|

ISO 22000:2018 Certification — Complete Food Safety Management System Guide

Food safety is not controlled at only one point in the food chain. It begins with raw materials, agricultural production and suppliers, continues through processing, manufacturing, packaging, storage and transportation, and ultimately reaches retail, food…

ISO 22000:2018 implementation and certification roadmap showing gap analysis, PRPs, HACCP, hazard control, internal audit, management review and certification readiness

Food safety is not controlled at only one point in the food chain.

It begins with raw materials, agricultural production and suppliers, continues through processing, manufacturing, packaging, storage and transportation, and ultimately reaches retail, food service and the consumer.

A weakness at any stage can potentially affect the safety of the final food product.

This is where ISO 22000:2018 becomes relevant.

ISO 22000:2018 is an international standard specifying requirements for a Food Safety Management System (FSMS). It is intended for organizations directly or indirectly involved in the food chain and can be applied regardless of their size or position within that chain. ISO currently lists ISO 22000:2018 as the published edition, together with Amendment 1:2024 — Climate action changes.

But ISO 22000 is more than a food-safety checklist.

It combines management-system thinking, prerequisite programmes, hazard analysis, operational controls, communication, traceability, verification, internal auditing, management review and continual improvement into a structured Food Safety Management System.

What is ISO 22000:2018 certification?

ISO 22000:2018 certification is third-party certification of an organization’s Food Safety Management System (FSMS) against the requirements of ISO 22000:2018. The standard is designed for organizations directly or indirectly involved in the food chain and provides a systematic framework for identifying, evaluating and controlling food-safety hazards.

It connects food-safety controls with broader management-system processes such as leadership, planning, competence, communication, documented information, monitoring, internal audit, management review and continual improvement.

ISO 22000 can apply to organizations such as food manufacturers, processors, farms, food-service organizations, retailers, storage and distribution providers, packaging-material suppliers and other organizations involved in the food chain. ISO 22000 is therefore broader than HACCP alone: it incorporates hazard-control principles within a management-system framework.

What Is ISO 22000?

ISO 22000 is an international Food Safety Management System standard that specifies requirements for organizations in the food chain to systematically manage food-safety hazards and demonstrate their ability to provide safe products and services.

It can be used by organizations of different sizes and across different stages of the food chain, from primary production and food manufacturing to storage, transportation, retail and food services.


1. What Is ISO 22000:2018?

ISO 22000:2018 — Food safety management systems — Requirements for any organization in the food chain provides a framework for establishing, implementing, maintaining and continually improving a Food Safety Management System.

The standard’s purpose is not simply to ask an organization:

“Do you have a HACCP plan?”

It asks a much broader management question:

“Does your organization have a systematic and controlled way of managing food-safety risks throughout the relevant processes of the food chain?”

That distinction is important.

An organization may have food-safety procedures, laboratory testing, sanitation programmes and HACCP documentation. However, those individual controls need to operate within a coherent system.

An FSMS brings together:

  • Food-safety policy
  • Organizational responsibilities
  • Food-safety objectives
  • Risk-based planning
  • Prerequisite programmes
  • Hazard analysis
  • Operational controls
  • HACCP principles
  • Traceability
  • Emergency preparedness
  • Competence
  • Communication
  • Verification
  • Internal audit
  • Management review
  • Corrective action
  • Continual improvement

ISO describes ISO 22000 as applicable to organizations regardless of size or position in the food chain.


2. What Does FSMS Mean?

FSMS = Food Safety Management System.

It is the organized system through which an organization manages food-safety responsibilities and controls.

Think of it as the connection between:

PEOPLE

Who is responsible?

↓

PROCESSES

What activities affect food safety?

↓

HAZARDS

What could make the food unsafe?

↓

CONTROLS

How are those hazards controlled?

↓

MONITORING

How do we know the controls are working?

↓

VERIFICATION

How do we confirm the system works as intended?

↓

IMPROVEMENT

What do we change when performance is not satisfactory?

This is why ISO 22000 should not be treated as a collection of documents.

The documentation supports the system.

The system itself is the way the organization manages food safety.


3. Why Is Food Safety Management Different From Ordinary Quality Management?

Food quality and food safety are related, but they are not identical.

For example, a food product might have:

  • attractive packaging,
  • good taste,
  • consistent appearance,
  • correct weight,
  • good customer acceptance,

and still present a food-safety concern if a relevant biological, chemical or physical hazard has not been adequately controlled.

Food safety therefore requires systematic identification and control of hazards.

ISO 22000 is specifically designed around this food-safety perspective.

ISO notes that food-safety management standards help organizations identify and control food-safety hazards while supporting safety throughout the global food supply chain.


4. Who Needs ISO 22000 Certification?

One of the most important things to understand about ISO 22000 is the phrase:

“Any organization in the food chain.”

That means ISO 22000 is not limited to large food factories.

Organizations at different stages of the food chain may establish an FSMS according to their activities, risks and applicable requirements.

Examples include:

1. Food Manufacturers

Examples:

  • dairy products
  • beverages
  • bakery products
  • snacks
  • ready-to-eat foods
  • frozen foods
  • processed foods
  • packaged foods

A manufacturing organization may need to control hazards associated with raw materials, processing, equipment, personnel, environment, packaging and storage.


2. Food Processing Organizations

Processing activities can introduce or modify food-safety risks.

Examples include:

  • grain processing
  • milling
  • oil processing
  • fruit and vegetable processing
  • meat processing
  • seafood processing
  • spice processing
  • ingredient processing

An FSMS helps the organization systematically identify where hazards can arise and how they are controlled.


3. Food Ingredient Manufacturers and Suppliers

Ingredients can become a critical part of the food-safety chain.

Examples include suppliers of:

  • spices
  • additives
  • flavours
  • preservatives
  • food ingredients
  • oils
  • concentrates
  • premixes

The organization needs to understand the food-safety implications of its products and processes.


4. Primary Producers and Farms

Food safety can begin before the product reaches a processing facility.

Relevant organizations can include:

  • farms
  • agricultural producers
  • aquaculture operations
  • primary food producers
  • organizations involved in harvesting

The applicable controls will depend on the organization’s activities and the scope of its FSMS.


5. Food Packaging Organizations

Packaging materials can form part of the food chain, particularly where they come into contact with food.

Organizations may therefore need to consider:

  • material suitability
  • contamination risks
  • production hygiene
  • storage
  • handling
  • traceability
  • supplier controls

6. Warehousing and Storage Organizations

Food can be exposed to risks during storage even when the original product was manufactured correctly.

Relevant considerations can include:

  • temperature
  • humidity
  • pest control
  • hygiene
  • segregation
  • product identification
  • stock rotation
  • contamination prevention
  • traceability

7. Transportation and Distribution Organizations

Food safety does not stop when a product leaves the manufacturing facility.

Transportation and distribution activities may affect:

  • temperature control
  • product integrity
  • contamination
  • handling
  • traceability
  • delivery conditions

The FSMS should address controls relevant to the organization’s activities.


8. Food Retail Organizations

Retail operations may handle food through:

  • receiving
  • storage
  • display
  • handling
  • preparation
  • distribution

The appropriate FSMS scope and controls depend on the organization’s actual activities.


9. Catering and Food-Service Organizations

Examples include:

  • institutional catering
  • commercial catering
  • restaurants
  • food-service operations
  • central kitchens
  • contract catering

Food-safety controls may include:

  • receiving
  • storage
  • preparation
  • cooking
  • holding
  • serving
  • cleaning
  • personnel hygiene
  • allergen controls
  • waste management

10. Cleaning and Sanitation Service Providers

Organizations providing services that directly or indirectly affect food safety can also be relevant to the food chain.

This is particularly important where sanitation activities affect food-production environments.


11. Equipment and Service Suppliers

Organizations supplying equipment, cleaning materials, disinfectants, packaging materials and other relevant inputs may form part of the broader food chain.

The current ISO/DIS 22000 material also identifies a broad range of directly and indirectly involved organizations, including equipment suppliers, cleaning and disinfectant suppliers, packaging-material suppliers and food-contact-material suppliers.


5. Understanding the Food Chain

A useful way to understand ISO 22000 is to visualize the journey of food:

Primary Production

↓

Raw Materials

↓

Ingredient Suppliers

↓

Food Processing

↓

Manufacturing

↓

Packaging

↓

Storage

↓

Transportation

↓

Distribution

↓

Retail / Food Service

↓

Consumer

Food safety can be influenced at every stage.

That is why an effective FSMS needs to consider not just what happens inside one facility, but also relevant interactions with suppliers, customers and other organizations within the food chain.


6. What Are Food-Safety Hazards?

At the heart of ISO 22000 is the need to identify and control relevant food-safety hazards.

Broadly, organizations may need to consider hazards such as:

🦠 Biological Hazards

Examples can include:

  • pathogenic bacteria
  • viruses
  • parasites
  • biological toxins

🧪 Chemical Hazards

Examples can include:

  • chemical contamination
  • cleaning-chemical residues
  • pesticide residues
  • veterinary-drug residues
  • naturally occurring toxins

🧱 Physical Hazards

Examples can include:

  • glass
  • metal
  • stones
  • hard plastic
  • other foreign materials

⚠️ Allergen-Related Risks

Depending on the product and applicable requirements, allergen management can become a significant part of food-safety controls.

The exact hazards, significance and controls must be determined based on the organization’s products, processes, intended use and applicable requirements.


7. ISO 22000 and HACCP — Are They the Same?

No.

This is one of the most common questions.

HACCP

Hazard Analysis and Critical Control Points is a systematic methodology for identifying and controlling food-safety hazards.

ISO 22000

ISO 22000 is a Food Safety Management System standard.

It incorporates HACCP-based hazard-control thinking into a broader management system.

ISO explains that ISO 22000 strengthens the traditional HACCP approach by combining food-safety hazard controls with management-system requirements such as policy, planning, implementation, performance assessment, management review and improvement.

A simplified way to understand the relationship is:

HACCP = Food-safety hazard-control methodology

ISO 22000 = Food-safety management system incorporating hazard-control principles


8. What Does ISO 22000 Add to HACCP?

This is where ISO 22000 becomes particularly valuable for organizations looking for a structured management system.

ISO 22000 connects food-safety hazard control with:

  • Leadership
  • Food-safety policy
  • Organizational context
  • Planning
  • Competence
  • Communication
  • Documented information
  • Operational control
  • Monitoring
  • Internal audit
  • Management review
  • Corrective action
  • Continual improvement

ISO also explains that ISO 22000 integrates PRPs, operational PRPs and HACCP plans through hazard analysis into an integrated food-control system.

So the relationship can be visualized as:

Management System

Leadership + Planning + Support + Evaluation + Improvement

↓

Food-Safety Controls

PRPs + OPRPs + HACCP Plan

↓

Food-Safety Performance

Safe Food + Evidence + Verification + Improvement


9. What Are PRPs?

PRP = Prerequisite Programme.

PRPs establish the basic conditions and activities needed to maintain an appropriate hygienic environment.

Depending on the organization, these may address areas such as:

  • cleaning and sanitation
  • pest control
  • personnel hygiene
  • facility hygiene
  • equipment maintenance
  • waste management
  • supplier controls
  • storage
  • transportation
  • utilities
  • contamination prevention

PRPs create the foundation on which the food-safety control system operates.

A useful way to think about it is:

PRPs establish the environment in which safe food can be produced.


10. What Are OPRPs?

OPRP = Operational Prerequisite Programme.

Within ISO 22000’s food-safety control framework, hazard analysis can identify controls that are necessary for managing significant hazards but are not controlled through CCPs.

These controls can be managed through OPRPs.

Therefore, ISO 22000 provides a structured way of connecting:

Hazard Analysis

→ PRPs

→ OPRPs

→ CCPs / HACCP Plan

→ Monitoring

→ Verification

The precise controls depend on the organization’s food products, processes and hazard analysis.


11. What Is a CCP?

CCP = Critical Control Point.

A CCP is a step at which control can be applied and is essential to prevent, eliminate or reduce a significant food-safety hazard to an acceptable level.

Examples in different food processes could involve controls associated with:

  • cooking
  • pasteurization
  • sterilization
  • metal detection
  • temperature control

However, organizations should not assume that a particular process is automatically a CCP.

The classification should result from the organization’s hazard analysis and established methodology.

This distinction is extremely important during ISO 22000 implementation.


12. ISO 22000 Is More Than “Food Safety Documentation”

A common implementation mistake is to start with:

“What documents do we need?”

A better starting point is:

1. What products do we make?

↓

2. What processes do we perform?

↓

3. What hazards could arise?

↓

4. Which hazards are significant?

↓

5. What controls are required?

↓

6. How are those controls monitored?

↓

7. How do we verify their effectiveness?

↓

8. What happens when something goes wrong?

↓

9. How does management evaluate performance?

↓

10. How does the organization improve?

Only after understanding those questions should documentation be designed.


13. Traceability — A Critical Element of Food Safety

Imagine a food manufacturer discovers that a particular raw material may have a safety issue.

Can the organization identify:

  • Which supplier supplied it?
  • Which batch was received?
  • Where was it used?
  • Which production batch contains it?
  • Where was the finished product distributed?
  • Which customers received it?

That is where traceability becomes important.

An effective traceability system should enable the organization to understand relevant links through the food chain and support appropriate action when a food-safety issue occurs.

Traceability should therefore not be treated as just a register.

It should be a working operational capability.


14. Emergency Preparedness and Response

Food-safety emergencies can arise from situations such as:

  • contamination events
  • equipment failures
  • utility failures
  • natural events
  • fire
  • water contamination
  • refrigeration failure
  • supply disruption
  • product incidents
  • suspected food-safety incidents

The organization should consider relevant emergency scenarios and establish appropriate response arrangements.

A mature FSMS asks:

“What happens if our normal food-safety controls fail?”

Not merely:

“Do we have an emergency procedure?”


15. Communication Is Central to ISO 22000

Food safety depends on information moving correctly.

Communication may occur between:

Suppliers ↔ Organization ↔ Customers ↔ Regulators ↔ Employees ↔ Other Food-Chain Organizations

Relevant information may include:

  • product requirements
  • food-safety hazards
  • specifications
  • changes
  • incidents
  • regulatory requirements
  • supplier information
  • customer requirements

Poor communication can create food-safety risks even when individual processes appear well controlled.


16. Food Safety Culture

A strong FSMS is not created only by the food-safety team.

It requires participation across the organization.

Consider a production employee who notices a possible contamination issue.

What happens next?

If employees are encouraged to report concerns and management responds appropriately, the organization has a stronger foundation for food-safety performance.

Food safety culture can therefore be reflected through:

  • leadership commitment
  • employee awareness
  • communication
  • accountability
  • reporting of issues
  • training
  • appropriate response to food-safety concerns
  • continual improvement

Consultant’s Insight

Food safety culture becomes visible when people make the right food-safety decision even when nobody is standing beside them.

That is why ISO 22000 implementation should not be reduced to training people on procedures.

People need to understand why the control exists.


17. ISO 22000 vs ISO 9001

Both are management-system standards, but their primary focus differs.

AreaISO 22000ISO 9001
Primary focusFood safetyQuality management
Main objectiveControl food-safety hazardsConsistent products/services and customer satisfaction
Food-chain applicabilitySpecifically designed for food chainGeneral applicability
Hazard analysisCentral to FSMSRisk-based quality approach
HACCP principlesIntegrated into food-safety control frameworkNot a core requirement
PRPsFundamental to food-safety controlsNot a central ISO 9001 requirement
Food-safety communicationSpecific importanceGeneral organizational/customer communication
CertificationAvailableAvailable

These standards can also be integrated.

For a food manufacturing organization, an integrated management system can combine:

ISO 9001 → Quality

ISO 22000 → Food Safety

potentially other systems such as:

ISO 14001 → Environment

ISO 45001 → Occupational Health & Safety

This can reduce duplication where processes genuinely overlap.


18. ISO 22000 vs FSSC 22000

Another common search question is:

“Is ISO 22000 the same as FSSC 22000?”

No.

ISO 22000 is an ISO Food Safety Management System standard.

FSSC 22000 is a separate food-safety certification scheme built around ISO 22000 together with additional requirements and relevant prerequisite-programme standards.

Therefore, organizations should not treat:

ISO 22000 = FSSC 22000

as equivalent statements.

The certification objective, scheme requirements and applicable additional requirements need to be understood before choosing the appropriate route.


19. ISO 22000:2018 and the 2026 Update

This is particularly important for anyone researching ISO 22000 certification now.

Current published standard

ISO 22000:2018

ISO currently lists this as the published edition and says it was last reviewed and confirmed in 2023.

Amendment

ISO 22000:2018/Amd 1:2024

The amendment is titled:

Climate action changes

and was published in February 2024.

Future revision

ISO/DIS 22000 is currently under development as the proposed revision of ISO 22000.

As of the latest ISO information available, the draft is in the enquiry/development lifecycle rather than being a published replacement standard. ISO’s lifecycle information shows the DIS process and indicates that the document has been referred back within the development process, so organizations should not treat the draft as the current certifiable edition.

Therefore:

Current published edition:
ISO 22000:2018 + applicable Amendment 1:2024

Future revision:
ISO/DIS 22000 — under development

This distinction is important for organizations planning certification in 2026.


20. What Does the Climate-Action Amendment Mean?

The 2024 amendment is titled Climate action changes.

This is part of a broader change affecting ISO management-system standards.

Organizations implementing or maintaining ISO 22000 should therefore consider the relevance of climate change to their management-system context and applicable interested-party requirements.

The important point is:

Do not create a separate climate document simply because the word “climate” appears in an amendment.

Instead, determine:

  • Is climate change relevant to our FSMS?
  • Could climate-related conditions affect food safety?
  • Could climate-related changes affect suppliers or the food chain?
  • Have relevant interested-party expectations changed?
  • Are risks and opportunities affected?

The organization’s actual context should determine the response.


21. Benefits of ISO 22000 Certification

ISO 22000 certification can provide a structured framework for organizations to strengthen food-safety management.

Potential benefits include:

🛡️ Better Food-Safety Control

Systematic identification and control of food-safety hazards.

🔍 Improved Traceability

Better ability to trace relevant materials and products.

📋 Structured Processes

Defined responsibilities and controlled food-safety processes.

🤝 Supplier and Food-Chain Control

Better management of relevant external interactions.

📊 Performance Evaluation

Monitoring, measurement, internal audit and management review.

🚨 Better Preparedness

Defined responses to relevant food-safety emergencies.

🔄 Continual Improvement

Corrective action and continual improvement become part of the management system.

🌍 Market Confidence

Certification can provide evidence to customers and other interested parties that an organization operates a certified FSMS.

ISO itself states that ISO 22000 can be certified and provides a framework for organizations to demonstrate their ability to control food-safety hazards and ensure food is safe.


22. What ISO 22000 Certification Does NOT Mean

Certification should not be misunderstood.

An ISO 22000 certificate does not mean:

❌ Every possible food-safety risk has been eliminated.

❌ The organization will never experience a food-safety incident.

❌ The certificate replaces legal or regulatory requirements.

❌ HACCP is no longer necessary.

❌ Every product is automatically “ISO certified.”

❌ Certification eliminates the need for monitoring and verification.

Instead, certification provides independent conformity assessment of the organization’s management system against the applicable certification requirements.

Food safety remains an ongoing operational responsibility.


23. ISO 22000 Implementation: The Basic Management Cycle

A practical implementation can be visualized as:

UNDERSTAND

Understand the organization, food chain and requirements.

↓

IDENTIFY

Identify hazards, processes, interested parties and risks.

↓

CONTROL

Establish PRPs, OPRPs, CCP-related controls and operational processes.

↓

IMPLEMENT

Put the FSMS into practice.

↓

MONITOR

Measure and monitor relevant controls and processes.

↓

VERIFY

Verify that the system is functioning as intended.

↓

AUDIT

Conduct internal audits.

↓

REVIEW

Management evaluates the FSMS.

↓

IMPROVE

Correct problems and continually improve.

This is the management-system thinking behind ISO 22000.


24. What Does an ISO 22000 Auditor Actually Want to See?

One of the biggest misconceptions is that certification audits are primarily about checking documents.

Documentation matters.

But the auditor ultimately needs objective evidence that the system is implemented and functioning.

The evidence chain can be thought of as:

Requirement

↓

Process

↓

Implementation

↓

Record / Evidence

↓

Monitoring

↓

Verification

↓

Improvement

For example:

Requirement: Control a food-safety hazard.

↓

Process: Defined control method.

↓

Implementation: Employees follow the control.

↓

Evidence: Monitoring records.

↓

Verification: Verification activities confirm control effectiveness.

↓

Improvement: Corrective action is taken when performance is inadequate.

That is much stronger than simply presenting a procedure to an auditor.


25. ISO 22000 for Indian Food Businesses

For Indian organizations, an FSMS may need to operate alongside applicable statutory and regulatory food-safety requirements.

Organizations may include:

  • food manufacturers
  • food processors
  • restaurants
  • catering companies
  • food packaging companies
  • warehouses
  • distributors
  • exporters
  • ingredient suppliers
  • food-service organizations

The exact regulatory obligations depend on the organization’s activities, products, location and market.

Therefore:

ISO 22000 ≠ regulatory compliance

Instead:

ISO 22000 + applicable statutory/regulatory requirements

should work together within the organization’s food-safety management framework.

This distinction is particularly important when preparing for certification.


26. ISO 22000 for Hyderabad and Telangana Food Businesses

Hyderabad and Telangana have a broad ecosystem of food-related organizations, including:

  • food manufacturers
  • packaged-food businesses
  • food-processing companies
  • dairy-related businesses
  • spice and ingredient suppliers
  • restaurants
  • catering organizations
  • cloud kitchens
  • warehouses
  • distributors
  • food-export businesses

For these organizations, ISO 22000 implementation should begin with the actual food-safety risks and processes of the organization, rather than copying a generic FSMS manual.

A food manufacturer, restaurant, warehouse and packaging supplier may all use ISO 22000, but their processes and hazard profiles will not be identical.

That is why scope and hazard analysis are foundational activities.


27. Common ISO 22000 Implementation Mistakes

Mistake 1 — Treating ISO 22000 as Only HACCP

ISO 22000 is broader than HACCP because it establishes a management-system framework around food safety.


Mistake 2 — Copying a Generic HACCP Plan

Hazard analysis should reflect the organization’s actual products, processes and intended use.


Mistake 3 — Creating Documents Before Understanding Processes

Documentation should represent the actual FSMS.


Mistake 4 — Ignoring PRPs

Food-safety controls cannot be considered in isolation from the prerequisite conditions supporting hygienic operations.


Mistake 5 — Weak Traceability

A traceability procedure that cannot be demonstrated through an actual exercise is a weakness.


Mistake 6 — Collecting Monitoring Records Without Verification

A completed form does not automatically demonstrate that the FSMS is effective.


Mistake 7 — Treating Internal Audit as a Formality

Internal audit should evaluate the effectiveness and conformity of the system.


Mistake 8 — Management Review Without Management Decisions

Management review should result in meaningful evaluation and decisions where appropriate.


Mistake 9 — Ignoring Supplier Controls

Food safety can be influenced before raw materials enter the organization.


Mistake 10 — Confusing the Current Standard With the Draft Revision

In 2026, this is especially important.

ISO 22000:2018 remains the published edition, with Amendment 1:2024, while the revision represented by ISO/DIS 22000 remains under development.

What exactly does ISO 22000:2018 require?

ISO 22000:2018 is structured around the familiar ISO management-system framework, with the core requirements for the FSMS contained in Clauses 4 through 10.

These clauses move logically from:

Context → Leadership → Planning → Support → Operation → Performance Evaluation → Improvement

The important distinction is that ISO 22000 adds a highly specialized food-safety operational layer, particularly in Clause 8, covering prerequisite programmes, traceability, emergency preparedness, hazard analysis, hazard control plans, verification and control of nonconforming products and processes.

ISO currently lists ISO 22000:2018 as the published edition, with Amendment 1:2024 on climate-action changes. ISO also identifies a future ISO/DIS 22000 revision under development.

So let’s examine the clauses from an implementation and auditor perspective.

What are the ISO 22000:2018 Clauses?

The main ISO 22000:2018 Food Safety Management System requirements are contained in Clauses 4–10:

ClauseMain Area
4Context of the Organization
5Leadership
6Planning
7Support
8Operation
9Performance Evaluation
10Improvement

For food businesses, Clause 8 is particularly significant because it contains the operational food-safety controls, including prerequisite programmes (PRPs), traceability, emergency preparedness, hazard analysis, validation of control measures, HACCP/OPRP plans, monitoring, verification and control of nonconforming products and processes.

The clauses work together rather than operating as separate checklists.

Clause 4 defines the context → Clause 5 establishes leadership → Clause 6 plans the system → Clause 7 provides support → Clause 8 controls operations → Clause 9 evaluates performance → Clause 10 drives improvement.


ISO 22000:2018 Clause Structure at a Glance

Before going into the details, this is the management-system architecture we should keep in mind:

CLAUSE 4

Context

↓

CLAUSE 5

Leadership

↓

CLAUSE 6

Planning

↓

CLAUSE 7

Support

↓

CLAUSE 8

Food-Safety Operations

↓

CLAUSE 9

Performance Evaluation

↓

CLAUSE 10

Improvement

And throughout the system:

Communication + System Management + PRPs + HACCP Principles

ISO itself identifies these as key components of ISO 22000.

Clause 4 — Context of the Organization

Clause 4 establishes the environment in which the FSMS operates.

It asks:

What is the organization, what affects its food-safety objectives, who matters to it, and what is included in the FSMS?


4.1 Understanding the Organization and Its Context

The organization needs to determine the internal and external issues relevant to its purpose and that can affect its ability to achieve the intended outcomes of the FSMS.

External issues could include:

  • Food-safety regulations
  • Market requirements
  • Customer requirements
  • Supply-chain conditions
  • Technology
  • Climate-related conditions
  • Economic factors
  • Industry developments
  • Emerging food-safety hazards

Internal issues could include:

  • Organization structure
  • Employee competence
  • Production capacity
  • Equipment
  • Food-safety culture
  • Existing processes
  • Organizational knowledge
  • Infrastructure
  • Internal communication

Example

Consider a packaged-food manufacturer in Hyderabad.

External issues could include:

Regulatory requirements → customer specifications → supplier risks → climate conditions → market expectations

Internal issues could include:

Production capacity → employee competency → equipment condition → sanitation controls → laboratory capability

These issues can influence how the FSMS is designed and maintained.


🌡️ 2026 Climate-Action Consideration

The 2024 amendment to ISO 22000:2018 is titled Climate action changes.

Therefore, organizations maintaining an ISO 22000 FSMS should consider whether climate change is a relevant issue in their context and whether relevant interested parties have climate-related requirements.

This should be treated as a contextual assessment, not as an instruction to create a generic “climate document.”

The question is:

Could climate change affect our food-safety management system or our ability to achieve intended FSMS outcomes?

The answer should be based on the organization’s actual circumstances.

ISO lists Amendment 1:2024 as part of the current ISO 22000:2018 edition.

4.2 Understanding the Needs and Expectations of Interested Parties

Food safety rarely depends on one organization alone.

Relevant interested parties may include:

  • Consumers
  • Customers
  • Regulatory authorities
  • Suppliers
  • Employees
  • Contractors
  • Certification bodies
  • Owners
  • Distribution partners
  • Retailers
  • Industry organizations

Each may have requirements relevant to the FSMS.

Example

A food manufacturer may need to consider:

Regulator → statutory requirements

Customer → product specification

Consumer → allergen information

Supplier → raw-material information

Employee → food-safety responsibilities

Certification body → conformity requirements

The organization should determine which of these requirements are relevant to its FSMS.


4.3 Determining the Scope of the FSMS

The scope defines the boundaries of the Food Safety Management System.

It should clearly identify the relevant:

  • Products
  • Processes
  • Sites
  • Activities
  • Food-chain categories
  • Organizational boundaries

Example

Instead of writing:

“Food manufacturing.”

A more useful scope could identify the actual activities covered, such as:

“Manufacture and packaging of ready-to-eat cereal-based food products at the Hyderabad manufacturing facility.”

The exact wording must reflect the organization’s actual activities.


4.4 Food Safety Management System

The organization needs to establish, implement, maintain, update and continually improve the FSMS.

This means the FSMS is not a one-time certification project.

It is a living management system.


Clause 4 — What an Auditor May Look For

RequirementPossible Evidence
Organizational contextContext analysis
Interested partiesInterested-party register
Relevant requirementsRegulatory/customer requirements
FSMS scopeApproved scope statement
FSMS processesProcess interaction map
System maintenanceReview/update records

Auditor mindset

An auditor may ask:

“Why did you identify this issue as relevant to your FSMS?”

The organization should be able to explain the reasoning.


Clause 5 — Leadership

Food safety cannot be delegated entirely to the quality or food-safety department.

Top management has an important role in establishing and maintaining the FSMS.


5.1 Leadership and Commitment

Leadership should demonstrate commitment to the FSMS.

This can include:

  • Ensuring the FSMS is integrated into business processes
  • Providing necessary resources
  • Supporting food-safety objectives
  • Communicating the importance of food safety
  • Ensuring the FSMS achieves intended outcomes
  • Supporting relevant personnel
  • Promoting continual improvement

The practical question

If production targets conflict with a food-safety control, what does management do?

That is where leadership commitment becomes visible.


5.2 Food Safety Policy

The organization should establish a food-safety policy appropriate to its purpose and context.

A useful policy should communicate the organization’s commitment to:

  • Food safety
  • Applicable requirements
  • Relevant objectives
  • Continual improvement
  • Appropriate communication

But a policy should not simply be displayed on a wall.

Employees should understand what it means for their work.


5.3 Organizational Roles, Responsibilities and Authorities

Who is responsible for:

  • Food-safety decisions?
  • Hazard analysis?
  • PRPs?
  • Monitoring?
  • Verification?
  • Product release?
  • Nonconforming product?
  • Traceability?
  • Recall?
  • Internal audit?
  • Corrective action?

Responsibilities need to be clear.

A common implementation weakness is:

“The Quality Manager is responsible for everything.”

An effective FSMS distributes responsibility according to actual organizational roles.


Food Safety Team

ISO 22000 uses a food-safety-team approach for important FSMS activities.

The team should have appropriate knowledge and competence relevant to the organization’s food products, processes and food-safety hazards.

This could involve expertise in:

  • Food technology
  • Microbiology
  • Production
  • Quality
  • Engineering
  • Maintenance
  • Sanitation
  • Regulatory requirements

The exact team composition depends on the organization’s size and complexity.


Clause 5 — Auditor Evidence

AreaExample Evidence
LeadershipManagement commitment
PolicyApproved food-safety policy
ResponsibilitiesOrganization chart / responsibility matrix
Food-safety teamTeam appointment
CompetenceQualification/training records
CommunicationMeeting records
ResourcesBudget/equipment/personnel evidence

Clause 6 — Planning

Clause 6 converts context and leadership direction into structured planning.

It answers:

What could affect the FSMS, what are we trying to achieve, and how will we manage change?


6.1 Actions to Address Risks and Opportunities

The organization should determine risks and opportunities that need to be addressed to ensure the FSMS can achieve its intended outcomes.

This is different from the detailed food-hazard analysis in Clause 8.

Important distinction

Clause 6 risk planning

looks at risks and opportunities affecting the FSMS.

Clause 8 hazard analysis

looks specifically at food-safety hazards associated with products, processes and the process environment.

They should not simply be treated as the same exercise.


6.2 FSMS Objectives and Planning to Achieve Them

Organizations should establish appropriate food-safety objectives.

A good objective should be:

  • Relevant
  • Measurable where appropriate
  • Monitored
  • Communicated
  • Updated when necessary

Example objectives

Instead of:

“Improve food safety.”

Consider objectives such as:

  • Reduce repeat sanitation-related nonconformities.
  • Improve traceability exercise performance.
  • Increase completion of food-safety training.
  • Reduce supplier-related food-safety deviations.
  • Improve corrective-action closure performance.

The actual objective should reflect the organization’s context and risks.


6.3 Planning of Changes

Food-safety changes should be planned.

Changes might involve:

  • New products
  • New ingredients
  • New suppliers
  • New equipment
  • New production lines
  • New packaging
  • New facility layouts
  • Process changes
  • New regulatory requirements
  • Changes in personnel
  • Changes in production volumes

The organization should consider the potential impact of the change on the FSMS.


Clause 6 — Auditor Evidence

Possible evidence includes:

  • Risk and opportunity assessment
  • FSMS objectives
  • KPI records
  • Action plans
  • Change-management records
  • Management decisions
  • Objective monitoring

Clause 7 — Support

Clause 7 asks:

Does the organization have the people, infrastructure, knowledge, communication and documented information necessary to operate the FSMS?


7.1 Resources

Resources can include:

People

Adequately competent personnel.

Infrastructure

Such as:

  • Buildings
  • Production equipment
  • Utilities
  • Storage facilities
  • IT systems
  • Transportation arrangements

Work environment

Conditions necessary to support food-safety operations.

Monitoring and measuring resources

Where monitoring and measurement are required, suitable resources need to be available and appropriately controlled.


7.2 Competence

People performing work that affects food safety should have appropriate competence.

Competence may come from:

  • Education
  • Training
  • Experience
  • Skills
  • Supervision
  • Demonstrated capability

Example

A person responsible for monitoring a food-safety control should understand:

  • What needs to be monitored
  • How it is monitored
  • The required limits/criteria
  • What to do when monitoring indicates loss of control
  • How to record results

Training should therefore be connected to actual responsibilities.


7.3 Awareness

Employees should understand relevant aspects of food safety, including the implications of not following applicable FSMS requirements.

This is where food-safety culture and employee behavior become important.


7.4 Communication

ISO 22000 places significant importance on communication.

External communication can include:

  • Suppliers
  • Customers
  • Regulatory authorities
  • Contractors
  • Certification bodies
  • Other food-chain organizations

Internal communication can include:

  • Changes in processes
  • Food-safety incidents
  • New hazards
  • Product changes
  • Customer requirements
  • Regulatory changes
  • Monitoring results

Food safety depends heavily on timely and accurate information flow.


7.5 Documented Information

The FSMS needs appropriate documented information.

This may include:

  • Policies
  • Procedures
  • Hazard-analysis information
  • PRPs
  • HACCP/OPRP plans
  • Monitoring records
  • Verification records
  • Traceability records
  • Internal audit records
  • Management review records
  • Corrective-action records

But documentation should be proportional to the organization’s needs.

The objective is not:

More documents.

The objective is:

Controlled information that supports safe and consistent operation.


Clause 7 — Auditor Evidence

AreaExample Evidence
CompetenceTraining/qualification records
AwarenessInterviews
InfrastructureFacility/equipment records
Monitoring resourcesCalibration/verification evidence
CommunicationEmails, meetings, notifications
Documented informationControlled procedures and records

Clause 8 — Operation

🔥 The Technical Heart of ISO 22000

Clause 8 is where the management system meets the actual food-safety operation.

It includes:

  • Operational planning and control
  • PRPs
  • Traceability
  • Emergency preparedness
  • Hazard control
  • Hazard analysis
  • Validation
  • HACCP/OPRP plan
  • Monitoring
  • Verification
  • Product/process nonconformities
  • Withdrawal and recall

ISO 22000’s operational structure specifically includes these elements.

8.1 Operational Planning and Control

The organization needs to plan, implement, control, maintain and update processes necessary to meet food-safety requirements.

This includes implementing actions identified during planning and controlling relevant operational changes.

Think of it as:

Plan → Implement → Control → Monitor → Update


8.2 Prerequisite Programmes — PRPs

PRPs provide the basic conditions and activities needed to support a hygienic environment suitable for safe food production and handling.

Examples may include:

  • Cleaning and sanitation
  • Pest control
  • Personnel hygiene
  • Waste management
  • Utilities
  • Equipment maintenance
  • Storage
  • Transportation
  • Supplier controls
  • Prevention of cross-contamination
  • Facility hygiene

Important 2026 update

The ISO 22002 series was significantly restructured and updated in 2025.

ISO 22002-100:2025 provides common PRP requirements for the food, feed and packaging supply chain, while sector-specific documents address areas such as food manufacturing, catering, packaging, transport and storage. ISO

For food manufacturing specifically, ISO 22002-1:2025 specifies PRP requirements to be used with ISO 22002-100. ISO lists the previous ISO/TS 22002-1:2009 as withdrawn and ISO 22002-1:2025 as the published replacement. ISO

This is an important point for organizations implementing or updating their FSMS in 2026.


8.3 Traceability System

The organization needs a traceability system appropriate to its products and processes.

The objective is to establish relevant links between:

Input → Process → Output

For example:

Supplier

↓

Raw-material batch

↓

Production batch

↓

Finished product

↓

Customer/distribution

A traceability exercise should demonstrate that the system actually works.


8.4 Emergency Preparedness and Response

The organization should establish processes for responding to relevant emergencies and incidents that can affect food safety.

Possible scenarios include:

  • Power failure
  • Water contamination
  • Fire
  • Flood
  • Refrigeration failure
  • Equipment failure
  • Product contamination
  • Natural events
  • Supply disruption
  • Food-safety incident

The organization should not merely maintain a list of emergencies.

It should understand:

Who responds?

What is communicated?

What product is affected?

How is food safety protected?

How is the incident recorded?

What happens after the emergency?


8.5 Hazard Control

This is one of the most important sections in ISO 22000.

The organization needs to conduct systematic hazard analysis and establish appropriate control measures.


8.5.1 Preliminary Steps to Enable Hazard Analysis

Before performing hazard analysis, the organization needs appropriate information about:

  • Products
  • Raw materials
  • Ingredients
  • Product characteristics
  • Intended use
  • Process steps
  • Process environment
  • Existing PRPs
  • Regulatory/customer requirements

8.5.1.4 Intended Use

The intended use of the product is important because the same hazard can have different implications depending on how the product is expected to be used.

Consider:

Ready-to-eat product

versus

Product intended to be cooked before consumption

The hazard-control analysis needs to reflect the intended use.


8.5.1.5 Process Description

The food-safety team should understand the actual process.

This can involve:

  • Process flow
  • Equipment
  • Materials
  • Contact surfaces
  • Processing conditions
  • Existing controls
  • Process environment
  • Seasonal variations
  • Shift-related variations

The flow diagram should represent reality.

Auditor question:

“Can I walk through the production floor and see the same process described in your flow diagram?”

If the answer is no, the organization has a problem.


8.5.2 Hazard Analysis

Now comes the core food-safety analysis.

The organization should identify hazards that are reasonably expected to occur.

These may include:

Biological

  • Pathogens
  • Viruses
  • Parasites
  • Toxins

Chemical

  • Cleaning chemicals
  • Pesticide residues
  • Chemical contaminants
  • Naturally occurring toxins

Physical

  • Glass
  • Metal
  • Stone
  • Hard plastic

Other relevant hazards

Including allergen-related risks where applicable.

The hazard identification should be based on relevant information, experience, scientific and historical information, food-chain information and applicable statutory, regulatory and customer requirements. studylib.net


Hazard Assessment

Identifying a hazard does not automatically mean that it is a significant food-safety hazard requiring the same type of control.

The organization needs a defined methodology for evaluating hazards.

Factors can include:

Likelihood of occurrence

Severity of adverse health effects

→

Significance of the hazard

The organization should document the methodology and results.


Acceptable Levels

Where applicable, the organization needs to establish acceptable levels for identified food-safety hazards.

These levels need to consider relevant:

  • Legal requirements
  • Regulatory requirements
  • Customer requirements
  • Intended use
  • Scientific information
  • Other relevant information

The rationale should be documented.


8.5.2.4 Selection and Categorization of Control Measures

Once significant hazards are identified, appropriate control measures need to be selected.

This is where the food-safety team determines:

What control is required?

Where should it be applied?

How effective does it need to be?

How will it be monitored?

Control measures can then be categorized within the ISO 22000 framework, including through:

  • PRPs
  • OPRPs
  • CCPs

PRP vs OPRP vs CCP

This is one of the most important concepts in ISO 22000.

ElementMain PurposeTypical Question
PRPEstablish basic hygienic/operational conditionsIs the environment suitable for safe food?
OPRPControl a significant hazard through an operational prerequisite controlWhat operational control is necessary to prevent/reduce a significant hazard?
CCPControl a significant hazard at a critical pointAt what step is control essential and measurable against critical limits?

Simplified model

PRPs

↓

Create the hygienic foundation

↓

Hazard Analysis

↓

Determine significant hazards

↓

OPRPs / CCPs

↓

Control significant hazards

↓

Monitoring + Verification

↓

Demonstrate control

The organization should use a defined methodology rather than simply labeling every important control as a CCP.


8.5.3 Validation of Control Measures

Before relying on a control measure or combination of control measures, the organization needs to establish that the measure is capable of achieving the intended level of control.

Example

Suppose a heat treatment is being used to control a microbiological hazard.

The organization needs evidence supporting the effectiveness of the specified control conditions.

This is different from routine monitoring.

Validation asks:

Will this control work?

Monitoring asks:

Are we applying the control as planned?

Verification asks:

Is the FSMS and its controls working as intended?

These three concepts should not be confused.


8.5.4 Hazard Control Plan — HACCP / OPRP Plan

The organization should establish an appropriate hazard-control plan.

The plan should identify relevant information such as:

  • Hazard
  • Control measure
  • CCP or OPRP categorization
  • Critical limits or action criteria, as applicable
  • Monitoring
  • Responsibilities
  • Frequency
  • Corrections/corrective actions
  • Records

Example

ProcessHazardControlClassificationMonitoring
CookingBiologicalControlled cooking conditionCCPTemperature/time
Metal detectionPhysicalMetal detectorCCP/appropriate control based on analysisChallenge/monitoring
CleaningCross-contaminationSanitation programmePRP/OPRP as determinedInspection/testing

These examples are illustrative only. The actual classification must come from the organization’s hazard analysis.


8.6 Updating Information Specifying PRPs and Hazard-Control Plan

Food-safety systems need to change when the organization changes.

Triggers can include:

  • New raw materials
  • New suppliers
  • New equipment
  • New products
  • Process changes
  • New hazards
  • Incidents
  • Regulatory changes
  • Customer requirements
  • Verification findings

When relevant information changes, the organization should review whether its PRPs and hazard-control plan also need updating.


8.7 Control of Monitoring and Measuring

Monitoring and measuring equipment used for food-safety controls needs appropriate management.

Depending on the equipment, this can involve:

  • Calibration
  • Verification
  • Maintenance
  • Identification
  • Protection from damage
  • Suitable measurement capability

Example

If temperature is a food-safety control, the organization needs confidence that the thermometer or temperature-monitoring system provides reliable information.

A completed temperature log is only useful if the measurement system itself is trustworthy.


8.8 Verification Related to PRPs and Hazard-Control Plan

Verification asks whether the FSMS controls are operating as intended.

Verification can involve:

  • Review of monitoring records
  • Inspection
  • Testing
  • Sampling
  • Internal audits
  • Analysis of results
  • Review of PRP effectiveness
  • Review of hazard-control performance

The difference:

Monitoring: What is happening now?

Verification: Is the control system working as intended?

Validation: Will the selected control work?

These distinctions are extremely important during an ISO 22000 audit.


8.9 Control of Product and Process Nonconformities

What happens when a food-safety control fails?

The organization needs processes for dealing with:

  • Nonconforming products
  • Process deviations
  • Loss of control
  • Potentially unsafe products
  • Corrective action

The organization should determine appropriate action based on the food-safety implications.


Withdrawal and Recall

If a product that may be unsafe has entered the food chain, the organization may need an appropriate withdrawal or recall process.

This should answer:

Who decides?

Who communicates?

How are affected batches identified?

How are customers informed?

How is product controlled?

How is the effectiveness of the withdrawal/recall evaluated?

A mock recall/traceability exercise can be an excellent way to test whether the system actually works.


Clause 8 — The Auditor’s Evidence Chain

This is the part I recommend organizations memorize:

Hazard → Control → Monitoring → Deviation → Action → Verification

For example:

Hazard: Microbiological contamination

↓

Control: Validated process condition

↓

Monitoring: Defined monitoring frequency

↓

Deviation: Control parameter outside required condition

↓

Action: Correction/corrective action and product disposition

↓

Verification: Evidence that the control system remains effective

That is what turns a food-safety plan into an operating FSMS.


Clause 9 — Performance Evaluation

Once the FSMS is implemented, the organization needs to determine:

Is it actually working?

Clause 9 provides the performance-evaluation framework.


9.1 Monitoring, Measurement, Analysis and Evaluation

The organization should determine what needs to be:

  • Monitored
  • Measured
  • Analyzed
  • Evaluated

Examples can include:

  • Food-safety objectives
  • Monitoring results
  • Verification results
  • Nonconformities
  • Customer complaints
  • Supplier performance
  • Audit findings
  • Product testing
  • Environmental monitoring, where applicable

The objective is not to collect data simply because it is available.

The organization should use relevant data to understand FSMS performance.


9.2 Internal Audit

Internal audit is one of the most important readiness activities.

The audit programme should consider:

  • Importance of processes
  • Changes affecting the organization
  • Previous audit results
  • Relevant requirements

The audit should determine whether the FSMS:

Conforms

and

Is effectively implemented and maintained.


A Strong ISO 22000 Internal Audit

A weak internal audit asks:

“Do you have a procedure?”

A stronger audit asks:

“Show me how this control operates.”

And then:

“Show me the evidence.”

And then:

“What happens when the control fails?”

And finally:

“How do you verify that the corrective action was effective?”

That is process-based auditing.


9.3 Management Review

Top management needs to review the FSMS at planned intervals to determine its continuing suitability, adequacy and effectiveness. SCS Global Services

Management review can consider:

  • Previous review actions
  • Changes in context
  • Monitoring and measurement
  • Verification results
  • Nonconformities
  • Corrective actions
  • Internal/external audit results
  • Regulatory/customer inspections
  • External-provider performance
  • Risks and opportunities
  • Achievement of FSMS objectives
  • Resource adequacy
  • Emergency situations
  • Incidents
  • Withdrawal/recall
  • Communication
  • Complaints
  • Improvement opportunities

The output should include decisions and actions concerning improvement and necessary updates or changes to the FSMS. SCS Global Services

Management Review Is Not:

“Management signed the minutes.”

Management Review Is:

Management evaluates FSMS performance and makes decisions.


Clause 10 — Improvement

Clause 10 closes the management-system loop.

It addresses:

  • Nonconformity
  • Corrective action
  • Continual improvement
  • FSMS updating

10.1 Nonconformity and Corrective Action

When a nonconformity occurs, the organization should:

1. React

Control and correct the issue.

2. Determine the cause

Understand why it happened.

3. Determine whether similar issues exist

Look beyond the individual incident.

4. Implement appropriate corrective action

Address the cause.

5. Review effectiveness

Determine whether the action worked.

6. Update the FSMS where necessary

Make appropriate changes.


Example: Repeated Temperature Deviation

Imagine a refrigerated food-storage area repeatedly exceeds the defined temperature requirement.

A weak response would be:

“Temperature corrected.”

A stronger FSMS response would ask:

What happened?

Temperature exceeded the required condition.

↓

What product was affected?

Identify affected batches.

↓

Why did it happen?

Equipment failure / monitoring failure / process issue.

↓

What immediate correction was taken?

Restore appropriate conditions and assess affected product.

↓

What corrective action is required?

Address the underlying cause.

↓

Was effectiveness verified?

Review subsequent monitoring data.

↓

Does the FSMS need updating?

Update controls if required.

That is continual-improvement thinking.


10.2 Continual Improvement

Continual improvement should be based on actual information.

Potential inputs include:

  • Audit results
  • Complaints
  • Verification results
  • Nonconformities
  • Corrective actions
  • Food-safety incidents
  • Performance trends
  • Management review
  • New knowledge
  • Changes in technology
  • Supplier performance

The goal is not simply:

“Improve.”

It is:

Use evidence to identify where the FSMS can perform better and take appropriate action.


ISO 22000:2018 Clauses 4–10 — Complete Matrix

ClauseRequirement AreaMain QuestionTypical Evidence
4ContextWhat affects our FSMS?Context, interested parties, scope
5LeadershipWho leads food safety?Policy, roles, leadership evidence
6PlanningWhat risks/objectives/change need management?Risk assessment, objectives, change planning
7SupportDo we have resources and competence?Training, infrastructure, communication, documents
8OperationHow do we control food-safety hazards?PRPs, hazard analysis, HACCP/OPRP plan, monitoring
9Performance EvaluationIs the FSMS working?KPI analysis, verification, internal audit, management review
10ImprovementHow do we correct and improve?NC, CAPA, improvement records

ISO 22000 Auditor Evidence Chain

A certification audit should ultimately connect the requirements to actual evidence.

Requirement

What does the FSMS require?

↓

Process

How does the organization implement it?

↓

Personnel

Who performs the activity?

↓

Control

What prevents or controls the food-safety hazard?

↓

Monitoring

How is the control monitored?

↓

Record

What evidence is retained?

↓

Verification

How does the organization confirm effectiveness?

↓

Corrective Action

What happens when the control fails?

↓

Improvement

What did the organization learn and change?

This is the difference between a documented FSMS and an implemented FSMS.


PRP → OPRP → CCP: The Relationship Explained

One of the most searched and misunderstood areas of ISO 22000 is the relationship between PRP, OPRP and CCP.

A practical conceptual model is:

PRPs

Create the basic hygienic environment.

Examples: cleaning, pest control, personnel hygiene, maintenance.

↓

Hazard Analysis

Identify and evaluate food-safety hazards.

↓

Significant Hazards

Determine which hazards require specific control.

↓

Control Measures

Select appropriate measures.

↓

Categorization

Determine the appropriate control framework, including OPRPs and CCPs as applicable.

↓

Monitoring

Establish monitoring methods and criteria.

↓

Verification

Confirm that controls operate effectively.

This is why hazard analysis should come before simply labeling controls as CCPs.


ISO 22000:2018 vs ISO 22002-1:2025

This distinction is increasingly important in 2026.

ISO 22000:2018

Provides the overall Food Safety Management System requirements.

ISO 22002-100:2025

Provides common PRP requirements for the food, feed and packaging supply chain.

ISO 22002-1:2025

Provides PRP requirements specifically for food manufacturing, used in conjunction with ISO 22002

Other 2025 ISO 22002 documents include sector-specific PRPs

The ISO catalogue lists published 2025 documents covering areas such as:

  • Catering
  • Food packaging manufacturing
  • Transport and storage
  • Feed and animal food production

The ISO food-safety committee also lists these as part of the updated ISO 22002 series.

Therefore:

ISO 22000 = FSMS

ISO 22002 series = PRP framework supporting food-safety controls

They should not be treated as interchangeable standards.


Common Clause-Level Implementation Mistakes

1. Weak Scope

The FSMS scope does not clearly reflect the actual food processes.

2. Generic Context Analysis

Organizations copy a generic SWOT/PESTLE document without connecting it to food safety.

3. Food Safety Policy With No Awareness

Employees cannot explain what the policy means for their work.

4. Food Safety Team Without Real Competence

People are appointed but lack relevant knowledge.

5. PRPs Copied From Another Company

PRPs do not reflect the actual facility or process.

6. Hazard Analysis Based on Templates

Hazards are copied instead of being evaluated from the organization’s real products and processes.

7. Too Many CCPs

Every important control is labeled a CCP.

8. Weak Monitoring

Monitoring forms are completed but deviations are not properly handled.

9. No Traceability Test

The organization has a traceability procedure but has never tested it.

10. Internal Audit Becomes a Checklist

The auditor checks documents instead of examining process effectiveness.

11. Management Review Becomes a Formal Meeting

Management signs minutes without analyzing performance.

12. Corrective Action Stops at Correction

The organization fixes the immediate problem but never addresses the underlying cause.


Consultant’s Insight

The strongest ISO 22000 systems connect the management system to the production floor.

If your FSMS exists in a computer folder but employees cannot explain the controls, the system is not mature.

If your HACCP plan identifies a hazard but the production team does not understand the control, the system is weak.

If monitoring records are completed but deviations are ignored, the system is weak.

If internal audits identify problems but management does not act, the system is weak.

A mature ISO 22000 system creates a continuous chain:

Leadership → Food-Safety Team → Hazard Analysis → Controls → Monitoring → Verification → Audit → Management Review → Corrective Action → Improvement

That is the real architecture of an effective FSMS.


ISO 22000 Certification Readiness — Clause-by-Clause Quick Check

Before moving toward certification, ask:

Clause 4

☑ Is the FSMS scope clear?
☑ Have relevant internal/external issues been identified?
☑ Have interested parties been identified?
☑ Has climate-change relevance been considered where applicable?

Clause 5

☑ Is top management involved?
☑ Is the food-safety policy established?
☑ Are responsibilities defined?
☑ Is the food-safety team competent?

Clause 6

☑ Are FSMS risks/opportunities addressed?
☑ Are objectives established?
☑ Are changes planned?

Clause 7

☑ Are people competent?
☑ Is awareness demonstrated?
☑ Is communication effective?
☑ Is documented information controlled?

Clause 8

☑ Are PRPs implemented?
☑ Is traceability functional?
☑ Is emergency preparedness established?
☑ Is hazard analysis completed?
☑ Are control measures validated?
☑ Are HACCP/OPRP plans implemented?
☑ Is monitoring effective?
☑ Is verification performed?
☑ Are nonconforming products controlled?
☑ Is withdrawal/recall capability tested?

Clause 9

☑ Are performance results evaluated?
☑ Has internal audit been completed?
☑ Has management review been conducted?

Clause 10

☑ Are nonconformities addressed?
☑ Is root-cause analysis appropriate?
☑ Is corrective-action effectiveness verified?
☑ Is continual improvement demonstrated?


The ISO 22000 Management System in One Diagram

CONTEXT

What affects food safety?

↓

LEADERSHIP

Who is responsible?

↓

PLANNING

What risks and objectives matter?

↓

SUPPORT

Do we have people, resources and knowledge?

↓

OPERATION

How are hazards controlled?

↓

PRPs + HAZARD ANALYSIS + OPRPs + CCPs + TRACEABILITY

↓

PERFORMANCE EVALUATION

Is the system working?

↓

MONITORING + VERIFICATION + INTERNAL AUDIT + MANAGEMENT REVIEW

↓

IMPROVEMENT

What needs to change?

↓

CORRECTIVE ACTION + CONTINUAL IMPROVEMENT

↓

A STRONGER FSMS

ISO 22000:2018 implementation and certification roadmap showing gap analysis, PRPs, HACCP, hazard control, internal audit, management review and certification readiness

How do you actually implement ISO 22000:2018 in an organization?

An effective Food Safety Management System cannot be created by simply purchasing a set of procedures, preparing a HACCP plan and scheduling a certification audit.

The implementation needs to connect:

Organization → Food Chain → Processes → Hazards → Controls → Monitoring → Verification → Audit → Management Review → Improvement

ISO 22000:2018 is the current published edition, and ISO says it remains current following its 2023 review. It has Amendment 1:2024 on climate-action changes. ISO/DIS 22000 is currently under development as the future revision, so organizations planning certification in 2026 should distinguish the current certifiable standard from the draft revision.

This guide provides a practical implementation roadmap for food manufacturers, processors, packaging organizations, catering businesses, warehouses, distributors and other organizations within the food chain.

How do you implement ISO 22000:2018?

ISO 22000:2018 implementation normally begins by defining the FSMS scope and conducting a gap analysis against the organization’s existing food-safety practices. The organization then establishes its food-safety team, context, interested-party requirements, policy, objectives and prerequisite programmes (PRPs). The food-safety team maps processes, identifies hazards, conducts hazard analysis and establishes appropriate control measures through the organization’s hazard-control plan. The FSMS is then implemented through training, operational controls, monitoring, traceability, verification and documented evidence.

After implementation, the organization conducts internal audits, addresses nonconformities, performs management review and evaluates certification readiness. A competent independent certification body can then audit the FSMS for certification. ISO itself does not perform certification; certification is carried out by independent certification bodies.

The ISO 22000 Implementation Journey

A practical implementation model is:

1. Define

FSMS Scope

↓

2. Understand

Context & Interested Parties

↓

3. Assess

Gap Analysis

↓

4. Organize

Food Safety Team

↓

5. Establish

PRPs

↓

6. Analyze

Food-Safety Hazards

↓

7. Control

OPRPs / CCPs / Hazard-Control Plan

↓

8. Implement

Processes & Training

↓

9. Monitor

Food-Safety Performance

↓

10. Verify

Controls & FSMS

↓

11. Audit

Internal Audit

↓

12. Review

Management Review

↓

13. Improve

Corrective Action

↓

14. Prepare

Certification Readiness

↓

15. Certify

Third-Party Certification Audit

↓

16. Maintain

Continual Improvement


Step 1 — Define the FSMS Scope

Before creating procedures, determine:

What exactly is the Food Safety Management System going to cover?

The scope should reflect the organization’s actual activities, products, processes, locations and relevant food-chain boundaries.

For example:

Food Manufacturer

Manufacture and packaging of ready-to-eat food products at the organization’s defined production facility.

The actual scope should be developed based on the organization’s operations rather than copied from another company.


Questions to Ask

  • Which products are covered?
  • Which production lines are covered?
  • Which locations are covered?
  • Which processes are included?
  • Are storage activities included?
  • Are transportation activities included?
  • Which outsourced processes affect food safety?
  • Which food-chain categories apply?
  • Are there justified exclusions?

A clearly defined scope becomes the foundation for the rest of the FSMS.


Step 2 — Understand the Organization and Its Food Chain

The organization should understand its internal and external context.

Consider:

Internal

  • People
  • Processes
  • Infrastructure
  • Equipment
  • Competence
  • Food-safety culture
  • Existing controls
  • Organizational structure

External

  • Customers
  • Regulators
  • Suppliers
  • Market requirements
  • Technology
  • Supply-chain conditions
  • Environmental conditions
  • Applicable legislation
  • Industry developments

The 2024 climate-action amendment also means organizations should consider whether climate change is relevant to their FSMS context and relevant interested-party requirements.

Step 3 — Identify Interested Parties

Food safety is not controlled by one department.

Relevant interested parties may include:

  • Consumers
  • Customers
  • Suppliers
  • Regulatory authorities
  • Employees
  • Contractors
  • Distributors
  • Retailers
  • Certification bodies
  • Owners
  • Industry organizations

For each relevant interested party, ask:

What do they require?

Is the requirement relevant to food safety?

How is it controlled?

What evidence demonstrates conformity?


Step 4 — Conduct an ISO 22000 Gap Analysis

This is one of the most important stages of implementation.

A gap analysis compares:

Current State

against

ISO 22000 Requirements

Example

AreaCurrent SituationRequirementGapAction
FSMS scopeInformalDefined scopeYesEstablish scope
PRPsExistingControlled PRPsPartialReview/update
Hazard analysisHACCP availableISO 22000 methodologyPartialReassess
TraceabilityBasicEffective systemPartialTest system
Internal auditInformalPlanned audit programmeYesEstablish
Management reviewNot formalManagement reviewYesImplement

The gap analysis should not be used simply to produce a long checklist.

It should answer:

What is already working, what is missing, what needs improvement and what should be prioritized?


Step 5 — Establish the Food Safety Team

ISO 22000 implementation requires appropriate food-safety knowledge and competence.

The food-safety team may include people from:

  • Quality
  • Production
  • Food technology
  • Microbiology
  • Engineering
  • Maintenance
  • Procurement
  • Warehouse
  • Sanitation
  • Regulatory/compliance

The exact structure depends on the organization.

Important point

The food-safety team should not exist only on paper.

Its members should actually participate in:

  • Hazard analysis
  • PRP evaluation
  • Control-measure selection
  • Verification
  • FSMS review
  • Food-safety decisions

Step 6 — Establish the Food Safety Policy

Top management should establish an appropriate food-safety policy.

The policy should connect to the organization’s:

  • Purpose
  • Food-safety responsibilities
  • Applicable requirements
  • Objectives
  • Continual improvement

But there is a critical implementation test:

Ask an employee:

“What does our food-safety policy mean for your job?”

If the answer is:

“I don’t know.”

the organization has a communication and awareness gap.


Step 7 — Establish Food-Safety Objectives

Objectives should be connected to measurable food-safety performance.

Examples could include:

  • Reduce repeat food-safety nonconformities.
  • Improve traceability exercise performance.
  • Improve completion of food-safety training.
  • Reduce supplier-related food-safety deviations.
  • Improve sanitation verification performance.
  • Improve corrective-action closure.
  • Improve complaint-response performance.

The actual objectives should reflect the organization’s risks and priorities.


Step 8 — Establish and Review PRPs

PRPs form the foundation for hygienic food operations.

Depending on the organization’s activities, PRPs may address:

  • Building and facility hygiene
  • Equipment
  • Cleaning and sanitation
  • Pest control
  • Personnel hygiene
  • Utilities
  • Waste management
  • Storage
  • Transportation
  • Supplier controls
  • Cross-contamination prevention
  • Maintenance
  • Food-contact surfaces
  • Temperature control

Important 2026 Update

The PRP landscape has changed significantly.

ISO 22002-100:2025 establishes common PRP requirements for the food, feed and packaging supply chain. Sector-specific standards then provide additional requirements for specific activities

For food manufacturing, ISO 22002-1:2025 is the current published PRP standard for food manufacturing and is intended to be used with ISO 22002-100. ISO lists the previous ISO/TS 22002-1:2009 as withdrawn

This means a food manufacturer updating its FSMS in 2026 should review its PRP framework against the current ISO 22002 series, rather than automatically continuing to rely on an old 2009 PRP document.


Step 9 — Map the Food-Safety Processes

Now move from documents to actual operations.

Map the organization’s process from beginning to end.

For a food manufacturer, this could look like:

Supplier Approval

↓

Raw Material Receipt

↓

Inspection

↓

Storage

↓

Preparation

↓

Processing

↓

Cooking / Treatment

↓

Cooling

↓

Packaging

↓

Metal Detection / Inspection

↓

Finished Product Storage

↓

Dispatch

↓

Customer

The exact flow depends on the organization.


Step 10 — Develop and Verify the Process Flow Diagram

The flow diagram should reflect the actual process.

The food-safety team should verify it on-site.

Walk the floor.

Compare:

Documented Flow

with

Actual Flow

Look for:

  • Additional process steps
  • Rework
  • Temporary storage
  • Cross-connections
  • Waste flows
  • Personnel movement
  • Material movement
  • Cleaning activities
  • Outsourced activities
  • Process deviations

A flow diagram that looks correct on paper but does not represent the actual production process creates problems during hazard analysis.


Step 11 — Define Product Characteristics and Intended Use

The food-safety team should understand the product.

Relevant information can include:

  • Ingredients
  • Physical characteristics
  • Chemical characteristics
  • Biological characteristics
  • Processing method
  • Packaging
  • Storage conditions
  • Shelf life
  • Distribution conditions
  • Intended use
  • Intended consumer

Why does intended use matter?

Consider:

Ready-to-eat product

versus

Product that must be cooked before consumption.

The hazard assessment and controls need to reflect how the product will actually be used.


Step 12 — Conduct Hazard Analysis

Now the core technical food-safety work begins.

For each relevant process step, ask:

What hazards could occur?

Biological

→ pathogens, viruses, parasites, toxins

Chemical

→ chemical contamination, residues, toxins

Physical

→ metal, glass, stone, hard plastic

Allergen-related

→ cross-contact or incorrect allergen control, where relevant

Then ask:

How likely is the hazard?

How severe could the consequence be?

Is the hazard significant?

What controls are required?


Step 13 — Establish Control Measures

Once significant hazards are identified, appropriate control measures need to be established.

The food-safety team determines whether controls are managed through:

  • PRPs
  • OPRPs
  • CCPs

The classification must result from the organization’s hazard analysis and defined methodology.

Simplified example

Hazard

Biological contamination

↓

Control

Validated heat treatment

↓

Classification

Could be a CCP where the hazard analysis establishes that the step meets the relevant criteria.

↓

Monitoring

Temperature + time

↓

Deviation

Required condition not achieved

↓

Action

Correction + product evaluation + corrective action as appropriate

↓

Verification

Evidence that the control remains effective


Step 14 — Establish the HACCP / OPRP Plan

The hazard-control plan should define how significant hazards are controlled.

Depending on the applicable control, the plan may establish:

  • Hazard
  • Control measure
  • Control classification
  • Critical limits or action criteria
  • Monitoring method
  • Monitoring frequency
  • Responsibility
  • Correction
  • Corrective action
  • Records
  • Verification

Important

Do not simply create a HACCP table because a certification auditor expects one.

The hazard-control plan should represent the organization’s actual food-safety control strategy.


Step 15 — Validate Control Measures

Validation asks:

Can this control actually achieve the intended food-safety outcome?

For example, where a process condition is being relied upon to control a microbiological hazard, the organization needs appropriate evidence that the control is capable of achieving the intended result.

Validation may involve relevant:

  • Scientific information
  • Technical studies
  • Process data
  • Historical evidence
  • Testing
  • Specialist knowledge

Remember:

Validation ≠ Monitoring

Validation:

Will the control work?

Monitoring:

Are we applying the control?

Verification:

Is the system operating effectively?


Step 16 — Establish Monitoring

Once controls are established, define:

  • What is monitored?
  • Who monitors it?
  • How is it monitored?
  • How often?
  • What criteria apply?
  • What happens when results are outside requirements?
  • What records are maintained?

Example

Control: Refrigerated storage

Monitoring: Temperature

Frequency: Defined by the organization

Responsible person: Assigned employee

Deviation: Temperature outside established criteria

Action: Defined response and product evaluation

The actual criteria must be established according to the organization’s hazard analysis and applicable requirements.


Step 17 — Establish Traceability

Traceability should connect relevant inputs and outputs.

Example

Supplier

→ Raw-material batch

→ Production batch

→ Finished-product batch

→ Dispatch

→ Customer

A good implementation should be capable of answering:

“Where did this material come from?”

and:

“Where did this finished product go?”


Step 18 — Conduct a Traceability / Mock Recall Exercise

Do not wait for a real incident to discover whether the traceability system works.

Conduct a controlled exercise.

For example:

Scenario

A raw-material batch is suspected of being unsafe.

Can the organization identify:

  • Supplier?
  • Receipt date?
  • Batch number?
  • Production batches affected?
  • Quantity produced?
  • Quantity in stock?
  • Quantity dispatched?
  • Customers affected?
  • Actions required?

Then measure:

How quickly can the organization reconstruct the chain?

The exercise should generate learning and improvement opportunities.


Step 19 — Establish Emergency Preparedness

Identify relevant food-safety emergency scenarios.

Depending on the organization, these could include:

  • Power failure
  • Refrigeration failure
  • Flooding
  • Fire
  • Water contamination
  • Equipment breakdown
  • Product contamination
  • Supply-chain disruption
  • Utility failure
  • Food-safety incident

For each relevant scenario, determine:

Who responds?

What product could be affected?

What immediate controls are required?

Who must be informed?

How is the incident documented?

How is recovery managed?


Step 20 — Implement the FSMS

Now move from system design to actual implementation.

This means people should start using:

  • Procedures
  • Work instructions
  • Monitoring records
  • Cleaning records
  • Inspection records
  • Traceability records
  • Supplier controls
  • Hazard-control records
  • Verification records
  • Corrective-action processes

The golden rule:

If the process is not actually being followed, the document does not demonstrate implementation.


Step 21 — Training and Awareness

Training should be role-specific.

Production employees

Need to understand relevant operational controls.

Food-safety team

Needs deeper competence in hazard analysis and FSMS requirements.

Warehouse employees

Need to understand storage, identification, segregation and traceability controls.

Procurement

Needs to understand relevant supplier and material requirements.

Maintenance

Needs to understand how maintenance activities can affect food safety.

Management

Needs to understand FSMS performance and responsibilities.


Step 22 — Start Collecting Objective Evidence

An implemented FSMS generates evidence.

Examples:

  • Monitoring records
  • Verification records
  • Training records
  • Supplier evaluations
  • Inspection reports
  • Cleaning records
  • Calibration/verification records
  • Traceability tests
  • Complaint records
  • Nonconformity records
  • Corrective actions
  • Internal audit reports
  • Management review records

The objective is not to generate paperwork.

The objective is to generate evidence of controlled processes.


Step 23 — Monitor FSMS Performance

Establish appropriate performance indicators.

Potential indicators include:

  • Food-safety incidents
  • Customer complaints
  • Supplier nonconformities
  • Internal audit findings
  • Corrective-action closure
  • Traceability exercise performance
  • Training completion
  • Verification results
  • Product-testing trends
  • PRP verification results

Do not measure everything.

Measure what helps management understand whether the FSMS is performing.


Step 24 — Conduct Internal Audit

The internal audit should evaluate:

Conformity

Does the FSMS meet the applicable requirements?

Implementation

Are the processes actually being followed?

Effectiveness

Are the controls achieving their intended outcomes?

Evidence

Can the organization demonstrate this objectively?


How to Conduct a Strong ISO 22000 Internal Audit

Instead of:

“Show me the procedure.”

Use:

“Show me how this process operates.”

Then:

“Show me the monitoring evidence.”

Then:

“What happens when there is a deviation?”

Then:

“Show me the corrective action.”

Then:

“How did you verify effectiveness?”

This creates a process-based audit.


Step 25 — Correct Nonconformities

Internal audits will identify issues.

Do not simply close them by writing:

“Training given.”

Ask:

What happened?

Why did it happen?

Is it an isolated issue?

Could it happen elsewhere?

What correction is required?

What corrective action is required?

How will effectiveness be verified?

This creates a stronger corrective-action system.


Step 26 — Conduct Management Review

Top management should review FSMS performance.

Inputs can include:

  • Audit results
  • Food-safety incidents
  • Customer complaints
  • Verification results
  • Supplier performance
  • Objectives
  • Corrective actions
  • Changes in context
  • Risks and opportunities
  • Resource requirements
  • Regulatory developments
  • Emergency events
  • Improvement opportunities

Management review should result in meaningful decisions and actions.

Examples

Management may decide to:

  • Invest in new equipment
  • Increase training
  • Change a supplier
  • Modify a process
  • Increase verification
  • Improve infrastructure
  • Change objectives
  • Update the FSMS

That is much more meaningful than simply signing meeting minutes.


Step 27 — Certification Readiness Review

Before contacting the certification body for the formal audit, conduct a final readiness review.

Ask:

Scope

☑ Is the FSMS scope finalized?

Context

☑ Have relevant issues and interested parties been addressed?

Leadership

☑ Is management actively involved?

PRPs

☑ Are PRPs implemented?

Hazard Analysis

☑ Is hazard analysis complete?

Control Measures

☑ Are OPRPs/CCPs appropriately established?

Monitoring

☑ Are monitoring records available?

Verification

☑ Is verification effective?

Traceability

☑ Has traceability been tested?

Emergency Preparedness

☑ Has the organization tested relevant response arrangements?

Internal Audit

☑ Has an effective internal audit been completed?

Corrective Action

☑ Have significant findings been addressed?

Management Review

☑ Has management review been completed?

Objective Evidence

☑ Can the organization demonstrate implementation?

If several answers are “No,” the organization should address the gaps before the certification audit.


Step 28 — Select an Independent Certification Body

This is an important distinction:

ISO does not issue ISO 22000 certificates.

ISO develops and publishes the standard.

Certification is performed by independent certification bodies.

ISO specifically states that organizations choosing certification should find a reputable third-party certification body

When selecting a certification body, consider:

  • Accreditation status
  • Relevant food-sector competence
  • Scope of accreditation
  • Auditor competence
  • Geographic coverage
  • Certification process
  • Audit duration
  • Fees
  • Sector experience
  • Client references where appropriate

For organizations seeking accredited certification, verify the certification body’s accreditation and scope rather than selecting solely on price.


Step 29 — Certification Audit

The certification audit is generally conducted in stages.

The certification body establishes the applicable audit programme and requirements.

A typical certification process involves:

Stage 1

Assessment of readiness and documented/system information.

The auditor may evaluate:

  • FSMS scope
  • Context
  • Documentation
  • Process understanding
  • Site readiness
  • Hazard-control approach
  • Audit planning

Stage 2

A more detailed assessment of the implemented FSMS.

The auditor may examine:

  • Actual production/process activities
  • PRPs
  • Hazard analysis
  • HACCP/OPRP controls
  • Monitoring
  • Traceability
  • Employee competence
  • Records
  • Internal audit
  • Management review
  • Corrective actions

The exact audit arrangements and duration depend on the certification body’s applicable rules, organization size, complexity, sites, processes and other factors.


Step 30 — Certification Decision

Following the audit, the certification body evaluates the audit results and any nonconformities according to its certification process.

The organization may need to:

  • Correct nonconformities
  • Provide root-cause analysis
  • Submit corrective-action evidence
  • Demonstrate effectiveness where required

Certification is issued only through the certification body’s conformity-assessment process.


Step 31 — Maintain the FSMS After Certification

Certification is not the end.

It is the beginning of maintaining the management system.

The organization should continue:

Monitor

↓

Audit

↓

Review

↓

Correct

↓

Improve

↓

Maintain

The certification body will also conduct ongoing surveillance/reassessment activities according to the applicable certification programme.

Therefore:

An ISO 22000 certificate should never become a reason to stop improving the FSMS.


ISO 22000 Implementation Timeline

There is no single universal implementation duration.

The timeline depends on:

  • Organization size
  • Number of sites
  • Product complexity
  • Existing HACCP system
  • Existing PRPs
  • Existing ISO management systems
  • Number of employees
  • Process complexity
  • Food-safety hazards
  • Regulatory requirements
  • Documentation maturity
  • Availability of internal resources
  • Scope of certification

Indicative implementation model

PhaseTypical Activity
Phase 1Scope + Gap Analysis
Phase 2Context + Food Safety Team
Phase 3PRPs + Process Mapping
Phase 4Hazard Analysis + Control Measures
Phase 5Documentation + Implementation
Phase 6Training + Monitoring
Phase 7Verification + Traceability
Phase 8Internal Audit
Phase 9Corrective Action
Phase 10Management Review
Phase 11Certification Readiness
Phase 12Certification Audit

For a relatively straightforward organization with an established HACCP/food-safety system, implementation can be significantly faster than for an organization starting from the beginning.

Therefore, it is better to determine the timeline after the gap analysis rather than promise a fixed number of days to every organization.


ISO 22000 Certification Cost — What Determines the Price?

There is no single ISO 22000 certification price applicable to every organization.

Cost can involve two different components:

1. Implementation / Consultancy Cost

Potential factors:

  • Scope
  • Number of sites
  • Employee count
  • Existing FSMS maturity
  • HACCP maturity
  • PRP status
  • Process complexity
  • Documentation requirements
  • Training requirements
  • Internal audit support
  • Management-review support
  • Certification-readiness support

2. Certification Body Cost

The certification body’s fee can depend on factors such as:

  • Number of employees
  • Number of sites
  • Complexity
  • Food-chain category
  • Audit duration
  • Certification programme
  • Travel
  • Surveillance requirements

Important:

Consultancy fee ≠ certification fee.

They are separate commercial components.


ISO 22000 + ISO 9001 Integration

Many food organizations already operate or plan to operate an ISO 9001 Quality Management System.

Because ISO 22000 uses the common ISO management-system structure, integration can be practical.

Shared processes may include:

  • Context
  • Interested parties
  • Leadership
  • Policy
  • Objectives
  • Document control
  • Competence
  • Internal audit
  • Management review
  • Corrective action
  • Continual improvement

Food-safety-specific processes include:

  • PRPs
  • Hazard analysis
  • HACCP/OPRP controls
  • Food-safety verification
  • Traceability
  • Food-safety emergency response

Therefore:

ISO 9001

Quality

ISO 22000

Food Safety

can form an integrated management-system structure.


ISO 22000 + ISO 9001 + ISO 14001 + ISO 45001

For larger food-processing organizations, multiple management systems may be integrated.

For example:

StandardPrimary Focus
ISO 9001Quality
ISO 22000Food Safety
ISO 14001Environment
ISO 45001Occupational Health & Safety

The opportunity is to share common management-system processes while retaining the technical controls specific to each standard.

This can reduce unnecessary duplication where the processes genuinely overlap.


ISO 22000 vs FSSC 22000 — Implementation Decision

An organization considering food-safety certification may encounter both:

ISO 22000

and

FSSC 22000

They should not be treated as identical certification routes.

ISO 22000 is the international FSMS standard.

FSSC 22000 is a separate certification scheme that builds on ISO 22000 with additional requirements and applicable PRP standards.

The right route depends on factors such as:

  • Customer requirements
  • Market expectations
  • Sector
  • Supply-chain requirements
  • Certification objective
  • Applicable scheme requirements

Therefore, the organization should determine its intended certification route before designing the entire implementation programme.


ISO 22000 Implementation for Different Food Businesses

Food Manufacturer

Focus areas:

PRPs + HACCP + OPRPs/CCPs + Traceability + Process Controls


Restaurant / Catering

Focus areas:

Food handling + Hygiene + Storage + Preparation + Temperature Control + Allergen Management + Cleaning

The applicable PRP framework should reflect the sector. ISO’s updated 22002 series includes a 2025 catering PRP standard

Food Warehouse

Focus areas:

Storage + Temperature + Pest Control + Segregation + Traceability + Dispatch


Food Packaging Manufacturer

Focus areas:

Food-contact materials + Contamination Control + Hygiene + Traceability + Supplier Control

ISO’s updated 22002 series includes ISO 22002-4:2025 for food packaging manufacturing

Food Transport & Storage

Focus areas:

Temperature + Hygiene + Vehicle/Facility Conditions + Product Integrity + Traceability

The updated ISO 22002 series includes sector-specific PRP requirements for transport and storage

A Practical ISO 22000 Documentation Structure

Documentation should be designed around the organization’s actual system.

A practical structure can include:

Level 1 — FSMS Framework

  • FSMS scope
  • Food-safety policy
  • Context
  • Interested parties
  • Process interaction

Level 2 — System Procedures

  • Document control
  • Internal audit
  • Corrective action
  • Management review
  • Communication
  • Competence

Level 3 — Food-Safety Controls

  • PRPs
  • Hazard analysis
  • Hazard-control plan
  • Traceability
  • Emergency preparedness
  • Product withdrawal/recall
  • Verification

Level 4 — Operational Records

  • Monitoring records
  • Inspection records
  • Cleaning records
  • Training records
  • Verification records
  • Traceability records
  • Audit records
  • Corrective-action records

The actual documentation structure should be tailored to the organization.


The Biggest ISO 22000 Implementation Mistake

Starting With Documents Instead of Food Safety

A weak implementation model looks like:

Buy Templates

↓

Modify Documents

↓

Print Procedures

↓

Fill Forms

↓

Call Auditor

A stronger model is:

Understand Organization

↓

Define Scope

↓

Map Processes

↓

Identify Hazards

↓

Establish PRPs

↓

Determine Controls

↓

Implement

↓

Monitor

↓

Verify

↓

Audit

↓

Review

↓

Improve

↓

Certification


The 5-Layer ISO 22000 Implementation Model

At CK Associates, a practical way to explain implementation is through five connected layers:

Layer 1 — MANAGEMENT

Leadership + Policy + Objectives + Resources

↓

Layer 2 — FOUNDATION

PRPs + Infrastructure + Hygiene + Competence

↓

Layer 3 — HAZARD CONTROL

Hazard Analysis + OPRPs + CCPs + HACCP

↓

Layer 4 — ASSURANCE

Monitoring + Verification + Traceability + Internal Audit

↓

Layer 5 — IMPROVEMENT

Corrective Action + Management Review + Continual Improvement

When these five layers work together, the FSMS becomes much more than a certification file.


ISO 22000 Certification Readiness Checklist

Before the certification audit, verify:

Organization

☑ FSMS scope defined
☑ Context established
☑ Interested parties identified
☑ Applicable requirements identified

Leadership

☑ Food-safety policy established
☑ Responsibilities defined
☑ Food-safety team established
☑ Management commitment demonstrated

Planning

☑ Risks and opportunities addressed
☑ Objectives established
☑ Change planning established

PRPs

☑ Applicable PRPs implemented
☑ PRP verification performed
☑ Current applicable PRP standards reviewed

Hazard Analysis

☑ Product characteristics documented
☑ Intended use identified
☑ Process flow verified
☑ Hazards identified
☑ Hazard significance evaluated
☑ Control measures established
☑ OPRPs/CCPs appropriately determined
☑ Control measures validated where required

Operation

☑ Monitoring implemented
☑ Traceability implemented
☑ Emergency preparedness established
☑ Nonconforming-product controls established
☑ Withdrawal/recall process established

Performance Evaluation

☑ Monitoring results evaluated
☑ Verification completed
☑ Internal audit completed
☑ Management review completed

Improvement

☑ Nonconformities addressed
☑ Corrective actions implemented
☑ Effectiveness verified
☑ Continual improvement demonstrated


Consultant’s Insight

The certification audit should not be the first time the organization discovers whether its FSMS works.

A mature organization should test itself before the certification body arrives.

Ask:

If an auditor walked into our production area tomorrow, could our employees explain the controls that affect food safety?

Then ask:

Could we demonstrate the evidence?

Then:

Could we show what happens when a control fails?

And finally:

Could management demonstrate what has been improved as a result of monitoring, audits, incidents and feedback?

If the answer is yes, the organization is moving toward a functioning FSMS rather than simply preparing for a certificate.


ISO 22000:2018 — The Complete Implementation Cycle

DEFINE

Scope

↓

UNDERSTAND

Context + Interested Parties

↓

ASSESS

Gap Analysis

↓

BUILD

Food Safety Team + PRPs

↓

ANALYZE

Hazards

↓

CONTROL

PRPs + OPRPs + CCPs

↓

IMPLEMENT

Processes + Training

↓

MONITOR

Operational Controls

↓

VERIFY

Evidence + Testing + Review

↓

AUDIT

Internal Audit

↓

CORRECT

Nonconformities

↓

REVIEW

Management Review

↓

IMPROVE

FSMS

↓

CERTIFICATION

Independent Certification Body

↓

MAINTAIN

Surveillance + Continual Improvement


2026 ISO 22000 Update — What Organizations Should Watch

There are two important developments organizations should keep on their radar.

Current ISO 22000

ISO 22000:2018 + Amendment 1:2024

This remains the published standard. ISO says ISO 22000:2018 was reviewed and confirmed in 2023

Future ISO 22000 Revision

ISO/DIS 22000

The revision is currently under development. ISO’s current project page identifies it as a Draft International Standard intended to replace ISO 22000:2018. Its development has progressed through the enquiry stage, but it is not yet the published replacement standard

Updated PRP Framework

The ISO 22002 series was updated in 2025, including ISO 22002-100:2025 and sector-specific documents such as ISO 22002-1:2025 for food manufacturing

Therefore, organizations implementing ISO 22000 in 2026 should make sure their PRP framework reflects the applicable current requirements rather than relying automatically on legacy documents.


Frequently Asked Questions

How long does ISO 22000 implementation take?

There is no universal timeline. Duration depends on the organization’s size, number of sites, existing HACCP/FSMS maturity, product complexity, PRPs, hazard profile, resources and certification scope. A gap analysis is the appropriate starting point for developing a realistic implementation schedule.

How much does ISO 22000 certification cost?

The cost varies according to implementation scope, organization size, complexity, number of sites, existing systems, consultancy requirements and certification-body audit requirements. Consultancy and certification-body fees are separate costs.

Can an organization implement ISO 22000 without a consultant?

Yes. ISO 22000 does not require the use of a consultant. An organization can develop and implement its FSMS using internal and/or external resources, provided it can meet the applicable requirements.

Does ISO provide ISO 22000 certification?

No. ISO develops and publishes the standard but does not conduct certification. Organizations seeking certification use an independent certification body

Can ISO 22000 be integrated with ISO 9001?

Yes. ISO 22000 follows the common ISO management-system structure and ISO explicitly notes that it can be integrated into existing management processes, including systems such as ISO 9001

Is HACCP required for ISO 22000?

ISO 22000 integrates the principles of HACCP into the FSMS. The hazard-control framework must therefore be established in accordance with the standard and the organization’s actual food-safety hazards.

What is the role of PRPs in ISO 22000?

PRPs establish the foundational hygienic and operational conditions needed to support food safety. For food manufacturing, ISO 22002-1:2025 is the current sector-specific PRP standard used with ISO 22002-100:2025

Is ISO 22000:2018 still valid in 2026?

Yes. ISO currently lists ISO 22000:2018 as the published/current edition, with Amendment 1:2024. A replacement, ISO/DIS 22000, is under development

What happens after ISO 22000 certification?

The organization needs to maintain and continually improve its FSMS. The certification body also conducts ongoing surveillance/reassessment according to its certification programme.


Key Takeaways

ISO 22000 implementation is not a document-creation exercise.

A successful implementation connects:

Management

→ Food Safety Team

→ PRPs

→ Hazard Analysis

→ Control Measures

→ Monitoring

→ Verification

→ Internal Audit

→ Management Review

→ Corrective Action

→ Continual Improvement

The certification journey can be summarized as:

DEFINE → ANALYZE → CONTROL → IMPLEMENT → MONITOR → VERIFY → AUDIT → REVIEW → IMPROVE → CERTIFY

The certificate is the result of the system.

The system is the real objective.


About CK Associates

CK Associates provides ISO certification consultancy and implementation support across Hyderabad, Telangana and India.

Our practical implementation approach covers:

Gap Analysis → Documentation → System Design → Implementation → Training → Internal Audit → Management Review → Certification Readiness

Why Trust This Guidance?

20+ Years Experience
450+ Certification Projects
400+ ISO 9001 Projects
25+ ISO 27001 Projects
4+ ISO 42001 Projects
45+ ISO 14001 Projects
45+ ISO 45001 Projects

Sirish K

Founder & Lead ISO Consultant
CK Associates

Summary

ISO 22000:2018 implementation involves establishing and operating a Food Safety Management System that connects organizational context and leadership with prerequisite programmes, hazard analysis, food-safety controls, monitoring, verification, internal audit, management review and continual improvement. A practical implementation starts with defining the FSMS scope and conducting a gap analysis, followed by establishing the food-safety team, PRPs, process flow, product characteristics, hazard analysis and appropriate OPRP/CCP controls. The organization then implements monitoring, traceability, emergency preparedness, verification, internal audits and corrective actions before conducting management review and a final certification-readiness assessment. Certification is performed by an independent certification body, not ISO itself. ISO currently lists ISO 22000:2018 as the published edition with Amendment 1:2024, while ISO/DIS 22000 is under development as its intended replacement. The updated ISO 22002 series, including ISO 22002-100:2025 and ISO 22002-1:2025 for food manufacturing, should also be considered when establishing the applicable PRP framework

Similar Posts