ISO 22000 Certification: Complete Guide
ISO 22000 is the base international food safety management system standard — HACCP-based, applicable across the entire food supply chain — but it is not itself GFSI-benchmarked, which is the key distinction buyers and manufacturers need to understand before assuming it satisfies major retailers' certification requirements.

What ISO 22000 Actually Is
ISO 22000 sets requirements for a food safety management system built around HACCP principles (hazard analysis and critical control points), interactive communication across the supply chain, system management, and prerequisite programmes — it's a genuinely rigorous standard, but its GFSI status is the practical detail that determines whether it satisfies a specific retail customer's certification requirement.
ISO 22000 vs. FSSC 22000: The Distinction That Matters
FSSC 22000 is built on top of ISO 22000, adding the sector-specific prerequisite programmes needed for GFSI benchmarking — a facility can hold ISO 22000 certification alone and have a genuinely strong food safety system, but if a customer specifically requires GFSI-benchmarked certification, ISO 22000 alone won't satisfy that requirement without the additional FSSC layer.

Assessing Which Certification You Actually Need
Check directly with your largest or most demanding customers (or target customers) what certification they actually require — some accept ISO 22000 alone, many major European retailers specifically require GFSI-benchmarked certification (FSSC 22000, BRCGS, or IFS), and building the wrong certification wastes real time and cost.
Implementation Steps
ISO 22000 implementation follows a similar path to FSSC 22000: gap analysis against the standard, building out the food safety management system and required documentation, internal audit and management review, then external certification audit — for a facility with no prior formal food safety system, this is a genuine, multi-month undertaking, not a paperwork formality.
Have questions before you keep reading?
Get pricing, MOQs and lead times for your market.
Documentation and Record-Keeping Requirements
ISO 22000 requires documented hazard analysis, critical control point monitoring records, corrective action logs, and management review records — auditors specifically check that these records reflect actual ongoing practice, not documentation assembled just ahead of an audit.
Choosing an Auditor and Certification Body
As with FSSC 22000, certification is granted by accredited third-party bodies — confectionery-sector audit experience specifically is worth confirming, since a generalist food-safety auditor may not probe the specific risks relevant to candy production (sugar handling, allergen cross-contact between formats, temperature-sensitive storage).

Ongoing Maintenance
ISO 22000 certification also runs on a multi-year cycle with periodic surveillance audits — treat it as an ongoing operational system to maintain, not a one-time certificate to file away, since a lapsed or failed surveillance audit puts the certification itself at risk.
FAQ
Frequently asked questions
No — FSSC 22000 is built on top of ISO 22000, adding sector-specific prerequisite programmes required for GFSI benchmarking. ISO 22000 alone is a genuine, rigorous standard but isn't itself GFSI-benchmarked.
Check directly with your target customers. Some accept ISO 22000 alone; many major European retailers specifically require GFSI-benchmarked certification, which means FSSC 22000 (or BRCGS/IFS) rather than ISO 22000 by itself.
ISO 22000 is built around HACCP principles but adds broader food safety management system requirements — interactive supply-chain communication, system management, and prerequisite programmes — beyond HACCP's hazard-analysis focus alone.
It runs on a multi-year certification cycle with periodic surveillance audits in between, similar to FSSC 22000 — ongoing maintenance is required, not a one-time certificate.
Ready to get started?
Contact our team to discuss volumes, pricing, and supply structures for your market.