Counterfeit parts and supplier identity: the certificate of conformance problem
Counterfeit avoidance standards prescribe testing, traceability and approved sourcing. All of it rests on a document that asserts what a lot is, produced by whoever is selling it.
What does a certificate of conformance actually prove?
That someone produced a PDF asserting a lot meets specification. Counterfeiters produce convincing ones, and verification means contacting the supplier — which nobody does per lot. The certificate is the control, and it is the least testable artefact in the supply chain.
- Conformance documentation was designed for trusted bilateral relationships and did not change when independent distribution and grey-market sourcing broke that assumption.
- A verifiable certificate eliminates forged documents and unauthorised signatories. It does not detect a genuine supplier certifying counterfeit stock.
- Service life is the design constraint: a part installed in 2026 may be examined in 2056, so verification must not depend on any company's continued existence.
Part of Defense industrial base identity
The denominator problem
Counterfeit parts discourse suffers from a measurement gap. Detected counterfeits are counted; undetected ones are not, by definition. The FAA has linked suspect unapproved parts to a substantial number of documented incidents, and defense counterfeit reporting captures cases that reached inspection or failure.
What nobody has is a rate. That matters for this argument because it means the case for verification cannot rest on a frequency claim, and any vendor asserting one should be asked for their denominator.
The case rests instead on consequence and on cost of investigation, both of which are measurable within a programme.
What a certificate of conformance is
A statement by a supplier that the delivered items conform to the purchase order requirements and applicable specifications. It typically identifies the part number, lot or date code, quantity, applicable specifications, and carries a signature from the supplier's quality representative.
It is a PDF. Its authenticity is assessed by receiving inspection staff comparing it against expectations and, occasionally, contacting the supplier.
Where the trust model broke
| Sourcing channel | Original trust basis | Current reality |
|---|---|---|
| Franchised distributor | Direct manufacturer relationship | Intact; the strongest channel |
| Authorised distributor | Contractual authorisation | Generally intact |
| Independent distributor | Reputation and audit | Variable; broker chains obscure origin |
| Broker / open market | None inherent | Used under allocation pressure; highest risk |
| Parted-out or surplus material | Documentation trail | Documentation may be reconstructed |
Allocation shortages push sourcing down this table. That is not a procurement failure — it is the choice between a non-conforming source and a programme stoppage — and it is exactly when verification matters most and is least available.
The Conformance Receipt
{
"type": "manav-stmt/1",
"action": "certificate_of_conformance",
"render": [
"Part number: [pn] Manufacturer: [name]",
"Lot / date code: [value] Quantity: [n]",
"Specifications: [list, revisions]",
"Test basis: [acceptance testing performed / referenced]",
"Traceability: [chain as known to the signer]"
],
"signatory": "[named quality representative, credential]",
"organisation": "[supplier, countersignature]"
}
The traceability field is deliberately phrased as as known to the signer. A distributor cannot attest to what happened before the material reached them, and a certificate implying otherwise is the problem rather than the solution.
The limitation, stated prominently
A verifiable certificate does not detect counterfeit material. A supplier who genuinely believes their stock is authentic, and signs accordingly, produces a valid receipt for counterfeit parts.
What it eliminates is a specific and well-documented subset: forged certificates, certificates signed by people without authority, and certificates attributed to organisations that never issued them. Those are a meaningful share of documented cases and they are the share that testing does not catch, because the receiving inspector accepted the paperwork and skipped the test.
The fifty-year requirement
An electronic component installed in an airframe or a ground system may be examined decades later, after the distributor has been acquired twice and the manufacturer has exited the product line.
That imposes two design requirements that rule out most schemes: verification must not require contacting anyone, and the verifier must be open source so it can be run in 2056. Neither is a preference; both are records-retention constraints.
What to do first
- Identify the part families where a counterfeit would be programme-significant. This is a short list.
- For those, require conformance receipts from franchised and authorised channels, where compliance is easy and establishes the pattern.
- Extend to independent distribution as a purchase order condition, which is where it actually matters.
- Retain receipts with the part records, not in a separate quality system that will be migrated away.
Why counterfeit parts survive incoming inspection
| Check | Catches |
|---|---|
| Visual and dimensional | Crude counterfeits |
| Markings and packaging | Careless counterfeits |
| Documentation review | Nothing — the document is the counterfeiter's best work |
| Destructive or electrical test | Good counterfeits, at a cost per lot nobody pays |
| Signature verification | Fabricated documentation, in milliseconds |
Objections and honest limits
“We buy only from franchised distributors.” Which is the right primary control and it narrows rather than removes the problem — shortages push buyers to the broker market, and that is where the documentation matters most.
“This needs industry-wide adoption.” A manufacturer can sign unilaterally. A receiver who can verify does; one who cannot sees an unchanged PDF.
Making conformance testable
- Sign the certificate contents. Part, lot, specification, test results, the named signatory.
- Publish the key at a stable location. Retained for the life of the parts, not the contract.
- Verify on receipt, automatically. Milliseconds, no phone call, every lot.
- Flag unsigned certificates for the broker market. Where the risk concentrates.
Terms used here
- Certificate of conformance
- A supplier's statement that a lot meets the stated specification.
- Franchised distributor
- An authorised distributor with a direct relationship to the manufacturer, and the lowest-risk purchase channel.
- Broker market
- The open market for parts outside authorised channels, used during shortages and where counterfeits concentrate.
Frequently asked questions
Does this detect counterfeit parts? No. It eliminates forged certificates and unauthorised signatories. A supplier certifying counterfeit stock in good faith produces a valid receipt, and only testing catches that.
Will independent distributors participate? Those competing on quality will, because it differentiates them from brokers. Those competing on price and availability will resist, which is itself informative.
How does this interact with counterfeit avoidance standards? It supports traceability and documentation requirements. It does not replace testing, inspection or approved-source requirements.
Why does the verifier need to be open source? Because the part outlives the software. A proprietary verifier is a dependency on a company that may not exist when verification is needed.
Why doesn't incoming inspection catch counterfeits? Visual and documentation checks catch crude ones. The documentation is the counterfeiter's strongest work, and destructive testing is not run per lot.
Can a manufacturer adopt this alone? Yes. Signing is unilateral; receivers who can verify do, and others see an unchanged PDF.
Where does the risk concentrate? The broker market, used during shortages, where documentation carries the most weight and is least testable.
Where this fits in Manav
Manav binds the authorising individual to the exact record being released or approved, and produces a receipt a prime, a government customer or an auditor can verify without access to your systems.
Sources and further reading
- Counterfeit avoidance standards for aerospace and defense electronic components.
- CMMC program — DoD CIO
- Federal Aviation Administration regulations and policies
- FCC — protecting consumers from SIM swap and port-out fraud
- GIDEP — Government-Industry Data Exchange Program
- NIST SP 800-171 Rev. 3 — Protecting CUI