V5 Ultimate
Ultimate
PricingResourcesCompany
Start free trial
HomeGlossaryCoC
Quality · The complete guide

CoCCertificate of Conformance

In short

A Certificate of Conformance is the lighter-touch cousin of a CoA — a vendor's signed statement that the supplied product meets the agreed specification, without per-attribute test data. This page explains when a CoC is acceptable and when a CoA is required, the data a usable CoC must contain, how the rules differ across pharma (21 CFR 211.84), supplements (21 CFR 111.75), medical devices (21 CFR 820.50) and ISO 9001 §8.4, the supplier qualification framework that any CoC programme rests on, the common ways CoC processes fail receiving inspections, what auditors actually look for, and how V5 Ultimate captures CoCs against the lot at goods-in so a missing or unsigned document blocks lot release automatically.

3,600 words · ~17 min read
On this page
  1. 01What a CoC is
  2. 02CoA vs CoC
  3. 03What a usable CoC contains
  4. 04When a CoC is not enough — by regulation
  5. 05Supplier qualification — the framework CoCs rely on
  6. 06Common failure modes
  7. 07What auditors actually look for
  8. 08Electronic CoCs and Part 11
  9. 09Where CoCs sit in supplier quality
  10. 10Sub-contractor and second-tier CoCs
  11. 11Receiving inspection workflow tied to CoC
  12. 12Discrepancy and dispute handling
On this page · 12 sections
  1. 1What a CoC is
  2. 2CoA vs CoC
  3. 3What a usable CoC contains
  4. 4When a CoC is not enough — by regulation
  5. 5Supplier qualification — the framework CoCs rely on
  6. 6Common failure modes
  7. 7What auditors actually look for
  8. 8Electronic CoCs and Part 11
  9. 9Where CoCs sit in supplier quality
  10. 10Sub-contractor and second-tier CoCs
  11. 11Receiving inspection workflow tied to CoC
  12. 12Discrepancy and dispute handling
AI · Explain it for MY operation

How does CoC apply to your shop floor?

Pick your industry and scale — Ask V5 rewrites the definition in your context, gives a worked example, and shows what V5 does on day one.

Your scale

01What a CoC is

A Certificate of Conformance (CoC) — sometimes called a Certificate of Compliance, Conformity, or Conformity to Specification — is a signed statement from a supplier that the lot or batch supplied conforms to the agreed specification or purchase order. Unlike a Certificate of Analysis, it typically does not include per-attribute test results — it is an attestation, not a data report.

CoCs are widely used for off-the-shelf components, packaging materials, hardware, fasteners, labels, cartons, and any item where the supplier's quality system is trusted and the spec is straightforward ("this carton meets drawing X rev Y", "this label meets artwork file Z, version 4"). They are the right tool when the spec is clear, the supplier is qualified, and the cost of per-lot testing outweighs the risk.

A CoC is a regulated record in every quality system. ISO 9001 §8.4 expects you to control externally provided products; a CoC is one of the most common evidence types for that control. Pharma (21 CFR 211.84), supplements (111.75) and medical devices (820.50) have additional rules layered on top — covered in the sections below.

02CoA vs CoC

AspectCoACoC
Contains test data?Yes — attribute, spec, result, method, analystNo — attestation only
Typical useRaw materials, APIs, active food ingredients, excipientsComponents, packaging, labels, hardware, consumables
Regulator expectation (pharma raw material)Required — and verified by in-house identity test (211.84)Not sufficient on its own
Regulator expectation (component / packaging)Often not requiredAcceptable with documented supplier qualification
Effort to produceLab work per lotPrint and sign
What goes wrong most oftenSpec/method mismatch, OOS values hidden as "meets spec"Missing lot number, missing signature, generic boilerplate
What an auditor pulls firstThe matching test result for a non-conforming lotThe lot number tied to a finished-product trace

The two are not interchangeable. A CoC where a CoA is required is a finding. A CoA where a CoC is fine is overkill but harmless. Some quality agreements require both: a CoA from the manufacturer plus a CoC from the distributor confirming the CoA matches the lot delivered.

03What a usable CoC contains

  • Supplier name, address and (if applicable) DUNS / GLN / regulatory establishment number.
  • Customer name, PO number, and customer part number.
  • Product description, supplier part number, GTIN (where assigned).
  • Lot / batch number and the quantity supplied under that lot.
  • Date of manufacture and (where applicable) expiry / retest / shelf-life date.
  • Reference to the specification, drawing or material standard conformed to, including the revision in force at the time of manufacture.
  • Statement of conformity — explicit language that the lot meets the referenced specification.
  • Signature of an authorised representative of the supplier — name, title, and date.
  • Date of issue.
  • Optional but increasingly expected: country of origin, batch traceability reference back to the supplier's MRP / MES, and reference to any sub-contracted operations.
Common gap

CoCs that omit the lot number are useless for traceability. If a CoC arrives without a lot number tied to it, treat the lot as undocumented and quarantine until the supplier issues a corrected CoC.

04When a CoC is not enough — by regulation

Pharma — 21 CFR 211.84

Under 21 CFR 211.84, a pharma manufacturer cannot rely on a supplier's CoA or CoC alone for the identity of an active or excipient — at minimum, identity must be confirmed in-house through an appropriate test (typically IR / NIR / HPLC depending on the material). The CoA or CoC can substitute for other attribute testing (assay, purity, residual solvents) only after the supplier is qualified through audit and ongoing validation.

Dietary supplements — 21 CFR 111.75

For dietary supplements (21 CFR 111.75), the rule is similar — at least one identity test must be performed in-house even with a supplier CoA or CoC on file. The qualified person performing the identity test must be documented, and the test methods must be validated for the specific component.

Medical devices — 21 CFR 820.50

For medical devices (21 CFR 820.50), purchasing controls require that suppliers be evaluated and that incoming product meet specified requirements — a CoC alone may be acceptable for low-risk components if supported by supplier qualification and documented purchasing data. For critical components (those that affect device safety or performance), the device manufacturer typically requires both a CoC and either incoming test or third-party verification per the supplier-control SOP.

Food (FSMA Preventive Controls / GFSI)

Under FSMA Preventive Controls (21 CFR 117) and any GFSI-recognised scheme, a CoC is part of the documented supplier verification programme. Where a supplier-controlled hazard (allergen, pathogen, mycotoxin) is identified, a CoC alone is generally insufficient — verification activities (audit, in-house test, third-party COA) are also required.

ISO 9001:2015 §8.4

ISO 9001 requires the organisation to determine and apply criteria for the evaluation, selection, monitoring of performance and re-evaluation of external providers. A CoC is one of the most common pieces of evidence; the depth of additional verification is risk-based and documented.

05Supplier qualification — the framework CoCs rely on

A CoC programme only works if the underlying supplier qualification works. A signature from an unqualified supplier on a CoC is worth less than the paper it's printed on. Defensible supplier qualification has four moving parts:

  1. Initial qualification — audit (on-site, remote, or paper-based depending on risk), questionnaire, capability assessment, regulatory licence verification, samples tested against spec, financial-stability check.
  2. Quality agreement — a written agreement covering specification, change-notification (PCN), recall obligations, sub-contracting rights, CoA/CoC requirements per material, retain-sample policy, and audit access.
  3. Ongoing monitoring — non-conformance trend, on-time-in-full performance, periodic CoA re-verification, complaint handling.
  4. Periodic re-qualification — typically every 1–3 years depending on risk, more frequent if the trend deteriorates.

V5's supplier portal lets suppliers upload CoAs and CoCs against your POs directly, with structured fields so the lot number, dates and spec reference are captured automatically — no PDF parsing at receiving, and no copy-paste from email.

06Common failure modes

  • Generic CoCs that do not name the lot — useless for traceability.
  • Treating CoC as sufficient for materials that legally need a CoA + identity test (pharma APIs, supplement actives).
  • Filing CoCs in email rather than against the inventory lot they describe.
  • Not noticing when a CoC arrives without a required signature, or with an electronic signature that has no certificate behind it.
  • Letting suppliers downgrade from CoA to CoC silently without re-qualification (often happens with second-source materials).
  • CoC references a specification revision that is no longer current — meaning the supplier manufactured to an obsolete spec.
  • CoC signed by a name that nobody at the supplier can identify when challenged.
  • Letter of conformance covering "all product supplied" with no lot enumeration — a single signature pretending to cover an indefinite future.
How V5 handles it

V5 attaches each CoC (and CoA) directly to the inventory lot at goods-in, blocks release of the lot if the document is missing or unsigned, validates that the lot number on the CoC matches the lot number on the goods-receipt, flags expired-revision spec references, and routes mismatched spec / CoC pairs into an NCR automatically.

07What auditors actually look for

  1. Sample a finished-product lot. Walk back to every raw / component lot it consumed. For each, demand the CoA or CoC.
  2. For each CoC, verify the lot number matches the goods-receipt and the inventory transaction.
  3. Verify the supplier is on the approved supplier list, current, with an in-date qualification on file.
  4. Verify the specification reference on the CoC matches the current released specification at the time of receipt.
  5. Verify the signature is a real person whose authority to sign is documented (delegation list, signature register).
  6. Verify that any non-conformance noted on the CoC was triaged through your NCR / deviation process before lot release.
  7. For pharma / supplements: verify the in-house identity test was performed and signed off.

An auditor will pick one or two finished-product lots and follow this trace end-to-end. If any link is weak — missing CoC, mismatched lot number, expired supplier qualification, missing identity test — the finding will be cited at the system level, not the lot level.

08Electronic CoCs and Part 11

Electronic CoCs are now the norm for any supplier with a modern QMS. They count as electronic records under 21 CFR Part 11 and EU Annex 11 when used to satisfy a regulated requirement. The same data-integrity expectations apply — the e-signature must be uniquely attributable to the signer, the record must be tamper-evident, and the audit trail of any changes must be preserved.

Where a supplier sends a PDF CoC by email, treat the PDF as a controlled record once attached to the lot in your QMS. Do not allow the lot record to point at a mailbox attachment that can be deleted or modified — pull it into the QMS and lock it.

09Where CoCs sit in supplier quality

You qualify the supplier (audit, history, capability), agree the spec and what documentation accompanies each shipment (CoA per lot, CoC per lot, both, neither), then accept CoCs against that agreement. Periodic re-qualification keeps it honest. The CoC is the routine evidence; the periodic audit is the trust-but-verify check. Without the audit, the CoC is just a piece of paper.

In risk-based supplier programmes (ISO 9001, GFSI, ICH Q9), the depth of verification scales with the risk of the material. A label that's miscoloured is annoying; a label with the wrong allergen statement is a recall. A CoC alone is fine for the first; the second needs CoC + sample-on-receipt verification.

10Sub-contractor and second-tier CoCs

Many components arrive with a CoC from a distributor or contract manufacturer rather than from the original maker. The regulatory expectation does not stop at your immediate supplier — the supplier-control loop must reach back to wherever the spec-affecting operation actually happened. A distributor's CoC saying "we re-packed product manufactured by X" is acceptable only if X is also on your approved-supplier list with a current qualification, and your quality agreement with the distributor mandates pass-through of the original manufacturer's CoA where the regulation requires one.

The pattern that survives audit:

  1. Map every sub-contracted operation per supplier — packing, sterilisation, irradiation, blending, particle-size reduction, labelling. Each one shifts the spec.
  2. Qualify each sub-contractor that performs a spec-affecting operation, even if you transact only with the prime supplier. The quality agreement must give you the right to audit them, or evidence that the prime has audited them on a defined cadence.
  3. Require the prime supplier's CoC to reference (by name and lot) any sub-contracted operation performed on the lot, plus pass-through of the sub-contractor's CoA where the regulation requires test data (e.g. sterilisation cycle records for medical devices, contract-analytical CoAs for pharma actives).
  4. Treat unannounced changes in sub-contractor as a Permanent Change Notification (PCN) trigger — if the prime supplier swaps the sub-contractor without notifying you, the supplier qualification is in breach and lots produced after the switch are unauthenticated.

The most common failure mode is a distributor with three or four upstream sources rotating silently — each lot legitimately conforms to spec, but no two lots come from the same upstream chain, and no individual upstream is qualified by the receiving site. The first complaint that has to trace back to a specific upstream operation exposes the gap.

11Receiving inspection workflow tied to CoC

Goods-in is where the CoC programme either works or fails. A workflow that prevents release of an undocumented lot is non-negotiable; a workflow that captures the CoC into the lot record at the moment of receipt makes every downstream trace one click rather than one hour. The minimum sequence:

  1. Scan the inbound delivery: PO matched, supplier confirmed against approved list, qualification in date.
  2. Capture lot number, quantity, date of manufacture, expiry from the case / pallet label (GS1-128 preferred).
  3. Attach the CoC (and CoA if required by spec) to the lot record at the point of receipt. The system blocks the put-away transaction until the document is present and the lot number on the document matches the goods-receipt.
  4. Validate the spec revision quoted on the CoC against the current released spec — out-of-date references route the lot to NCR for QA decision before release.
  5. Validate the signer against the supplier's signature register where one exists (most quality agreements maintain one for high-risk materials).
  6. For materials needing in-house verification (pharma identity per 211.84, supplement identity per 111.75, medical-device incoming inspection per 820.80), the lot stays quarantined until the verification is signed off.
  7. Lot status moves from received-quarantined to released only on QA disposition with electronic signature and timestamp.
Goods-in in V5

V5's receiving workflow enforces this sequence at the kiosk: no CoC, no put-away; mismatched lot, no release; out-of-date spec reference, automatic NCR; in-house verification required, lot held until lab returns the signed result. The audit trail of every release decision is captured in one place with the Part 11 e-signature meaning string.

12Discrepancy and dispute handling

The hard cases are not the missing CoCs — those quarantine cleanly and force a phone call. The hard cases are the CoCs that arrive complete but contradict your incoming verification: supplier says identity confirmed; your IR scan disagrees. Supplier says assay 99.4%; your retest says 97.8%. Supplier says lot Z; your label says lot Z-A. The workflow for these:

  • Quarantine the lot immediately; do not consume any of it pending resolution.
  • Open an NCR with the lot, the CoC, the contradicting evidence, and the disposition options (use as-is with documented justification, return to supplier, rework, scrap, deviation to use under exceptional conditions).
  • Notify the supplier formally within the timeframe agreed in the quality agreement (typically 5 business days for routine, 24 hours for safety-critical).
  • Run an independent confirmatory test (different analyst, different instrument, ideally different method) before concluding the supplier's CoC is wrong.
  • Document the resolution and feed it into the supplier's performance file — recurrent discrepancies drop the supplier's qualification score and may trigger a for-cause audit.
  • If the issue is systemic (multiple lots, same defect), invoke the recall clause of the quality agreement and treat as a market-withdrawal candidate even if the lots are still in your warehouse.

The audit-defence asset here is the trend report: discrepancies per supplier per year, broken down by category (identity / assay / quantity / lot mismatch / spec-revision mismatch). A trend that is flat or improving demonstrates the supplier-quality programme works; a trend that is rising and clusters on one supplier is the auditor's lead-in to questioning re-qualification frequency.

Cover of The Reference Material & Analytical Standard Production Guide
For reference material & analytical standard production

Putting CoC into practice

It explains where a certificate of conformity is enough and where buyers expect lot-specific results instead.

The Reference Material & Analytical Standard Production Guide · 22-page PDF

Get the guide See the industry page

Frequently asked questions

Q.Is a CoC legally equivalent to a CoA?+

No. A CoC is a conformance statement; a CoA is a data report. Regulators expect CoAs for regulated raw materials and a CoC plus supplier qualification for many components.

Q.Do I need a CoC for every shipment?+

Most quality agreements require it. Without it you have no signed evidence that the supplier intends the shipment to meet your spec.

Q.Can a CoC reference multiple lots?+

Yes, but each lot must be individually identified on the CoC. A blanket CoC saying "all product on this PO conforms" without lot detail will not survive a traceability test.

Q.Can the supplier email me a PDF CoC?+

Yes, but the moment it satisfies a regulated requirement it must be controlled — attached to the lot in your QMS, locked against modification, and accessible to QA and to regulators on request.

Q.What if the CoC says the lot meets spec but my incoming test fails?+

Quarantine the lot, raise an NCR, and contact the supplier. The CoC does not override your own test data. If incoming tests routinely contradict CoCs from the same supplier, the supplier qualification is broken — not your test.

Q.Do I need a CoC for indirect materials (lubricants, gloves, cleaning chemicals)?+

For GxP-relevant indirect materials (anything that contacts product or product-contact surfaces) yes — the same supplier-control principles apply. For non-contact consumables, your quality system defines the threshold.

Q.Can a CoC reference a sub-contractor's CoA?+

Yes, and it must where regulation requires test data the prime supplier did not generate. The prime CoC should name the sub-contractor, lot, operation performed, and attach (or reference a retrievable copy of) the sub-contractor's CoA.

Q.How long must I keep CoCs?+

At least as long as the longest applicable record-retention rule for the product they fed: typically the product expiry plus one year for pharma (211.180(c)), the device lifetime plus two years for medical devices (820.180), and two years from event for FSMA 204 traceability records. Practically most QMS systems retain seven years by default.

Q.What if a CoC is signed by an electronic signature with no certificate behind it?+

If the CoC is satisfying a Part 11 / Annex 11 requirement, the e-signature must be uniquely attributable, non-repudiable, and tamper-evident. A typed name in a Word footer doesn't qualify. Request a re-issue using the supplier's qualified e-signature system, or treat the lot as undocumented until a wet-signed PDF arrives.

Q.Can I accept a single CoC covering multiple shipments under the same PO?+

Only if each shipment's lot is individually enumerated on the CoC and the document is updated as each shipment leaves. A standing blanket CoC covering future shipments has no traceability value and fails an audit trace exercise.

Q.Who signs the customer side when we accept the CoC?+

The QA or release authority defined in your SOP — usually the same person or role that releases the lot to production. The signature must be on the disposition record (release, quarantine, reject), not on the CoC itself, and must be linked to the CoC in the lot record.

Primary sources

  • 21 CFR 211.84 — Testing and approval or rejection of components
  • 21 CFR 211.137 — Expiration dating
  • 21 CFR 111.75 — Quality control for dietary supplements (component identity)
  • 21 CFR 820.50 — Purchasing controls (medical devices)
  • ISO 9001:2015 §8.4 — Control of externally provided processes
  • ISO 9001:2015 §8.6 — Release of products and services

Further reading

  • CoA
    The fuller per-attribute version with test data.
  • QMS
    Where supplier-quality documents live.
  • FEFO
    Why expiry on the CoC matters.
  • Supplier qualification
    The framework that makes CoC programmes defensible.
Software that covers CoC
V5 Ultimate CGT Manufacturing Software
Autologous COI from apheresis to infusion, allogeneic lot genealogy from donor to bag, viral-vector eBR, ISBT 128 / SEC-178…
V5 Ultimate Quality Control Software
In-process checks, sampling plans, spec limits, SPC trending, CoA generation and hold/release — enforced at the kiosk while the…
V5 Ultimate Supplier Quality Management Software
Keep why each supplier is approved, and for which materials, connected to the purchasing and receiving records that use them —…

Explore this topic

CoC sits inside this topic cluster in our glossary. Every neighbour is one click away.

Batch & device records
16 related entries

Master and executed records that prove a batch or device was made to spec.

BMReBMRMMRBPRBatch recordDHReDHRDMRDHFCoAPIF21 CFR 21121 CFR 11121 CFR 820Technical FileDesign controls
Talk to us about CoC

Want to see how CoC could fit into your own records and workflows? Explore the related V5 pages or talk to our team about what applies to your operation.

Start free
Back to glossary
Where this term comes up
Packaging & food contactReference materials
Inside V5
  • → Receiving — material lands, V5 already knows it’s coming.
Related terms
  • → CoA
  • → Supplier CoA verification programme
  • → Certified Reference Material
  • → BMR
  • → eBMR
  • → MMR
  • → BPR
  • → Batch record
  • → DHR
  • → eDHR
  • → DMR
  • → DHF
  • → PIF
  • → 21 CFR 211
  • → 21 CFR 111
  • → 21 CFR 820
  • → Technical File

Next step

Try V5 with your own records, or ask a question first. Ask V5 opens with an editable question; nothing is sent until you choose to.

Start your free trial Browse all features
V5 Ultimate
Ultimate

Warehouse, quality and manufacturing software for regulated operations.

ProductIndustriesPricingResourcesSecurity & TrustCompanyLegal centre

© V5 Ultimate