[email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
HomeBlogHow to Get ISO 22000 Certification: A Step-by-Step Guide for Food Businesses

How to Get ISO 22000 Certification: A Step-by-Step Guide for Food Businesses

If you manufacture, process, store or transport food, or you supply packaging that touches food, a buyer will eventually ask you for one thing: proof that your food safety system is certified. Not just written down in a binder somewhere. Certified, by someone outside your company who checked. That proof is ISO 22000, and it's worth reading why it's become one of the more valuable tools for minimising foodborne hazards rather than just another certificate on the wall.

Quick answer: Getting ISO 22000 certified means building a documented Food Safety Management System (FSMS) around HACCP principles, running it long enough that records actually accumulate, then passing a two-stage external audit (a documentation review, followed by an on-site verification) with an accredited certification body. Most organizations go from a standing start to a certificate in 8 to 16 weeks, depending on how much of the system already exists.

That's the summary. Here's what each stage actually involves, and where organizations tend to lose time they didn't need to lose.

What You Need Before You Start

You don't need to hire a food safety consultant on day one. But you do need three things in place, or at least assigned to someone with a name.

A food safety team, first. ISO 22000 requires a named team with defined competence. Not necessarily full-time hires: in a 20-person facility, this is usually the production manager plus one quality person, not a dedicated department. Second, a process map: every input, every step, every output, from raw material intake to dispatch. If you can't sketch this on a whiteboard in fifteen minutes, your hazard analysis is going to have gaps nobody notices until an auditor does.

Third, and this one gets skipped more than it should: management commitment that's actually real. ISO 22000 gets audited on whether top management reviews the system, not on whether a policy statement exists with someone's signature at the bottom. Auditors ask to see management review minutes. If there aren't any, that's a finding on your very first audit.

Skip any of these three and you can still start the process. You'll just end up building them under time pressure once the certification body has already locked in your audit date, which is a worse way to do it.

The Certification Process, Step by Step

Step 1: Gap assessment against ISO 22000:2018

Compare what you currently do against the standard's clauses: hazard analysis, operational prerequisite programs, traceability, emergency preparedness, and the rest. Most organizations discover they already do 60 to 70 percent of this informally. The gap is usually documentation and record-keeping, not actual practice. Skip this step and you find out what's missing during the audit instead of before it, which is the single most common reason certification timelines double.

Step 2: Build or update your FSMS documentation

This covers your food safety policy, hazard analysis and CCP (Critical Control Point) determination, operational and infrastructure PRPs (pest control, cleaning, water quality, and similar prerequisite programs), traceability and recall procedures, plus internal audit and management review records. If your organization already runs an ISO 9001 quality management system, don't rebuild this from scratch. ISO 22000 shares enough structure with ISO 9001 (management review, internal audit, document control, corrective action) that the two can sit inside one integrated management system rather than two separate paper trails.

One thing to avoid: don't copy a template FSMS off the internet and swap in your logo. Auditors can tell within the first ten minutes of a document review when hazard analysis was done generically instead of against your actual process. The CCPs simply won't match your real risk points, and that mismatch is obvious to anyone who's read a few hundred of these.

Step 3: Implement the system and let it run

This is the step people try to shortcut, and it's the one that causes the most non-conformities. Auditors expect to see records: internal audits completed, corrective actions closed, at least one management review meeting minuted, monitoring records for your CCPs and PRPs filled in day after day, not backfilled the night before. A system that went live the week before the audit has no evidence trail to check. Give it four to six weeks minimum before Stage 1.

Step 4: Internal audit and management review

Run at least one internal audit covering the full scope of your FSMS. Hold a documented management review where leadership actually looks at the results: non-conformities, customer complaints, audit findings, changes to the process. This isn't a box to tick. It's a specific requirement under Clause 9, and it's one of the first things a Stage 1 auditor asks for.

Step 5: Stage 1 audit (documentation review)

The certification body reviews your FSMS documentation and runs a readiness check, on-site or remote depending on the body and your setup. It's not pass/fail the way Stage 2 is. Stage 1 exists to catch documentation gaps before you commit to the full on-site audit, and to confirm your scope, sites, and shift patterns match what's actually on file.

Step 6: Close Stage 1 findings

Address whatever the Stage 1 auditor flagged. Usually it's small: a missing procedure reference, an unclear scope statement, a CCP that needs re-justifying. Rush straight to Stage 2 without closing these properly, and that's how organizations end up with major non-conformities at the worst possible point in the process.

Step 7: Stage 2 audit (on-site certification audit)

The full audit. Process observation on the floor, record checks, staff interviews, verification that what's documented matches what actually happens. This is where "we have a pest control procedure" gets tested against "show me this month's records and the corrective action from the finding you had in March." Non-conformities here get graded major or minor. Majors need to close before certification is issued; minors typically get 30 to 90 days.

Step 8: Certification decision and issuance

Once findings are closed, the certification body issues your ISO 22000 certificate, usually valid for a three-year cycle with annual surveillance audits in between to confirm the system is still operating, not that it merely existed on the day someone showed up to check.

Documents You'll Need

At minimum, expect to produce: a food safety policy and objectives, an FSMS scope statement, hazard analysis and CCP/OPRP determination records, PRP procedures (cleaning, pest control, personnel hygiene, water/air/energy supply, waste management, supplier control), a traceability procedure with a mock recall record on file, an emergency preparedness and response procedure, internal audit records, management review minutes, and training records for the food safety team and relevant staff. Certification bodies don't demand a specific document format. A spreadsheet-based traceability log works fine, as long as it actually holds up when someone tests it.

Common Mistakes That Slow Down Certification

Generic hazard analysis tops the list: copying a template's hazard set instead of analyzing your actual process. Auditors spot this immediately, because the CCPs won't line up with your real risk points.

Close behind it is having no evidence trail: implementing the system the week before Stage 1 instead of running it for a few weeks first, so there's simply nothing on record to audit against.

Then there's treating PRPs as paperwork. Prerequisite programs like pest control, cleaning schedules, and supplier approval are often the weakest part of an FSMS, precisely because teams see them as background tasks rather than part of the certified system itself. They get audited just as hard as your CCPs do.

Scope mismatch causes its own delays: applying for certification with a scope statement that doesn't match what the certification body actually finds on-site, whether that's an extra product line, an unlisted second shift, or a site that never made it into the application. This gets flagged in Stage 1 and pushes everything downstream.

And underestimating the food safety team's ongoing time is the quiet one. ISO 22000 isn't a project you finish and file away. The team needs continuing time for internal audits, record review, and corrective actions, not just a burst of effort in the weeks before the audit.

ISO 22000 vs. HACCP vs. FSSC 22000

Short version: HACCP is a method for identifying and controlling food safety hazards. ISO 22000 is a full management system standard that folds HACCP principles into a broader framework of management commitment, PRPs, communication, and continual improvement, and it's independently certifiable against an international standard on its own. FSSC 22000 goes a step further still. It's ISO 22000 plus sector-specific technical PRPs (drawn from the ISO/TS 22002 series) plus additional GFSI-benchmarking requirements, which matters if your buyers are global retailers or brands that specifically require GFSI-recognized certification.

If your customers are asking for "ISO 22000," this guide covers what you need. If they're asking for GFSI recognition specifically, which is common with large export accounts and multinational retail buyers, you'll need FSSC 22000 on top of it, not instead of it.

Who Actually Needs ISO 22000

Any organization in the food chain, not just manufacturers: primary producers, food processors, packaging manufacturers, transport and storage providers, catering services, and retailers. If your product or service touches food anywhere between farm and fork, a buyer further down that chain can reasonably ask you for this.

Food manufacturers often carry ISO 22000 alongside other management system certifications too. ISO 14001 for environmental compliance around waste and effluent, or ISO 45001 for worker safety on a production floor where slips, machinery, and chemical handling are everyday risks. If your facility also needs to demonstrate Good Manufacturing Practices to a pharmaceutical or nutraceutical buyer, our GMP certification page covers where that standard overlaps with, and differs from, ISO 22000.

Export-oriented food businesses see ISO 22000 most often as a contractual requirement rather than a voluntary quality initiative. A buyer's procurement team simply won't sign off without it, full stop. If you're still deciding whether now is the right time to apply, our post on when to go for ISO 22000 certification walks through the signals worth watching for.

FAQ

How long does ISO 22000 certification take?

For an organization with basic food safety practices already in place, 8 to 16 weeks from gap assessment to certificate is typical. Organizations starting from close to zero, with no documented procedures and no hazard analysis on file, should plan for 4 to 6 months to build a system that will actually hold up under audit rather than just scrape past a rushed one.

What's the difference between Stage 1 and Stage 2 audits?

Stage 1 reviews your documentation and readiness, checking whether your FSMS is complete enough to be meaningfully audited at all. Stage 2 is the full on-site audit: process observation, record verification, and staff interviews that determine whether you're actually certified.

Does ISO 22000 replace HACCP?

No. ISO 22000 incorporates HACCP as one of its core requirements rather than replacing it. You still need a proper hazard analysis and CCP determination. ISO 22000 just wraps that inside a broader management system, with added requirements for communication, PRPs, and continual improvement.

How often is ISO 22000 recertified?

Certificates typically run on a three-year cycle, with annual surveillance audits in between to confirm the system is still being maintained, not just that it existed on certification day.

Related Reading

If you want more background before you commit to an audit date, our guide to food safety certifications covers how ISO 22000 fits alongside other food safety schemes, and how ISO 22000 helps local food businesses meet global standards is worth a read if you're planning to export.

Next Steps

If you're weighing ISO 22000 against FSSC 22000 because a buyer mentioned GFSI recognition, or you'd like a straight read on where your current food safety documentation stands against the standard, that's usually a five-minute conversation that saves weeks of rework later. Visit our ISO 22000 certification page for cost factors and next steps, browse our other industries served if food safety sits alongside other compliance needs in your business, or get in touch with our certification team to scope what your organization specifically needs before you commit to an audit date. You can also check our FAQs for answers to other common certification questions.

Related Certifications

Related Industries

Email Us
✉ EmailGet Quote