Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Certificate of Analysis (COA): Required Fields, How to Verify One, and When It Isn’t Enough

What a Certificate of Analysis (COA) is, the fields a usable one must include, how to verify it against the material it accompanies, and why a supplier COA alone is rarely sufficient under GMP/ISO rules.

Ask about Certificate of Analysis (COA): Required Fields, How to Verify One, and When It Isn’t Enough

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

A Certificate of Analysis (COA) is a document issued by a manufacturer or supplier’s quality control laboratory that reports the actual test results obtained for a specific batch or lot of a material, and confirms those results meet the material’s stated specification before that lot is released for use. It is a lot-specific quality record, not a generic product datasheet: a COA for lot 4471 of a reagent describes only lot 4471, and a new lot requires a new COA. For procurement and QA staff receiving reagents, raw materials, calibration standards, or active ingredients, the COA is the primary evidence a supplier provides that a given shipment actually is what it was ordered as.

This guide covers what a COA must contain to be usable, how to check one against the material it accompanies, and — the part most incoming-inspection SOPs get wrong — why a supplier’s COA, however complete, is rarely sufficient on its own in a GMP or accredited-testing environment.

What a COA Is For

A COA exists to transfer quality information from the party that tested a material to the party that will use it, without the receiving lab having to re-run every test itself. It typically accompanies chemicals, reagents, active pharmaceutical ingredients (APIs), reference standards, biological materials, and manufactured components at the point of shipment. The issuing lab — usually the manufacturer’s own QC unit, sometimes a contract or third-party testing lab — lists the specification for each tested parameter (an acceptable range, limit, or identity criterion) alongside the actual result obtained for that specific lot, and states whether the lot conforms.

A COA is evidence of testing performed at the point of manufacture or release. It is not, by itself, evidence that the material still meets specification when it arrives, that the container wasn’t compromised in transit, or that the lot number on the paperwork matches the lot number on the container in front of you — all of which is why receiving inspection exists as a separate step (see “When a Supplier COA Is Not Enough” below).

Required Fields on a Usable COA

There’s no single universal COA template — format varies by supplier, industry, and material type — but a COA that’s actually usable for incoming-material qualification needs to include, at minimum:

  • Manufacturer/supplier name and address — who tested and released the material.
  • Product name and catalog/part number — unambiguous identification of what was ordered.
  • Lot or batch number — the single most important field to cross-check; this is what ties the paper to the physical container.
  • Manufacture date and expiration or retest date — when the lot was produced and how long the stated results remain valid.
  • Each tested parameter, its specification, and the actual result — not just a pass/fail summary. A COA that states only “conforms to specification” without the underlying numeric or qualitative results for each parameter is materially weaker evidence than one that shows, for example, assay = 99.7% against a specification of 98.0–102.0%.
  • Test method reference — the compendial method (USP, EP, ASTM, ISO) or in-house method used for each result, so the receiving lab can judge whether the method is appropriate and comparable to its own.
  • Units for every quantitative result.
  • An overall conformance statement (e.g., “meets specification” / “released”).
  • Signature, name, and date of the authorized QC/QA reviewer who approved the lot for release — an unsigned or undated COA has no accountable approver behind it.

Chemical COAs commonly add a CAS number and purity/assay percentage; biological materials commonly add sterility, endotoxin, and identity (e.g., species/strain) results; calibration standards and reference materials commonly add traceability to a national metrology institute (e.g., NIST) and an assigned uncertainty value.

How to Read and Verify a COA

Verifying a COA is a specific, repeatable checklist step in incoming inspection, not a glance to confirm a document exists:

  1. Match the lot number. Confirm the lot/batch number on the COA is identical to the lot number printed on the physical container’s label. A COA for the right product but the wrong lot is not valid evidence for the material in hand — this is the single most common COA-verification failure found in supplier audits.
  2. Check results against your own specification, not just the supplier’s pass/fail statement. Your specification and the supplier’s may not be identical; a result that satisfies the supplier’s internal spec can still fall outside what your process requires. Read the actual numbers.
  3. Confirm the test method is appropriate. If your process depends on a specific compendial method (e.g., a USP identity test) and the COA reports results from a different method, that’s a gap worth flagging, not assuming away.
  4. Check the expiration/retest date against your intended use window. A COA reporting results that were valid at release doesn’t extend the material’s shelf life indefinitely.
  5. Confirm signature and approval. An authorized-signatory field left blank, or a photocopied/reused signature block, is a red flag worth escalating.
  6. Use the supplier’s verification portal where one exists. Many manufacturers now let customers look up a COA by lot number directly on the supplier’s website (via a QR code on the container or a lot-lookup tool) — cross-checking the document you received against the supplier’s own system is a stronger control than trusting a PDF alone, since it catches altered or mismatched paperwork.

When a Supplier COA Is Not Enough

Relying on a supplier’s COA without any independent verification is a recurring finding in FDA inspections and ISO/IEC 17025 and ISO 9001 audits (see GxP Compliance: What GLP, GCP, GMP, and GDP Actually Require for the broader framework), and for GMP-regulated manufacturers it isn’t optional to skip. Under 21 CFR Part 211 (current Good Manufacturing Practice for finished pharmaceuticals), Subpart E governs testing and approval of components — 21 CFR 211.84 specifically addresses supplier certificates of analysis, and the general expectation regulators apply is that a manufacturer cannot simply file an incoming COA and release the component on that basis alone. At minimum, the receiving firm is expected to perform at least one confirmatory identity test on each lot of a component, and may only reduce further testing and rely more heavily on a supplier’s COA where it has established, and periodically re-validates, the reliability of that supplier’s testing through documented supplier qualification (e.g., periodic on-site or remote audits, historical conformance data, and comparative testing; see Nonconformity: ISO Definition, Major vs. Minor, and the NCR/NCAR Process for how a failed verification should be handled).

ISO 9001:2015 builds in the same principle from the buyer’s side under its requirements for control of externally provided processes, products and services (clause 8.4): an organization has to define and apply criteria for verifying that purchased material meets requirements before use, and a COA is one input to that verification, not a substitute for it. ISO/IEC 17025-accredited testing laboratories face an equivalent expectation for any reference materials, reagents, or calibration standards they bring in and rely on for accredited test results — the same accreditation logic that underpins proficiency testing and external quality assessment — the accreditation body expects to see the lab’s own verification activity, not just a filed supplier certificate.

In practice, “not enough on its own” usually means one or more of the following, calibrated to the material’s risk and criticality: an identity confirmation test performed in-house, a documented supplier-qualification program that periodically audits or re-verifies the supplier’s own testing reliability, comparative or trend analysis of COA results across multiple lots from the same supplier, and a physical/visual inspection of the container and label against the COA on every receipt regardless of testing decisions.

Certificate of Analysis vs. Related Documents

COAs are frequently confused with, or bundled alongside, several adjacent documents that serve different purposes:

  • Certificate of Conformance (CoC) — a shorter statement that a lot meets its specification, typically without reporting the underlying test results. A CoC tells you the supplier says it passed; a COA shows you the numbers behind that claim. Where both are available, the COA is the stronger record for incoming inspection.
  • Safety Data Sheet (SDS) — covers hazard, handling, and safety information for a chemical product generally; it is not lot-specific and does not report quality test results.
  • Certificate of Origin — a customs/trade document confirming where a product was manufactured, used for import/export and tariff purposes, unrelated to quality testing.

COA Recordkeeping

Because a COA is the documented evidence behind a lot-release decision, it becomes part of the batch or lot record and is subject to the same retention and data-integrity expectations as other quality records under a GMP or ISO-based quality management system — attributable, legible, contemporaneous, original, and accurate (the ALCOA+ data-integrity principles commonly applied by regulators and auditors). Retention periods should follow the organization’s document-control procedure and any applicable regulatory minimum (for GMP-regulated components, retention is generally tied to the shelf life of the drug product the component was used in, plus a defined additional period) rather than a single fixed default.

Frequently Asked Questions

Is a Certificate of Analysis legally required?

Requirements depend on the material and the regulatory framework governing its use. GMP-regulated pharmaceutical components fall under 21 CFR 211.84’s testing-and-approval requirements in the U.S.; many other materials (general lab reagents, non-regulated chemicals) have no independent legal mandate for a COA, but most reputable suppliers issue one as standard practice, and most quality management systems (ISO 9001, ISO/IEC 17025, ISO 13485) require some form of documented incoming verification for which a COA is common supporting evidence.

What’s the difference between a COA and a Certificate of Conformance (CoC)?

A COA reports the actual test results obtained for a specific parameter against its specification. A CoC is a shorter statement that a lot conforms, generally without the underlying data. A COA is the more informative document for verification purposes.

Does a COA guarantee the material is sterile or safe to use?

Only for whatever parameters it actually reports on. A COA that doesn’t include a sterility or endotoxin result says nothing about sterility, regardless of how complete the rest of the document looks — always check which specific tests were run, not just that testing happened.

Can a COA be trusted without any further verification?

Not in a GMP, ISO/IEC 17025, or ISO 9001 context. Regulators and accreditation bodies expect documented, risk-based verification beyond simply filing the supplier’s paperwork — see “When a Supplier COA Is Not Enough” above.

How long should a COA be retained?

Follow your organization’s document-control procedure and any applicable regulatory minimum retention period; for GMP-regulated components this is typically tied to the shelf life of the finished product the component went into, plus an additional defined period, not a single universal number.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →