What is ISO 22000 certification?
- What it managesFood safety hazards along your part of the food chain, using HACCP inside a management system.
- Who certifies to itFood manufacturers, processors, packers, cold chain and logistics operators, ingredient suppliers and exporters.
- Why it matters in IndiaVoluntary and separate from your FSSAI licence, which stays the legal requirement to operate.
ISO 22000 is the international standard for a food safety management system. It wraps Codex HACCP principles and prerequisite programmes inside a management system, and runs risk on two levels at once, organisational risk and operational food safety hazards. It is what export buyers and organised retail ask for once an FSSAI licence alone stops being enough.
Edition status. The draft of the next edition went to DIS ballot on 6 May 2026 for a 12-week vote. The 2018 edition remains the certifiable version until the new one is published.
Climate action amendment. Climate action amendments were issued across the ISO management system standards in February 2024.
ISO 22000 does not replace your FSSAI licence
An FSSAI registration or licence under the Food Safety and Standards Act, 2006 is the legal permission to operate a food business in India, obtained through the FoSCoS portal, and no ISO certificate substitutes for it. ISO 22000 is a voluntary management system certificate that buyers ask for on top. If you need the licence itself, start with FSSAI registration; if a buyer has asked for a certified food safety system, that is this page.
Who needs ISO 22000?
Certification is almost always triggered by a specific buyer requirement rather than an internal decision. These are the segments where it comes up.
| Segment | What usually triggers it |
|---|---|
| Food manufacturers and processors | Export buyer requirements and modern trade supplier conditions |
| Dairy, meat and seafood units | High-risk categories with close buyer and regulator scrutiny |
| Spice, agri and ingredient exporters | Overseas buyer audits and importer due diligence |
| Cold chain, storage and transport operators | Part of the food chain, and covered by their own PRP specification |
| Packaging manufacturers for food contact | Food chain category with a dedicated ISO/TS 22002 part |
| Central kitchens, QSR chains and caterers | Institutional and aggregator supplier requirements |
The auditable clauses of ISO 22000:2018
What each clause actually demands, and what an auditor will ask to see against it.
| Clause | Title | What it requires |
|---|---|---|
| 4 | Context of the organisation | Internal and external issues, interested parties and their requirements, and the certification scope in writing. Since the 2024 climate amendment you must also determine whether climate change is a relevant issue. |
| 5 | Leadership | Top management accountability, a signed policy, and roles and responsibilities assigned and communicated. Auditors interview leadership directly, and delegation to a quality manager is a finding. |
| 6 | Planning | Risks and opportunities, measurable objectives, and documented plans setting out what will be done, by whom, with what resources and how results are evaluated. |
| 7 | Support | Resources, competence, awareness, communication, and control of documented information including version control, access and retention. |
| 8 | Operation | The food safety core: prerequisite programmes, the traceability system, emergency preparedness, and the hazard analysis leading to a control plan of critical control points and operational prerequisite programmes, with validation, monitoring, verification and control of nonconforming product, withdrawal and recall. |
| 9 | Performance evaluation | Monitoring and measurement, internal audit covering every clause by independent auditors, and a management review with all required inputs. |
| 10 | Improvement | Nonconformity handling with root cause analysis, corrective action, verification of effectiveness, and continual improvement of the system. |
What ISO 22000 actually gets you
Opens export buyers
The standard is the common language for food safety across borders, so an overseas buyer can rely on it instead of running their own audit.
Required by organised retail
Modern trade and institutional buyers increasingly set a certified FSMS as a supplier condition.
Recall becomes survivable
Tested traceability, one step back and one step forward, is what limits a recall to a batch instead of your entire stock.
Controls chosen on evidence
Validation under clause 8.5.3 forces you to prove a control works, rather than assuming a temperature or a time is sufficient.
Allergen management gets structured
Allergens are treated as a hazard class in their own right, which is where most consumer complaints and recalls originate.
Base for FSSC 22000
FSSC 22000, the GFSI-recognised scheme many global buyers name, is built on ISO 22000 plus sector PRPs and additional requirements.
Documented information ISO 22000 requires
The records an auditor will ask for, and the clause behind each one.
| Document or record | Why the auditor wants it |
|---|---|
| Food safety policy and scope | Clauses 4.3 and 5.2, defining the products, processes and sites covered. |
| Food safety team and competence records | Clause 5.3 and 7.2. The team must be multidisciplinary; a single named person is a finding. |
| Prerequisite programmes (PRPs) | Clause 8.2, selected against the ISO/TS 22002 series for your sector, covering hygiene, pest control, cleaning, personnel and infrastructure. |
| Product descriptions and intended use | Clause 8.5.1, including allergens, shelf life and vulnerable consumer groups. |
| Process flow diagrams, verified on site | Clause 8.5.1.5. Auditors walk the line against the diagram; an unverified diagram is a common finding. |
| Hazard analysis and significance assessment | Clause 8.5.2, covering biological, chemical, physical and allergen hazards at each step. |
| Control plan: CCPs and OPRPs | Clause 8.5.4, with critical limits, monitoring, corrections and corrective actions for each. |
| Validation evidence for control measures | Clause 8.5.3, proving the control is capable of achieving the intended level of control, not just that it is monitored. |
| Traceability system records | Clause 8.3, one step back and one step forward, with tested recall capability. |
| Emergency preparedness, withdrawal and recall records | Clauses 8.4 and 8.9.5, including mock recall records. |
| Verification activities and results | Clause 8.8, including verification that PRPs and the control plan are being implemented. |
| Internal audit reports and management review minutes | Clauses 9.2 and 9.3, mandatory before stage 2. |
How to get ISO 22000 certified
Nine stages. The last two are set by ISO/IEC 17021-1 and are the same for every standard, which is why a second certification costs far less than the first.
Gap analysis against the standard
We audit what you already do against every auditable clause of ISO 22000 and hand back a gap register, not a sales document. Most organisations are already meeting 40 to 60 percent of the requirements without having written them down.
Scope, context and risk
Fix the certification scope in writing, the sites, processes and exclusions it covers, then build the clause 4 context, interested parties and the risk register that the auditor will trace everything else back to.
Documented information
Policy, objectives, process maps, procedures and the records each clause requires. We supply working templates and adapt them to how you actually operate, because an auditor tests the system you run, not the one you filed.
Implementation and training
Roll the system out across the departments in scope and run awareness training, plus competence training for the people who will hold specific responsibilities. Keep attendance and competence records; they are audited.
Internal audit
A full internal audit covering every clause and every process in scope, by someone independent of the work being audited. Findings are logged as nonconformities and closed with corrective action, and this evidence is mandatory before a certification body will proceed.
Management review
Top management formally reviews performance against the standard's required inputs: audit results, objectives, nonconformities, feedback and improvement opportunities. Minutes are a stage 1 audit deliverable.
Stage 1 audit (readiness)
The certification body reviews your documentation, confirms the scope, checks your internal audit and management review are real, and identifies what it will focus on in stage 2. Findings here are usually fixable in days.
Stage 2 audit (implementation)
An on-site or remote audit of the system in operation: interviews, records and evidence sampled against each clause. Major nonconformities must be closed before a recommendation for certification; minors are closed within an agreed window.
Certificate issued, then maintained
The certification body issues a certificate with a three-year cycle. Surveillance audits follow in years one and two, and a recertification audit before the third anniversary. Miss a surveillance audit and the certificate can be suspended or withdrawn.
Check accreditation before you buy a certificate
ISO writes standards. It does not audit anyone, does not issue certificates and does not permit its logo to be used on one, so any certificate that presents itself as issued by ISO is wrong on its face. A certificate is worth what its accreditation is worth. In India the accreditation body is the National Accreditation Board for Certification Bodies (NABCB), which operates under the Quality Council of India, accredits certification bodies against ISO/IEC 17021-1, and is a signatory to the IAF Multilateral Recognition Arrangement, which is what makes an Indian certificate acceptable abroad. Before signing, ask for the certification body's accreditation number, confirm the standard and scope are inside its accredited scope, and verify the certificate on the accreditation body's directory or on IAF CertSearch. A certificate issued in 24 hours with no audit is not a certificate a tender committee, an OEM or an enterprise security review will accept.
Start with a ISO 22000 gap analysis
A free consultation with an IncorpX certification specialist: what you already meet, what is missing, an honest timeline, and what the audit will cost.
What ISO 22000 costs
Two separate costs, paid to two different parties. Anyone quoting a single all-in number for an accredited certificate is quoting one of them and hoping you do not ask about the other.
| Cost | Paid to | What drives it |
|---|---|---|
| IncorpX professional fee | IncorpX | Fixed and quoted upfront. From ₹9,999 for ISO 22000, depending on scope, sites and how much of the system already exists. |
| Certification audit fee | The certification body | Audit days, calculated from effective headcount, number of sites and sector risk category under the IAF mandatory documents. |
| Surveillance audit fees | The certification body | Years 1 and 2 of the cycle. Typically a fraction of the initial certification audit. |
| Recertification audit fee | The certification body | Before the third anniversary, to issue a new three-year certificate. |
| Auditor travel and expenses | The certification body | At actuals, where the audit is conducted on site. |
The cheapest quote is usually the unaccredited one
If one quotation is dramatically below the others, the difference is almost never efficiency. It is the audit days. An accredited certification body cannot reduce audit duration below what the IAF mandatory documents require for your headcount and risk category, so a quote that undercuts that arithmetic is either not accredited for ISO 22000, or is not planning to conduct the audit it is quoting for.
Other ISO standards for your sector
Ordered by how often they are held alongside ISO 22000. Because clauses 4 to 10 are shared, a second standard is largely new operational content rather than a new system.
ISO 22000 guides and reference reading
Longer reference reading on ISO 22000 and on ISO certification generally.
Frequently asked questions about ISO 22000
12 questions answered against ISO 22000:2018 and the ISO/IEC 17021-1 certification rules as they stand in August 2026.
Get ISO 22000 certified without the guesswork
Talk to an IncorpX certification specialist for free. Accredited certification bodies, an honest timeline, and a gap analysis before you commit.

