How to Verify a Development Partner’s Certifications and Credentials

ISO 9001 verifies how a firm manages its own quality system, not whether your product will pass FCC or UL testing. Here is how to check company certifications, entity status, and accreditation independently before you sign a contract.

Key takeaways

  • A company certification describes the firm’s internal processes. A product certification describes your product. They are not interchangeable.
  • ISO 9001 means an accredited body audited the quality management system. It says nothing about whether the firm is good at engineering.
  • ISO/IEC 27001 is the one that covers how your confidential design data is handled.
  • Every link in a certification chain is checkable without the firm’s help: ask for the certificate number and the certification body, then verify both directly.

Verifying a development partner’s certifications means checking claims about the company itself, separately from any claims about your future product. A firm that says it is “ISO 9001 certified” is making a statement about how it manages its own business. A claim that your finished product will pass FCC or UL testing is a completely different kind of claim, made about a device that does not exist yet. Confusing the two is one of the more common mistakes founders make when comparing vendors, and this guide is built around keeping that line clear.

This is one piece of a larger vetting process. For the full sequence from shortlist to signature, see our guide to how to vet a hardware development company before you sign.

Company certifications versus product certifications

A company certification says something about the firm’s internal processes: how it manages quality, documentation, or information security. A product certification says something about a specific device: whether it meets FCC radio-frequency rules, UL safety standards, or CE requirements for a market. A development firm being ISO 9001 certified tells you nothing about whether your specific product will pass FCC testing, and a firm’s FCC compliance experience on past projects tells you nothing about the rigor of its own internal quality system.

Question What it verifies
Is the firm ISO 9001 certified? Company: how the firm manages its own quality processes
Is the firm ISO/IEC 27001 certified? Company: how the firm protects confidential information, including your files
Is my product FCC certified? Product: whether a specific device meets radio-frequency rules
Is my product UL listed? Product: whether a specific device meets electrical safety standards

This guide covers only the company side of that table. Product certification cost and process is a separate topic with its own considerations.

ISO 9001 and what it does and does not prove

ISO 9001 certification means an accredited, independent certification body has audited the firm’s quality management system against the ISO 9001 standard and found it compliant. ISO itself does not perform certification and does not issue certificates; certification is carried out by separate, accredited bodies. ISO 9001 verifies that the firm has a documented, monitored, and continually reviewed process for managing quality. It does not verify engineering competence on any specific kind of product.

Scope statements and why they matter

Every ISO 9001 certificate carries a scope statement describing which activities, products, and services it actually covers, at which physical locations. A firm can be legitimately certified for one part of its business while a different, uncertified part handles your project. Ask for the certificate’s scope directly, not just the badge on the website, and confirm your engagement actually falls inside it.

  • Ask which physical site the certificate covers, if the firm operates more than one location.
  • Ask whether product design and engineering are inside the certified scope, or only manufacturing operations.
  • Ask when the certificate was last audited; certifications require ongoing surveillance audits, not a one-time badge.

ISO/IEC 27001 and handling your confidential design data

ISO/IEC 27001 certification means the firm has implemented an information security management system audited against that standard, covering how it manages risk to the confidentiality, integrity, and availability of information. For a development engagement, the practical question is whether that certified scope includes the engineering function specifically, since that is the team that will hold your CAD files, firmware, and bill of materials. A firm certified only for its finance or HR systems, with engineering outside the certified scope, has not actually demonstrated anything about how your files are protected.

Regulated-industry credentials

What FDA-cleared means and who it applies to

These terms are precise and frequently used loosely in sales conversations, so verify the specific one being claimed.

  • FDA registered is an administrative filing under 21 CFR Part 807. Under 21 CFR § 807.39, registration “does not in any way denote approval” of the facility or its products, and FDA states plainly that any representation implying otherwise is misleading and constitutes misbranding. A firm that displays an “FDA registration certificate” to imply official approval is misusing an administrative filing, and FDA has noted that no such certificates are issued by the agency at all.
  • 510(k) cleared means FDA reviewed a submission and found the device substantially equivalent to a legally marketed predicate device. This applies to a specific device, not a company generally.
  • FDA approved refers to premarket approval, reserved for Class III devices requiring the most extensive review, based on submitted evidence of safety and effectiveness.

A firm claiming any of these on your behalf should be able to point to the specific device and submission type involved, since none of the three applies to a company as a blanket credential.

Entity checks

Where the company is registered and who you contract with

The name on a firm’s website is not always the name on the contract. Confirm the exact legal entity, its state of registration, and its current standing before you rely on any of its other claims.

  • Ask for the exact legal entity name that will appear on your contract, not just the brand name.
  • Check that state’s Secretary of State business search. Most states publish an entity’s status as active, suspended, forfeited, or dissolved, and a status other than active is worth asking about directly.
  • Do not expect a public EIN lookup for a for-profit company. The IRS only publishes a searchable EIN database for tax-exempt organizations, so a commercial vendor’s EIN is not independently checkable that way.
  • If the firm does federal contracting work, it will have a Unique Entity ID through SAM.gov, which replaced the older D-U-N-S number on 4 April 2022. This is a federal-contracting identifier, not a general-purpose credential for a private buyer, so treat it as supporting evidence rather than a primary check.

How to verify a certificate independently

Verifying an accredited certification is a short chain, and each link is checkable without the firm’s help.

  1. Ask for the certificate number and the name of the certification body that issued it.
  2. Confirm that certification body is itself accredited, through the ANSI National Accreditation Board’s directory in North America or an equivalent national accreditation body elsewhere.
  3. Cross-check the organization, the certification body, and the accreditation body together through IAF CertSearch, the database used across the international accreditation system. The International Accreditation Forum and the International Laboratory Accreditation Cooperation both ceased operating as independent bodies on 1 January 2026, unified into Global Accreditation Cooperation Incorporated, though the certificate search itself continues to run under its existing name.
  4. Check the certificate’s stated scope and its next surveillance audit date, not just whether it is currently listed as active.

When a certificate is not the point

A certification is evidence of a process, not a guarantee of a good outcome on your specific product. A firm with every relevant certificate can still be the wrong fit if it has never worked on anything like what you are building, and a younger firm without a formal certificate can still run a disciplined process if you can see it directly. Certificates narrow your risk. They do not replace looking at the firm’s actual work and talking to people who have worked with it, covered in our companion guide to how to check a product development company’s references.

Frequently asked questions

Does ISO 9001 certification mean a firm is good at engineering?

No. It means the firm has a documented, audited quality management system. It says nothing about the technical quality of its engineering work on any particular kind of product.

Is ISO certification required to be a legitimate development partner?

No. Many capable firms, particularly smaller ones, are not ISO certified. Certification is one useful data point, not a requirement, and its absence is not itself disqualifying.

What does “FDA registered” actually mean?

It means the facility filed an administrative registration with FDA. By federal regulation, this does not denote approval of the facility or its products, and presenting it as approval is considered misleading.

How do I check if a certification body is legitimate?

Confirm it is accredited by a recognized national accreditation body, such as the ANSI National Accreditation Board in the United States, and cross-check the certificate through IAF CertSearch.

Does my development partner need to be ISO 13485 certified for a medical device?

Medical device manufacturing quality requirements are a specialized area with their own regulatory framework, tied to FDA’s Quality Management System Regulation. If your product is a medical device, ask directly about the firm’s specific experience and certifications in that framework, and confirm the details with an attorney or regulatory consultant rather than relying on general guidance.

What is the single most useful question to ask about a certification claim?

“What is the certificate number, and which accredited body issued it?” A firm with a real, current certification answers immediately. A vague answer is worth following up on directly.

Where Inventornest fits

Inventornest can point you to the specific certifications relevant to your engagement, describe exactly what each one covers, and tell you plainly where a claim does not apply rather than letting a vague credential do the work of a real answer. If you want to walk through what matters for your specific product, you can book a consultation. Our OEM development and manufacturing services page has more on how we structure and document engagements.

Not sure what comes next?

Describe your product and we will tell you honestly which stage comes next, and what it would cost.

Book a free consultation
Every engagement begins under NDA, and you retain full ownership of all resulting IP, design files, firmware and documentation.
Muhammad Mohsin Aslam, Founder and CEO of InventornestWritten byMohsin Aslam

Electrical engineer and Founder & CEO of Inventornest. He leads an in-house team covering industrial design, mechanical engineering, electronics, embedded firmware and manufacturing.

On this page

Free consultation

Tell us what you are building. We will tell you which stage comes next.

Book now

Bring us the idea. We will tell you what it takes to build it.

Feasibility analysis, prototyping, design for manufacturing and certification, from one in-house team.

Free Consultation
Keep reading

Related guides