Skip to content

In development, not yet available

Never get caught by an expired supplier certificate

Supplier ISO certificates expire quietly. The PDF sits in a folder, the date sits in a spreadsheet, and nothing happens when it lapses. You find out during a surveillance audit, when an assessor picks three names off your approved supplier list and asks for current evidence.

We are building this. Join the early access list and we will email you when it opens.

We add you to the early access list for this one feature. One email when it opens. No newsletter, no drip sequence, and your suppliers are never contacted.

Not ready to wait? Two free supplier tools on this site work right now, in your browser:the approved supplier list templateandthe supplier scorecard calculator.

Why an expired certificate is a silent failure

Nothing breaks when a supplier certificate expires. Parts keep arriving, invoices keep clearing, and the person who set up that supplier three years ago may not work here anymore. The certificate is a piece of paper with a date on it, and a date in a spreadsheet has no clock attached. It does not raise its hand. That is the whole problem in one sentence.

The failure surfaces somewhere expensive. An assessor samples your approved supplier list and asks for current evidence on three of them. A customer runs a supply chain audit before releasing a new program. A recall investigation traces a nonconforming lot back to a heat treater whose approval lapsed eleven months ago. In each case the work was probably fine. What you cannot show is that you were controlling it, and control you cannot show is control you do not get credit for.

Where the spreadsheet gives out

Almost every small and mid-size manufacturer starts here, and for a while it is the right answer. A tab called Approved Suppliers, a column for the certificate expiry, a folder of PDFs beside it. It stops working in predictable ways.

  • No clock. The sheet knows the date. It just never tells anyone. Somebody has to remember to open it, sort by expiry, and act, every month, forever.
  • One owner. The list is usually maintained by one person who knows which rows are stale and which supplier is mid-renewal. When they change roles, that knowledge leaves with them.
  • No history. Typing over a cell erases the state before it. Ask who moved a supplier from conditional to approved, when, and on what evidence, and the honest answer is a memory rather than a record.
  • The file drifts from the row. The expiry date in the sheet and the date on the actual certificate stop agreeing, usually because a renewal arrived by email and got filed but not entered.
  • Scope is not modeled. A supplier is not approved in general. They are approved for something. A shop cleared for machining is not automatically cleared for the special process on the next print, but a single Approved column cannot say that.
  • Copies multiply. A second site keeps its own version. Purchasing keeps a third. All three are slightly different, and the one the assessor is handed is whichever was easiest to find.

None of that is a discipline problem. It is a tooling problem. A spreadsheet is a very good way to hold a list and a very poor way to hold a schedule with consequences attached to it.

What we are building

This is the plan, written as a plan. None of it is shipping yet, so read every line below as intent rather than a feature list you can go and use. The early access list is where the details get confirmed, including what makes the first release and what waits.

Every supplier certificate and audit date in one list

ISO 9001, AS9100, IATF 16949, ISO 13485, Nadcap, ISO/IEC 17025 scopes, insurance, and any other dated document, each with the issuing body, certificate number, scope of approval, and expiry date. One list your team maintains, not fifteen PDFs in a shared drive and a spreadsheet column that was accurate the day it was typed.

Alerted before a certificate expires, not after

Lead times you set, so a certificate that lapses in 90, 60, or 30 days reaches the person who owns that supplier while there is still time to ask for the renewal. The failure mode today is silence: nothing happens on the expiry date, so nobody notices until an auditor picks that supplier off your list.

An approved vendor list with status and history

Approved, conditional, on hold, or removed, with the scope each supplier is approved for. Every status change keeps the date, the person, and the reason, so the question every assessor asks, who approved this supplier and on what evidence, has an answer you can show instead of recall.

Supplier performance you can score and re-evaluate

Quality acceptance, on-time delivery, and responsiveness recorded per period, rolled into a score you define the weighting for. Re-evaluation stops being an annual scramble through emails and becomes a record that already exists, which is what clause 8.4.1 is really asking you to retain.

What it will not do

Being clear about the edges now is cheaper than disappointing you later.

  • No supplier portal. Your suppliers never log in. There is no account for them to create, no upload for them to forget, and no adoption problem for you to manage. Your team holds the records.
  • Not a full QMS. No document control, CAPA, internal audit scheduling, or training records. It is a supplier records tool, and it should sit next to whatever QMS you already run.
  • Not a sourcing marketplace. It will not find you new suppliers, rate them against an industry database, or broker introductions. It manages the suppliers you have already chosen.
  • It does not read the certificate for you.You enter or confirm what the document says. Automatic extraction that is right most of the time is worse than useless on a date this consequential.

Why we are the ones building it

Axiospec already makes calibration management software. That product is live today, and it exists to answer one question under pressure: can you prove this instrument was in tolerance when it was used. It is built around ISO 9001, ISO/IEC 17025, AS9100, IATF 16949, and ISO 13485 requirements, and it is built for the person supplier records usually land on: a small quality team with a lot of ground to cover and no appetite for another system to babysit.

Calibration records and supplier approvals have the same shape. Both are a decision, made by a person, on a date, supported by evidence, valid until something expires. Both are worthless in an audit unless the history behind them survived. So the machinery we would build for supplier records is the machinery we already run for calibration records.

The specific piece worth naming is the ledger. Calibration events in Axiospec are written to an append-only, tamper-evident ledger with maker and checker review, so a result cannot be quietly edited after the fact. A correction is recorded as a correction, with the original still visible and the person who made it attached. Supplier approvals would be recorded the same way: adding a supplier, changing a status, renewing a certificate, and recording a re-evaluation all become ledger entries rather than overwritten cells.

That is also the reason we are validating this with a list instead of a launch. We would rather find out now that the real pain is somewhere else, and build that instead.

What the standards actually ask for

Worth saying plainly first: no standard requires you to collect an ISO certificate from a supplier. The certificate is evidence you chose to rely on, not the requirement itself. The requirement is that you control external providers in a way proportionate to their effect on your product, and that you keep records of doing it. Once you decide a certificate is part of that control, keeping it current stops being optional, because a lapsed certificate quietly removes the basis for the approval you granted.

ISO 9001 clause 8.4

Clause 8.4.1 asks you to determine and apply criteria for the evaluation, selection, monitoring of performance, and re-evaluation of external providers, and to retain documented information of those activities and of any actions arising from them. Read the verbs. Monitoring and re-evaluation are continuous, not a one-time gate at onboarding. Clause 8.4.2 asks you to define the type and extent of control based on the effect the supplier has on conforming product, which is why a fastener distributor and a special process house should not be governed by the same rule. Clause 8.4.3 covers the requirements you communicate to the provider before the work starts.

In practice an assessor at a small manufacturer opens the approved supplier list, picks a few rows, and asks three things: what criteria did this supplier meet, where is the evidence, and when did you last re-evaluate them. A list with a stale certificate date answers none of the three.

AS9100 in aerospace

AS9100 keeps the 8.4 structure and tightens it. You maintain a register of approved external providers that includes the scope of each approval, you review supplier performance periodically and keep records of the review, and you take action when performance slips. Approvals are explicitly scope-limited, so a supplier approved for one process is not approved for another by default. Requirements flow down through the chain, including customer directed sources and, where it applies, Nadcap accreditation for special processes such as heat treat, welding, chemical processing, and nondestructive testing. Those accreditations carry their own expiry dates, and they are the ones most likely to lapse unnoticed because they sit one level below the supplier ISO 9001 certificate everyone remembers to check.

IATF 16949 in automotive

IATF 16949 is the least forgiving of the four about supplier monitoring, because it names the indicators. You are expected to have a documented supplier selection process, a supplier quality management system development path toward third-party ISO 9001 certification, and ongoing monitoring of delivered part quality, customer disruptions including field returns, delivery schedule performance including incidents of premium freight, and any special status customer notifications. That is a scorecard whether you call it one or not, and it has to be maintained rather than reconstructed the week before the audit.

ISO 13485 in medical devices

ISO 13485 clause 7.4.1 asks for criteria for evaluating and selecting suppliers that are proportionate to the risk the purchased product carries and to its effect on the finished device, plus monitoring and re-evaluation of supplier performance and records of the results, including any necessary actions. The risk proportionality is the part that trips people up: the same evaluation depth applied to every supplier is both too much work for the low-risk ones and too little scrutiny for the critical ones.

The common thread

Four standards, one underlying demand: know the current status of every supplier you rely on, be able to show how you decided, and be able to show that the decision is still being maintained. Certificates and audit dates are the clearest, most checkable slice of that, which is why they are where a supplier records tool should start.

Two things you can use today

The software is not ready. These are, and they are free with no account. Between them they cover the two jobs most teams are doing by hand: holding the approved supplier list in a structure that will survive an audit, and turning supplier performance into a number you can defend.

Approved supplier list template

A structured approved vendor list you can fill in and export, with the fields assessors actually ask about: scope of approval, approval status, certificate and expiry, last evaluation, and next re-evaluation. Built to match the record set clause 8.4 expects you to retain.

Open the template

Supplier scorecard calculator

Turn quality acceptance, on-time delivery, and responsiveness into a weighted supplier score with the weighting visible rather than buried. Useful for the periodic performance review that AS9100 and IATF 16949 both expect you to record.

Open the calculator

Common questions

  • Is this available yet?

    No. Supplier certificate expiry tracking is in development and is not something you can buy or use today. The early access list is how you hear first. When it opens we email the list before we announce it anywhere else, and we will say plainly what is finished and what is not. If you need something you can use this week, the approved supplier list template and the supplier scorecard calculator on this site are free and ready now.

  • What will it cost?

    Pricing is not final, so we are not going to quote a number we might have to walk back. The direction we expect to follow is the same one our calibration product uses: priced per site rather than per user, so adding a quality engineer or a buyer to the account does not raise the bill. We will confirm the actual pricing with the early access list before anyone is asked to pay for anything.

  • Do my suppliers need an account?

    No. It is designed so only your team logs in. You hold the supplier records, you enter or confirm the certificate details, and you keep the evidence files. There is no supplier portal, no supplier login, and no request for your suppliers to adopt a new system. Chasing a certificate is already awkward enough without also asking the supplier to create an account before they can send you a PDF.

  • Does it replace my QMS?

    No. It focuses on supplier records and expiry: certificates, audit dates, approval status, scope of approval, performance scores, and the history behind each decision. Document control, CAPA, internal audit scheduling, training records, and management review stay wherever you run them today. The aim is to close one specific gap well rather than become a second, weaker QMS.

  • What standards does it help with?

    The design follows the supplier control requirements common to ISO 9001 clause 8.4, AS9100, IATF 16949, and ISO 13485 clause 7.4: defined criteria for evaluating and selecting external providers, ongoing monitoring of their performance, periodic re-evaluation, and retained records of those activities and any actions arising. Certificate expiry tracking supports that work. It does not certify you, and no software can.

This page describes software that is in development and not available for purchase or use. Nothing here is a commitment to a release date, a feature set, or a price. The clause references above are short summaries written to be useful, not substitutes for ISO 9001, AS9100, IATF 16949, or ISO 13485. Read the standards themselves, and confirm how each requirement applies with your own certification body.

Hear about it first

Supplier cert expiry tracking is still being built. Join the early access list and we will email you when it opens. If you want to shape it, tell us what your supplier list looks like now.

The live demo is our calibration management software, which is available today. Supplier records are not part of it yet.