Guides guide

How to Read a Cannabis COA

Cannabis certificate of analysis beside hemp products

A cannabis COA is the lab report behind a hemp or cannabis product. Reading it well helps you verify potency, spot weak documentation, and avoid products that rely on marketing claims instead of test data.

Quick answer

Start by matching the COA batch number to the product. A lab report for a different batch is not enough.

Check cannabinoid potency next: delta-9 THC, THCA, CBD, other cannabinoids, serving size if applicable, and total THC if listed.

Then review safety testing: pesticides, heavy metals, residual solvents, microbials, mycotoxins, test date, and the lab name.

Key takeaways

  • A COA should match the exact product batch, not just the brand or product line.
  • For THCA flower, delta-9 THC alone is not enough; look for THCA and total THC context.
  • For vapes and concentrates, residual solvents and heavy metals matter alongside potency.
  • Old, blurry, incomplete, or impossible-to-match COAs are buyer red flags.

Related topic

Explore the THC Guides hub

Not sure where to start? These foundational guides explain how different cannabinoids work, how to figure out your dose, and what to expect from edibles, vapes, and tinctures — before you buy anything.

Open THC Guides

Helpful tools

THC Dosage CalculatorHelp adults estimate a conservative starting point for hemp-derived THC products without making medical claims.Edible Timing CalculatorSet conservative timing expectations for edibles so shoppers can plan ahead and avoid re-dosing too quickly.THC vs CBD Comparison ToolHelp adults think through intoxicating versus non-intoxicating product directions without making outcome guarantees.

Best for

Adults 21+ comparing hemp-derived THC products, THCA flower, gummies, tinctures, vapes, or product reviews.

Most important check

Batch matching. If the COA does not match the product you are buying, the rest of the report is less useful.

Trust signal

Good retailers make COAs easy to find, current, readable, and tied to the exact product.

How they compare

Good COA vs weak COA

Good: batch-matched, recent, full cannabinoid panel, contaminant results, readable lab name, complete pages.
Weak: old, cropped, missing batch data, potency-only, no contaminants, or uploaded as an unreadable image.

A COA is only useful when it proves something about the specific product being sold.

Flower vs vape COA priorities

Flower: cannabinoid profile, THCA, total THC, moisture, microbials, pesticides, and heavy metals.
Vapes: cannabinoid profile, oil ingredients, residual solvents, pesticides, heavy metals, and hardware-related contaminants.

The right COA checks depend on product format. Do not use one generic standard for every product.

What a cannabis COA is

A COA, or Certificate of Analysis, is a lab report that summarizes what a product sample contained when it was tested. In the hemp-derived THC market, it is one of the most important trust documents a retailer can provide.

A good COA helps answer two buyer questions: what cannabinoids are in this product, and did the lab check for contaminants that should not be there?

Start with the batch match

Before reading potency numbers, confirm the COA belongs to the product you are buying. Look for a batch number, lot number, SKU, product name, or sample identifier that matches the product page or packaging.

If the seller shows a generic COA for the brand, an old COA for a previous batch, or a report with identifying details removed, treat that as a weaker trust signal.

Read the potency panel

The potency section should list cannabinoids such as delta-9 THC, THCA, CBD, CBDA, CBG, CBN, and others when present. For gummies and tinctures, look for milligrams per serving and per package. For flower, look for percentages by weight.

For THCA products, pay special attention to THCA and total THC. A product can show less than 0.3% delta-9 THC while still having high THCA. Read What is total THC? if that formula is new to you.

Check contaminant testing

Potency is only one part of a useful COA. Responsible products should also include contaminant testing appropriate to the format. Common panels include pesticides, heavy metals, residual solvents, microbials, mycotoxins, and sometimes moisture or water activity for flower.

Residual solvents matter more for extracts and vapes. Microbial and moisture results matter more for flower. Heavy metals and pesticides are broadly relevant across product types.

COA red flags before you buy

Watch for reports that are old, blurry, cropped, missing pages, missing lab details, or impossible to match to the product. Also be cautious when a seller only provides potency but no contaminant results for products where safety testing should be expected.

A clear COA does not guarantee a product will be right for you or legal in your state, but weak documentation is a strong reason to slow down. Pair COA review with state-law checks, conservative dosing, and format-specific expectations.

Buyer checklist

  • Match the batch or lot number on the COA to the product page or packaging.
  • Confirm the test date is recent enough to be meaningful.
  • Review delta-9 THC, THCA, CBD, minor cannabinoids, and total THC where available.
  • Check contaminant panels for pesticides, heavy metals, residual solvents, microbials, and mycotoxins.
  • Look for the lab name, accreditation details, and complete report pages.
  • Avoid products with missing, cropped, blurry, or unrelated COAs.

Frequently asked questions

What does COA stand for?

COA stands for Certificate of Analysis. It is a lab report showing potency and, when complete, contaminant testing for a product sample.

What is the most important thing to check on a COA?

Start with batch matching. The COA should clearly correspond to the product batch being sold. Then check potency, test date, lab identity, and contaminant panels.

Do all hemp products need a COA?

Any hemp-derived THC product worth serious consideration should provide readable lab documentation. The exact panels vary by product type, but missing COAs are a major trust problem.