If a retail customer has to accept the certificate, you need FSSC 22000. If you want a food safety management system that fits inside an existing ISO estate and no customer is demanding GFSI recognition, ISO 22000 on its own is a legitimate and cheaper answer.
The reason is structural rather than a matter of rigour. ISO 22000 specifies a management system and requires the organisation to establish prerequisite programmes, but it does not say in detail what those programmes must contain. FSSC 22000 takes ISO 22000 as its management system core, adds a sector-specific prerequisite specification from the ISO/TS 22002 series, and adds a set of additional scheme requirements. That combination is what makes it auditable to a consistent level across sites, and consistency is what GFSI benchmarking is testing for.
| Criterion | ISO 22000 | FSSC 22000 |
|---|---|---|
| What it is | An international management system standard | A certification scheme built on ISO 22000 |
| Published by | International Organization for Standardization | Foundation FSSC, a not-for-profit scheme owner |
| Prerequisite programmes | Required, but the content is left to the organisation | Specified through the applicable ISO/TS 22002 part for the sector |
| Additional requirements | None beyond the standard | A defined set covering matters such as food fraud, food defence, allergen management and logistics services |
| GFSI recognition | No | Yes |
| Retail acceptance | Limited; treated as supporting evidence rather than as the certificate | Broad, alongside BRCGS and IFS |
| Integration with ISO 9001 and ISO 14001 | Direct, through the common high level structure | Direct, since the core is ISO 22000 |
| Audit basis | The standard’s clauses | The standard, the prerequisite specification and the additional requirements together |
| Typical certification cost | Lower | Higher, because the audit covers more and the scheme carries its own fees |
When to choose ISO 22000
Choose ISO 22000 when nobody in your customer base is requiring a GFSI-recognised certificate and you want the management system for its own sake. That is a real situation: a business selling into food service, into industrial buyers who run their own second-party audits, or into markets where retail certification culture is thinner, can get most of the operational benefit without the scheme overhead.
Choose it when you already run ISO 9001 or ISO 14001 and want a single integrated management system. ISO 22000 uses the same high level structure, so the management review, internal audit, document control, competence and improvement clauses can be run once rather than three times. For a site with a mature ISO culture this is the least disruptive route to a formal food safety system, and it is the route that produces the least parallel paperwork.
Choose it as a staged step. Certifying to ISO 22000 first and adding the prerequisite specification and additional requirements later to reach FSSC 22000 is a well-worn path, and it lets a site spread cost across two budget years while still having a certificate to show in the interim.
Choose it when your operation is not a food manufacturing site in the conventional sense. ISO 22000 applies across the food chain, and for an organisation whose role is storage, transport or a service into the chain, the standard can be a better conceptual fit than a manufacturing-oriented retail scheme – though note that FSSC also has scope categories for storage, transport and packaging.
When to choose FSSC 22000
Choose FSSC 22000 when a customer requires a GFSI-recognised scheme and you would rather run an ISO-format system than a retail-association standard. This is its central use case, and it is a strong one: FSSC gives you the same recognition status as BRCGS and IFS Food while keeping the ISO management architecture, which matters if your organisation is already run that way.
Choose it when you operate several sites in different countries. FSSC’s ISO base makes multi-site consistency easier to argue internally than a scheme whose language is rooted in one retail market, and the certification structure travels well.
Choose it when your business sits in a part of the chain where the retail schemes are a poor fit. FSSC’s scope categories cover food manufacturing, animal feed, packaging manufacturing, storage and distribution, catering and transport, which makes it the practical GFSI route for a number of operations that would have to force themselves into a manufacturing standard otherwise.
Choose it when you want the additional requirements as a framework rather than as a burden. Food fraud vulnerability assessment, food defence, allergen management, environmental monitoring where relevant and equipment management are all things a serious operation should be doing; having them specified saves the argument about scope. The FSSC 22000 record lists what the scheme adds.
What changes in your process
Moving from an informal HACCP plan to ISO 22000 mainly adds management system machinery: a defined context and interested parties analysis, documented objectives, a competence and awareness framework, internal audit, management review, and a nonconformity and corrective action process with records. The food safety content itself – hazard analysis, control measure validation, verification, traceability, withdrawal and recall – is recognisable from Codex HACCP, structured into the ISO format with operational prerequisite programmes sitting between prerequisites and critical control points.
Moving from ISO 22000 to FSSC 22000 adds three things. The applicable part of ISO/TS 22002 becomes an auditable specification, so prerequisite programmes stop being “adequate in the organisation’s judgement” and start being checked against a written list covering building layout, utilities, waste, equipment suitability, cleaning, pest control, personnel hygiene, rework, recall procedures, storage, product information and food defence. The scheme’s additional requirements are added on top. And the audit becomes subject to scheme rules on unannounced audits, certification body oversight and reporting.
For most sites the gap is not conceptual. It is a list of prerequisite programme details that were previously handled by custom and are now handled by a documented procedure with a record behind it.
- Utilities: water, air, steam and ice quality specified and monitored rather than assumed.
- Equipment: hygienic design and maintenance treated as a food safety control with a change management step.
- Personnel: hygiene, protective clothing and medical screening written down at the level the specification asks for.
- Storage and transport: conditions specified, monitored and recorded, which for frozen product means the cold chain evidence a buyer already wants.
What the table does not show
ISO 22000 is not a weak standard. The reason it is not GFSI-recognised on its own has nothing to do with rigour and everything to do with specification. Benchmarking requires that a scheme define what is audited to a consistent depth across every site that holds it. A standard that says “establish prerequisite programmes appropriate to the organisation” cannot deliver that consistency, however well any individual organisation implements it. What GFSI benchmarking is answers this directly.
ISO 22000 plus ISO/TS 22002 is not FSSC 22000. A site can implement both documents and be substantially compliant, but the certificate is issued against the scheme, including its additional requirements and its rules for certification bodies. Buyers check the certificate, not the intention, and a supplier claiming “we work to FSSC principles” is telling you it is not certified.
Nor is FSSC automatically interchangeable with BRCGS or IFS. GFSI recognition puts them in the same category; it does not force any individual retailer to accept all three. Some buyer specifications name a scheme. Check the customer’s policy before spending money on the assumption that recognition equals acceptance.
Version and transition risk applies here too. Both ISO 22000 and the FSSC scheme are revised on their own cycles, with transition windows during which certificates issued under the previous version remain valid. A specification should require the version in force at the audit date rather than fixing a number, and a buyer verifying a certificate should check the version alongside the scope and the expiry.
Scope is where certificates fail in practice. A certificate covers named products, processes and sites. A frozen fruit certificate that does not include the freezing operation, or a certificate that covers packing but not the cold store on the same address, is a real and common problem. Read the scope statement before reading the logo.
FAQ
Is FSSC 22000 equivalent to BRCGS or IFS?
For the purpose of GFSI recognition, yes: all three are recognised schemes benchmarked against the same requirements. For the purpose of a specific buyer’s approval policy, not necessarily. Recognition means the schemes have been assessed as delivering comparable food safety outcomes; acceptance is a commercial decision the buyer makes. The practical test is what the customer’s supplier standard actually says.
Can we certify to ISO 22000 first and upgrade later?
Yes, and it is a common route. The management system work is the larger part of the effort and it carries over completely. The upgrade audit then focuses on the prerequisite specification and the additional requirements. Budget for a real gap assessment before committing to a date, because prerequisite gaps are usually physical and physical work takes longer than documentation.
Does FSSC cover storage and transport?
Yes, through its scope categories for storage and distribution and for transport services. That is one of the reasons it appears in supply chains where a manufacturing standard would not fit, including cold stores handling third-party frozen product. Check that the specific certificate names the category you need.
Which certificate should a buyer ask for?
Ask for a GFSI-recognised scheme rather than for a named one, unless your own downstream customer requires a particular scheme. Naming one narrows your supply base for no food safety gain. What matters more is verifying the certificate: scope, sites, validity dates, the certification body and its accreditation, and whether the audit was announced or unannounced. Understanding food safety standards sets out the checks.
Is ISO 22000 worth holding if it will not be accepted?
It depends who is looking. As evidence in a supplier approval file it carries real weight, particularly alongside a completed questionnaire and an audit report. As the certificate that satisfies a retail specification, it will usually not be enough on its own. A supplier holding ISO 22000 and no GFSI-recognised scheme is not disqualified; it is a supplier whose approval will take more work on both sides.