How to read a certificate of analysis
What a COA states, which fields tie it to a physical vial, how publication postures differ, and what a certificate does not establish.
Topic: Reading laboratory documents
Audience: Anyone evaluating a vendor’s certificates
Reading time: 7–9 minutes
On this page
- 1.What a certificate of analysis is
- 2.The fields that carry the weight
- 3.A sample document is a claim, not a certificate
- 4.How vendors publish certificates: five postures
- 5.A file handed over, or a record looked up
- 6.What a test panel covers, and why panels differ
- 7.When a certificate cannot be read
- 8.Where to go next
What a certificate of analysis is
A certificate of analysis (COA) is a laboratory’s record of what it measured in a specific sample it received. It reports findings about that sample: what the material was identified as, how pure it measured, and what contaminants were screened for. Everything a certificate is worth rests on how tightly it is tied to the vial in question.
Three things a certificate is often assumed to establish, and does not. It is not a statement about a vendor’s catalog — it covers one material, tested once. It is not a guarantee about a vial bought months later, unless the lot on the certificate matches the lot on that vial. And it is not an accreditation: a laboratory’s ISO/IEC 17025 status, where it holds one, is a separate fact printed separately, and a certificate carrying no accreditation statement is not evidence that one exists.
What a certificate does establish is narrow and real: an independent laboratory received a sample, ran named methods against it, and published figures with its name attached. That is a materially different thing from a vendor stating its own purity.
The fields that carry the weight
Most of a certificate is boilerplate. A small number of fields determine whether the document is traceable to a physical vial, and those are the ones worth reading first.
- Lot or batch number. The link between the document and a physical production run. A certificate whose lot number matches the lot printed on a vial covers that vial. One that does not, does not — however good its figures are.
- Client field. Who the laboratory says commissioned the test. This is the most reliable statement of the relationship between a vendor and a laboratory that exists anywhere — more reliable than a laboratory’s marketing site, and far more reliable than a vendor’s prose. It is also the authority on how a company’s name is spelled.
- Test date and report date. A certificate without a date cannot be placed relative to a purchase.
- Methods, named individually. “Tested” is not a method. HPLC-UV, LC-MS, MALDI-MS, ICP-MS and the USP chapter for an endotoxin assay are methods, and a certificate that names them can be evaluated.
- Signatory or laboratory identification. A named analyst, a laboratory address, or a resolvable verification code. A document with none of these has nothing behind its figures.
- A verification code, where the laboratory issues one. Some certificates print a search or access code that resolves the same record on the laboratory’s own domain. Where one is present it is the single most useful field on the page — see verifying a certificate at the laboratory.
A sample document is a claim, not a certificate
The most common document mistaken for a certificate is a specimen: a formatted page showing what a certificate would look like, with no lot number and no signatory. It is a design artifact.
A specimen page is recognisable by absence rather than by anything it says. There is no lot or batch identifier, or the field is present and reads N/A. No analyst is named and no laboratory address appears. There is no verification code, or the code does not resolve. Often there is exactly one such document for the whole catalog, rather than one per product or per lot.
Read this way, such a page asserts that testing happens. That assertion may well be true. It is a claim about a practice, and it is a different kind of evidence from a document tied to a lot a reader can match against a vial. Prof. Peptide records the two separately for that reason: a testing claim and a publication posture are distinct facts about a vendor, and one does not imply the other.
The N/A lot field. A lot field reading N/A is not a defect in the document and not an attempt to mislead. It usually means the certificate is filed per product rather than per batch — one certificate standing for a compound, re-tested when the vendor chooses. It is a weaker tie to a vial than a lot-stamped certificate, and it is honest about being one.
How vendors publish certificates: five postures
Prof. Peptide classifies every vendor in its registry by how that vendor publishes certificates, written by hand from the vendor’s own site. The postures differ in how much work a reader has to do and in how tightly a document ties to a vial.
- Per-batch. A certificate published for each production lot, carrying that lot’s identifier. The strongest posture: a reader can match a vial to a document.
- Per-product. One current certificate per compound, replaced when the vendor re-tests. Traceable to a compound, not to a vial.
- Library. A COA page or archive listing many certificates together, sometimes with previous batches kept alongside the current one. Coverage varies within a single library, so the posture describes the page rather than every document on it.
- On request. No certificates published; the vendor states it will supply one on request. Nothing is verifiable before contact.
- Login-gated. Certificates exist behind an account. ⚠️ An age or researcher attestation — a checkbox — is not a login, and the two are easy to conflate: one needs only a browser, the other needs an account.
A posture is a fact about publication, not a verdict on testing. A vendor that tests thoroughly and publishes nothing and a vendor that publishes a specimen page are in different positions, and neither is described by its certificates alone. The per-vendor summaries in the vendor COA and testing-transparency index record what each one actually does.
A file handed over, or a record looked up
Two vendors can use the same laboratory and publish certificates that differ in one respect that matters: whether the document is an artifact hosted by the vendor, or a pointer into the laboratory’s own system.
In the first arrangement, a vendor’s COA page links out to the testing laboratory’s own system, and what a reader opens is a live record held by the laboratory. In the second, the certificate is a PDF served from the vendor’s own domain, with a verification code or QR printed inside it; the same laboratory record is reachable, but only if the reader acts on the code.
Prof. Peptide has observed both arrangements from a single laboratory across different vendors. The difference is not the testing, which is identical. It is where the default sits: one arrangement verifies by construction, the other makes verification available to a reader who goes looking. Both are materially stronger than a certificate with no route back to the laboratory at all.
What a test panel covers, and why panels differ
Purity is the figure most readers look for and the least informative on its own. A certificate’s panel — what it tested for at all — says more about the laboratory’s thoroughness than any single percentage.
Across the certificates Prof. Peptide has read first-hand, panels range from an identity and purity pair to a substantially deeper set: identity by mass spectrometry, purity by HPLC-UV, net peptide content, bacterial endotoxin run in duplicate against the relevant USP chapter, microbial screening, elemental impurities by ICP-MS, and a fentanyl screen.
⚠️ Panels differ by laboratory, not by vendor. Two vendors using different laboratories will publish certificates of different depth even where both are diligent, and a thinner panel is a fact about the laboratory’s template. Comparing a purity figure across two laboratories compares two measurements made by different methods against different reference standards.
Per-vial reporting is the detail worth noticing. Some certificates report purity and content for several vials from the same lot, each measured and reported individually rather than averaged into one figure. Where that appears, a reader can see the spread within a lot instead of a single number standing for all of it.
A published standard is not a measurement. “≥98% by HPLC” on a product page is a specification the vendor commits to. A certificate’s “99.52%” is what one sample measured. Prof. Peptide records those separately, and where a vendor states its purity inconsistently across its own site, no figure is adopted at all — the certificate’s own measured result stands instead.
When a certificate cannot be read
A document that resists reading is not the same as a document that fails inspection, and the two are easy to confuse when working at volume.
A meaningful share of certificates are scans with no text layer — roughly one in twelve of those Prof. Peptide sampled from one laboratory. Automated text extraction returns nothing from them; a human reading the page sees a perfectly ordinary certificate. A vendor whose sampled certificates happen to be image-only looks unverifiable when its documents are merely unsearchable.
The same distinction applies to access. A page that returns an error to an automated request frequently opens normally in a browser. Prof. Peptide recorded three vendors as blocked on that basis and found all three readable on a second attempt with ordinary browser headers — which is why a single failed fetch is treated as a fact about the attempt rather than about the vendor.
Where to go next
Reading a certificate establishes what it states. Confirming it against the laboratory that issued it is a separate step, and it is possible for some laboratories and not others.
- How to verify a certificate at the laboratory — which laboratories publish a searchable index, which issue per-record codes, and how a document can be checked against the laboratory’s own copy.
- Vendor COA and testing-transparency index — what each vendor publishes and which laboratory is named on its certificates.
- Testing laboratories — the laboratories named across the registry.
- Peptide research basics — what quality testing verifies, in context.
We may earn commissions from peptide vendor affiliate links.
