How Do You Get ISO Certificates From Suppliers?
Get ISO certificates from suppliers by sending a specific request to the quality contact (not sales or purchasing), following up on a defined cadence, and verifying that what you receive is current, accredited, and scoped to the right entity and site. A single vague email almost never works. A Senior SQE at a Fortune 100 life sciences company managing 900+ suppliers described the default outcome: “You reach out 2, 3, 4, 5 times. Nobody responds. You just give up.”
Which ISO certificates do regulated manufacturers usually need?
| Standard | Covers |
|---|---|
| ISO 9001 | General quality management |
| ISO 13485 | Medical device quality (design controls, traceability) |
| ISO 14001 | Environmental management |
| ISO 45001 | Occupational health and safety |
| ISO 27001 | Information security |
| IATF 16949 / AS9100 | Automotive / aerospace quality |
Request the standard that matches your industry and the supplier’s role in your supply chain.
What should you ask for specifically?
“Send us your ISO cert” produces the wrong document, an expired copy, or silence. Specify:
- Exact standard and version (ISO 13485:2016, not just “ISO 13485”)
- Scope (e.g., “manufacturing of injection-molded components”)
- Legal entity matching your POs (large suppliers hold certs under multiple subsidiaries)
- Specific site if you source from one facility
- Format: PDF of the original certificate, not a screenshot or self-declaration
Who should receive the request?
| Certificate | Contact |
|---|---|
| ISO 9001, ISO 13485, IATF 16949 | Quality Manager, Quality Director, QMR |
| ISO 14001, ISO 45001 | EHS Manager, Sustainability Manager |
| ISO 27001 | Information Security Officer, IT Director |
At suppliers under 100 employees, the General Manager or Plant Manager often holds the records. ERP purchasing contacts typically cannot help and will not forward the request.
How do you verify a certificate you receive?
A PDF is not enough. Check five things:
- Dates: Issue and expiration. Most certs run three years with annual surveillance audits.
- Accreditation body: Logo and name (ANAB, UKAS, DAkkS, JAS-ANZ). Verify through IAF or the accreditor’s site.
- Scope: Matches what the supplier does for you. “Distribution only” does not cover manufacturing you buy.
- Legal entity and site: Name and address match your supplier record and shipping location.
- Certification body lookup: BSI, TÜV, SGS, Bureau Veritas, and DNV offer online verification by cert number.
Why do suppliers not respond?
- Wrong contact (most common)
- Stale email (person left, address dead)
- No perceived priority unless commercial consequences are clear
- Cert is lapsed or missing (silence instead of admission)
- Volume fatigue when the gap is dozens or hundreds of suppliers
An SQE described discovering the real scale: “The auditor only found three. But then you realize that out of the 116, you have 60 or 64 that doesn’t have the compliance certificates, because someone tried to reach out to maybe 20 of them and gave up.”
What follow-up cadence should you use?
- Day 0: Specific request to quality contact with deadline.
- Day 5-7: Resend. Reference original date.
- Day 10-14: Note compliance requirement and supplier approval consequences.
- Day 21: Escalate to senior contact at supplier or loop in procurement.
- Day 30: Formal notice of supplier hold or removal from approved list.
Document every touchpoint for audit trail.
What if the supplier cannot provide the certificate?
- Require certification within a defined timeline as a condition of continued business.
- Accept alternatives (second-party audit, self-assessment) if your framework allows.
- Reclassify risk and increase incoming inspection.
- Source from a certified alternate if one exists.
The right choice depends on supplier criticality, regulatory requirement, and available alternatives.
Frequently asked questions
Is a self-declaration enough?
Usually no for regulated supply chains. You need the certificate issued by an accredited certification body unless your quality agreement explicitly allows otherwise.
What if the cert covers a parent company but not the site you use?
Flag it. Multi-site certs exist, but if your facility is not listed, the certification may not cover your supply.
How often should you refresh certificates on file?
Check expirations quarterly. Request renewals 90 days before expiration, not after.
Where Bridgecurrent fits
Bridgecurrent finds the quality contact at each supplier, sends the specific certificate request, follows up on cadence, and tracks what comes back. Teams running ISO collection across hundreds of suppliers use it to replace the daily email grind that otherwise consumes hours of SQE time.