US Manufacturing
How Certifications Influence Manufacturing Supplier Selection

TL;DR
Certifications are a screening filter, not a guarantee of the sale. Different industries require different credentials: aerospace wants AS9100, automotive wants IATF 16949, medical device wants ISO 13485, defense work often needs ITAR registration and NIST 800-171 compliance. Not every buyer requires every certification. Publish what you actually hold, link to the issuing body, and never claim a certification you do not have current audit evidence for.
Quick answers
- What is the difference between ISO 9001 and AS9100?
- AS9100 is built on ISO 9001 with additional aerospace-specific requirements around traceability, configuration management, and risk. A shop can hold ISO 9001 without AS9100, but AS9100 always includes ISO 9001's core quality management requirements.
- Do I need IATF 16949 to supply automotive Tier 2 or Tier 3 work?
- It depends on the OEM and program. Some Tier 1s require full IATF 16949 certification from sub-suppliers; others accept ISO 9001 plus a documented PPAP process. Confirm directly with the buyer's quality department.
- Is ITAR a certification?
- No. ITAR is a registration with the U.S. Department of State's Directorate of Defense Trade Controls, required for manufacturers that produce, export, or handle defense articles and technical data on the U.S. Munitions List.
- What does NIST 800-171 compliance mean for a small manufacturer?
- It means implementing the security controls in NIST Special Publication 800-171 to protect Controlled Unclassified Information, typically required as part of DFARS clauses for Department of Defense supply chain contracts.
- Does every buyer require ISO 9001?
- No. Many commercial and industrial buyers work with uncertified shops if the quality system, inspection records, and references hold up. ISO 9001 reduces friction in the qualification process but is not universally mandatory.
Certifications do not win the job on their own, but the wrong certification story, missing, outdated, or overstated, can eliminate you from consideration before an engineer even reviews your capability. Here is what each major manufacturing certification and registration actually covers, who requires it, and how to present it accurately.
Why this matters more than most shops treat it
Procurement and quality teams commonly run a first-pass filter on certifications before reading anything else about a supplier. Get this wrong in either direction, claiming something you do not hold or failing to clarify what you do hold, and you either get disqualified on an audit check or waste a sales cycle on a program you were never going to qualify for.
The certifications and registrations that come up most often
ISO 9001 - Quality Management Systems
ISO 9001 is the baseline international standard for quality management systems, applicable across nearly every manufacturing sector. It covers documented processes, corrective action, management review, and continual improvement. It is issued by accredited registrars following the ISO 9001 standard published by the International Organization for Standardization.
Most commercial and industrial buyers see ISO 9001 as a baseline signal of process discipline, not a differentiator on its own.
AS9100 - Aerospace Quality Management
AS9100 builds on ISO 9001 with aerospace-specific requirements: configuration management, risk management, first article inspection, and counterfeit parts prevention. It is required by most aerospace primes and Tier 1 suppliers before a shop can bid on flight-critical or safety-critical work. Standard details are maintained by the International Aerospace Quality Group.
IATF 16949 - Automotive Quality Management
IATF 16949 is the automotive industry's quality management standard, layering requirements like production part approval process (PPAP), advanced product quality planning (APQP), and statistical process control on top of ISO 9001 fundamentals. It is governed by the International Automotive Task Force. Many Tier 1 automotive OEMs require it from direct suppliers; Tier 2 and Tier 3 shops are sometimes accepted with ISO 9001 plus a documented PPAP capability instead, depending on the program.
ISO 13485 - Medical Device Quality Management
ISO 13485 is the standalone quality management standard for medical device manufacturers, covering risk management, design controls, and regulatory traceability specific to devices. It is published and maintained by ISO. Medical device OEMs and contract manufacturers commonly require it from suppliers producing components that go into a regulated device, particularly where FDA design history file traceability is involved.
ITAR Registration - Defense Trade Controls
ITAR (International Traffic in Arms Regulations) registration is administered by the U.S. Department of State's Directorate of Defense Trade Controls. It is not a quality certification; it is a legal registration required for manufacturers that produce, export, or provide technical data related to items on the U.S. Munitions List. Holding ITAR registration signals a shop can legally handle defense-related work, but it says nothing about quality system maturity on its own.
NIST 800-171 - Protecting Controlled Unclassified Information
NIST Special Publication 800-171, published by the National Institute of Standards and Technology, defines security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems. It is typically required through DFARS clauses for manufacturers in the Department of Defense supply chain. Compliance is generally self-attested and increasingly verified through the Cybersecurity Maturity Model Certification (CMMC) program layered on top of it.
The certification-to-industry map
| Certification / Registration | Governing Body | Primary Industry | Typically Required By |
|---|---|---|---|
| ISO 9001 | ISO | General manufacturing | Broad commercial and industrial buyers |
| AS9100 | IAQG | Aerospace and defense | Aerospace primes, Tier 1 suppliers |
| IATF 16949 | IATF | Automotive | Automotive OEMs, some Tier 1s |
| ISO 13485 | ISO | Medical devices | Medical device OEMs and contract manufacturers |
| ITAR registration | U.S. Dept. of State DDTC | Defense articles / technical data | Defense primes, munitions list programs |
| NIST 800-171 | NIST | DoD supply chain / CUI handling | Department of Defense contracts via DFARS |
Not every buyer requires every certification
This is the point most manufacturer websites get wrong in both directions. A shop serving general industrial and commercial customers does not need AS9100 or ITAR registration, and claiming them without an active program behind them creates a credibility problem the moment a buyer asks for documentation. Conversely, a shop pursuing aerospace or defense work without the relevant certification will be filtered out before the RFQ stage regardless of machine capability.
The practical approach:
- Audit your actual buyer base. If you have never bid a defense or aerospace program, do not lead your homepage with ITAR or AS9100 language.
- Publish only certifications with current, verifiable status. Include the certificate number, registrar name, and last audit or renewal date.
- Link to the issuing body's page describing the standard, not just a badge image. This gives buyers and search engines a verifiable reference point and avoids the appearance of a decorative logo.
- State plainly what you are pursuing versus what you hold. "AS9100 certification in progress, target completion Q2" is honest and still useful information; presenting it as already complete is not.
How this connects to the rest of your capability story
Certifications answer "can I trust your quality system." They do not answer "can your equipment make this part," which is a separate question covered in how to present materials, tolerances, and machine capability online. Buyers evaluate both together, and a strong capability page with an accurate, well-documented certifications page is what moves a supplier from "found" to "shortlisted" in the process our manufacturing capability pages and RFQ guide describes in more detail.
Once certifications are documented accurately, the next step is proving you can deliver against them, which is where verifiable case studies matter; see manufacturing case studies buyers actually trust.
CTA
Want to know if your certifications and quality documentation are presented the way engineering and procurement teams expect? Run my free Buyer Reach Audit to check your current site against what buyers actually search for. To go deeper on your full qualification funnel, book a 30 minute manufacturing growth audit.
60-second live scan
See where your buyers are searching - right now.
Run your buyer-intent keywords through live Google. Get a competitor map and ranking gaps in 60 seconds. Free, no pitch.
Run my free Buyer Reach AuditPrefer a working session?
Book a 30-min call with our team.
No pitch. Walk away with a written action plan - whether you hire us or not.
Book a strategy callFor US manufacturers
Tired of ThomasNet junk leads?
Run a free 60-second audit of where your buyers are searching in the US. Get a real diagnosis — no pitch.
Questions about this topic
How long does it take to get ISO 9001 certified?
Timelines vary by shop size and existing documentation maturity, commonly ranging from several months to over a year including the required stage 1 and stage 2 audits by an accredited registrar.
Can a shop claim 'ISO 9001 compliant' without being certified?
It can claim to follow ISO 9001 principles, but should not present itself as certified unless it holds a current certificate from an accredited registrar, since buyers commonly ask for the certificate number and audit date.
What is the relationship between AS9100 and ITAR?
None directly. AS9100 is a quality management standard; ITAR is an export control registration. An aerospace defense supplier may need both, but one does not substitute for the other.
Does ISO 13485 replace ISO 9001 for medical device manufacturers?
ISO 13485 is a standalone quality management standard for medical devices, though it is structured similarly to ISO 9001. Many medical device manufacturers hold ISO 13485 without separately maintaining ISO 9001 certification.
Where should certification information live on a website?
On a dedicated certifications or quality page with certificate numbers, issuing registrar, expiration or renewal cycle, and a link to the issuing organization's page describing the standard.
What happens if I list a certification I let lapse?
It creates a compliance and credibility risk. Buyers doing supplier audits or RFQ due diligence commonly verify certificates directly with the registrar or issuing body, and a lapsed certification presented as active can disqualify you from a bid.
Related field guides