GreatLight CNC Machining Factory logo
CNC Machining
Rapid Prototyping
Materials
Industries
News
About GL

Get Instant Quote

Quality systems

Machining certification: what the four certificates actually cover

The certificates on a machine shop's wall are not the same thing. Each one governs a different part of the process, and each one matters to a different buyer. This page explains what ISO 9001, IATF 16949, ISO 13485 and ISO 27001 change about the way parts get made, and how to use them when you audit a supplier.

ISO 9001:2015IATF 16949:2016ISO 13485:2016ISO 27001:2022
Machining certification guide covering ISO 9001, IATF 16949, ISO 13485 and ISO 27001
Short version

Key takeaways

Certification is a system, not a testAn audit checks whether process controls exist and are followed. It does not rate one operator's skill.
Four certificates, four scopesISO 9001 is the base. IATF 16949, ISO 13485 and ISO 27001 each add controls for one industry or one risk.
Scope statements matter more than logosRead the certificate's scope line. A site certificate may not cover the process you are buying.
Certificates do not replace inspection dataAsk for dimensional reports, material certs and traceability on the actual lot.
The basics

What machining certification actually certifies

A machining certification is issued to a company and a site, not to a person. The auditor walks the floor, reads the work instructions, checks calibration records and samples the paperwork behind finished parts. If the shop can show that the process is defined and followed, the certificate is issued. Nothing in that audit measures whether a specific machinist can hold ±0.005 mm on a thin-wall aluminum part.

That distinction causes most of the confusion in sourcing. Buyers see ISO 9001 on a website and read it as a quality guarantee. Suppliers treat it as a baseline that almost every serious shop already holds. Both readings miss the useful part: the certificate tells you which controls exist, and you can then ask for the records those controls are supposed to produce.

The practical value shows up in three places. First, document control: drawings, revisions and change orders follow a defined path, so the part you receive matches the revision you approved. Second, traceability: material heats, machine logs and inspection results can be pulled back to a lot number. Third, corrective action: when something goes wrong, there is a record of what changed and why.

For a prototype run of five brackets, none of that changes the outcome much. For a 10,000-part automotive run or an implant housing, it is the difference between a manageable problem and an unanswerable one. The rest of this page explains which certificate covers which risk.

ISO 9001

ISO 9001: the base layer every other certificate builds on

ISO 9001:2015 is a process standard. It asks a shop to define how work moves from order to shipment, to measure whether that flow performs, and to fix it when it does not. There are no required tolerances, no mandated inspection frequency and no material list. The shop writes its own procedures and the auditor checks that they are followed.

On a CNC floor, that usually shows up as a traveler document that follows each job. The traveler lists the operation sequence, the fixture, the tool, the inspection points and the sign-off. When a job is reworked, the traveler records why. This is why a certified shop tends to produce more consistent paperwork than an uncertified one, even when both run the same machines.

The weak point is that ISO 9001 is flexible by design. A shop can write loose procedures and still pass. That is why the certificate alone rarely decides a sourcing question. It tells you a system exists. It does not tell you the system is tight.

When GreatLight holds ISO 9001:2015 across its Dongguan and Singapore operations, the useful output for a buyer is not the logo. It is the ability to request raw material checks, in-process monitoring and final inspection records for a specific lot, and to get them.

  • 1
    Ask for the scope statementConfirm the certificate names the site and processes that will make your part.
  • 2
    Ask for a sample travelerA redacted job packet shows how much detail the system actually captures.
  • 3
    Check the expiry dateCertificates run on three-year cycles with surveillance audits in between.
Automotive

IATF 16949: what changes for automotive and EV parts

IATF 16949:2016 sits on top of ISO 9001 and adds the rules automotive customers expect. The core additions are part approval, statistical process control and a disciplined reaction to nonconforming product. A shop holding it has agreed to run PPAP-style documentation, maintain control plans, and track capability on the features that matter.

In practice, this changes how a job is set up before the first chip is cut. The control plan names each critical dimension, the gauge used to check it, and how often it is checked. Capability studies on a turning operation may require Cpk data across a sample run. If a dimension drifts, the reaction plan triggers before parts ship, not after.

This is heavier than most buyers need. A one-off fixture plate or a handful of brackets does not justify PPAP paperwork, and asking for it adds cost and time without reducing risk. IATF 16949 earns its keep when the part goes into a vehicle program with a multi-year production window and a recall exposure behind it.

For EV work, the added controls often center on high-current housings, busbars and thermal parts where a dimensional miss affects assembly or conductivity. The relevant question during sourcing is not whether the shop holds the certificate, but whether the certificate scope covers the process and the site doing your work.

Medical

ISO 13485: process control where records are the product

ISO 13485:2016 is written for medical device manufacturing. The emphasis is on documented traceability, controlled environments where needed, and validation of processes that cannot be fully verified by inspection alone. Cleaning, passivation and surface treatment often fall into that category because the result is hard to measure after the fact.

For a CNC shop, the practical impact is that every step has a record attached. Material certifications are kept with the lot. Inspection results are kept with the serial or lot number. If a device OEM needs to trace a batch back through machining, finishing and inspection, the shop can produce that chain.

The standard does not set a tolerance or a surface finish. A shop can hold ±0.005 mm and Ra 0.8–1.6 μm with or without it. What the certificate adds is confidence that the records describing those results were created under control, not reconstructed afterward.

This matters most for implant components, surgical instruments and diagnostic hardware, where a field issue can trigger a traceability request years later. For a non-medical bracket, the same paperwork burden buys little.

Information security

ISO 27001: the certificate most buyers overlook

ISO 27001:2022 covers information security, not manufacturing quality. It governs how a shop stores, transmits and disposes of customer data: CAD files, drawings, revision history, and anything a buyer would not want in public hands. The standard requires a risk assessment, defined access controls and an incident process.

Most sourcing teams never ask about this. They should, because the quote process already moves sensitive geometry across email and upload portals. A drawing for an unreleased product is exactly the kind of file that creates a problem if it leaks. A shop with ISO 27001 has defined who can open those files and how access is revoked.

The certificate is not a substitute for a non-disclosure agreement. It is a sign that the internal controls behind the NDA exist. GreatLight publishes its NDA terms and keeps uploads secure and confidential; ISO 27001:2022 is the formal structure behind that practice.

If your part is a prototype for an unannounced product, or your drawings carry proprietary geometry, this certificate belongs on your supplier checklist alongside the quality ones. It answers a different question than ISO 9001 does.

In practice

How to use certificates when you audit a supplier

Start with the scope statement on each certificate. It names the legal entity, the site and the activities covered. A certificate issued to a parent company does not automatically cover a satellite plant, and a certificate covering assembly does not cover machining. This is the single most common gap buyers miss.

Next, map the certificate to your part. A general industrial bracket usually needs ISO 9001 and a clear inspection report. An automotive production part needs IATF 16949 and the control plan behind it. A medical housing needs ISO 13485 and traceable records. A confidential prototype needs ISO 27001 and a signed NDA.

Then ask for evidence tied to your job, not the system in general. Request the material certificate for the actual lot, the dimensional report for the actual parts, and the inspection method used to produce it. A certified system makes those documents easy to produce. That ease is the real benefit.

Finally, separate certification from capability. A certificate says nothing about whether a shop can machine a 4,000 mm part, hold ±0.005 mm on a thin wall, or finish titanium without galling. Those are machine, tooling and experience questions. Ask them separately, and expect answers in numbers.

  • 1
    Match scope to siteThe plant making your part must appear on the certificate.
  • 2
    Match certificate to industryUse the table above to pick the one that fits your risk.
  • 3
    Request lot-level recordsMaterial certs and inspection reports for the parts you receive.
  • 4
    Check capability separatelyTolerance, size envelope and material experience are not covered by any certificate.
At a glance

Which certificate covers which risk

Scopes as defined by each standard; applicability depends on your part and industry.

CertificateMain risk it controlsTypical buyerWhat it does not cover
ISO 9001:2015General process consistencyIndustrial, robotics, electronicsIndustry-specific rules or part-level data
IATF 16949:2016Automotive part and process approvalAutomotive and EV programsMedical or information security
ISO 13485:2016Medical device manufacturing controlsMedical device OEMsAutomotive PPAP or IT security
ISO 27001:2022Protection of customer data and filesAny buyer sending CAD or IPMachining accuracy or material trace
Decision table

Which certificate your part actually needs

Match the part and its end use to the controls you should request.

Your situationAsk forAlso requestUsually unnecessary
Industrial bracket, low volumeISO 9001:2015Dimensional report on first articlePPAP, IQ/OQ/PQ
Automotive production partIATF 16949:2016Control plan, capability dataMedical traceability
Medical device componentISO 13485:2016Lot traceability, process validationAutomotive PPAP
Confidential prototypeISO 27001:2022Signed NDA, access controlsPPAP, capability studies
Aerospace prototypeISO 9001:2015Material certs, inspection dataAutomotive control plan

The short answer

If your part ships into a regulated program, pick the certificate that matches the industry and verify the scope covers the site. If you are buying prototypes or low-volume industrial parts, ISO 9001 plus lot-level inspection data beats a stack of logos you will never use.

FAQs

Common questions about machining certification

Is a machining certification the same as an operator certificate?

No. A machining certification issued to a company covers the management system: how jobs are planned, documented, inspected and corrected. An operator certificate covers one person's skill on a machine.

Buyers auditing a supplier care about the first. The second is an internal staffing question, and no standard body issues it on a supplier's behalf.

Does ISO 9001 guarantee a specific tolerance or surface finish?

It does not. ISO 9001 contains no dimensional or finish requirement. It asks the shop to define its process and follow it.

Tolerance and finish are capability questions. Ask what the shop can hold on your geometry and material, and ask for inspection data from comparable parts.

Can a shop hold IATF 16949 without making automotive parts?

The certificate is issued for automotive production and service parts. A shop may hold it and use the same controls on other work.

For your project, the relevant question is whether the scope line covers the site and process that will run your part.

What does ISO 27001 change for a buyer sending CAD files?

It sets out how the shop classifies, stores and restricts access to your files, and how it responds if access is misused.

It does not replace an NDA, but it shows that the internal controls behind an NDA are audited.

How often do these certificates expire?

They run on three-year cycles with surveillance audits between full renewals. A certificate can be suspended if a surveillance audit finds a major gap.

Check the issue and expiry dates, and confirm the certificate number with the issuing body if the project risk justifies it.

We only need a few prototypes. Do certificates matter at all?

Less than for production. For a handful of parts, inspection data on the actual lot tells you more than a system certificate.

If the prototype is for an unannounced product, ISO 27001 and an NDA become relevant because the risk is the file, not the part.

Send drawings, get a quote and a DFM review

Quotation and free DFM analysis within 12 hours. Uploads are secure and confidential, and an NDA is available on request.

12-hour quote100% inspectionISO 9001:2015IATF 16949:2016

Follow

More from GreatLight

We publish setup notes, tooling trials and inspection data from the factory floor.

FacebookTikTokYouTubeLinkedInInstagramThreadsPinterest

Trusted by engineers and manufacturers worldwide

Tesla Ford Motor Company BYD Auto Denso Magna International Boeing Airbus Medtronic KUKA FANUC