procurea.Book a call
Supplier Intelligence

ISO 9001 vs IATF 16949 vs FDA: The Supplier Certifications Guide for B2B Buyers

What each certification actually guarantees (and does not), how to verify claims against issuer registries, the red flags, and an industry-by-industry cheat sheet for mandatory vs nice-to-have.

4656
Pages read
472
Shortlisted
1053
Rejected with a reason
300
With an email

ALL 8 PUBLISHED CAMPAIGNS, SUMMED. THE FAILED ONES INCLUDED.

Why supplier certifications matter (and when they do not)

A certification does three practical things for a buyer. First, it is a liability shield, if a supplier delivers a defective product and you can prove you relied on their valid certification, your negligence exposure drops substantially. Second, it is a gate for customer contracts, if your customer's purchase terms require IATF 16949 in your supply chain, you cannot buy from a non-certified supplier regardless of how good they look otherwise. Third, it is a weak signal of operational maturity, the supplier has at least built the documentation and process discipline to pass an audit.

What certifications do not do: guarantee quality, guarantee the company is solvent, or guarantee the cert is still valid by the time you read the PDF. A certificate is a snapshot of a point in time when an auditor visited. Fourteen months later, the quality system may have decayed, the certifying body may have been de-accredited, or the company may have let the certification lapse while keeping the old PDF in their sales deck.

The practical rule: certifications are necessary but not sufficient. A certified supplier is in the game; an uncertified one is usually out for regulated categories. But the real diligence is verifying that the cert is current, issued by an accredited body, and has not been withdrawn, and that your specific quality expectations are met by the supplier's actual operations, which no certificate can guarantee.

When certifications are theater: a long list of certificates on a supplier website with no verifiable numbers, no expiration dates, and no issuing-body links. Treat that the way you would treat a résumé claiming a PhD without naming the university. The absence of verifiable specifics is the red flag.

Five certifications that matter most for B2B buyers in 2026.
One query, five of twenty six
🇨🇳CHINESE二甲双胍原料药 GMP 生产商
🇩🇪GERMANMetformin Wirkstoff Hersteller GMP
🇯🇵JAPANESEメトホルミン 原薬 GMP 製造
🇸🇪SWEDISHmetformin API tillverkare GMP
🇮🇹ITALIANmetformina API produttore GMP
FIG. 01 · THE SAME BRIEF, DISPATCHED IN ITS MARKETS' OWN LANGUAGES

ISO 9001, the quality management baseline

ISO 9001 is the global quality management system standard, covering process documentation, quality-objective setting, corrective action, and continual improvement. It is not industry-specific, it applies equally to a plastics factory, a software company, and a marketing agency. Roughly 1 million companies hold it globally.

What ISO 9001 actually requires. A documented quality management system, defined roles and responsibilities, customer-focused processes, risk-based thinking in planning, measurable objectives, internal audits, management review, and corrective action for nonconformities. The 2015 revision added the "risk-based thinking" element and moved away from mandatory procedure documents toward documented information.

What ISO 9001 does not require. Any specific level of quality performance. A supplier with 5% defect rate can hold ISO 9001 if their defect rate is measured, analyzed, and addressed in the management system. The standard is about having the system, not about the absolute quality output. This is why ISO 9001 alone is a weak quality signal, it confirms the supplier has a quality system, not that the system produces low defect rates.

Common weaknesses in certified suppliers. The certification is held by the corporate entity but not uniformly applied across sites (the audit was done at one site, others never got the process). Documentation exists but is not followed in practice (certification-day vs operations-day behavior). The certifying body is not accredited by a recognized accreditation body (IAF signatories), this means the certificate looks official but is not. The last audit found major nonconformities that were documented as closed without real evidence.

How to verify. Ask the supplier for three data points: certificate number, issuing body name, expiration date. Look up the certificate number at IAF CertSearch or the issuing body's own register. A certificate from a body not listed in IAF is a red flag, some certifying bodies operate without IAF accreditation, and their certificates carry little weight with sophisticated buyers or regulators.

Bottom line. ISO 9001 is the minimum expected for any export-active manufacturer in 2026. Its absence is a significant negative signal. Its presence is a small positive signal that must be combined with other verification.

A missing certificate never drops a good maker. It lowers a score, and the score is a number you can argue with.

IATF 16949, ISO 13485, FDA, regulated-industry certifications

Three certifications where the stakes and specificity are higher than ISO 9001, and where getting verification right matters commercially.

IATF 16949, automotive supply chain. Builds on ISO 9001 with automotive-specific requirements: advanced product quality planning (APQP), production part approval process (PPAP), failure mode and effects analysis (FMEA), statistical process control. Mandatory for Tier 1 suppliers to most global automakers, cascaded to Tier 2 for critical components. Verification: IATF publishes a searchable database at iatfglobaloversight.org. Red flag: a supplier claiming IATF 16949 whose number is not in the database, this happens more than buyers expect, sometimes because the cert was withdrawn, sometimes because it was never issued. Critical audit trail: the IATF process requires surveillance audits every 12 months; ask for the date of the most recent surveillance audit, not just the original certificate date.

ISO 13485, medical devices. Quality management specific to medical devices and in vitro diagnostics. Required for CE marking of medical devices under EU MDR (2017/745) and for US FDA device registration. It differs from ISO 9001 in risk-management emphasis, traceability requirements, and post-market surveillance. Verification: ISO 13485 is not in IAF CertSearch for all countries; check the specific certifying body's register. For EU MDR compliance, cross-reference the notified body number (four-digit code like 0123) on the supplier's CE documentation, notified bodies are listed publicly in the EU NANDO database.

FDA registration: US imports. Not a certification in the ISO sense, but a mandatory registration for facilities manufacturing food, drugs, medical devices, or cosmetics for the US market. FDA registration is not a quality endorsement, a registered facility has not been evaluated for quality, only listed. The distinction matters: "FDA-registered" means "allowed to export to the US"; "FDA-approved" (for drugs and medical devices) means "evaluated and cleared." Many suppliers blur the two in marketing. Verification: FDA's facility registration lookup is at accessdata.fda.gov for drugs, and via 510(k) or PMA databases for medical devices. Do the lookup, do not trust a supplier's claim at face value.

Additional industry-specific certs worth knowing. AS9100 (aerospace, builds on ISO 9001), TL 9000 (telecom), ISO 22000 / FSSC 22000 / BRC (food safety), ISO 27001 (information security, relevant for IT suppliers and any supplier processing personal data), ISO 14001 (environmental management, increasingly referenced in CSDDD questionnaires), SA 8000 (social accountability).

CE marking and HACCP, EU product conformity and food safety

CE marking. A mandatory conformity marking for products sold in the European Economic Area across 30+ product directives (machinery, toys, medical devices, radio equipment, PPE, etc.). For most product categories, CE marking is based on supplier self-declaration, the manufacturer asserts compliance and takes liability. For higher-risk categories (medical devices Class IIb and III, certain machinery, pressure equipment), CE marking requires a notified body's assessment and appears on the product with a four-digit notified-body number.

What CE does and does not guarantee. CE guarantees that the manufacturer has declared conformity with applicable directives and has a technical file supporting that declaration. It does not guarantee quality, durability, or truthfulness of the declaration, the self-declaration pathway is heavily abused by imports from outside the EU. A buyer finding a CE mark on a Chinese-origin product should request the EU Declaration of Conformity document, the manufacturer's technical file summary, and (for notified-body categories) the notified body certificate. If the supplier cannot produce these, the CE mark is suspicious.

Common CE fraud patterns. The "China Export" mark, which resembles CE but uses different letter spacing (a confusion that EU enforcement has repeatedly warned about). Self-declared CE on products that actually require notified-body assessment. Expired notified-body certificates used after the notified body withdrew accreditation.

HACCP, food safety. Hazard Analysis and Critical Control Points. A methodology rather than a certification in the ISO sense; many countries and retailers require HACCP-based systems, and multiple schemes (FSSC 22000, BRC, IFS) certify HACCP-based food safety systems. For EU food imports, HACCP is mandatory. For global retailers' private-label supply, BRC or FSSC 22000 certification is usually required.

Verification approach for CE and HACCP. For CE: ask for the Declaration of Conformity and (for notified-body categories) the notified body certificate number. Cross-reference the notified body number in the EU NANDO database. For HACCP/FSSC/BRC: ask for certificate number and certifying body, verify against the scheme's own public register (FSSC 22000 and BRC both maintain searchable registers). The principle is identical across all certifications: if the supplier cannot produce a verifiable number from an accredited issuer, treat the claim as unverified.

How to verify a certificate is genuine (in 90 seconds)

A four-step routine that works for any ISO-family certification:

Step 1: Get the three data points. Ask the supplier for the certificate number, the full name of the certifying body (not just "certified by Bureau Veritas", the full legal entity), and the expiration date. A supplier who cannot provide all three has either lost track or is bluffing.

Step 2: Look up the certifying body in the IAF database. IAF CertSearch lists accredited certifying bodies. If the named body is not in the list, the certificate is not IAF-accredited and carries limited weight. This is the fastest filter, most fake certifications come from non-accredited bodies.

Step 3: Search the certifying body's own register. Every IAF-accredited body maintains a public register of its active certificates. Enter the certificate number; the record should show the company name (match to supplier), certification scope (match to what the supplier claimed), and current status (active or withdrawn). A "withdrawn" result is conclusive: the supplier is not certified even if they still have the old PDF.

Step 4: Check expiration and surveillance date. An active certificate is typically valid for 3 years with annual surveillance audits. The certificate is valid until the expiration date, but only if surveillance audits happened on schedule. Ask for the date of the most recent surveillance. If a supplier's ISO 9001 is valid until 2027 but their last surveillance was 18 months ago, the certificate is technically in violation and could be withdrawn by the certifying body.

Total time with practice: 90 seconds per certification. For a shortlist of 5 strategic suppliers with 3 certifications each, that is under 25 minutes. Reject the ones with gaps.

For non-ISO certifications (FDA, CE notified body, IATF, HACCP schemes), the sources are different but the logic is identical: find the official register, look up the number, confirm the status is current, match the identity to the supplier.

  1. Get the three data points

    Ask the supplier for the certificate number, the full legal name of the certifying body, and the expiration date. A supplier who cannot provide all three has either lost track or is bluffing.

  2. Check the issuer in IAF CertSearch

    iafcertsearch.org lists every accredited certifying body. If the named body is not on the list, the cert is not IAF-accredited and carries limited weight, the fastest fake-filter available.

  3. Match name and scope in the issuer register

    Every IAF-accredited body maintains a public register. Enter the number; the record must show the supplier's legal name, the claimed scope, and an active status. "Withdrawn" is conclusive, the supplier is not certified even if the PDF still exists.

  4. Confirm expiration and last surveillance audit

    ISO certificates are 3-year cycles with annual surveillance. Ask for the date of the most recent surveillance audit. A certificate valid to 2027 but with surveillance 18 months stale is technically in violation.

By-industry cheat sheet, mandatory vs recommended

Compressing the certification landscape to a practical table per industry. "Mandatory" means your customer contracts or regulatory regime typically require it; "Strongly recommended" means most serious buyers will reject suppliers lacking it even without a contractual requirement; "Nice-to-have" means it is a tiebreaker rather than a gate.

Automotive (Tier 1 and Tier 2). Mandatory: IATF 16949. Strongly recommended: ISO 14001, ISO 45001 (OH&S). Nice-to-have: ISO 50001 (energy management, increasingly for OEM ESG reporting).

Medical devices. Mandatory: ISO 13485, CE marking (EU market, notified-body assessed for Class IIb/III), FDA registration + 510(k) or PMA (US market, product-dependent). Strongly recommended: ISO 14971 (risk management), MDSAP where relevant.

Food and beverage. Mandatory: HACCP-based system. Strongly recommended: FSSC 22000 or BRC (for EU and UK retail), SQF (for US retail). Nice-to-have: organic certification per regional scheme (USDA Organic, EU organic, JAS).

Electronics and IT hardware. Mandatory: CE (EU), FCC (US). Strongly recommended: ISO 9001, RoHS compliance documentation, REACH compliance. Nice-to-have: ISO 27001 for data-handling suppliers, EPEAT registration for IT hardware sold to government buyers.

Textiles and apparel. Strongly recommended: OEKO-TEX Standard 100 (chemical safety), BSCI or SA 8000 (social compliance). Common for specific product lines: GOTS (organic textiles), bluesign (environmental). Nice-to-have: ISO 9001 (less universal in textiles than other industries).

Chemicals. Mandatory: REACH registration (EU market). Strongly recommended: ISO 9001, ISO 14001, Responsible Care certification for chemical manufacturers. Nice-to-have: ISCC PLUS for sustainable sourcing claims.

Packaging. Strongly recommended: ISO 9001, BRC Global Standard for Packaging (for food-contact packaging). Nice-to-have: FSC/PEFC (forestry for paper/cardboard), ISCC PLUS (recycled plastics).

Construction materials. Mandatory: CE marking for construction products (Regulation EU 305/2011). Strongly recommended: ISO 9001, ISO 14001. Nice-to-have: EPD (Environmental Product Declarations) for ESG-aware commercial buyers.

Use the cheat sheet to set your RFQ certification requirements. Every mandatory cert goes in as a hard-fail gate. Strongly recommended goes in as a scoring criterion with higher weight. Nice-to-have is a small weight or a tiebreaker. Skip certifications not relevant to your category, long lists dilute the signal.

IndustryMust-haveNice-to-haveCommon red flag
Medical devicesISO 13485 + CE (EU) or FDA 510(k)/PMA (US)ISO 14971, MDSAPSelf-declared CE on a Class IIb/III device (requires notified body)
Food & beverageHACCP-based systemFSSC 22000 / BRC / SQF, organic schemeHACCP plan claimed but no certifying-body audit on file
Automotive (Tier 1/2)IATF 16949ISO 14001, ISO 45001, ISO 50001IATF number not found on iatfglobaloversight.org
General manufacturingISO 9001 (IAF-accredited issuer)ISO 14001, ISO 45001, ISO 27001Certifying body missing from the IAF signatory database
Industry-by-industry cheat sheet for mandatory vs nice-to-have certifications and common fraud patterns.
Read the campaigns behind these numbers
All 8 campaigns, published unedited.

472 suppliers across 8 briefs, 1053 rejections still on the record with the reason each one was given.

Questions buyers ask about this

What is the difference between ISO 9001 and IATF 16949?
ISO 9001 is a general quality management system standard applicable to any industry. IATF 16949 builds on ISO 9001 with automotive-specific requirements: APQP, PPAP, FMEA, statistical process control, and tighter customer-specific requirements cascaded from OEMs. All IATF 16949 certified suppliers are also ISO 9001 compliant; the reverse is not true. For automotive Tier 1 and most Tier 2 work, IATF 16949 is mandatory: ISO 9001 alone will not clear customer audits.
Do I need an FDA-registered supplier?
Only if you are selling food, drugs, medical devices, or cosmetics into the US market. FDA registration is a facility listing, not a quality endorsement, a registered facility is allowed to export to the US but has not been evaluated. For drugs and medical devices, you usually need both FDA registration and product-specific clearance (510(k) or PMA). For categories not sold in the US, FDA registration is irrelevant.
What does CE marking actually guarantee?
CE guarantees the manufacturer has declared conformity with applicable EU directives and maintains a technical file supporting the declaration. For lower-risk categories this is self-declaration, the manufacturer takes liability with no third-party check. For higher-risk categories (medical devices class IIb/III, certain machinery) a notified body assesses and issues a certificate. CE does not guarantee quality or durability. Always ask for the Declaration of Conformity and, where applicable, the notified body certificate number.
How do I verify a supplier's ISO certificate is real?
Four steps under 90 seconds each. (1) Ask for the certificate number, certifying body name, and expiration date. (2) Check the certifying body is IAF-accredited at iafcertsearch.org. (3) Look up the certificate number on the certifying body's own register. (4) Confirm the status is active and the most recent surveillance audit was within 12 months. A certificate from a non-IAF body or one missing from the issuer's register is a red flag.
Which certifications are mandatory by industry?
Depends on category and target market. Automotive Tier 1/2: IATF 16949. Medical devices for EU: ISO 13485 + CE marking. Medical devices for US: FDA registration + 510(k) or PMA. Food for EU retail: HACCP + usually FSSC 22000 or BRC. Construction products in EU: CE marking under EU 305/2011. Electronics in EU: CE + RoHS. Chemicals in EU: REACH. The "mandatory vs recommended" distinction matters, treat mandatory as hard-fail gates, recommended as weighted scoring.