A Certificate of Analysis (COA) is the document that tells you what’s actually inside the vial. The good ones independently verify purity, identity, and contamination. The bad ones are marketing dressed up as paperwork. Here’s how to read one — and which red flags say your vial isn’t what the label claims.
What a COA actually proves
A Certificate of Analysis is a manufacturer’s (or testing lab’s) signed document stating that a specific batch of product has been tested and meets specified criteria. It’s the supplier saying “here’s the analytical evidence that what’s in this vial matches what’s on the label.”
A good COA proves four things:
- Identity — the compound in the vial is the one named on the label, not a different molecule with similar mass
- Purity — how much of the vial contents is the target compound vs impurities
- Quantity — the stated mg actually matches what’s in the vial
- Contamination — absence of endotoxins, residual solvents, heavy metals, etc.
What a COA does not prove: safety in your specific research context, regulatory approval, or any claim about the compound’s effects. Those are separate concerns.
The fields that matter
Every legitimate COA has these fields. If any are missing, it’s not a full COA.
| Field | What to look for |
|---|---|
| Product name | Specific compound, not “peptide blend” or generic term |
| Batch / Lot number | Unique identifier — matches the number on your vial |
| Manufacture date | Recent (within last 12 months is ideal for peptides) |
| Expiry / retest date | Future date, with stated storage condition |
| Molecular formula | e.g. C62H98N16O22 for BPC-157 — should match published structure |
| Molecular weight | Numerical, should match published value for the compound |
| Appearance | “White lyophilised powder” or similar — describes what you should see when you open the vial |
| Purity (%) | Typically by HPLC, should be ≥98% for research-grade peptides |
| Test methods | Named techniques (HPLC, MS, etc.) — see below |
| Date of analysis | When the testing was performed |
| Authorising signature / lab name | A person, role, or accredited lab |
Test methods — what they tell you
HPLC (High-Performance Liquid Chromatography)
The standard purity test. Separates compounds in a sample and measures how much of each is present. A clean HPLC trace with a single dominant peak (≥98%) means the vial contents are mostly the target compound. Multiple peaks of comparable height mean there’s other stuff in there.
MS (Mass Spectrometry)
The standard identity test. Measures the molecular mass of compounds in the sample. The reported mass should match the known molecular weight of the target peptide within a small tolerance (typically ±0.1 Da). Mismatched mass means whatever you have, it’s not what the label says.
HPLC-MS combined
The gold standard. Combines purity (HPLC) with identity (MS) in one analysis. A COA citing HPLC-MS is generally more trustworthy than one citing either alone.
Endotoxin testing (LAL assay)
Tests for bacterial endotoxin contamination. Important for injectable peptides — endotoxins survive sterilisation and cause inflammatory reactions even at trace levels. A research-grade COA should report endotoxin levels in EU/mg (Endotoxin Units per milligram). Acceptable: ≤10 EU/mg. Better: ≤1 EU/mg.
Residual solvent / heavy metals
Some COAs include these. Not always required for peptides (the synthesis chemistry rarely produces residual solvents at concerning levels), but their presence on a COA indicates the supplier is being thorough.
Red flags
Third-party vs in-house COAs
A COA can come from either the manufacturer’s internal QC lab or a third-party testing facility. Both can be legitimate, but the trust profile differs:
- In-house COA: faster, cheaper, but the manufacturer is grading their own homework. Most volume research suppliers operate this way.
- Third-party COA: the sample is sent to an external accredited lab. Costs the supplier more but is far harder to fake. Ideal for high-stakes batches.
Many suppliers offer both — an in-house COA included by default and a third-party COA available on request (sometimes for a fee). For most research applications, an in-house COA from an established supplier is sufficient. For batches where you want maximum verification, third-party testing closes the trust gap.