How to Verify Supplier Certificates

Why a Certificate PDF Is Not Proof
Every fiber optic supplier has a folder of certificate PDFs. ISO 9001, CE, RoHS, sometimes UL or CPR — they arrive attached to the quote, neatly scanned, and they look convincing. The problem: a certificate is a document, and documents can be edited. Scanned logos get pasted onto fresh letterheads, validity dates get extended in image editors, and one manufacturer's certificate number turns up on another company's datasheet more often than most buyers expect.
Before you wire a deposit, you need to know how to verify supplier certificate authenticity — and most of the checks in this guide take under ten minutes per certificate. The cost of skipping them is not theoretical. A cable that carries a fake CPR Euroclass can fail a building inspection or a fire-safety audit. A CE-marked product without a valid Declaration of Conformity can be stopped at customs in the EU. A supplier whose ISO certificate belongs to another legal entity is a supply-chain liability that outlives the order.
The working rule: a certificate is only as good as the number on it — and whether that number resolves in the issuing body's official database. Everything else in this article is a practical method for making that check quickly, certificate type by certificate type. For the big picture — what CPR, UL, CE, and RoHS actually require from fiber optic products — start with our fiber optic standards and certifications hub, then come back here to run the checks.

What a Legitimate Certificate Looks Like
A supplier certificate is a document issued by a certification body — or self-declared by a manufacturer — attesting that a product, process, or management system meets a stated standard. Before checking anything online, learn to read the document itself. Every genuine certificate, whatever the scheme, carries the same skeleton:
- A certificate or registration number — the single most important field. No number, or a number that looks decorative ("No. 001"), is the first red flag.
- The issuing body — name, logo, and ideally the accreditation mark of the body that accredits them (for ISO certificates, the national accreditation body; for UL, UL itself; for CPR, a notified body).
- The standard or regulation referenced, with the version and year (ISO 9001:2015, not "ISO 9001").
- The scope — precisely what products, activities, or sites the certificate covers.
- Issue and expiry dates, plus any surveillance cycle.
One distinction matters before you start searching: who issues, and who accredits. ISO 9001 and ISO 14001 certificates are issued by certification bodies (SGS, TÜV, BSI, Bureau Veritas, and hundreds of others) that are themselves accredited by national accreditation bodies (ANAB, UKAS, CNAS, and so on). A UL listing is issued and owned by UL. A CPR declaration for cable is the manufacturer's Declaration of Performance, based on testing by a notified body. And a CE mark is — by design — a manufacturer's self-declaration. These differences decide which database you check, so they are summarized here and detailed in the sections that follow:
Certificate | Where you verify it | What must match |
|---|---|---|
UL Listing (cables) | UL Product iQ / UL Certifications Directory | File number, category, product description, company name |
CE marking | Manufacturer's Declaration of Conformity (no central CE registry) | Directives, harmonized standards, signatory, EU representative |
CPR (construction cables) | Declaration of Performance + notified body in NANDO | DoP number, Euroclass, notified body number |
RoHS / REACH | Supplier test reports and declarations (no central registry) | Test lab, report number, batch, substances |
ISO 9001 / 14001 | IAF CertSearch + the certification body's database | Certificate number, scope, validity, accreditation |
Verify UL Listings in UL Product iQ
UL markings on fiber optic cable are a fire-safety matter, not a marketing badge. Plenum-rated fiber (OFNP, OFCP) and riser-rated fiber (OFNR, OFCR) are tested to UL 1651 and referenced by the National Electrical Code, so a buyer specifying plenum cable needs a real UL listing, not a sticker.
UL runs the authoritative database for its own marks: UL Product iQ (searchable at UL Product iQ, with an overview of what it covers at UL's Product iQ page). The verification routine:
- Get the file number from the certificate — a UL file number (often written as an "E-number") is printed on the certificate and usually on the cable jacket itself.
- Search it in Product iQ. Genuine listings resolve to a company and a product category. Fiber optic cables sit in the optical fiber cable category, and the entry will name the exact cable types covered (OFNP, OFNR, OFCP, and so on).
- Compare the product description. The listing must describe what you are actually buying — cable type, temperature rating, and construction. A listing that covers "patch cords" while you are buying bulk outdoor cable does not verify the product you are sourcing.
- Check the company name. The legal entity in the listing must be the entity you are contracting with. Listings are not transferable: a supplier cannot "borrow" a file number from a sister company.
A UL mark without a resolving file number, or a file number that resolves to a different company or a different product family, is a hard stop. Ask the supplier to send the Product iQ link themselves — a legitimate manufacturer will send it without hesitation.
Verify CE Marking and the Declaration of Conformity
CE marking is where buyers most often get the verification model backwards. There is no central EU registry of CE certificates, and there is no "CE certificate" issued by a third party. The CE mark is a manufacturer's self-declaration that the product meets the EU directives that apply to it (how CE marking works, on the European Commission's site). What you verify is the Declaration of Conformity (DoC) — the document behind the mark.
A valid DoC for a fiber optic product should state:
- the manufacturer's name and address (and, for non-EU manufacturers, the authorized EU representative, which several directives require);
- the product identification (model, type, batch);
- the directives applied — for passive fiber products this typically means RoHS (2011/65/EU), and for active equipment the Low Voltage Directive (2014/35/EU) and EMC Directive (2014/30/EU);
- the harmonized standards used to demonstrate conformity, with their numbers and years;
- date and signature.
To verify a CE certificate claim, work through those fields: are the directives still current (a DoC citing the repealed 2002/95/EC RoHS directive is either stale or fabricated)? Do the standards numbers exist and match the product? Is there a named EU representative for a Chinese or US manufacturer? Then ask for the underlying test evidence — the DoC is a statement, and the statement is only as trustworthy as the test reports behind it.
One honest caveat that belongs in every CE discussion: because the mark is self-declared, anyone can print it. That is exactly why the DoC and its test evidence, not the logo, are the object of verification.
Verify CPR Certificates for Fiber Optic Cables
For cables installed permanently in buildings in the EU, the Construction Products Regulation (EU 305/2011) applies. Under CPR, a cable needs a Declaration of Performance (DoP) and a CE mark, and its reaction-to-fire behavior must be declared as a Euroclass (Aca through Fca, plus smoke, droplet, and acidity subclasses). If you are buying cable for an EU building project, the Euroclass on the documents must match what your project specification demands — our CPR Euroclass ratings guide and indoor vs outdoor CPR rating guide cover those classes in detail.
CPR certificate verification starts with the DoP:
- Ask for the DoP with its DoP number. Every CPR-compliant cable has one; the manufacturer must also make it available on request (typically on their website).
- Check the Euroclass against your requirement. A DoP declaring Dca-s2,d2 when the spec calls for Cca is a genuine mismatch, not a paperwork nuance.
- Verify the notified body. For cables, initial type testing is done by a notified body under assessment system 1+ or 3, and the notified body's number appears on the DoP. The European Commission's NANDO database (notified bodies for construction products) lists every notified body and the products it is authorized to test. A DoP citing a body number that does not exist in NANDO — or a body whose authorization does not cover cable — means the declaration has no valid technical basis.
- Confirm the DoP is current. CPR requires ongoing factory production control; a DoP referencing a long-superseded test standard should be questioned.
Verify RoHS and REACH Compliance
RoHS (Directive 2011/65/EU) restricts ten hazardous substances in electrical and electronic equipment, and REACH (Regulation EC 1907/2006) governs chemical substances generally. In fiber optic sourcing, RoHS and REACH declarations are routine requirements — and they are also the easiest compliance claims to fake, because there is no central registry to check.
Verification therefore rests on test reports, not declarations:
- Demand a RoHS test report from an accredited laboratory (tested to IEC 62321 methods) with the lab's name, report number, test date, and the batch it covers. A general "RoHS compliant" stamp on a datasheet, with no report behind it, is a statement with zero evidence.
- Ask for the REACH SVHC declaration, and ask whether the supplier tracks the SVHC Candidate List updates — the list grows roughly twice a year, and a declaration that never changes is a red flag.
- For cable jacketing and buffer materials, connect the compliance story to the material itself: LSZH compounds and PVC differ in halogen content and recyclability, and the material choice should line up with the RoHS/REACH claims — see LSZH vs PVC vs plenum jacketing.
If the supplier produces a test report, look at the batch traceability: does the report reference the batch or model you are buying, or is it a generic, undated document that could cover anything?
Verify ISO Certificates Through the Issuing Body
ISO does not certify companies. ISO publishes standards; certification bodies issue certificates, and those bodies are accredited by national accreditation bodies under ISO/IEC 17021. So when a supplier sends an "ISO 9001" certificate, the verification has two steps: is the certificate real, and is the issuing body legitimate?
- Identify the certification body. The certificate names it and shows its logo.
- Confirm the body is accredited. Accreditation bodies publish directories of the certification bodies they accredit (ANAB, UKAS, CNAS, and every other member of the IAF). An ISO certificate from a body that no accreditation directory lists is not a recognized certificate.
- Search the certificate number. The global search point is IAF CertSearch (iafcertsearch.org), a free database of organizations certified by IAF-accredited bodies, maintained under the IAF Multilateral Recognition Arrangement (IAF MLA). Many certification bodies also run their own public certificate-search pages — the body's own database is the definitive check for its certificates.
- Match the scope. The certificate's scope must cover what the supplier claims to do. A certificate whose scope says "trading of optical components" does not verify a manufacturer's production claims. TTI Fiber's own ISO 9001:2015 certificate, for example, is scoped to "design, development, production and sales of fiber optic cables, patch cords, pigtails, connectors, adapters, splitters and related passive optical components" — a manufacturing scope, not a trading scope.
- Check the dates. ISO certificates run on a three-year cycle with annual surveillance audits; an "ISO 9001" document with no expiry date or no surveillance record is incomplete at best.
And one boundary worth stating plainly: an ISO 9001 certificate verifies a management system, not a product. It is not a substitute for UL, CE, or CPR product compliance — it is the quality-process layer underneath them.
Red Flags That Scream Fake Certificate
Some problems only show up after you have the certificate open next to the registry results. These are the patterns that recur in real sourcing:
- The number does not resolve. The file number, DoP number, or certificate number is not found in the official database. This is the decisive check.
- The registry shows a different company. The certificate is real, but it belongs to another legal entity — sometimes the parent, sometimes an unrelated firm. Certificates do not transfer with resale agreements.
- The scope does not match the claim. "Manufacturer" is on the website, "trading" is in the certificate scope. Or the scope lists products you are not buying.
- Dates that cannot be true. A certificate issued before the company's registration date, or an expiry date that has silently extended year after year.
- The issuing body is wrong. A "CE certificate" from a private company (there is no such thing), an ISO certificate from a body no accreditation directory lists, a CPR DoP citing a notified body number that NANDO does not know.
- The document has no number at all, or the number is decorative ("No. 001") — a certificate someone expects you to accept on appearance alone.
- The evidence trail stops. The supplier sends certificates readily but cannot produce the DoC, the DoP, or the test report behind them, or promises them "after the order."
- Vague standards references. "ISO 9001" without a year, "CE approved" without directives, "RoHS" without a directive reference.
None of these individually proves fraud — but any one of them is a legitimate reason to pause and demand a resolution before money moves.
What to Demand From Your OEM Supplier
Verification is a two-way street: your job is to check, and a serious OEM's job is to make checking easy. When you qualify a fiber optic supplier, ask for the complete document pack up front, in writing:
- Certificate copies with certificate numbers visible — not logo pages.
- The Declaration of Conformity for CE-marked products, naming directives, standards, and the EU authorized representative.
- The DoP for any CPR-classified cable, with Euroclass and notified body number.
- RoHS and REACH test reports from accredited labs, with report numbers and batch references.
- The UL file number and a link to the Product iQ listing for any UL-marked product.
- The ISO certificate number and issuing body, so you can run the IAF CertSearch check yourself.
- Audit access — the right to visit, or to commission a third-party inspection (services like SGS's supplier verification program exist precisely for this).
- A change-notification commitment: the supplier must tell you when materials, processes, or certificates change — otherwise last year's verified batch tells you nothing about this year's.
- Batch traceability tying test reports and certificates to the specific lots you order.
A useful benchmark when you evaluate the responses: how openly does the supplier publish its credentials? TTI Fiber, for example, publishes its certifications page with ISO 9001:2015 and ISO 14001:2015 certificate numbers, its CE, CPR, RoHS, and REACH compliance portfolio, and SGS third-party verification — the full evidence pack, no email ping-pong required. Any supplier that hesitates over the same documents is telling you something about how those documents would survive scrutiny.
A 10-Minute Supplier Certificate Verification Checklist
Run this the next time a certificate PDF lands in your inbox:
- Write down every certificate number on the documents.
- Open the right database for each type: UL Product iQ for UL, the Declaration of Conformity for CE, the NANDO database for CPR notified bodies, IAF CertSearch for ISO — all linked in the sections above.
- Search each number. If it does not resolve — stop and ask why.
- Match four things: company name, product scope, standards version, validity dates.
- Demand the evidence behind the declarations: DoC, DoP, RoHS/REACH test reports.
- Ask for audit access and a change-notification commitment.
- Re-verify annually, and whenever the supplier announces a change — certificates are living documents, and so is your approval of them.
A note on the limits of any checklist: the methods here are practical verification guidance, not legal advice, and the compliance decisions for your project — which Euroclass is required, which directives apply to your product — belong to your engineering and compliance teams. What the checklist guarantees is that you stop accepting scanned claims as proof. The ten minutes you spend verifying a supplier's certificates are the cheapest insurance in the fiber optic supply chain.
If you are evaluating manufacturers right now, compare how openly they publish their credentials, and use our guide to shortlisting fiber optic manufacturers to build the starting list. The suppliers who document themselves clearly at the qualification stage are usually the ones who keep their paperwork straight after the contract is signed.



