Steps to Obtain ISO 22000 Certification
Looking to obtain ISO 22000 certification? Learn the main steps involved in obtaining certification for a Food Safety Management System, from defining the certification scope and selecting an independent certification body to completing the audit and certification decision.
Steps to Get ISO 22000 Certification ISO 22000 is one of the leading international standards for Food Safety Management Systems (FSMS). It is designed for organizations directly or indirectly involved in the food chain. The standard provides a systematic framework for managing food safety risks while considering applicable legal, regulatory, and customer requirements. ISO 22000 combines management system principles with Prerequisite Programs (PRPs) and HACCP principles to support effective food safety management. Organizations across different parts of the food chain may use ISO 22000, including: Food and beverage manufacturers. Food packaging organizations. Food storage facilities. Food transportation and distribution companies. Restaurants and catering organizations. Food traders and distributors. Organizations providing services related to the food chain. It is also important to understand that ISO itself does not issue ISO 22000 certificates . Organizations seeking certification work with an independent third-party certification body that performs the conformity assessment and issues the certificate when the applicable requirements have been fulfilled. So, what are the main steps for obtaining ISO 22000 certification? 1. Determine Why Your Organization Needs ISO 22000 Certification The process begins by identifying the organization's reasons for seeking certification. An organization may seek ISO 22000 certification to: Strengthen confidence in its Food Safety Management System. Meet customer requirements. Support supplier qualification. Respond to contractual requirements. Improve the systematic management of food safety risks. Support market expansion. Demonstrate that its Food Safety Management System has undergone an independent conformity assessment. ISO 22000 is not limited to food manufacturers. It can be relevant to different organizations operating within the food chain. 2. Define the ISO 22000 Certification Scope One of the most important steps is defining the certification scope . The organization should clearly identify: Activities included within the certification. Relevant products or services. Certified locations. Processes related to food safety. Boundaries of the Food Safety Management System. For example, a certification scope could relate to: Manufacturing, packaging, and storage of food products. Or: Preparation and provision of food and beverage services. Or: Storage and distribution of food products. The certification scope should accurately reflect the organization's actual activities and the processes that will be assessed. Certification does not automatically cover every activity performed by an organization. 3. Identify Requirements Relevant to the Organization After defining the certification scope, the organization needs to understand the requirements applicable to its Food Safety Management System. ISO 22000 includes key elements such as: Interactive communication throughout the food chain. Management system requirements. Prerequisite Programs (PRPs). HACCP principles. Risks and opportunities. Documented information. Performance evaluation. Continual improvement. ISO 22000 integrates management system elements, prerequisite programs, HACCP principles, and communication across the food chain to support food safety management. 4. Establish the Food Safety Management System At this stage, the organization establishes a Food Safety Management System appropriate to its activities and certification scope. The system may include arrangements related to: Food safety policy. Food safety objectives. Responsibilities and authorities. Internal and external communication. Control of documented information. Risk management. Prerequisite Programs. Food safety hazard analysis. Operational controls. Monitoring and measurement. Management of nonconformities. Continual improvement. The objective is not simply to create documents. The organization needs to have a functioning management system that can be evaluated for conformity and effectiveness during the certification audit. 5. Implement the System Having procedures and documented information alone is not sufficient. The Food Safety Management System should be effectively implemented across the activities included within the certification scope. Evidence of implementation may include: Operational records. Monitoring results. Verification records. Performance evaluation. Process monitoring. Records of issues and corrective actions. Food safety-related evidence. Measurement and analysis results. Records demonstrating that defined controls are being implemented. During the certification audit, the focus is not only on whether documentation exists, but also on whether the management system is implemented and effective in managing food safety risks. 6. Confirm Audit Readiness Before the external certification audit, the organization should ensure that its management system is functioning and that sufficient evidence of implementation is available. The organization should be able to demonstrate: Implementation within the defined scope. Monitoring of relevant processes. Maintenance of required records. Monitoring and verification activities. Management of nonconformities. Performance evaluation. Appropriate improvement activities. This stage is important because certification audits rely on objective evidence to determine conformity. 7. Select an ISO 22000 Certification Body After defining the certification scope and establishing the management system, the organization selects an independent certification body to conduct the certification audit. ISO does not issue ISO 22000 certificates itself. Certification is performed by independent third-party certification bodies. When selecting a certification body, organizations may consider: Accreditation scope. Applicable certification standard. Auditor competence and sector experience. Audit arrangements. Relevant accreditation requirements. Transparency of the certification process. Impartiality and independence. The certification process should remain independent from organizations that provide consultancy, implementation, or other activities that could compromise impartiality. 8. Stage 1 Audit The certification process may include structured audit stages to evaluate the organization's readiness. Stage 1 generally focuses on assessing the readiness of the management system for the detailed certification audit. The review may include: Food Safety Management System scope. Relevant documented information. Understanding of applicable requirements. Key elements of the management system. Processes and locations. Readiness for Stage 2. Stage 1 helps determine whether the organization is adequately prepared to proceed to the detailed assessment. 9. Stage 2 Audit Stage 2 is the main conformity assessment stage. During Stage 2, the certification body evaluates the implementation and effectiveness of the Food Safety Management System. The audit may include assessment of: Actual operational processes. Implementation of management system requirements. Food safety hazard analysis. Operational controls. Monitoring and measurement. Records and objective evidence. Achievement of system objectives. Applicable legal and regulatory requirements. Conformity with ISO 22000 requirements. Auditors may obtain objective evidence through methods such as interviews, review of documented information, observation of activities, and evaluation of records and other relevant evidence. 10. Address Audit Findings After the audit, the findings are evaluated according to the applicable certification procedures. The result is not necessarily an immediate certification decision. If nonconformities are identified, the organization must address them according to the applicable certification process. This may involve: Analyzing the nonconformity. Identifying its cause. Taking appropriate corrective action. Providing required evidence. Verification of corrective action or closure, depen