ISO 17025 Certification in USA

Looking at ISO 17025 certification? Talk to an assessor who reads scope schedules for a living. Contact IAS and send us your test and calibration method list.

✓ IAS is accredited by UQAS | ✓ Assessors with bench experience | ✓ Scope written method by method | ✓ Clear reporting, no surprises

ISO/IEC 17025 sets out what testing and calibration laboratories need in order to produce results that other people can rely on. It is short compared with most management system standards. It is also harder, because it asks technical questions that a quality manual cannot answer. Can you show the method works? Can you trace your measurements back to a reference? Do you know how wrong your number might be?

This page explains what ISO 17025 certification involves when a US laboratory applies to IAS, what gets examined, and where laboratories usually lose time.

What ISO 17025 asks of a laboratory

The standard has two halves that matter in practice.

The structural and management half looks familiar if you have been near ISO 9001. It covers impartiality, confidentiality, document control, complaints, nonconforming work, internal audit and management review. Most laboratories can build this, and anyone who has been through ISO 9001 internal auditor training will recognise the machinery.

The technical half is the one that decides the outcome. It covers personnel competence, equipment, metrological traceability, sampling, handling of test items, method selection and validation, evaluation of measurement uncertainty, quality control of results, and reporting. These clauses are assessed against what your bench actually does, not against what your procedure says it does.

An assessment team normally includes a technical assessor for each field in your scope. That person reads raw data. They ask to see the calculation behind a reported value, then work backward to the instrument, the calibration certificate and the analyst’s authorization record.

ISO 17025 certification, accreditation, and why this page says “certification”

A short, honest note before anything else. Laboratories are normally accredited to ISO/IEC 17025, not certified to it. That is the language the standard itself uses, and it is the language most purchasers use.

The distinction is real. Certification usually means a third party confirming that a management system conforms to a standard. Accreditation goes further: it is a formal attestation of technical competence to perform specific tests or calibrations, listed one by one on a scope document. An ISO 17025 assessment looks at whether you can produce a valid result for a named method on a named item, not merely whether you have a system.

This page uses the word “certification” because that is the service name and the term most people search for. Do not let the word mislead you. Whatever it is called on the cover, what is being examined is competence against a defined scope, and the scope is the part your customer should be reading. If you need the distinction spelled out for a procurement team, our note on accreditation and on certification bodies covers the general structure.

Who IAS is, and who accredits IAS

IAS — Integrated Assessment Services — is the body that assesses your laboratory and issues the certificate. IAS is itself assessed. IAS is accredited by UQAS. UQAS examines how IAS operates as a certification body: assessor competence, decision-making independence from the assessment team, impartiality controls, how scopes are granted and restricted, and record control.

The accreditation chain behind ISO 17025 certification: UQAS accredits IAS as a certification body, IAS assesses the laboratory, and the laboratory is
The accreditation chain behind ISO 17025 certification: UQAS accredits IAS as a certification body, IAS assesses the laboratory, and the laboratory issues reports and certificates to its own customers.

Read the chain in the right direction. UQAS accredits IAS. IAS assesses laboratories. The laboratory reports to its customers.

One point deserves saying plainly, because it is often blurred in marketing. Accreditation is an assessment of IAS, not an endorsement of any laboratory IAS certifies. UQAS has not examined your bench, your analysts or your uncertainty budgets. It has examined the body that will. When a customer asks “who accredits your certification body,” the answer is UQAS. When they ask “what does that say about our lab,” the answer is: nothing directly — that is what your own certificate and scope are for. You can read more about the organization on our about us page.

The scope schedule matters more than the certificate

The certificate is one page. It carries your name, the standard, dates and a reference number. It tells a reader almost nothing about what you can actually do.

The scope schedule is the document that matters. It lists, line by line, the field of testing or calibration, the item or material, the specific measurand or property, the method or standard used, and usually the measurement range and, for calibration work, its best measurement capability. A purchaser who knows the scheme reads the schedule and ignores the certificate.

This is also where disputes start. A laboratory holds a valid certificate, the customer sends a sample, and the specific test is not on the schedule. The certificate is genuine. The work is out of scope. Both facts are true at once.

Question a customer asksAnswered by the certificateAnswered by the scope schedule
Is this lab certified at all?YesNo
Can it run ASTM method X on my material?NoYes
What measurement range is covered?NoYes
What uncertainty can I expect on a calibration?NoUsually
Which site did the work?SometimesYes
Was the specific analyst authorized?NoNo — internal records only
Is the certificate current today?YesYes, if dated

Ask for both documents. If a supplier sends you only the certificate, ask again.

Method validation: the requirement laboratories underestimate

Standard methods used exactly as published need verification, not full validation. You show that your laboratory, with your staff and equipment, meets the method’s stated performance: precision data, a check against a reference material, and a documented conclusion.

Full validation is required when you develop your own method, modify a standard one, or use one outside its intended scope. Modification is the trap. Substituting a column, changing a digestion time, scaling a sample mass down — each takes you outside the published method. If the change is not documented and evaluated, the assessor treats the method as non-validated.

What a validation file needs:

  • A statement of the intended use, including matrix and range
  • The performance characteristics evaluated, with a reason for each
  • The raw data, not just the summary
  • Acceptance criteria decided before the work, not after
  • A signed conclusion on fitness for the intended use
  • A record of what changed from the published method, and why

The most common finding here is not absent validation. It is validation done once, years ago, on an instrument that has since been replaced, with no reassessment on record.

Metrological traceability, from the bench back to the SI

Traceability is an unbroken chain of calibrations, each with a stated uncertainty, linking your result to a reference. For most measurements that reference is the SI, delivered through a national metrology institute or a competent calibration laboratory.

Three things break the chain. First, a calibration certificate reporting “pass” or “within tolerance” without measured values and uncertainties — that is a conformity statement, not a calibration result. Second, reference materials bought without a certificate stating traceability and uncertainty; a material sold as “high purity” is not a certified reference material. Third, intermediate checks that are scheduled but never acted on, so drift is recorded and the instrument stays in use anyway.

Keep a traceability map: one page per measurement quantity, showing the instrument, its calibration source, the reference used, the interval and the last certificate number.

Measurement uncertainty, stated plainly

Every quantitative result has an uncertainty. The standard asks you to evaluate it, keep the working, and report it where relevant — where it affects validity, where the customer asks, or where it bears on a statement of conformity.

An uncertainty budget lists the contributions with their magnitudes, distributions and sensitivity coefficients, combined into a standard uncertainty and then expanded. It does not need to be elegant. It needs to be complete, defensible and current.

Two recurring problems: budgets that include only the main instrument’s calibration uncertainty, ignoring repeatability, operator effects, environmental variation and sample inhomogeneity; and budgets never revisited after a method change or an equipment swap.

Uncertainty also drives decision rules. If you state conformity to a specification, you must have a documented decision rule saying how uncertainty is handled at the limit — simple acceptance, guard bands, or something else — and the customer must have agreed to it. Reports that say “pass” with no decision rule on file are a frequent finding.

Impartiality, confidentiality and structure

The structural clauses are easy to pass and easy to fail carelessly.

Impartiality means identifying risks to it and showing what you do about them. A laboratory owned by a manufacturer that tests that manufacturer’s product has an obvious risk. That is not disqualifying, but it must be identified, evaluated and controlled in writing.

Confidentiality means customer information is protected, and that if you must release information you tell the customer unless prohibited. Electronic systems count. Shared drives with open permissions get written up. Laboratories holding a lot of sensitive client data sometimes handle that side formally through ISO 27001 certification.

You also need a defined legal identity, named management with technical responsibility, and deputies for key roles. A laboratory with one technical signatory and no deputy has a single point of failure, and assessors will say so. Our overview of system certification covers how these structural clauses sit alongside other schemes — ISO 14001 certification and ISO 45001 certification among them — and where laboratory certification asks for more than a system audit does.

Competence, training and authorization of staff

Competence is not a training certificate. It is a documented chain: job requirements, education and experience, training delivered, competence demonstrated on the actual method, formal authorization by a named person, and ongoing monitoring.

The step most often missing is authorization. Analysts run methods because they always have, with no record of who authorized them, for which method, on what date. Fixing this is administrative, not technical, but it takes longer than people expect.

Monitoring matters too. Proficiency testing, inter-analyst comparisons, blind replicates and supervised reruns all evidence that competence is maintained. For teams building internal capability, ISO 17025 internal auditor training covers auditing the technical clauses, and ISO 17025 lead auditor training suits those who will lead assessments or manage the program. Dates for both sit on the training schedule, and staff new to management system work often start with foundation training before the technical clauses. Current themes in that training are discussed in our note on lead auditor training trends.

The pathway to ISO 17025 certification

The route a laboratory takes from scope definition and application through document review, on-site assessment of the technical clauses, corrective ac
The route a laboratory takes from scope definition and application through document review, on-site assessment of the technical clauses, corrective action and the certification decision.

The sequence below is the normal route. The certification process and audit procedure pages describe the general mechanics; the table adds what is specific to an ISO 17025 audit of a laboratory.

StageWhat IAS doesWhat the laboratory needs ready
Scope definitionReviews the proposed method list and fieldsDraft scope: item, measurand, method, range
Application reviewConfirms competence to assess, assigns teamSite details, staff numbers, shift pattern
Document reviewReads the management system and key technical recordsManual, procedures, validation files, uncertainty budgets
On-site assessmentWitnesses testing, traces data, interviews analystsLive work to witness, raw data access, analysts present
Findings and responseIssues findings with clause referencesRoot cause analysis and evidence, not promises
DecisionIndependent review of the file and scopeNothing — the laboratory is not part of this step
IssueGrants certificate and scope scheduleLogo and claim controls in place

Two practical notes. Witnessing is the heart of the on-site stage, so schedule the assessment when real work is running. And do not submit a scope wider than you can demonstrate; a scope cut at the decision stage costs more time than a modest one extended later.

What good looks like, what weak looks like

This table reflects the findings that come up most often across laboratory assessments.

AreaWhat an assessor acceptsWhat an assessor questions
Method validationRaw data retained, criteria set in advance, revisited after changesSummary report only, criteria written after the result
TraceabilityCalibration certificates with values and uncertainties, mapped per quantity“Pass” certificates, no reference material documentation
UncertaintyBudget reflects the method as run today, all significant contributionsInstrument calibration uncertainty alone, never updated
Decision rulesAgreed with the customer, stated on the reportConformity stated with no rule on file
CompetenceAuthorization per analyst per method, dated and signedTraining certificates in a folder, no authorization step
EquipmentIntermediate checks reviewed, trends acted onChecks recorded, drift visible, nothing done
ReportingAmendments controlled and traceable to the originalReports reissued by overwriting the file
Internal auditTechnical clauses audited by someone competent in themAudit covers the manual, skips the bench
SubcontractingCustomer informed, subcontractor competence verifiedWork passed on quietly, results reported as your own

Most laboratories find the left-hand column already exists for their best methods. The work is extending it across everything on the scope.

After ISO 17025 certification: the surveillance cycle

The certification cycle: initial assessment, surveillance visits across the certificate's validity period, and reassessment before expiry, with scope
The certification cycle: initial assessment, surveillance visits across the certificate’s validity period, and reassessment before expiry, with scope changes handled as they arise.

ISO 17025 certification is not a one-time event. Surveillance visits sample the scope, follow up on previous findings, and check the system is still operating. Reassessment before expiry covers the scope again more fully.

Between visits, tell IAS what changes the basis of the certificate: a new site, a new or heavily modified method, loss of a sole technical signatory, a change in legal identity, or a significant equipment change. Adding a method is a scope extension and needs its own assessment.

Logo and claim use is controlled. Use the mark as permitted and do not imply a broader scope than you hold. The logo usage guideline sets out what is allowed.

What the scope schedule tells a customer

Be precise about this with your customers, because overstating it causes more trouble than the certificate is worth.

The certificate means IAS assessed your laboratory against ISO/IEC 17025 at a point in time, that the assessment covered the methods named on the scope schedule, and that the decision was made independently of the assessment team. Competence was demonstrated for that work, on that equipment, with those staff, at that site.

It does not mean every result you issue is correct. It does not cover methods outside the scope schedule, work at sites not listed, or results produced after competence has lapsed. It is not a product approval — that is what product certification is for — nor a safety certificate, nor a substitute for your customer’s own checks. It is not a guarantee, and nobody in the scheme offers one. Between visits, the certificate rests on your own controls.

Separately, this page makes no claim about the law in any country. Nothing here states or implies what a statute, regulation or contract requires of you. Whether ISO 17025 is needed for a particular purpose, and what legal duties apply to your laboratory, are questions for your own legal and regulatory advisers.

ISO 17025 certification: frequently asked questions

Is ISO 17025 certification the same thing as accreditation?

The standard’s own language is accreditation, because it attests technical competence for named methods. “Certification” is used here because it is the service name and the common search term. What is assessed is the same either way.

Does ISO 17025 certification cover every test we run?

No. It covers only what is on the scope schedule. Work outside the schedule is not covered, even while the certificate is valid.

Who accredits IAS?

IAS is accredited by UQAS. UQAS assesses IAS as a certification body — assessor competence, impartiality, decision independence and record control. That accreditation is an assessment of IAS, not of any laboratory IAS certifies.

Can we use a standard method without validating it?

You still need verification: evidence that your laboratory, staff and equipment meet the method’s stated performance. Full validation is required if you modify the method or use it outside its intended scope.

Do we have to report measurement uncertainty on every report?

Not always. Report it when it affects the validity or application of the result, when the customer requests it, and when it bears on a statement of conformity. Evaluate it in all cases for quantitative work.

What is a decision rule and do we need one?

It is the documented rule for how measurement uncertainty is handled when you state conformity to a specification. If you issue pass or fail statements, you need one, and the customer must have agreed to it.

How do we add a new method later?

Apply for a scope extension. IAS assesses the new method, and the scope schedule is updated. This is usually narrower than a full assessment.

What happens if our only technical signatory leaves?

Tell IAS. A sole signatory with no trained deputy is a real risk to the scope, and part of it may need to be suspended until competence is re-established. It is the same single-point-of-failure thinking that ISO 22301 certification applies at organisation level.

Does ISO 17025 replace ISO 9001 for our laboratory?

No. ISO 9001 addresses the quality management system broadly; ISO 17025 addresses laboratory competence for specific methods. Some laboratories hold both.

We are a medical laboratory. Is this the right standard?

Medical laboratories usually look at ISO 15189 instead, and medical device manufacturers at ISO 13485. Laboratories serving food producers often sit alongside ISO 22000 certification, and those in pharmaceutical supply chains alongside cGMP certification. Ask us if your work spans more than one.

Can we subcontract work and still report it under our certificate?

Only with the customer informed and the subcontractor’s competence verified and documented. Undisclosed subcontracting is a serious finding.

Where do we start with ISO 17025 certification if we have never done this?

Write the scope first, method by method. Then check each line against your validation, traceability and uncertainty records. The gaps will be obvious. Our ISO certification overview and the general FAQ page cover the wider picture, and training options are listed separately.

Ready to define your scope for ISO 17025 certification? Send your method list and we will tell you what evidence each line needs. Contact IAS or browse internal auditor training to build the capability in-house first.