Insights · 4 min read
Three steps to verify any ISO certificate before accepting a supplier
A supplier sends you a certificate. You have three minutes and no specialist knowledge. Here is exactly what to do with them.
Published by CAS — Conformity Assessment Services · 4 September 2026
A supplier sends you a certificate. You have three minutes and no specialist knowledge. Here is exactly what to do with them.
This is the operational version. If you want the reasoning behind it — what accreditation is and why public registers exist at all — that is a separate piece. This one assumes you already accept the premise and just want the procedure.
Step 1 — Read the certificate face
Before opening a browser, find four things on the document itself.
The certification body's name. Not the accreditation body, not the standard — who issued this.
The accreditation body and an accreditation number. Usually near a mark or in the footer. If neither appears anywhere on the document, you have already learned the most important thing: this is not an accredited certificate, and the remaining steps will confirm it rather than discover it.
The standard, with its year. ISO 9001:2015, not "ISO 9001". The year matters when transitions are running.
The scope statement and the sites. This is the field most people skip and the one that most often turns out to matter. Read it now; you will compare it against the register in step 3.
Note the certificate number and the exact legal name of the certified organization. Both are what you will search with, and both are where mismatches appear.
Step 2 — Check the certification body
Take the accreditation number to the accreditation body's public register — not to the certification body's own website.
That distinction is the entire point of the step. Anyone can publish a page claiming accreditation. The register is maintained by the party that granted it.
Confirm three things:
The body appears, and the accreditation is current rather than expired, suspended or withdrawn.
The scope covers the standard on your certificate. Accreditation is granted scheme by scheme. A body accredited for ISO 9001 is not thereby accredited for ISO 22000, and this is a real and common gap rather than a theoretical one.
The technical sector fits the certified activity. Within a scheme, accreditation is granted for specific IAF technical sectors. A body accredited for ISO 9001 in construction and IT is not accredited for ISO 9001 in pharmaceuticals.
Most people stop after confirming the body exists. The scope and sector checks are where the useful findings are.
Step 3 — Check the certificate
Now the certificate itself, in two places.
IAF CertSearch — the global registry. Search by the certified organization's legal name. Accredited management system certificates from participating bodies are published there.
The certification body's own verification page. This gives you status, scope and expiry at source. Ours is at cas.com.eg/certsearch.
Then compare what you find against what you read in step 1. Four things should match: the organization's legal name, the standard and its year, the scope statement, and the status.
A mismatch in any of them is worth a question. A mismatch in scope is worth a serious one, because it is the difference between a certificate that covers what you are buying and one that does not.
Reading the scope properly
The scope statement names the activities, processes, products and services the certification applies to, at which sites. It is not decoration and it is not a description of the company.
Three checks:
Does it cover the product or service you are buying? A manufacturer certified for "design and manufacture of steel fasteners" is not certified for the plastics line in the same building.
Does it cover the site that will produce your order? Multi-site certification is common and legitimate, and the certificate says which sites.
Is it specific enough to mean something? A scope broad enough to describe any organization in the sector was probably written to avoid saying anything. Under ISO/IEC 17021-1 clause 8.2.2, the scope must be stated without being misleading or ambiguous.
Three minutes, and a procedure rather than a habit
The whole sequence takes about three minutes once you have done it twice. What makes it work is doing it every time rather than when something feels off — because nothing feels off about a well-made certificate that does not exist.
The practical way to achieve that is to make it a step in supplier onboarding with a named owner, rather than something the quality manager does when they remember. A field in the supplier record for the certificate number, the date checked, and the result turns a habit into a control.
ISO/IEC 17021-1 clause 8.1.2 requires a certification body to provide the status of a given certificate on request. So where a register is unclear, asking is not an imposition — it is a right the standard gives the person relying on the certificate.