CoA vs CoC: What QA and Lab Professionals Need to Know

A Certificate of Analysis (CoA) delivers batch-specific, measured test results. A Certificate of Compliance or Conformance (CoC) is a supplier’s declaration that a product meets stated requirements, with no raw data attached. For QA and procurement decisions, the distinction is straightforward: request a CoA whenever analytical proof matters; accept a CoC only for low-risk parts or when your purchase order explicitly permits it.

Immediate action steps for incoming shipments:

  • Request a lot-numbered CoA for any regulated, safety-critical, or research-grade material before releasing it to production or use.
  • Accept a CoC in place of a CoA only after formal supplier qualification and only when your risk assessment supports it.
  • Verify that any CoC references underlying test reports or third-party lab data — a bare declaration with no supporting evidence carries limited audit weight.
  • Flag missing lot numbers or absent QA signatures immediately; do not release the shipment pending resolution.
  • Include explicit documentation requirements (required fields, acceptable accreditations, retention periods) in every purchase order.

Table of Contents

What is a Certificate of Analysis?

A CoA is a signed, batch- or lot-specific report of measured analytical results. It ties quantitative data — purity percentages, contaminant levels, identity confirmation — to a specific production lot through named analytical methods such as HPLC, GC, or mass spectrometry. The European Medicines Agency treats CoAs as standard documentation for regulated fields including pharmaceuticals, chemicals, and biotech, precisely because they provide verifiable, method-linked evidence rather than a supplier’s word.

Who issues a CoA depends on the supply chain. The manufacturer’s own QA laboratory may generate it, or an independent accredited testing laboratory operating under ISO/IEC 17025 may produce it. Third-party issuance carries more audit weight because it removes the conflict of interest inherent in self-certification.

Typical fields on a well-formed CoA:

  • Lot or batch number tied directly to production records
  • Product name, CAS number, or catalog ID
  • Analytical methods (e.g., HPLC with column parameters, GC conditions, MS ionization mode)
  • Measured values with units (e.g., 99.2% purity by HPLC area normalization)
  • Acceptance criteria for each parameter tested
  • Contaminant results (heavy metals, residual solvents, microbial limits where applicable)
  • Limits of detection for critical contaminants
  • Analyst signature and QA approver sign-off
  • Date of testing and expiry or retest date
  • Lab name, accreditation statement, and accreditation ID
CoA Field Why It Matters
Lot/batch number Enables traceability, recall scoping, and audit linkage
Analytical method reference Allows independent verification and reproducibility
Measured value + acceptance criteria Proves the specific lot passed, not just that the product type can pass
Analyst and QA signatures Establishes accountability and document authenticity
Lab accreditation (ISO/IEC 17025) Confirms technical competence for the specific tests reported
Expiry or retest date Defines the window of guaranteed specification compliance

Batch linkage is what separates a CoA from a generic product specification sheet. Because the results are tied to a specific lot, a CoA enables targeted recalls, supports audit trails, and gives downstream users the data they need to reproduce experimental conditions or defend a quality decision.


What is a Certificate of Compliance or Conformance?

A CoC is a declaration. The manufacturer, authorized representative, or notified body states that a product, lot, or shipment meets named regulatory standards or contractual requirements. Critically, the underlying test data is usually absent from the document itself. As SeqOps notes, CoCs are common in customs and market-access workflows where an administrative declaration satisfies the filing requirement, even when the technical receiving inspection would demand more.

Typical fields on a CoC:

  • Product or part identification (part number, description, revision level)
  • Referenced standards or specifications (RoHS, REACH, ASTM, purchase order number)
  • Manufacturer name, address, and authorized signature
  • Date of issue and shipment or lot reference
  • Any cited supporting documents (test reports, third-party lab references)

Where CoCs are commonly accepted:

  • Low-risk hardware and non-critical mechanical components after supplier qualification
  • Customs and import filings where a conformity declaration meets the administrative rule
  • Electrical component compliance statements (RoHS, REACH) for non-safety-critical assemblies
  • Government contracting scenarios where the contracting office has explicitly authorized CoC use

The limitation is clear: a CoC tells you the supplier believes the product conforms. It does not show you the numbers. For any application where purity, potency, or contaminant levels affect safety or research validity, a declaration alone is insufficient.


Hands holding Certificate of Compliance document

How do CoA and CoC compare across key QA dimensions?

The headline distinction is evidence versus assertion. A CoA shows numeric proof; a CoC asserts conformity. Every other practical difference follows from that.

Dimension Certificate of Analysis (CoA) Certificate of Compliance/Conformance (CoC)
Primary purpose Prove a specific lot meets specifications with measured data Declare that a product or shipment meets stated standards or requirements
Evidence included Raw test results, methods, measured values, acceptance criteria Declaration only; underlying data usually not included
Issuer Manufacturer QA lab or independent accredited lab (ISO/IEC 17025) Manufacturer, authorized representative, or notified body
Typical fields Lot number, HPLC/GC/MS methods, purity %, contaminants, signatures, dates Part ID, referenced standards, PO number, authorized signature
Regulatory/audit weight (U.S.) High — required by FDA cGMP, USP, and most regulated-industry auditors Moderate to low — accepted for customs, low-risk parts, and authorized government contracting
When to require Regulated materials, research-grade inputs, safety-critical components Non-critical hardware, customs filings, finished assemblies after supplier qualification

Infographic comparing Certificate of Analysis and Certificate of Compliance

Procurement best practice in high-reliability supply chains often calls for both documents: a CoA for raw materials or active ingredients, and a CoC for the finished assembly attesting to process and regulatory conformity. SeqOps describes this combined approach as standard for critical assemblies, and it reflects the complementary roles each document plays.

Decision rules for QA and procurement:

  • If the material affects product safety, efficacy, or research reproducibility → require a CoA.
  • If the shipment is a low-risk, non-critical part and the supplier is qualified → a CoC may suffice.
  • If the application is customs or import documentation → a CoC-type conformity declaration is typically the correct document.
  • If you are unsure → default to requiring a CoA; the cost of unnecessary testing is lower than the cost of a recall or audit finding.

What to look for on each document

Knowing what fields to check is as important as knowing which document to request. A document titled “Certificate of Analysis” that lacks lot numbers and method references is functionally no better than a CoC.

For a CoA, verify:

  • Lot or batch number present and matching the shipment packing list
  • Analytical methods named specifically (e.g., “RP-HPLC, C18 column, UV detection at 220 nm”) rather than generically (“HPLC”)
  • Numeric results with units for every tested parameter
  • Acceptance criteria listed alongside measured values so pass/fail is unambiguous
  • Analyst signature and a separate QA approver sign-off
  • Lab accreditation statement with accreditation ID (ISO/IEC 17025 or equivalent)
  • Date of testing and expiry or retest date
  • Traceability statement linking results to production batch records

For a CoC, verify:

  • Referenced standards are specific (e.g., “RoHS Directive 2011/65/EU” rather than “meets applicable standards”)
  • Purchase order or contract number ties the declaration to your specific order
  • Authorized signature from a named, titled individual
  • Any cited supporting documents (test reports, third-party lab certificates) are actually available on request

Red flags on either document:

  • Missing or generic lot number (“batch 001” across multiple unrelated products)
  • Method descriptions that name only the technique without parameters
  • No QA approver signature, only an analyst signature
  • Product ID on the document does not match the shipment label
  • Identical numerical results across multiple unrelated batches (a strong indicator of a copied document)
  • No accreditation statement on a document claiming third-party testing

Pro Tip: Ask for method SOP references and the limit of detection for any contaminant that is material to your application. A supplier who cannot provide these is likely relying on a generic template rather than actual batch testing.


How do U.S. regulators treat CoAs and CoCs?

The short answer: FDA-regulated products and USP-covered materials require CoAs. Customs filings and certain government contracts accept CoC-type declarations, but with conditions.

Under FDA’s current Good Manufacturing Practice (cGMP) regulations and the Q7A guidance for active pharmaceutical ingredients, manufacturers must verify that incoming materials meet specifications before use. That verification requires batch-level analytical evidence — a CoA from the supplier, confirmed by at least identity testing at the receiving site. A CoC alone does not satisfy this requirement because it provides no testable data.

The United States Pharmacopeia (USP) sets analytical standards for pharmaceutical ingredients and requires batch-level documentation that includes identity, assay, and impurity data. Research-grade materials intended for regulated downstream use should meet the same documentation standard, because a gap in the CoA chain creates an audit vulnerability.

For government contracting, FAR/DFARS rules permit CoC use only when the contracting office explicitly authorizes it. Authorization does not eliminate quality obligations. The government retains inspection and rejection rights post-delivery, so a CoC in a government contract is an administrative convenience, not a quality guarantee.

Key regulatory mapping:

  • Customs/trade — Conformity declarations and certificates of origin serve administrative import functions; they do not replace technical release documentation.

Regulatory note: This article provides general information about U.S. documentation practices and is not legal or regulatory advice. Confirm current requirements with FDA guidance documents, USP, or a qualified regulatory professional for your specific product category.


Why lab accreditation and standards like ISO/IEC 17025 matter

ISO/IEC 17025 is the international standard for the competence of testing and calibration laboratories. When a CoA lists an accredited lab as the issuer, it means that lab has demonstrated technical competence for the specific tests it performs — not just that it has a quality management system. Accreditation is granted by national bodies such as A2LA (American Association for Laboratory Accreditation) or NVLAP in the United States, and each accreditation carries a scope that lists the specific test methods covered.

EN 10204 provides a parallel framework for procurement contracts, particularly in metals and industrial materials. Its inspection certificate types map directly to the CoA/CoC spectrum: Type 2.1 is a declaration of compliance (analogous to a CoC), while Types 3.1 and 3.2 are inspection certificates with specific test results and, in the case of 3.2, third-party verification. Specifying an EN 10204 type in a purchase order is a precise way to define the level of documentary evidence required without ambiguity.

What to check for accreditation:

  • Lab name on the CoA matches the accredited entity exactly
  • Accreditation ID is listed on the document
  • Scope of accreditation covers the specific test methods used (e.g., HPLC for purity, ICP-MS for heavy metals)
  • Accreditation is current — verify expiry with the issuing body

Pro Tip: When audit risk is high, request the accreditation certificate PDF directly from the supplier and cross-check the accreditation ID against the national body’s public database (A2LA’s directory is searchable online). A mismatched or expired accreditation ID is a disqualifying finding.

For third-party testing of research-grade peptides and similar materials, ISO/IEC 17025 accreditation is the minimum standard that gives a CoA meaningful audit weight. In-house testing by the manufacturer can satisfy internal release requirements but carries less weight in external audits or regulatory inspections.

Lab team reviewing ISO/IEC 17025 accreditation certificate


CoC, CoO, CoT — clearing up the naming confusion

The acronym “CoC” alone is ambiguous. In different contexts it can mean Certificate of Compliance, Certificate of Conformance, or Certificate of Conformity — three phrases that describe essentially the same document type (a declaration against a standard or requirement). The title matters less than the contents.

Related documents QA teams encounter:

  • Certificate of Origin (CoO): A trade document declaring the country where a product was manufactured. It serves customs and tariff purposes and carries no technical quality information.
  • Certificate of Testing (CoT) or Test Report: A document reporting the results of specific tests, often without the full CoA structure (no acceptance criteria, no QA sign-off). A CoT can support a CoC by providing underlying data, but it is not a substitute for a full CoA.
  • Report of Analysis (RoA): Common in chemical and pharmaceutical supply chains; functionally equivalent to a CoA in most contexts, though the exact fields may vary by issuer.
  • Declaration of Conformity (DoC): The EU regulatory term for a manufacturer’s declaration that a product meets applicable directives (CE marking). Analogous to a CoC in function.

The practical rule: read the document, not the title. A document called a “Certificate of Compliance” that includes lot-specific HPLC data, acceptance criteria, and a QA signature functions as a CoA regardless of its label. Conversely, a document titled “Certificate of Analysis” that contains only a general statement of conformity is functionally a CoC. Focus on whether the document contains measured data tied to a specific lot.


How to verify a CoA or CoC from a supplier

Verification is a sequential process. Work through these steps on receipt of any quality document before releasing material to production or research use.

Step-by-step verification checklist:

  1. Confirm document identity: Check that the product name, catalog or part number, and lot/batch number on the document match the shipment label and packing list exactly.
  2. Check the date: Confirm the test date precedes the shipment date and that the material is within its stated expiry or retest window.
  3. Review the methods: For a CoA, verify that specific analytical methods are named (HPLC, GC, MS) with enough detail to assess appropriateness for the parameter tested. Generic method names without parameters are a red flag.
  4. Validate the lab: Confirm the issuing lab’s name, check for an ISO/IEC 17025 accreditation ID, and verify that accreditation against the national body’s public database.
  5. Cross-check traceability: Link the CoA lot number to your internal receiving record and the supplier’s batch/packing documentation. Any mismatch requires resolution before release.
  6. Assess completeness: Confirm that all parameters required by your specification or purchase order are tested and reported, with both measured values and acceptance criteria present.
  7. Request additional evidence when needed: If results look anomalous or methods are insufficiently described, request raw instrument printouts, chromatograms, or method SOPs from the supplier.

Pro Tip: Include a standard document request clause in every purchase order that lists required CoA fields, acceptable accreditations, and the retention period. This eliminates ambiguity and reduces the chance a supplier substitutes a CoC where a CoA is contractually required.

For a detailed walkthrough of reading peptide-specific CoAs, Neolabpeptides publishes a practical CoA reading guide that covers HPLC and MS result interpretation in a research-grade context.


When is a Certificate of Compliance sufficient?

A CoC is appropriate when the risk profile of the material and the regulatory context both support it. Accepting a CoC where a CoA is required is a compliance failure; requiring a CoA where a CoC is contractually and regulatorily sufficient wastes resources and delays shipments.

Scenarios where a CoC is generally appropriate:

  • Non-critical hardware (fasteners, brackets, standard electrical connectors) purchased from a qualified supplier with an established quality history
  • Customs and import filings where a conformity declaration satisfies the administrative requirement
  • Finished assemblies where raw material CoAs have already been captured at the component level and the CoC attests to process conformity
  • Government contracts where the contracting office has explicitly authorized CoC use under FAR/DFARS

Scenarios that require a CoA regardless:

  • Any material going into an FDA-regulated product (drug, device, food ingredient)
  • Research-grade chemicals and peptides where purity and identity affect experimental validity
  • Ingredients where potency, concentration, or contaminant levels are safety-relevant
  • Any material subject to USP monograph requirements

Example purchase order language to reduce substitution risk:

This language closes the substitution gap that arises when procurement and QA have different assumptions about what documentation is required.


Typical timelines and costs for obtaining a CoA

Testing timelines vary significantly by method complexity and lab type. Identity testing alone — a single HPLC or MS run — can turn around in one to three business days at most accredited labs. A full analytical panel covering purity, identity, residual solvents, heavy metals, and microbial limits typically requires five to fifteen business days, depending on sample prep requirements and lab workload.

Key cost and timeline drivers:

  • Number of analytes: Each additional parameter (residual solvent species, individual heavy metals) adds cost and may require a separate method.
  • Accredited third-party lab vs. in-house testing: Third-party accredited labs carry higher per-test costs but provide greater audit credibility; in-house testing is faster and cheaper but requires the manufacturer to demonstrate method validation.
  • Sample preparation complexity: Lyophilized peptides and complex matrices require dissolution and preparation steps that add time before instrument analysis begins.
  • Rush fees: Most accredited labs offer expedited turnaround at a premium, typically 25–50% above standard pricing, though exact figures vary by lab and test type.

Batch release timing directly affects production and shipping schedules. A CoA that arrives after a shipment has already left the warehouse creates a documentation gap that auditors will flag. Build CoA turnaround time into your procurement lead time, particularly for materials sourced from third-party accredited labs.

For labs evaluating in-house verification options alongside supplier CoAs, a peptide testing kit guide can help identify supplemental testing approaches that fit within typical research budgets.


How Neolabpeptides issues CoAs in a research-grade workflow

Neolabpeptides provides a concrete example of a supplier-side CoA workflow that QA teams can use as a reference when evaluating other vendors. Each peptide product — including BPC-157, IPAMORELIN, CJC-1295, TB500, and GLP-1 analogs — ships with a lot-linked CoA generated from HPLC and mass spectrometry analysis, with purity verified at 98% or above.

Fields included on a Neolabpeptides CoA:

  • Lot number tied to the specific production batch
  • Product name and catalog reference
  • Assay/purity percentage by HPLC (area normalization method)
  • Mass spectrometry confirmation of molecular identity
  • Analytical method references
  • Expiry or retest date
  • QA sign-off and date of testing

The workflow follows a straightforward sequence: synthesis and lyophilization of the peptide, submission of a representative sample to third-party analytical testing, receipt of instrument data, QA review against acceptance criteria, and CoA issuance before shipment. Researchers receive the CoA with their order, enabling them to confirm lot identity, verify purity against their experimental requirements, and retain the document for institutional audit records.

CoA Element Neolabpeptides Practice
Purity verification HPLC, ≥98% purity stated per lot
Identity confirmation Mass spectrometry (molecular weight match)
Lot traceability Unique lot number on each CoA and shipment
QA authorization Signed and dated before shipment
Retest/expiry date Included to define specification window

This documentation approach supports reproducibility across experiments: if a researcher needs to replicate a result, the lot number on the CoA links back to a specific batch with known analytical characteristics. For guidance on interpreting the specific fields on a peptide CoA, Neolabpeptides maintains a detailed reading guide covering HPLC chromatogram interpretation and MS data review.

All Neolabpeptides products are supplied for research purposes only and are not approved for human or veterinary use. Researchers working in regulated institutional environments should confirm documentation requirements with their institutional compliance office before use.


Key Takeaways

A CoA provides batch-specific, method-linked analytical evidence; a CoC is a declaration of conformity — require a CoA for any regulated, safety-critical, or research-grade material, and accept a CoC only when risk assessment and purchase order terms explicitly support it.

Point Details
CoA vs CoC core distinction A CoA contains measured test data; a CoC is a declaration with no raw results attached.
When to require a CoA Regulated inputs, FDA-covered materials, USP-governed substances, and research-grade chemicals always warrant a CoA.
Verify lab accreditation Confirm ISO/IEC 17025 accreditation ID against the national body’s database before releasing any CoA-backed material.
Protect against substitution Include explicit CoA field requirements and accreditation standards in every purchase order to prevent CoC substitution.
Neolabpeptides CoA practice Neolabpeptides ships each peptide lot with an HPLC- and MS-verified CoA at ≥98% purity, with lot traceability and QA sign-off.

Why data beats declarations in high-stakes QA

The conventional framing of CoA versus CoC as a simple “more rigorous vs. less rigorous” choice misses the more useful point: the two documents answer different questions. A CoC answers “did the supplier say this conforms?” A CoA answers “what did the measurements show for this specific lot?” Those are not equivalent questions, and conflating them is where quality failures originate.

The practical risk is not that CoCs are inherently dishonest. Most are accurate. The risk is that a declaration cannot be independently verified without the underlying data, and in a dispute, a recall, or an FDA inspection, “the supplier said it was fine” is not a defensible position. A CoA with a lot number, named methods, and a signed QA approval is a document you can defend.

Where CoCs make sense — low-risk hardware, customs filings, finished assemblies with upstream CoAs already in the file — the risk profile genuinely supports the lighter document. The mistake is allowing CoCs to creep into material categories where the risk profile does not support them, usually because procurement is under schedule pressure and the supplier offers a CoC as a faster alternative. Specifying documentation requirements in the purchase order, not after the shipment arrives, is the only reliable way to prevent that substitution.

For research-grade materials specifically, the reproducibility argument is as strong as the compliance argument. A researcher who cannot trace their experimental inputs to a specific lot with known purity cannot defend their results if they are questioned. The CoA is not just a compliance document; it is part of the scientific record.


Research-grade peptides with verified CoAs, shipped across the U.S.

Neolabpeptides supplies research-grade peptides with lot-linked CoAs produced from HPLC and mass spectrometry analysis — the same documentation standard this article describes as the baseline for audit-ready, reproducible research.

Neolabpeptides

Every order ships with a CoA that includes lot number, purity percentage, method references, and QA sign-off. For labs that need documentation they can actually use in an audit or institutional review, that specificity matters.

  • 98%+ purity verification by HPLC and mass spectrometry, reported per lot
  • Downloadable, lot-linked CoAs available with every shipment for record retention
  • Fast U.S. shipping with documentation ready at the time of dispatch

Browse the full catalog and review CoA documentation practices at Neo Lab Peptides, or go directly to a commonly requested product like BPC-157 10mg to see product-level CoA details before ordering.


Useful sources and references for QA and regulatory teams

These primary and authoritative sources are worth bookmarking for audit preparation, procurement template development, and regulatory compliance work.

  • FDA Q7A Guidance — Good Manufacturing Practice for Active Pharmaceutical Ingredients: The primary U.S. regulatory reference for CoA requirements in pharmaceutical manufacturing. Cite this in supplier qualification procedures and audit responses.
  • United States Pharmacopeia (USP): Sets analytical standards and documentation expectations for pharmaceutical-grade materials. Reference USP monographs when specifying CoA acceptance criteria in purchase orders.
  • European Medicines Agency (EMA): Authoritative source for CoA standards in pharmaceutical and biotech supply chains; EMA guidance is widely referenced in U.S. regulated-industry audits.
  • Contract Laboratory — Certificate of Analysis Guide: Practical industry reference covering CoA fields, pharmaceutical and food applications, and when CoCs may be acceptable for lower-risk goods.
  • SeqOps — CoA vs CoC Comparison: Useful for procurement teams; covers customs/import distinctions and the combined CoA + CoC approach for critical assemblies.
  • LegalClarity — CoC vs CoA and EN 10204: Explains EN 10204 inspection certificate types and how to specify documentary evidence levels in procurement contracts.
  • Artemus Group — CoC vs CoA in Government Contracting: Covers FAR/DFARS rules for CoC authorization and government inspection rights.
  • Neolabpeptides — How to Read a Peptide CoA: Practical guide for interpreting HPLC and MS data on research-grade peptide CoAs; useful for lab teams new to reading supplier documentation.

When citing these sources in audit responses or procurement templates, reference the specific guidance document or standard by name and include the access date, since regulatory guidance documents are periodically updated.


Example blog post
Example blog post
Example blog post