FSSC 22000 Certification: Requirements Explained

By James Smith on August 3, 2026

fssc-22000-certification-iso-22000-prp-requirements

FSSC 22000 is often described as "ISO 22000 plus a few extras," which understates what actually separates the two. ISO 22000 is a single standard that gives you a food safety management system framework. FSSC 22000 is a full certification scheme — GFSI-recognized, retailer-accepted, built on top of ISO 22000 but composed of three distinct normative documents that must all be satisfied at audit. Understanding that architecture is the first thing that separates plants that pass certification on the first attempt from plants that come back for a second Stage 2 audit after unresolved nonconformities. Food safety and quality leaders scoping FSSC 22000 for their site can Book a Demo to see how iFactory structures HACCP, PRP verification, and additional-requirement evidence in one connected system.

FSSC 22000 CERTIFICATION · ISO 22000 · PRP · GFSI
FSSC 22000 Certification: The Three-Element Architecture, What Auditors Actually Check, and How to Get Ready
A complete plain-language walkthrough of the FSSC 22000 scheme — ISO 22000, sector PRPs, and the additional requirements — so quality teams know exactly what to build, in what order, and how to prove it at Stage 1 and Stage 2 audits.
3
Normative documents auditors verify at Stage 2
14+
FSSC additional requirements beyond ISO 22000
6–18
Months typical implementation window for a first-time site
3-yr
Certificate cycle with annual surveillance audits

Why FSSC 22000 Exists Alongside ISO 22000

ISO 22000 was published in 2005 and revised in 2018 as an international food safety management system standard, structured around the same High Level Structure used by ISO 9001 and ISO 14001. It is comprehensive as a management system framework — scope, leadership, planning, support, operation, evaluation, improvement — but it is deliberately generic. It does not tell a dairy processor which prerequisite programs are relevant, and it does not carry the specific additional controls that global retailers and the Global Food Safety Initiative require of their suppliers. This is the gap FSSC 22000 fills. The scheme keeps ISO 22000 as its management system backbone, layers a sector-specific prerequisite program on top for the technical hygiene controls, and adds a set of scheme-specific additional requirements — food defense, food fraud mitigation, allergen management, environmental monitoring, food safety culture, and more — that GFSI benchmarking demands. A plant certified only to ISO 22000 is not accepted by most major retailers as a GFSI-compliant supplier; the same plant certified to FSSC 22000 is. That distinction, more than any technical difference between the standards, is why FSSC 22000 has become the food-industry certification of choice for exporters, contract manufacturers, and private-label suppliers.

The Three-Element Architecture

FSSC 22000 audit requirements are made up of three normative elements that stack on top of each other. Missing or weak evidence in any one element produces a nonconformity, regardless of how strong the others are. Understanding these as three separate bodies of work — with three separate document sets, three separate implementation efforts, and three separate audit checkpoints — is the mental model that keeps first-time certification projects from underestimating scope.

01
ISO 22000:2018 — The Food Safety Management System

The foundation layer. ISO 22000 defines how the food safety management system is scoped, led, planned, operated, evaluated, and improved. It carries the HACCP methodology inside its operational planning clauses (Clause 8), the hazard analysis and control measure requirements, and the management system disciplines — internal audit, management review, corrective action, continual improvement — that hold everything else together. If ISO 22000 is weak, every element built on top of it wobbles.

Clause 4 Context Clause 5 Leadership Clause 7 Support Clause 8 HACCP Clause 9 Evaluation Clause 10 Improvement
02
Sector-Specific Prerequisite Programs (PRPs)

The technical hygiene layer. ISO 22000 requires PRPs but does not spell out what they must contain — the ISO/TS 22002 series does that, and each part is written for a specific segment of the food chain. A dairy processor uses ISO/TS 22002-1, a packaging manufacturer uses ISO/TS 22002-4, a caterer uses ISO/TS 22002-2, and so on. The PRP standard chosen must match the plant's food chain category as classified under ISO 22003-1:2022; picking the wrong one is a Stage 1 audit finding.

Building design Utilities Waste disposal Equipment suitability Personnel hygiene Pest control
03
FSSC 22000 Additional Requirements

The scheme-specific layer. These are the requirements FSSC added on top of ISO 22000 and the PRPs specifically to meet GFSI benchmarking — the topics stakeholders considered important enough to make mandatory even though the underlying standards did not fully address them. They include food defense, food fraud mitigation, allergen management, environmental monitoring, food safety and quality culture, quality control, equipment management, food loss and waste, and several others. This layer is where most first-time applicants discover work they had not planned for.

Food defense Food fraud Allergens Environmental monitoring Food safety culture Food loss & waste
FSSC 22000 READINESS · GAP ANALYSIS · EVIDENCE MANAGEMENT
Stop Chasing FSSC Evidence Across Spreadsheets and Binders
iFactory keeps HACCP plans, PRP verification records, allergen risk assessments, environmental monitoring results, and corrective actions in one connected system — so what auditors ask for is what you can produce in seconds.

Choosing the Right PRP Standard for Your Food Chain Category

The ISO/TS 22002 series is not a single document — it is a family of standards, each written for a specific slice of the food supply chain. Matching your plant to the correct one is done by looking up your food chain category under ISO 22003-1:2022 and cross-referencing to the PRP standard the FSSC scheme mandates for that category. A recent revision published the ISO 22002:2025 series, which introduces a common PRP standard (ISO 22002-100:2025) applied across sectors alongside sector-specific parts, and this series is planned for incorporation into FSSC 22000 Version 7. Currently certified sites operating under Version 6 continue to use the existing ISO/TS 22002-x parts referenced in the scheme.

PRP Standard Food Chain Category Typical Sites Covered
ISO/TS 22002-1 Category C — Food manufacturing Bakeries, dairy processors, meat and poultry, beverages, snacks, frozen food, ready meals
ISO/TS 22002-2 Category E — Catering Institutional caterers, contract food service, central production kitchens
ISO/TS 22002-3 Category A — Farming Primary crop and livestock production sites operating under FSSC scope
ISO/TS 22002-4 Category I — Packaging manufacturing Food contact primary and secondary packaging producers, flexible and rigid formats
ISO/TS 22002-5 Category G — Transport and storage Refrigerated logistics, warehousing, cold chain distribution
ISO/TS 22002-6 Category D — Animal feed production Feed mills, feed premix producers, pet food manufacturers
ISO 22002-7:2025 Category F — Retail and wholesale Grocery retail chains, food wholesale operators

The mistake to avoid at the PRP stage is treating the standard as a one-time compliance document — building the manual, meeting the initial audit, and then leaving it static. PRP verification is an ongoing activity under the additional requirements, and Stage 2 auditors do not just verify the PRP was written; they verify it is being followed, measured, and reviewed. That distinction is why sites that treat PRP work as a live operational system — with routine sanitation checks, pest control logs, calibration schedules, and maintenance records tied to the PRP clauses — clear surveillance audits smoothly, while sites that treat it as documentation drift into nonconformities within a year of first certification.

Inside the FSSC 22000 Additional Requirements

The additional requirements are where FSSC 22000 goes beyond ISO 22000, and where first-time implementations most often reveal unexpected work. These are not soft targets — each is a distinct clause with defined evidence expectations that Stage 2 auditors will probe individually. Reviewed carefully during the gap analysis phase, they save weeks of firefighting later.

2.5.1
Management of Services and Purchased Materials

A documented process for evaluating, approving, and monitoring suppliers of services and materials that impact food safety — including transport, pest control, cleaning services, and outsourced testing.

2.5.2
Product Labelling and Printed Materials

Controls to ensure product labels are accurate, comply with jurisdictional regulations, and undergo verification before release — including allergen declarations, ingredient lists, and claim substantiation.

2.5.3
Food Defense

A threat assessment identifying intentional adulteration risks and a documented food defense plan with mitigation measures, tested and reviewed on a defined cycle.

2.5.4
Food Fraud Mitigation

A vulnerability assessment across raw materials and a mitigation plan targeting economically motivated adulteration risks — including supplier controls and verification testing where relevant.

2.5.5
Logo Use

Strict controls on FSSC 22000 logo usage — marketing materials only, never on product labels, packaging, certificates of analysis, or anywhere that implies product-level certification approval.

2.5.6
Management of Allergens

A documented allergen management plan covering handled allergens, risk assessment of cross-contact sources, control measures, validation and verification, precautionary labelling rules, and annual review.

2.5.7
Environmental Monitoring

A risk-based environmental monitoring program covering pathogen indicators, sampling locations, frequencies, corrective actions, and trend analysis — required for applicable categories.

2.5.8
Food Safety and Quality Culture

Documented objectives for building food safety and quality culture, with measurable indicators tracked over time — communication, training, feedback, and leadership behaviors are all in scope.

2.5.9
Quality Control

Quality control procedures covering product specifications, process parameters, and analytical testing — extending FSSC 22000 beyond pure safety into product quality management.

2.5.10
Transport, Storage and Warehousing

Controls for temperature, cross-contamination prevention, hygiene, and pest control across transport and storage activities — including third-party logistics service providers.

2.5.11
Hazard Control and Cross-Contamination

Documented hazard control measures preventing physical, chemical, biological, and allergen cross-contamination across production zones, personnel movement, and equipment use.

2.5.12
PRP Verification

Ongoing verification that PRPs are functioning as intended — sanitation efficacy, pest control results, calibration records, and utility system performance are all reviewed and trended.

2.5.13
Product Development

Food safety and quality integrated into new product development — hazard analysis, allergen review, shelf-life validation, and labelling checks completed before commercial launch.

2.5.14
Health Status of Personnel

Procedures for identifying, reporting, and managing personnel health conditions that could compromise food safety — including return-to-work criteria after illness.

2.5.15
Equipment Management

A documented equipment management program covering hygienic design at specification, planned maintenance, calibration, spare parts control, and change management for new or modified equipment.

2.5.16
Food Loss and Waste

Documented objectives and measures for reducing food loss and waste, aligned with UN Sustainable Development Goals — a requirement added to reflect the sustainability dimension GFSI now benchmarks.

The Certification Journey: Six Phases from Gap Analysis to Certificate

FSSC 22000 certification is not a single event but a phased project running six to eighteen months for a first-time site, depending on existing maturity, plant complexity, and how much of the ISO 22000 backbone is already in place. Plants that treat it as a step-by-step build, resisting the temptation to skip gap analysis and jump straight to Stage 1, avoid the most common cause of failed certification attempts: showing up for the audit with documentation that is technically complete but operationally unpracticed.

A

Phase A — Gap Analysis
Weeks 1–4

Assess the current food safety management system against ISO 22000, the applicable PRP standard, and the fourteen-plus additional requirements. Produce a prioritized gap list, identifying which clauses are already met, partially met, or missing entirely. This is the single most important phase — a rushed gap analysis produces implementation plans that miss scope and blow their timelines.

B

Phase B — Documentation Build
Months 2–5

Build or upgrade the FSMS manual, HACCP plans, PRP procedures, and additional requirement documents — allergen management plan, food defense plan, food fraud mitigation plan, environmental monitoring program, food safety culture plan, and the rest. Written well, these documents describe how the site actually operates, not aspirational future state.

C

Phase C — Implementation and Training
Months 3–6

Train the food safety team, operators, and support functions on the new procedures. Begin running the system in daily operation, generating records, and building the evidence trail auditors will trace at Stage 2. Sites that skip implementation depth and try to fabricate records get flagged quickly during traceability exercises.

D

Phase D — Internal Audit and Management Review
Months 5–7

Conduct a full internal audit against the same checklist the external body will use, identifying and closing residual nonconformities. Complete a management review meeting with senior leadership, since ISO 22000 requires it and auditors will ask for the minutes at Stage 1. Both are mandatory evidence items.

E

Phase E — Stage 1 Audit (Documentation Review)
1–2 days on site

The certification body's auditor reviews FSMS documentation, HACCP plans, PRP manuals, additional requirement plans, internal audit results, and management review records. The purpose is to determine readiness for Stage 2 and identify any gaps to close in the interval — which must not exceed six months between the two stages.

F

Phase F — Stage 2 Audit and Certification Decision
2–5 days on site

The comprehensive on-site audit — facility inspections, staff interviews, traceability exercises, record reviews, and verification that the FSMS is operating in practice, not just on paper. Nonconformities identified are closed within defined timeframes; the certification decision follows, and the FSSC 22000 certificate is issued and published in the FSSC directory.

What Certification Actually Costs — and What Sustains It

Direct FSSC 22000 certification body fees typically range from €8,000 for a small single-site operation to €50,000 or more for large multi-site scopes, covering Stage 1, Stage 2, and the three-year audit cycle. That number, however, is the smaller part of the total investment — the internal effort of building the FSMS, upgrading PRPs, and standing up the additional requirement programs usually costs several multiples of the audit fees themselves. Sites that budget only for certification body fees and underestimate internal resource commitment are the same sites that stall mid-implementation.

€8k–€50k+
Certification body fees across the three-year cycle
3–6 mo
Gap analysis to Stage 1 documentation readiness
2–5 days
On-site Stage 2 audit duration by site scope
1 unannounced
Surveillance audit per three-year cycle is mandatory

The unannounced surveillance visit deserves attention. FSSC 22000 requires at least one surveillance visit in every audit cycle to be unannounced — no advance notification, no pre-shared agenda, and the first part of the audit spent inside the facility observing live operations before any documentation is reviewed. Sites that keep their FSMS ceremonial — records kept current only when an audit is expected — get exposed at unannounced surveillance far more visibly than at planned audits. The counter-strategy is to operate the FSMS as a daily working system rather than an audit-response system, so any given Tuesday looks the same as an audit day would.

FSSC 22000 vs ISO 22000: Which One Do You Actually Need

The choice between ISO 22000 and FSSC 22000 is not really a technical choice — it is a market access choice. ISO 22000 alone gives you a credible food safety management system framework and is often adequate for domestic-market suppliers, smaller operations, or sites early in their food safety maturity journey. FSSC 22000 gives you GFSI recognition, which most major global retailers, quick-service restaurant chains, and multinational food brands now require of their approved supplier list.

ISO 22000
  • International food safety management system standard
  • Covers hazard analysis, HACCP, and management system requirements
  • Not benchmarked by GFSI
  • Suitable for domestic markets and smaller operations
  • No mandatory sector PRP standard required
  • No additional scheme requirements for food defense, food fraud, or environmental monitoring
  • Lower implementation and audit cost
FSSC 22000
  • Full certification scheme built on ISO 22000 as its base
  • Includes ISO 22000 plus sector PRPs plus additional requirements
  • Benchmarked and recognized by GFSI since 2010
  • Accepted by major global retailers as an approved supplier standard
  • Mandatory sector-specific PRP standard from the ISO 22002 series
  • Fourteen-plus additional scheme requirements covering food defense, fraud, allergens, environmental monitoring, and more
  • Higher implementation effort, unlocking global supply chain access

A useful decision rule: if your sales target list includes any GFSI-benchmarked retailer or a global brand's private label program, FSSC 22000 is the practical minimum. If you serve only regional or domestic customers today but expect that to change within two to three years, starting the ISO 22000 build with FSSC 22000 in mind is far cheaper than certifying to ISO 22000 first and then adding the FSSC layer later. The gap between the two is significant enough that treating them as separate projects usually costs more than treating them as a single, more ambitious project from the outset.

Frequently Asked Questions: FSSC 22000 Certification

Is FSSC 22000 the same as ISO 22000, or is one certification enough?

They are related but not the same. ISO 22000 is a food safety management system standard, while FSSC 22000 is a full certification scheme that uses ISO 22000 as its base, adds a mandatory sector-specific PRP standard, and layers on additional scheme-specific requirements to meet GFSI benchmarking. A site certified only to ISO 22000 is not accepted as GFSI-compliant by most major retailers; the same site certified to FSSC 22000 is. If your customer list includes GFSI-benchmarked buyers, ISO 22000 alone will not be sufficient. Sites weighing which certification fits their market can Book a Demo to discuss their scope.

How long does FSSC 22000 certification actually take for a first-time site?

Realistic timelines run six to eighteen months from project start to certificate issuance, depending on the maturity of the existing food safety management system, the size and complexity of the plant, and how many of the additional requirements need to be built from scratch. Sites with an existing HACCP plan and ISO 9001 background typically move faster; sites building an FSMS from the ground up need the full window. Stage 1 and Stage 2 audits are separated by up to six months, and the on-site portion of Stage 2 runs two to five days depending on scope.

What are the FSSC 22000 additional requirements, and how many are there?

The additional requirements are the scheme-specific clauses FSSC adds on top of ISO 22000 and the PRPs to meet GFSI benchmarking. Under Version 6, there are fourteen main mandatory clauses covering topics such as food defense, food fraud mitigation, food safety and quality culture, allergen management, environmental monitoring, quality control, equipment management, food loss and waste, transport and storage controls, PRP verification, product development, personnel health, logo use, and management of services and purchased materials. These carry into Version 7 with tightened language on several clauses, particularly around fraud, defense, and culture. Contact iFactory Support to walk through how to structure the evidence.

How much does FSSC 22000 certification cost?

Certification body fees typically range from €8,000 for a small single-site operation to €50,000 or more for large multi-site scopes, covering the three-year audit cycle of Stage 1, Stage 2, annual surveillance visits, and recertification. The internal cost of building the food safety management system, upgrading PRPs, training staff, and standing up the additional requirement programs is usually several multiples of the audit fees themselves. Sites that budget only for the audit body fees consistently underestimate the total investment.

What is the difference between Version 6 and Version 7 of the FSSC 22000 scheme?

Version 6 has been the mandatory audit standard since April 2025 when Version 5.1 certificates expired. Version 7 publishes in early 2026 with a twelve-month transition window, adopts the new ISO 22002:2025 PRP series in place of the older ISO/TS 22002-x versions, aligns with the GFSI Benchmarking Requirements 2024, and strengthens sustainability, food loss and waste, quality control, allergen management, and food safety culture clauses. Version 6 audits stay valid throughout the Version 7 transition; certified sites gap-analyze against Version 7 and align internal audit checklists to the new PRP series before their transition audit.

FSSC 22000 · HACCP · PRP VERIFICATION · ADDITIONAL REQUIREMENTS
Give Your FSSC 22000 Program a System That Auditors Trust and Teams Actually Use
iFactory brings HACCP plans, PRP verification records, allergen assessments, environmental monitoring data, food defense and fraud plans, corrective actions, and internal audit findings into a single connected system — designed for how audit day actually goes, not how the binder makes it look.

Share This Story, Choose Your Platform!