Home / Third-party testing vs in-house testing
Quality credentials
Third-party testing vs in-house testing: who did it, and why it changes what the result means
The comparison almost everyone makes here is the wrong one. In-house testing is not the shortcut a company takes instead of testing properly — it is what federal law already requires of every US supplement manufacturer. So the choice is never between a product that was tested and a product that was not. What an outside party adds is independence, and independence turns out to have four separate ingredients that the single phrase "third-party tested" quietly collapses into one. This page separates them: who selected the sample, who set the scope, who can suppress an unwelcome result, and how often the testing actually happens.
What is the difference between third-party testing and in-house testing?
In-house testing is run by the company that made the product; third-party testing is run by an organisation outside it. That much is simple. The complication is that the difference most shoppers assume follows from it — that one product was tested and the other was not — does not follow at all.
Under 21 CFR Part 111, the federal good-manufacturing-practice rule for US dietary supplements, a manufacturer must establish written specifications for identity, purity, strength and composition, and must verify them. 21 CFR 111.75(a)(1) goes further and requires identity testing on every incoming dietary ingredient — not a sample of shipments, not trusted suppliers exempted — with the only escape a petition to FDA under 21 CFR 10.30 that must be granted before it applies. That rule was published in 2007 and has applied to even the smallest firms since 2010.
Which gives the framing this page runs on. In-house testing is the legal floor. It is not a credential, and a company advertising it is describing compliance with a regulation that is more than fifteen years old. The genuine variable is not whether testing happened but who was standing next to the instrument, and the shape of that argument should be familiar: it is exactly the distinction drawn on what "GMP certified" means on a supplement label, where compliance is mandatory and certification is the separate, voluntary act of paying someone independent to confirm it.
If in-house testing is required, why does independence matter?
Because a requirement is not a result, and FDA's own inspection record is the plainest available demonstration of the gap. The share of inspected dietary-supplement facilities issued a Form 483 — the list of observations an investigator leaves behind — has been reported by fiscal year at roughly 70% in FY12, 65% in FY13, 58% in FY17, 54% of 591 inspections in FY18, and 47% of domestic firms in FY23, with cited firms averaging around 5.7 observations each.
That trend deserves to be read evenhandedly rather than as ammunition: a fall of more than twenty percentage points across a decade is real improvement, and the industry should be given credit for it. But the level is the point. Close to one inspected facility in two still receives documented observations. A mandate written in 2007 has not produced universal compliance in 2026, and that is the honest answer to "if the law already requires it, why pay someone else to check?"
The nature of the most common failure is more interesting still, and it reframes what independence is guarding against. The single most frequent FDA observation is failing to establish product specifications for identity, purity, strength and composition — close to 33% of 483-receiving facilities in FY23, and the leading finding in FY18 (~24%) and FY17 as well. So the industry's characteristic failure is not a company falsifying a test result. It is a company never having written down what its product was supposed to contain in the first place. The failure mode is absence, not deception — and an outside party is useful less because it catches liars than because it will not proceed without a number to test against.
Is "third-party tested" a regulated phrase?
No. There is no FDA definition of "third-party tested", no approval behind it, and no public register of companies entitled to use it — any brand can print it on a label or a product page. In that respect it belongs to the same family as the ungraded grade words taken apart on oil of oregano vs oregano essential oil, where "therapeutic grade" turns out to be a marketing phrase rather than a certification.
But the two are not in quite the same class, and it is worth being precise rather than merely sceptical. "Therapeutic grade" refers to a grading system that does not exist. "Third-party tested" refers to an event that may very well have happened — a laboratory outside the company may genuinely have run a genuine test. The phrase is not empty; it is unspecified. So the correct response is not to dismiss it but to ask the four questions it leaves open: which third party, testing what, how often, and can the report be seen?
A phrase that names its source becomes checkable. A named accredited laboratory can be looked up. A named certification programme publishes a list of the products it certifies, which can be searched for the product in your hand. An unattributed claim cannot be checked by anyone, which is not evidence that it is false — only that it carries no information you could act on.
What are the different kinds of "third party"?
There are at least five, and they differ enormously in what they establish. The table below scores each on the four levers that actually determine independence — because the phrase on the bottle is identical in most of these rows while the evidence behind it is not.
| Arrangement | Who picks the sample | Who sets the scope | Can a bad result stay private? | What it tells you |
|---|---|---|---|---|
| In-house QC laboratory | The manufacturer | The manufacturer, within Part 111 minimums | Yes — records are held, not published | That the legal floor was met. It is also the only testing that touches every batch, which is not nothing |
| Contract laboratory hired by the brand | The manufacturer | The manufacturer (it commissions the panel) | Yes — the report belongs to the client | That an independent analyst produced the numbers. Scope and publication remain brand-controlled |
| Certification programme (e.g. NSF Certified for Sport, USP Verified, Informed Sport / Informed Choice, BSCG) | The programme, under its own rules | The programme — it owns the standard | No — the mark is withheld and the public listing is the record | That an outside body set the bar and the product cleared it. Frequency still varies by programme |
| Independent evaluator buying off the shelf | The evaluator — retail purchase | The evaluator | No — the brand is not the client | The strongest form of sampling independence, and usually the narrowest coverage |
| Retailer-mandated verification (Amazon's ISO/IEC 17025 COA requirement) | The manufacturer | The retailer sets minimum requirements | Partly — the listing depends on clearing it | That a compliance floor was met to be allowed to sell. An entry requirement, not a distinction |
Read the columns rather than the rows and the actual finding falls out: the arrangements differ far more in who controlled the process than in who held the pipette. Rows one, two and five all have the manufacturer choosing what gets measured. Only rows three and four move that decision outside the company.
Does paying for testing compromise its independence?
Not on its own, and the reflex that it must is the most common overcorrection in this topic. The brand pays in essentially every arrangement above, including the best-regarded certification programmes — someone has to fund the laboratory time, and a model where testing is free does not exist. If payment alone disqualified a result, no supplement testing of any kind would count.
What matters is control, and it separates into three specific powers. The power to choose the sample. The power to choose the scope — which tests get run, and against which limits. And the power to decide whether an unfavourable result is published or filed away. A laboratory hired to produce one report for one client typically leaves all three with the client. A certification programme that writes its own standard, owns its own mark and maintains a public list of certified products has taken all three off the table, because a product that fails simply does not appear on the list.
Stated as a single test: could an unwelcome number have quietly disappeared? If yes, what you are looking at is a competent measurement of a favourable sample. That is still worth more than nothing — it is a real result, produced by a real instrument, and it is much better than an adjective — but it is not the same thing as an outside body vouching for the product.
Who chooses the sample that gets tested?
In most arrangements, the manufacturer — and this is the weakest link in the whole chain, because it sits entirely outside the laboratory's accreditation. ISO/IEC 17025, the international standard for the competence of testing and calibration laboratories, assesses whether a laboratory can correctly run defined methods on material it receives. It makes no assessment whatever of how that material was selected before it arrived.
The consequence is worth stating flatly, because no consumer article on this topic seems to: an accredited laboratory handed an unrepresentative sample will measure it accurately and report it accurately. The accreditation is doing its job. The gap is one step upstream, in a link the credential was never designed to cover. This is the same structural point the certificate of analysis page makes about lot numbers, pushed one stage earlier: a document can only be as informative as the connection between the material tested and the material you own.
Which is exactly why the off-the-shelf model is analytically the strongest, whatever its other limits. When an evaluator walks into a shop, buys the product like anyone else and tests what it finds, the manufacturer had no opportunity to select the sample — because it did not know which bottle would be chosen. That single change closes the one gap that accreditation cannot.
How often does third-party testing actually happen?
It varies by programme, from every single batch to a limited number of products a year — and the phrase on the carton does not tell you which. This is the most consequential misreading of a certification mark, and it is straightforward to correct.
Some programmes operate every-lot testing: a batch is not released until it has been screened, so certification and your bottle are directly connected. Others operate a variable or periodic model, where production lots are sampled on a schedule rather than exhaustively. And independent evaluation programmes that buy products at retail test a limited number of items in a given year — a thorough look at a small slice of the market rather than continuous coverage of one product line.
All three are legitimate, and none is dishonest. But they answer different questions, and only the first speaks to a specific bottle. Which converges on the rule the COA page builds in full: a mark on a carton is about a product line; a lot number is about a batch. If you want to know what was in the bottle you own, the document you need is a lot-specific certificate of analysis whose batch code matches the code printed on the bottle. Nothing else does that job — not a facility audit, not a certification mark, not a general claim of third-party testing.
What does a mandatory floor look like on Amazon?
It looks like independent laboratory testing being the price of admission rather than a selling point. Amazon requires dietary supplement sellers to submit a certificate of analysis from an ISO/IEC 17025 accredited laboratory to an Amazon-approved testing, inspection and certification verifier — effective 8 April 2024, with the report issued within the previous six months.
This puts a marketplace-wide requirement in the same category as GMP compliance and in-house testing: something true of every product legitimately on the shelf, and therefore not a way to tell two of them apart. It is a genuinely good rule and it raised the floor considerably. It simply is not a differentiator, and a brand presenting it as one is describing a hurdle every competitor also cleared.
So the informative question moves one level up, and it is the same one the whole quality-credentials cluster keeps arriving at: what specification was the testing run against? A test compares a measurement with a target. Change the target and the identical clean report means something entirely different.
What can independent testing never tell you?
Whether the number being tested against was worth hitting. This is the ceiling on every credential in this category, and it is the reason they stack rather than substitute. An accredited laboratory can confirm with great precision that a product contains what a modest specification called for. The result is true, the laboratory is competent, the independence is real — and the bar was low.
There is a second silence, and it is the one that most often goes unnoticed on a botanical product. A test needs a target. No laboratory can assay a bottle against "premium", "potent", "maximum strength" or "high quality" — there is no method for an adjective. Every testable specification is a number attached to a named compound. So a label with no such number has not merely declined to publish its testing; it has described a product that cannot be tested for the thing the shopper cares about, however many independent laboratories are involved.
And a percentage does not close the gap either. A figure like 80% carvacrol is a ratio inside the oil — it says how concentrated the oil is, not how much of it a serving delivers, so two products quoting the same percentage can supply quite different amounts. The unit that survives comparison between two different bottles is milligrams of a named compound per serving, which is also the form an assay result takes. The full version of that argument sits on how to read a Supplement Facts panel.
What does this mean for a bottle of WaveDrops?
It means the specification is published in the unit an independent laboratory could actually verify. Each 2-drop serving is stated at about 18 mg of carvacrol and roughly 0.9 mg of thymoquinone — a named compound and a mass, which is exactly the shape of an assay result and exactly what a percentage alone cannot provide. Stating it that way makes the claim falsifiable, and a claim that could be shown wrong is a different kind of claim from one that could not.
The second half is what is not in the bottle. There is no filler carrier oil — no olive oil, sunflower oil or added blend making up the volume. The wild-harvested Greek Origanum vulgare oil and the cold-pressed Nigella sativa oil are both declared actives, so every millilitre is the two oils themselves. That matters for testing specifically: when a serving is mostly carrier, the concentration a shopper actually receives depends on how generously the diluent was added, and the headline percentage stops describing the serving at all.
The rest is stated as the floor it is. The 0.34 fl oz (10 mL) amber glass dropper gives about 200 two-drop servings, and the product is made in a GMP-certified facility — a floor described as a floor, not dressed up as a distinction. For the facility-level side of this, see what "GMP certified" means; for the lot-level side, what a certificate of analysis shows.
Three claims about testing this page refuses
Stating what is not true is part of stating what is.
"Third-party tested means an independent organisation certified this product." Sometimes it does. Often it means a laboratory was paid to produce one report on a sample the company selected, with a panel the company commissioned, and the result was published because it was favourable. Both of those are honestly described by the same three words, which is precisely why the phrase needs a name attached to it before it means anything.
"In-house testing can't be trusted because the company is testing itself." This is the overcorrection, and it gets the structure backwards. In-house testing is legally required, is performed under the record-keeping obligations of 21 CFR Part 111, and is the only testing that touches every batch a company makes. Independent testing adds a check on that system; it does not replace it, and no certification programme tests anything like every unit produced. A company with a serious internal quality system and no certification mark may well be testing more of its own product than a certified competitor.
"A certification mark means every bottle was tested." That depends entirely on the programme's frequency model, which the mark itself does not disclose. Some certify every lot before release; others sample periodically; independent evaluators test a limited number of products a year. If the question is about your specific bottle, the answer lives in a lot-matched certificate of analysis and nowhere else.
Refusing these three is not an argument that third-party testing is a marketing device — quite the opposite. Independent verification is one of the few genuinely load-bearing credentials in this category. It deserves to be read for what it actually establishes rather than treated as a badge that establishes everything.
Related reading: what "GMP certified" means on a supplement label, what a certificate of analysis shows, and how to choose a quality oregano oil. Or return to the WaveDrops homepage.
WaveDrops describes traditional use and structure/function support only. Terms like "antioxidant" and "immune-wellness support" describe how these compounds are traditionally understood, not a promise to diagnose, treat, cure, or prevent any condition. Always follow the serving printed on the label, keep the product out of reach of children, and consult your healthcare provider before use if you are pregnant, nursing, taking medications, or managing a medical condition.
These statements have not been evaluated by the FDA. This product is not intended to diagnose, treat, cure, or prevent any disease.