Machining certification: what the four certificates actually cover
The certificates on a machine shop's wall are not the same thing. Each one governs a different part of the process, and each one matters to a different buyer. This page explains what ISO 9001, IATF 16949, ISO 13485 and ISO 27001 change about the way parts get made, and how to use them when you audit a supplier.

In this article
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
Key takeaways
What machining certification actually certifies
A machining certification is issued to a company and a site, not to a person. The auditor walks the floor, reads the work instructions, checks calibration records and samples the paperwork behind finished parts. If the shop can show that the process is defined and followed, the certificate is issued. Nothing in that audit measures whether a specific machinist can hold ±0.005 mm on a thin-wall aluminum part.
That distinction causes most of the confusion in sourcing. Buyers see ISO 9001 on a website and read it as a quality guarantee. Suppliers treat it as a baseline that almost every serious shop already holds. Both readings miss the useful part: the certificate tells you which controls exist, and you can then ask for the records those controls are supposed to produce.
The practical value shows up in three places. First, document control: drawings, revisions and change orders follow a defined path, so the part you receive matches the revision you approved. Second, traceability: material heats, machine logs and inspection results can be pulled back to a lot number. Third, corrective action: when something goes wrong, there is a record of what changed and why.
For a prototype run of five brackets, none of that changes the outcome much. For a 10,000-part automotive run or an implant housing, it is the difference between a manageable problem and an unanswerable one. The rest of this page explains which certificate covers which risk.
ISO 9001: the base layer every other certificate builds on
ISO 9001:2015 is a process standard. It asks a shop to define how work moves from order to shipment, to measure whether that flow performs, and to fix it when it does not. There are no required tolerances, no mandated inspection frequency and no material list. The shop writes its own procedures and the auditor checks that they are followed.
On a CNC floor, that usually shows up as a traveler document that follows each job. The traveler lists the operation sequence, the fixture, the tool, the inspection points and the sign-off. When a job is reworked, the traveler records why. This is why a certified shop tends to produce more consistent paperwork than an uncertified one, even when both run the same machines.
The weak point is that ISO 9001 is flexible by design. A shop can write loose procedures and still pass. That is why the certificate alone rarely decides a sourcing question. It tells you a system exists. It does not tell you the system is tight.
When GreatLight holds ISO 9001:2015 across its Dongguan and Singapore operations, the useful output for a buyer is not the logo. It is the ability to request raw material checks, in-process monitoring and final inspection records for a specific lot, and to get them.
- 1Ask for the scope statementConfirm the certificate names the site and processes that will make your part.
- 2Ask for a sample travelerA redacted job packet shows how much detail the system actually captures.
- 3Check the expiry dateCertificates run on three-year cycles with surveillance audits in between.
IATF 16949: what changes for automotive and EV parts
IATF 16949:2016 sits on top of ISO 9001 and adds the rules automotive customers expect. The core additions are part approval, statistical process control and a disciplined reaction to nonconforming product. A shop holding it has agreed to run PPAP-style documentation, maintain control plans, and track capability on the features that matter.
In practice, this changes how a job is set up before the first chip is cut. The control plan names each critical dimension, the gauge used to check it, and how often it is checked. Capability studies on a turning operation may require Cpk data across a sample run. If a dimension drifts, the reaction plan triggers before parts ship, not after.
This is heavier than most buyers need. A one-off fixture plate or a handful of brackets does not justify PPAP paperwork, and asking for it adds cost and time without reducing risk. IATF 16949 earns its keep when the part goes into a vehicle program with a multi-year production window and a recall exposure behind it.
For EV work, the added controls often center on high-current housings, busbars and thermal parts where a dimensional miss affects assembly or conductivity. The relevant question during sourcing is not whether the shop holds the certificate, but whether the certificate scope covers the process and the site doing your work.
ISO 13485: process control where records are the product
ISO 13485:2016 is written for medical device manufacturing. The emphasis is on documented traceability, controlled environments where needed, and validation of processes that cannot be fully verified by inspection alone. Cleaning, passivation and surface treatment often fall into that category because the result is hard to measure after the fact.
For a CNC shop, the practical impact is that every step has a record attached. Material certifications are kept with the lot. Inspection results are kept with the serial or lot number. If a device OEM needs to trace a batch back through machining, finishing and inspection, the shop can produce that chain.
The standard does not set a tolerance or a surface finish. A shop can hold ±0.005 mm and Ra 0.8–1.6 μm with or without it. What the certificate adds is confidence that the records describing those results were created under control, not reconstructed afterward.
This matters most for implant components, surgical instruments and diagnostic hardware, where a field issue can trigger a traceability request years later. For a non-medical bracket, the same paperwork burden buys little.
ISO 27001: the certificate most buyers overlook
ISO 27001:2022 covers information security, not manufacturing quality. It governs how a shop stores, transmits and disposes of customer data: CAD files, drawings, revision history, and anything a buyer would not want in public hands. The standard requires a risk assessment, defined access controls and an incident process.
Most sourcing teams never ask about this. They should, because the quote process already moves sensitive geometry across email and upload portals. A drawing for an unreleased product is exactly the kind of file that creates a problem if it leaks. A shop with ISO 27001 has defined who can open those files and how access is revoked.
The certificate is not a substitute for a non-disclosure agreement. It is a sign that the internal controls behind the NDA exist. GreatLight publishes its NDA terms and keeps uploads secure and confidential; ISO 27001:2022 is the formal structure behind that practice.
If your part is a prototype for an unannounced product, or your drawings carry proprietary geometry, this certificate belongs on your supplier checklist alongside the quality ones. It answers a different question than ISO 9001 does.
How to use certificates when you audit a supplier
Start with the scope statement on each certificate. It names the legal entity, the site and the activities covered. A certificate issued to a parent company does not automatically cover a satellite plant, and a certificate covering assembly does not cover machining. This is the single most common gap buyers miss.
Next, map the certificate to your part. A general industrial bracket usually needs ISO 9001 and a clear inspection report. An automotive production part needs IATF 16949 and the control plan behind it. A medical housing needs ISO 13485 and traceable records. A confidential prototype needs ISO 27001 and a signed NDA.
Then ask for evidence tied to your job, not the system in general. Request the material certificate for the actual lot, the dimensional report for the actual parts, and the inspection method used to produce it. A certified system makes those documents easy to produce. That ease is the real benefit.
Finally, separate certification from capability. A certificate says nothing about whether a shop can machine a 4,000 mm part, hold ±0.005 mm on a thin wall, or finish titanium without galling. Those are machine, tooling and experience questions. Ask them separately, and expect answers in numbers.
- 1Match scope to siteThe plant making your part must appear on the certificate.
- 2Match certificate to industryUse the table above to pick the one that fits your risk.
- 3Request lot-level recordsMaterial certs and inspection reports for the parts you receive.
- 4Check capability separatelyTolerance, size envelope and material experience are not covered by any certificate.
Which certificate covers which risk
Scopes as defined by each standard; applicability depends on your part and industry.
| Certificate | Main risk it controls | Typical buyer | What it does not cover |
|---|---|---|---|
| ISO 9001:2015 | General process consistency | Industrial, robotics, electronics | Industry-specific rules or part-level data |
| IATF 16949:2016 | Automotive part and process approval | Automotive and EV programs | Medical or information security |
| ISO 13485:2016 | Medical device manufacturing controls | Medical device OEMs | Automotive PPAP or IT security |
| ISO 27001:2022 | Protection of customer data and files | Any buyer sending CAD or IP | Machining accuracy or material trace |
Which certificate your part actually needs
Match the part and its end use to the controls you should request.
| Your situation | Ask for | Also request | Usually unnecessary |
|---|---|---|---|
| Industrial bracket, low volume | ISO 9001:2015 | Dimensional report on first article | PPAP, IQ/OQ/PQ |
| Automotive production part | IATF 16949:2016 | Control plan, capability data | Medical traceability |
| Medical device component | ISO 13485:2016 | Lot traceability, process validation | Automotive PPAP |
| Confidential prototype | ISO 27001:2022 | Signed NDA, access controls | PPAP, capability studies |
| Aerospace prototype | ISO 9001:2015 | Material certs, inspection data | Automotive control plan |
The short answer
If your part ships into a regulated program, pick the certificate that matches the industry and verify the scope covers the site. If you are buying prototypes or low-volume industrial parts, ISO 9001 plus lot-level inspection data beats a stack of logos you will never use.
Common questions about machining certification
Is a machining certification the same as an operator certificate?
No. A machining certification issued to a company covers the management system: how jobs are planned, documented, inspected and corrected. An operator certificate covers one person's skill on a machine.
Buyers auditing a supplier care about the first. The second is an internal staffing question, and no standard body issues it on a supplier's behalf.
Does ISO 9001 guarantee a specific tolerance or surface finish?
It does not. ISO 9001 contains no dimensional or finish requirement. It asks the shop to define its process and follow it.
Tolerance and finish are capability questions. Ask what the shop can hold on your geometry and material, and ask for inspection data from comparable parts.
Can a shop hold IATF 16949 without making automotive parts?
The certificate is issued for automotive production and service parts. A shop may hold it and use the same controls on other work.
For your project, the relevant question is whether the scope line covers the site and process that will run your part.
What does ISO 27001 change for a buyer sending CAD files?
It sets out how the shop classifies, stores and restricts access to your files, and how it responds if access is misused.
It does not replace an NDA, but it shows that the internal controls behind an NDA are audited.
How often do these certificates expire?
They run on three-year cycles with surveillance audits between full renewals. A certificate can be suspended if a surveillance audit finds a major gap.
Check the issue and expiry dates, and confirm the certificate number with the issuing body if the project risk justifies it.
We only need a few prototypes. Do certificates matter at all?
Less than for production. For a handful of parts, inspection data on the actual lot tells you more than a system certificate.
If the prototype is for an unannounced product, ISO 27001 and an NDA become relevant because the risk is the file, not the part.
Send drawings, get a quote and a DFM review
Quotation and free DFM analysis within 12 hours. Uploads are secure and confidential, and an NDA is available on request.
12-hour quote100% inspectionISO 9001:2015IATF 16949:2016