ISO 22000 is the international standard for Food Safety Management Systems. It provides a structured framework that helps organizations anywhere in the food chain — from primary production through manufacturing, packaging, distribution, and food service — identify food safety hazards, implement controls based on HACCP principles, and demonstrate a credible, systematic commitment to food safety.
ISO 22000 is one of the most widely applicable management system standards in the world, relevant to any organization that is a part of the food chain — directly or indirectly. Organizations pursue it for different reasons: regulatory requirements, customer and supply chain pressure, and a commitment to preventing foodborne illness. This guide explains what ISO 22000 is, what it covers, who needs it, and what certification involves — drawing on the experience of Maria Falbo, a Lead Auditor with decades of food safety experience.
ISO 22000 is the international standard for Food Safety Management Systems, published by the International Organization for Standardization. It provides a framework organizations use to identify how their activities interact with food safety hazards, assess and control those hazards, and demonstrate continual improvement in food safety performance over time.
The standard doesn't prescribe specific product safety targets or dictate exactly what an organization's food safety practices must look like. Instead, it defines the system — the processes, hazard analysis, documentation, and governance mechanisms — through which an organization manages food safety. What that looks like in practice depends heavily on the organization's position in the food chain, its products, and its specific hazard profile.
ISO 22000 was first published in 2005 and most recently updated in 2018, with a 2024 amendment incorporating climate action considerations. The current edition is ISO 22000:2018 (as amended). It follows the Harmonized Structure shared by ISO 9001, ISO 14001, and ISO 45001, making it compatible for integration with those standards. A revision is currently in development within ISO's technical committee, but it remains at an early drafting stage with no confirmed publication timeline — ISO 22000:2018 remains the current, fully operative standard.
ISO 22000 applies across the entire food chain — a scope broader than most people initially assume. This includes primary producers like farmers and fisheries; feed producers; food manufacturers and processors; packaging manufacturers; transport, storage, and distribution operators; food service and catering; and retail. It also extends to organizations that support the food chain indirectly — producers of cleaning agents, equipment manufacturers, pest control services — since their activities can affect food safety even without directly handling food.
The FSMS required by ISO 22000 rests on several interconnected elements: a documented hazard analysis covering biological, chemical, physical, and allergen hazards; prerequisite programs establishing basic hygienic operating conditions; a HACCP plan identifying critical control points with defined critical limits and monitoring; traceability systems; and internal audits and management review to verify the whole system is functioning as intended.
What distinguishes ISO 22000 from informal food safety practice is that it requires the system to be planned, implemented, maintained, and continually improved — not just documented once and filed. For a full breakdown of what each clause requires, see our ISO 22000 requirements explained.
ISO 22000 is relevant to any organization within or supporting the food chain — which, given the standard's deliberately broad scope, includes a genuinely wide range of businesses well beyond food manufacturers alone.
Organizations most commonly pursuing certification include food and beverage manufacturers, food processors and packagers, catering and food service operators, primary producers, and logistics and distribution providers handling food products. Certification is also increasingly relevant to packaging manufacturers, ingredient suppliers, and providers of cleaning or pest control services to food facilities.
Certification is voluntary — ISO 22000 is not a legal requirement. However, in practice, it's increasingly driven by factors that make it effectively necessary. Customer and supply chain requirements frequently mandate certification as a condition of doing business, particularly for suppliers to larger manufacturers or retailers. Export markets often expect certification as evidence of food safety competence. And in many countries, elements of HACCP-based food safety management are legally required regardless of ISO certification status.
The gap between certification pursued for market access and certification pursued as genuine food safety commitment is visible the moment you look past the certificate on the wall. An organization that treats ISO 22000 as a customer requirement to satisfy typically has a hazard analysis that hasn't been touched since the initial certification audit — even as products, suppliers, and processes have changed. An organization that treats it as a genuine operating discipline has a food safety team that can explain, specifically and accurately, what's changed in their risk profile over the past year. The certificate looks the same in both cases. What's actually protecting consumers does not.
ISO 22000 doesn't replace HACCP — it formalizes and extends it within a full management system framework. The standard incorporates HACCP's seven principles as its technical foundation for hazard analysis and control, while adding requirements HACCP alone doesn't include: top management commitment, a formally empowered food safety team, interactive communication throughout the food chain, and a structured internal audit and management review cycle.
One of ISO 22000's distinctive technical contributions is the introduction of operational prerequisite programs (OPRPs) — a control category that sits between general prerequisite programs and critical control points, giving hazard analysis a more deliberate structure than traditional HACCP's binary approach. For a full explanation of how HACCP principles map into ISO 22000's requirements, see our guide to ISO 22000 and HACCP.
Our ISO 22000 Internal Auditor course covers FSMS requirements, hazard analysis, HACCP-based auditing methodology, and corrective action, built on ISO 22000 and ISO 19011.
ISO 22000 certification is conducted by an independent, accredited certification body — not by ISO itself. ISO publishes the standard; it does not certify organizations.
The certification process follows a defined sequence. Before engaging a certification body, the organization must implement the FSMS — building the hazard analysis and HACCP plan, establishing prerequisite programs, running the internal audit program, and conducting management review.
The certification audit proceeds in two stages. The Stage 1 audit is primarily a documentation review, assessing whether the FSMS documentation is in place and the organization is ready for Stage 2. The Stage 2 audit is the on-site implementation audit, verifying the documented FSMS is genuinely functioning in practice — including whether CCP monitoring is occurring as designed and whether the food safety team can demonstrate real competence, not just documented training.
Once certified, organizations undergo annual surveillance audits, with a full recertification audit every three years. For organizations preparing for their first certification audit, understanding what internal audits need to cover is one of the most important steps in preparation — for a complete guide, see our ISO 22000 Internal Audit: The Complete Guide.
ISO 22000 is often discussed alongside FSSC 22000, and the relationship between the two is a common point of confusion. FSSC 22000 is not an alternative to ISO 22000 — it's built directly on top of it, adding sector-specific prerequisite programs and additional scheme requirements to achieve recognition from the Global Food Safety Initiative (GFSI), something ISO 22000 alone has never obtained due to the deliberate generality of its requirements.
For organizations whose customers or markets specifically require GFSI-benchmarked certification, FSSC 22000 is typically the right path. For organizations without that specific pressure, ISO 22000 alone remains a fully legitimate, internationally recognized standard. For a full comparison of what FSSC 22000 adds and how to decide which path fits your organization, see our article on ISO 22000 vs FSSC 22000.
ISO 22000 certification is voluntary. However, it is increasingly required in practice by customers, supply chains, and export markets. Many organizations find that certification becomes effectively necessary when major customers or key markets require it as a qualification condition.
ISO 22000 certificates are valid for three years, subject to annual surveillance audits. The certification body conducts a surveillance audit in years one and two to confirm the FSMS continues functioning effectively, and a full recertification audit in year three.
A food safety permit or license is a legal instrument issued by a regulatory authority that authorizes an organization to operate. ISO 22000 is a management system standard that requires organizations to identify their legal obligations — including permit and licensing conditions — and demonstrate they're systematically meeting them. ISO 22000 certification does not replace regulatory permits; it requires organizations to manage compliance with them systematically.
Yes — ISO 22000 is designed to be scalable and applicable to organizations of any size across the food chain. The depth and formality of the FSMS should reflect the scale and complexity of the organization's hazards, not a fixed level of documentation regardless of size.
Yes, in many cases. ISO 22000's scope extends to organizations that support the food chain indirectly — packaging manufacturers, equipment suppliers, cleaning and pest control service providers — since their activities can affect food safety even without direct food handling.

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.
Learn more about Maria →Self-paced · 365-day access · Training certificate included