Skip to content
Industry12 min read

Fake CE Certificate Supplier Fraud in UK Procurement

How suppliers forge fake CE certificates, UKCA marking, Declaration of Conformity and ISO documents, and how UK procurement teams catch it before paying.

CheckFile Team
CheckFile Teamยท
Illustration for Fake CE Certificate Supplier Fraud in UK Procurement โ€” Industry

Summarize this article with

A fake CE certificate is rarely a crude forgery. Most are genuine templates with a substituted Notified Body number, a cloned Declaration of Conformity signed by nobody who exists, or a product certified for one category presented as cover for an entirely different one. Procurement and compliance teams that only check whether a certificate is present, rather than whether it is valid, are the ones this fraud is built to pass.

This article is provided for informational purposes only and does not constitute legal, financial, or regulatory advice. Regulatory references are accurate as of the publication date, 27 August 2026. Consult a qualified professional for guidance specific to your situation.

What a CE or UKCA Mark Actually Proves

A CE or UKCA mark proves that the manufacturer has self-declared, or in some cases had a Notified/Approved Body assess, that a product meets specific essential requirements under a named regulatory regime โ€” nothing more. The UK government confirmed on 1 August 2023 that CE marking will be recognised indefinitely in Great Britain for goods under 18 regulatory regimes, including machinery, PPE, toys, electrical equipment and pressure equipment, rather than requiring a hard switch to UKCA (Department for Business and Trade, CE mark recognition extension). This means a supplier presenting either mark is not automatically doing anything wrong; the fraud risk sits in whether the underlying assessment actually happened.

The mark itself carries no verification information. It is the accompanying Declaration of Conformity (DoC) โ€” a signed statement naming the manufacturer, the product, the standards applied, and, where relevant, the Notified Body number โ€” that a buyer actually needs to check. A CE mark with no DoC on file, or a DoC the supplier is reluctant to produce on request, is the first and cheapest red flag available before any document analysis begins.

How Fraudsters Actually Forge These Documents

Reusing a genuine certificate template and swapping the product name or batch number is the most common method, because most DoCs are unwatermarked PDFs or scanned letterheads that edit as easily as an invoice. A fraudster keeps the layout, logo and even a real Notified Body number, then substitutes the product description to cover an item that was never tested.

Notified Body number mismatch is a specific and checkable variant of this. Each Notified Body is accredited for defined product categories only, and compliance investigators have documented real cases of a certificate citing a Notified Body number allocated to one product class โ€” for example water pumps โ€” while being presented as cover for an entirely different, unrelated category (ComplianceGate, fake product certificates and test reports). A supplier who cannot explain why their Notified Body's published scope does not match their product is not making an administrative slip.

Fabrication from a design tool or generative AI is less common but rising, particularly for lower-value goods where a buyer is expected to glance rather than verify. A convincing DoC layout takes little skill to reproduce, and a fabricated certifying-body name or logo passes any reviewer who is not cross-checking it against a real register.

Impersonating a real certification body is the more damaging variant. Nova Certification, an accredited Greek conformity assessment body, publicly confirmed that a "document of conformity" circulating under its name was not one it had issued, after the fake document was used to support product claims it had never assessed โ€” a pattern that recurs across notified bodies whose branding is easy to copy but whose actual assessment records are not (cross-safety.org, False CE certificates). The certificate looks institutionally credible precisely because the institution is real; only the document is not.

Where This Fraud Shows Up in Procurement

Vendor onboarding for imported goods is the highest-risk moment, because a new supplier relationship rarely comes with an existing paper trail to compare against, and the pressure to close the purchase order outweighs the appetite to chase a Notified Body for confirmation. Construction materials procurement carries a parallel risk with the Declaration of Performance (DoP), the construction-sector cousin of the DoC that states a product's essential characteristics โ€” fire resistance, load-bearing capacity, thermal performance โ€” against a harmonised standard, rather than general safety compliance (Construction Products Association, DoC vs DoP comparison).

ISO management-system certificates (9001, 14001, 45001) follow a related but distinct fraud pattern: because these certify a company's processes rather than a specific product batch, a forged or lapsed ISO certificate is harder to catch through product inspection and only surfaces through direct cross-checking with the named certification body's public register. A certificate that does not name the accredited registrar who issued it, or names one that cannot be found on a national accreditation body's database, should be treated as unverifiable rather than borderline.

Re-sellers and distributors add a further layer: a distributor may hold a genuine DoC for a product batch from 2023 and continue circulating it against current stock that has since changed suppliers, materials or manufacturing location, without the certificate itself being edited at all. This is a stale-document problem rather than a forged one, and it is just as capable of putting a non-compliant product on the market.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.

Request a free pilot

Detection Techniques That Actually Work

Cross-checking the Notified Body number against its published accreditation scope is the single highest-value step, because it is fast, free, and catches both crude fabrications and the more damaging scope-mismatch pattern. The Office for Product Safety and Standards (OPSS) is the UK's national market surveillance authority, and where OPSS considers that a certifying body should reconsider a certificate it has issued, it can refer the matter directly to that conformity assessment body (OPSS guidance, product safety and market surveillance). Local Trading Standards teams enforce at ground level and are the practical first call when a supplier cannot substantiate a certificate on request.

Requesting the DoC directly, rather than accepting a CE mark alone, closes the most common gap: a self-applied mark with no declaration behind it. A genuine DoC names the manufacturer (not just a distributor), lists the specific standards tested against, states the product model or batch it covers, and is signed by a named individual with legal authority to make that declaration โ€” a document missing any of these fields warrants a follow-up before onboarding proceeds, not after.

Document forensics adds a layer manual review misses: PDF metadata often shows a certificate's true creation date and editing software, exposing a "2022 declaration" that was actually last modified in an image editor within the past month. Structural and font-level inconsistencies between a submitted certificate and a verified template from the same certifying body are a further signal worth checking systematically rather than case by case.

Red flag Verification method What it reveals
Notified Body number does not match its published accreditation scope Search the number against the EU NANDO database or the UK's designated bodies list Certificate covers a product category the body was never accredited to assess
CE or UKCA mark present with no Declaration of Conformity on file Request the DoC directly from the supplier before onboarding Self-applied mark with no underlying assessment behind it
ISO certificate does not name an identifiable accredited registrar Search the registrar on the national accreditation body's public database Certificate cannot be traced to any real certification body
Declaration references a product batch, model or manufacturing site that differs from current stock Compare the DoC's stated scope against the actual delivery or invoice Stale certificate reused for goods it was never issued to cover
PDF creation date or editing software inconsistent with the claimed issue date Inspect file metadata (creation tool, modification history) Document edited or fabricated after the date it claims to represent
Certifying body name is real but cannot confirm having issued the specific document Contact the certifying body directly using contact details from its own website, not the certificate Impersonation of a genuine certification body

What Procurement Teams Are Actually Asking

Compliance and procurement practitioners on industry forums frequently ask how to tell a supplier's honest paperwork mistake โ€” an expired certificate they forgot to renew โ€” from a document manufactured to deceive. The distinguishing factor is not how old the certificate looks; it is whether the supplier can produce a current DoC, a Notified Body reference that resolves correctly, and a certifying body willing to confirm the document when contacted directly. A supplier who stalls, redirects to a reseller, or offers to "resend a cleaner copy" instead of answering is behaving differently than one who simply missed a renewal date.

A second recurring question is how much of a full vendor audit pack suppliers actually hand over on first request. Procurement teams report that only around a third of suppliers asked for a full certification and audit report provide the complete pack unprompted โ€” the remainder offer partial documents, a summary, or nothing until pressed a second time (IFSQN forum discussion, supplier compliance documentation). Treating that reluctance as a data point in its own right, rather than assuming it will resolve itself after onboarding, is a pattern experienced compliance teams flag repeatedly.

Presenting a forged CE certificate, UKCA document, or Declaration of Conformity to induce a purchasing decision can constitute fraud by false representation under section 2 of the Fraud Act 2006, while creating or altering the document itself falls under the Forgery and Counterfeiting Act 1981. Both carry custodial sentences on indictment.

A new corporate offence under the Economic Crime and Corporate Transparency Act 2023 took effect on 1 September 2025, making a large organisation (turnover above ยฃ36 million, balance sheet above ยฃ18 million, or more than 250 employees) criminally liable if an employee or agent commits fraud intending to benefit the organisation and reasonable fraud-prevention procedures were not in place (gov.uk, guidance on the failure to prevent fraud offence). A purchasing team that accepts an uncheckable certificate and passes a non-compliant product onward is exactly the fact pattern this offence targets, which turns systematic certificate verification from good practice into a documented control regulators will expect to see.

For construction products specifically, the Construction Products (Amendment) Regulations 2025 came into force on 8 January 2026, confirming that CE marking continues to be recognised indefinitely for construction products placed on the UK market alongside UKCA, while a wider reform white paper consultation on test data and conformity oversight runs from February to May 2026. Medical devices sit on a separate timeline: devices CE-marked under the EU Medical Devices Directive can be placed on the Great Britain market until the earlier of certificate expiry or 30 June 2028, and in vitro diagnostics until 30 June 2030 (gov.uk, regulating medical devices in the UK).

A Layered Approach to Detection

No single check catches every forged certificate, which is why register cross-checking, DoC field verification, and document forensics need to run together rather than as alternatives. CheckFile's approach layers structural analysis, metadata checks, and cross-document validation, an approach built for high detection coverage across regulated document types rather than relying on any single signal. This complements, rather than replaces, the manual step of confirming a Notified Body number or ISO registrar against its own public register โ€” no document-level analysis substitutes for that direct confirmation.

Related reading: our industry verification guide covers sector-specific checks across construction, financing and regulated services, and our piece on detecting PDF metadata tampering goes deeper into the forensic technique referenced above for spotting an edited certificate. CheckFile is also used in construction and BTP compliance workflows, where forged Declarations of Performance recur alongside subcontractor paperwork fraud.

If your supplier onboarding still relies on a visual read of a PDF a vendor has emailed over, CheckFile's AI-generated document detection adds AI-generation signals as a complement to your existing register checks โ€” not a guarantee of catching every forgery, but a useful additional layer alongside Notified Body and accreditation-database cross-checks. See our security page, pricing and homepage for how this fits into a wider vendor compliance workflow.

Frequently Asked Questions

Can a fake CE certificate use a real Notified Body number?

Yes. Fraudsters frequently keep a genuine Notified Body number on a forged or altered certificate because the number itself looks legitimate on inspection. The mismatch only surfaces when the number is checked against that body's published accreditation scope โ€” a number valid for one product category presented as cover for a different one is a clear sign of fraud.

Is CE marking still valid in the UK in 2026, or must suppliers use UKCA?

CE marking remains valid for most goods sold in Great Britain. The UK government confirmed indefinite recognition of CE marking on 1 August 2023 for 18 regulatory regimes, and this was reaffirmed for construction products through the Construction Products (Amendment) Regulations 2025, in force from 8 January 2026. Medical devices follow separate deadlines of 30 June 2028 and 30 June 2030 depending on device type.

What is the fastest way to check if a Declaration of Conformity is genuine?

Request the full DoC, not just confirmation the CE mark is present, then check the named Notified Body's accreditation scope against the product category on a public register such as NANDO for EU bodies. Contact the certifying body directly using details from its own official website, never contact information printed on the certificate itself.

Who enforces CE and UKCA marking fraud in the UK?

The Office for Product Safety and Standards is the national market surveillance authority, supported by local Trading Standards teams for ground-level enforcement. Presenting a forged certificate can also trigger liability under the Fraud Act 2006, the Forgery and Counterfeiting Act 1981, and, for large organisations, the failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act 2023.

Does a genuine ISO certificate guarantee a supplier's product compliance?

No. ISO 9001, 14001 and 45001 certify a company's management processes, not a specific product batch's compliance with CE or UKCA requirements. A supplier can hold a genuine, current ISO certificate while still forging or misrepresenting a separate product-level Declaration of Conformity, so the two document types need to be verified independently.

Stay informed

Get our compliance insights and practical guides delivered to your inbox.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.