- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Quality & Manufacturing
FSSC 22000/ISO 22000
ISO 22000:2018 is the international standard for a food safety management system for any organization in the food chain, combining management system requirements with HACCP principles and prerequisite programs.
FSSC 22000 is a GFSI-benchmarked certification scheme built on top of it: ISO 22000 plus a sector-specific prerequisite program standard (the ISO/TS 22002 series) plus FSSC's own additional requirements on topics such as food fraud, food defense, allergen management, environmental monitoring, food safety culture, and labeling.
FSSC 22000 Version 6 was published in April 2023, became mandatory for audits from April 1, 2024, and all certified sites had to complete their upgrade audit by March 31, 2025.
In writing, both expect a food safety policy and objectives, a hazard analysis and HACCP plan with operational prerequisite programs, documented prerequisite programs, emergency and incident procedures, traceability, withdrawal and recall procedures, supplier control, and management system records.
FSSC adds documented food defense and food fraud mitigation plans, a food safety culture plan, and specific verification activities.
Who has to comply
Voluntary, but many global food manufacturers, ingredient suppliers, packaging makers, and retailers require a GFSI-recognized certificate such as FSSC 22000 from suppliers. ISO 22000 alone is not GFSI-recognized, so buyers who need GFSI usually ask for FSSC 22000, SQF, or BRCGS.
What the assessor asks to see
Food safety policy, objectives, and scope; context and interested parties; food safety team and competence; hazard analysis, HACCP plan, and operational prerequisite programs with validation; prerequisite program documentation mapped to the applicable ISO/TS 22002 part; monitoring and verification records; calibration; allergen management; food defense threat assessment and food fraud vulnerability assessment with mitigation plans; environmental monitoring program; supplier approval and incoming material verification; traceability and mock recall results; emergency preparedness; nonconformity and corrective action records; internal audit and management review records; food safety culture plan; labeling and product information controls.
Where the requirement sits: ISO 22000 7.5 documented information; 7.2 competence; 7.3 awareness; 8.5 hazard control plan
Version 6 timeline
FSSC 22000 Version 6 was published in April 2023. Audits against Version 6 started April 1, 2024, and every certified site had to complete an upgrade audit by March 31, 2025. Version 6 added requirements on food safety and quality culture, quality control, food loss and waste, equipment management, and communication of requirements.
Check the FSSC scheme documents page for any later amendments or a Version 6.1 (not confirmed in the sources reviewed here).
What AllyMatter does here
Document control and awareness layer.
AllyMatter publishes this site.
Assessors
Who assesses FSSC 22000/ISO 22000
FSSC-licensed certification bodies accredited to ISO/IEC 17021-1 with ISO/TS 22003-1 for the FSSC 22000 scheme; for ISO 22000 alone, any accredited certification body with food safety scope.
Accredited by National accreditation bodies recognized by Foundation FSSC (for example ANAB, UKAS, RvA, DAkkS), which are Global ACI (formerly IAF) signatories; FSSC also runs its own integrity program over licensed certification bodies.
Public register of assessors: https://www.fssc.com/certification-bodies/
No firm has claimed a FSSC 22000/ISO 22000 assessor listing yet. Claim yours →
Consultants
Who helps with FSSC 22000/ISO 22000
A large food safety consultant ecosystem exists. Implementers run the HACCP study, write prerequisite programs against the relevant ISO/TS 22002 part, build food defense and fraud assessments, run internal audits and mock audits, and support closing findings. Engagements typically run four to nine months.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for FSSC 22000/ISO 22000
Tools that name this framework in their own material.
Related reading
- FSSC releases Version 6 of the FSSC 22000 schemeBreaks down the Version 6 additional requirements, the category changes and what the food safety and quality culture clause asks for.NSF
- Understanding GFSI and the differences between FSSC 22000, SQF, BRCGS and IFSExplains how an ISO 22000 based scheme with prerequisite programmes differs structurally from the checklist-style schemes.SGS
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for FSSC 22000/ISO 22000
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of FSSC 22000/ISO 22000 in AllyMatter
Approve the policies FSSC 22000/ISO 22000 asks for, keep every version, and record a named acknowledgment from each person who has to read them.