-based traceability for research professionals
For QA professionals and researchers who need more than a supplier’s word, Peppy&Me provides a research peptide sourcing framework built around lot-specific documentation and independent verification. Every compound in the catalog carries a traceable lot number linked to third-party test results covering purity, mass accuracy, endotoxins, sterility, and heavy metals, all accessible through the secure member portal.
The COA Vault gives authorized researchers direct access to downloadable raw data, not just summary sheets, so verification is a matter of minutes rather than a back-and-forth with a supplier. Orders placed before 2 PM ship the same day, with lot information carried through to fulfillment. Support is available in real time for any documentation question. To review a sample COA package or access the full research compounds catalog, log in to the member portal or contact the Peppy&Me support team directly.
Sources
- What Is a Certificate of Analysis (COA)? Complete Guide for 2026 | The Laboratory Outsourcing Network – Contract Laboratory
- Certificate of Compliance vs. Certificate of Analysis: Their Key Differences – Inbound Logistics
- How to Read a Certificate of Analysis (COA) for Research Peptides
- How to Read a Peptide Certificate of Analysis (COA): Complete Guide
FAQ
What is a Certificate of Analysis?
A Certificate of Analysis is a batch-specific document issued by a QA/QC or accredited testing laboratory that records measured test results, specification limits, and test methods for a specific production lot. It is the primary evidentiary record used in regulated industries to confirm a lot was tested and met its specifications before release.
What is the difference between a COA and a CoC?
A COA provides numeric test data tied to a specific lot, while a CoC is a supplier’s declaration that a product meets defined requirements, typically without presenting the underlying test results. In FDA-regulated contexts, a COA carries significantly more evidentiary weight than a CoC alone.
What are the main types of certificates of conformance?
Certificates of conformance vary by industry: a General Certificate of Conformity (GCC) is used for CPSC-regulated consumer products, a Material Test Report (MTR) or mill certificate serves as a conformance document for metals and alloys, and supplier declarations of conformity (SDoC) are common in electronics under standards such as FCC or CE. Each references a specific standard or specification rather than presenting raw test data.
When should a QA team request a COA instead of accepting a CoC?
A COA is required whenever the material is FDA-regulated, the lot is a critical input where batch-specific data is needed for release, or the end use involves research, pharmaceutical, or food applications where a non-conforming lot carries meaningful risk. A CoC may be acceptable for low-risk, non-regulated commodity items with a documented supplier history.
What does a COA mean for research peptides specifically?
For research peptides, a credible COA must include a lot number, HPLC purity with a chromatogram, mass spectrometry identity confirmation, and results for endotoxins, sterility, and heavy metals. A purity percentage alone is not sufficient; identity confirmation via mass spectrometry is the standard that distinguishes a complete COA from an incomplete one.
