A certificate PDF can be useful evidence. It can also answer the wrong question.
The document may relate to a different company, factory, product model, material, standard, country, test sample, or time period. It may be a management-system certificate when you need product evidence. It may be a test report when you need a declaration, a current approval, or a certificate issued by a body with the right scope.
Do not start by asking whether the PDF looks official. Start by asking what you need to validate: which product, which requirement, which market, and which legal entity? Then check whether the document actually supports that claim.
This article provides a document-review process, not legal or regulatory advice. Product requirements vary by product, jurisdiction, sales role, and current rules. For a material launch or regulated product, confirm the current requirements with the relevant authority, certification or testing body, and qualified compliance professionals.
First, name the document correctly
Suppliers often use “certificate” as a catch-all word. That can create confusion before you have even reviewed the file.
A document may be one of the following:
| Document type | What it may show | What it does not automatically show |
|---|---|---|
| Management-system certificate | A company or facility has been assessed against a stated management standard and scope | That your exact product meets a market’s product rules |
| Product certificate or approval | A named product, family, or configuration was assessed under a stated scheme | That every version, material, factory, and later production batch is included |
| Test report | Results for the sample, method, date, and conditions described in the report | That all production is compliant or the report applies to a different product version |
| Declaration or conformity document | A responsible party’s stated conformity claim for a defined product and requirements | That an independent third party has assessed the product unless the regime requires it |
| Supplier declaration or material statement | A supplier’s statement about an ingredient, material, process, or restriction | That the statement has been independently verified or applies to every supplied lot |
ISO defines certification as written assurance from an independent body that a product, service, or system meets specified requirements. ISO also explains that certification bodies, not ISO itself, perform certification or issue certificates. [1]
That distinction matters. An ISO 9001 certificate may be relevant evidence about a supplier’s quality-management system. It is not an ISO-issued approval of your product, and it does not replace product-specific testing, documentation, or market checks.
Start with the claim you need to prove
Before reviewing any attachment, write one sentence that describes the claim.
For example:
- “This children’s product complies with the applicable requirements for sale in [market].”
- “This electrical product uses a component that meets the stated safety standard.”
- “This factory operates a quality-management system within the stated production scope.”
- “This material in the supplied product meets the required restricted-substance limit.”
Then write the product identification beside it: model, version, material, size, color, component, country of origin where relevant, and intended sales market.
This step sounds basic. It prevents a frequent mistake: accepting a document because it contains a familiar standard number while missing that the named product is not the one you plan to buy.
Check the entity, scope, and dates on the document
Read the document line by line. Do not only check the logo and certificate number.
For a supplier or factory certificate, compare the legal company name and address with the supplier entity record, contract seller, invoice issuer, and production site. A certificate may name a parent company, a different facility, a trading company, or an old legal entity. That does not make it useless. It means you need to understand the relationship and scope.
For product evidence, compare the following details with the product you are buying:
- Product name, model, SKU, drawing, or family description;
- Material, component, configuration, size, finish, or rating where relevant;
- Named manufacturer and production site, if shown;
- Standard, regulation, method, or scheme referenced;
- Date of issue, expiry, test date, surveillance date, or revision date;
- Report, certificate, approval, or declaration number;
- Any limitations, exclusions, conditions, or annexes.
A PDF can be genuine and still be too narrow for your product. A test report for one material color may not establish the same result for a different material or finish. A factory certificate can be real while covering a different location or activity. Treat mismatches as a request for clarification, not an accusation.
Verify the issuer through an independent route
Do not rely on a website address, QR code, or contact details printed only on the supplied PDF. Find the issuing organization independently and use its official registry, certificate-check function, or known contact route where available.
For accredited management-system certificates, ISO points users to IAF CertSearch and to relevant certification or accreditation bodies as ways to confirm certification and accreditation status. [1] IAF CertSearch describes itself as a global database for accredited certificates and other standard certificates. [2]
Your verification note should capture:
| Check | What to record |
|---|---|
| Issuer identity | Full name, website found independently, and the scheme or service it provides |
| Registry result | Certificate or report number searched, date searched, and the result shown |
| Organization match | Whether the registry record names the same legal entity and facility |
| Scope match | Whether the stated activity, standard, product category, or assessment scope fits the claim |
| Status and dates | Valid, expired, suspended, unavailable, or needs direct confirmation |
| Evidence gap | What the registry cannot confirm about the product or order |
Not every valid scheme has a public registry. A missing search result is not proof that a document is false. It is a reason to contact the named issuer through independently found details and ask whether it can confirm the document’s status and scope.
Do not confuse a company certificate with product compliance
This is one of the most common document mistakes in sourcing.
A management-system certificate can tell you that a company’s system was assessed against a named standard and scope. It does not establish that a particular product meets every requirement in a target market. Likewise, a report about one product sample does not automatically show that a supplier’s entire factory or product range is approved.
Match the evidence level to the claim:
| If your claim is about… | Look for evidence connected to… |
|---|---|
| The supplier’s management system | The correct legal entity, facility, management standard, scope, issuer, and certificate status |
| A product’s test result | The exact product/sample, test method, laboratory, report number, test date, and result scope |
| A market conformity statement | The applicable market requirement, responsible party, identified product, supporting documentation, and current status |
| A material or component | The exact material/component, supplier, lot or traceability information where needed, method, and intended use |
When a supplier sends a document that is relevant but incomplete, do not throw it away. Log what it supports and request the missing connection. You may need a current product specification, a lab report, a declaration, a certificate annex, a factory relationship explanation, or a written confirmation from the issuer.
Use country-specific conformity documents carefully
Different markets use different conformity systems. A familiar document title does not carry the same meaning everywhere.
For example, the U.S. Consumer Product Safety Commission states that manufacturers or importers of general-use products subject to applicable consumer product safety rules must issue a General Certificate of Conformity (GCC) based on testing of each product or a reasonable testing program. For overseas-made products, the GCC is issued by the importer. [3] That is a U.S.-specific example. It is not a universal certificate format for every product or market.
The European Commission makes a related but different point about CE marking. There is no central EU body that gives a general CE permission or certificate. The manufacturer must identify applicable requirements, use the required conformity-assessment procedure, gather supporting technical evidence, and draw up an EU Declaration of Conformity. [4]
For certain EU products, legislation requires assessment by a notified body. When that applies, the European Commission says to check the body’s authorization for the specific conformity-assessment procedure in the NANDO database. [4] A notified body’s name or four-digit number does not answer every question unless its listed scope matches the product and applicable law.
The lesson is not “CE documents are unreliable” or “a GCC is enough.” The lesson is to identify the regime first, then verify the document type and evidence that regime requires for your product.
Read the scope before you read the logo
Logos, seals, stamps, and branded templates can distract from the details that decide whether a document is useful.
Check the scope language. A certificate may cover “manufacture of plastic consumer goods,” while your risk is a specific product safety requirement. A report may cover a model family but exclude a component used in your version. A declaration may be dated before a design, material, supplier, or factory change.
Ask these questions:
- Which exact product or facility does this document name?
- Which standard, regulation, test method, or scheme does it reference?
- Does that requirement apply to my target market and product category?
- Are all relevant versions, components, materials, and variants included?
- Is the document still current, and what event would require it to be updated?
- Who issued or signed it, and what authority did that party have?
- What supporting test data, technical file, annex, or traceability record sits behind it?
For ongoing production, track changes that could make old evidence less relevant. The CPSC notes, in its U.S. context, that material changes to product design, manufacturing process, or component source can affect compliance and may require retesting or an updated GCC. [3] Use that as a reminder to ask a broader question: what has changed since this document was issued?
Check laboratories and notified bodies against the task they performed
A laboratory or conformity body may be legitimate and still not be the right body for the test or assessment you need.
For a test report, identify the laboratory, report number, sample description, method, date, and page count. Then use the laboratory’s independently found contact or registry where available to ask whether the report is authentic and whether the named sample matches the claimed product. Ask what the report does not cover.
For a third-party assessment, check whether the issuing body was authorized for the relevant product category and procedure. The European Commission explains that notified-body lists include identification numbers and the tasks for which a body has been notified. [5] That is why a general claim that a body is “approved” is not enough for an EU product assessment.
Do not ask an issuer to give you a blanket legal opinion about your whole product launch. Ask a narrow, factual question: “Can you confirm the status, named entity, scope, and issue date of document number [number]?”
Build a certificate-validation record
Create a separate record for each material document. This avoids treating a folder of attachments as a single pass/fail result.
| Field | What to capture |
|---|---|
| Claim being evaluated | Exact product, requirement, and target market |
| Document type | Certificate, report, declaration, approval, supplier statement, or other |
| Named entity and site | Legal company and facility covered, if relevant |
| Product scope | Model, material, component, family, and limitations |
| Standard or requirement | Exact standard, regulation, method, or scheme named |
| Issuer/laboratory | Identity, registry/contact route, and stated authority |
| Dates and status | Issue, expiry, test, revision, surveillance, and verification date |
| Independent check | Registry search, direct confirmation, or not available |
| Open gap | What the document does not establish for the order |
| Next step | Clarify, obtain an annex/report, arrange testing, seek specialist review, or hold |
Link this record to your wider supplier verification checklist before your first order. A certificate review should sit alongside entity, factory, product, capacity, quality, and payment evidence—not replace it.
Watch for questions the supplier cannot answer
A supplier may have a legitimate document and still be unable to explain how it applies to your order. That is the gap you need to resolve.
Ask for a clear answer when:
- The legal entity or factory address on the document differs from the order file;
- The product model, material, or version is absent or does not match;
- The referenced standard is unclear or unrelated to the target market;
- A report is incomplete, undated, or missing annexes or signature pages;
- The issuing body cannot be identified through an independent route;
- The document has expired, is suspended, or needs a status check;
- The supplier relies on a logo or a generic claim instead of product-specific evidence;
- The product, process, material, component source, or factory has changed since the document was issued.
These are not shortcuts to declaring a document fake. They are reasons to hold the compliance claim open until the document, issuer, product, and requirement tell a consistent story.
The quotation guide, Red Flags in a Chinese Supplier Quotation, explains how to log unsupported certificate claims when they appear in an offer before you select a supplier.
The practical rule
A PDF is a starting point. It is not the conclusion.
Identify the exact claim. Name the document type. Match the entity, product, scope, dates, and market requirement. Verify the issuer through a route you found independently. Record what the document proves, what it does not prove, and what must happen before you rely on it.
That process will not make regulation simple. It will stop a familiar-looking attachment from doing more work than it deserves.
References
[2] IAF CertSearch
[3] U.S. Consumer Product Safety Commission, “General Use Products: Certification and Testing”