ISO 22000 is the international standard that sets out requirements for a food safety management system (FSMS), covering any organization in the food chain regardless of size or position — growers, processors, manufacturers, packagers, and distributors alike. The current edition is ISO 22000:2018, published by the International Organization for Standardization. Certification to it is optional; an organization can use the standard to structure its food safety management without ever pursuing third-party certification.
What ISO 22000 requires
The standard is built around four core elements: interactive communication of hazard information up and down the supply chain, system management through policy, objectives, documentation, and continual improvement, prerequisite programmes covering the baseline operating conditions like sanitation and pest control, and HACCP principles applied to identify and control hazards specific to the organization's products and processes. On top of those four, ISO 22000 also requires defined traceability and emergency-preparedness procedures, so an organization can respond quickly and control affected product if a food safety incident occurs.
ISO 22000 vs. FSSC 22000 vs. a general QMS
These three terms get mixed up often, so it's worth being precise. ISO 22000 is the base international FSMS standard on its own — it is not, by itself, a GFSI-recognized certification. Our guide to FSSC 22000 certification covers a related but different thing: FSSC 22000 takes ISO 22000 as its foundation and adds sector-specific prerequisite programmes and additional requirements, which is what makes it a GFSI-recognized scheme that retailers and buyers actually ask for. A general quality management system, like ISO 9001, is a different, broader concept again — it covers quality processes across any industry and isn't food-safety-specific at all. Our guide to what a QMS is covers how that broader concept relates to food-specific standards like ISO 22000 in more detail.
Is ISO 22000 certification required?
No single body performs ISO certification — ISO writes the standard, and an organization that wants third-party certification engages an accredited certification body to audit against it. Because ISO 22000 alone isn't GFSI-recognized, most manufacturers selling to retailers that require GFSI certification pursue FSSC 22000 instead, which is built on ISO 22000 but satisfies that retailer requirement directly. Manufacturers not facing a specific GFSI mandate sometimes still adopt ISO 22000's structure internally without seeking certification, simply because it's a well-documented, internationally recognized framework.
Where IONI fits
Whether a facility is structuring its FSMS around ISO 22000 directly or working toward FSSC 22000 certification, the underlying documentation — hazard analysis, prerequisite programme records, traceability data — is what auditors actually check. See how IONI helps food manufacturers keep that documentation audit-ready.
Frequently asked questions
Is ISO 22000 the same as FSSC 22000?
No. ISO 22000 is the base international food safety management system standard. FSSC 22000 is a separate, GFSI-recognized certification scheme built on top of ISO 22000, adding sector-specific prerequisite programmes and additional requirements.
Do I need ISO 22000 certification to sell to major retailers?
Most retailers that require GFSI certification will accept FSSC 22000, BRCGS, or SQF rather than asking for ISO 22000 certification specifically, since ISO 22000 alone isn't GFSI-recognized.
What's the current version of ISO 22000?
ISO 22000:2018 is the current edition, published by the International Organization for Standardization.
Who certifies a company to ISO 22000?
ISO itself does not perform certification. An organization seeking certification engages an accredited third-party certification body to audit its food safety management system against the standard.


