ISO 22000 Certification in USA
Been asked for a food safety certificate? Talk to an assessor about scope, timing and audit readiness through IAS, and find out what an ISO 22000 audit will actually look at.
✓ IAS is accredited by UQAS | ✓ Food sector assessors | ✓ Clear scope wording | ✓ Surveillance you can plan around
Few organizations set out wanting a food safety management system certificate for its own sake. A retailer asks. A distributor sends a supplier questionnaire. A co-packing customer updates its approved supplier list and a line on the form says “third-party FSMS certification.” That is usually how ISO 22000 certification lands on someone’s desk.
This page explains what the standard asks for, what an IAS audit looks at, and what the certificate does and does not say about your operation. It sits behind the main ISO 22000 service page for the USA and sticks to the mechanics — records, prerequisite programs, verification evidence — because that is where audits are won or lost.
What ISO 22000 asks of a food business
ISO 22000 is the international standard for a food safety management system. It applies along the whole chain: growers, processors, manufacturers, packers, storage and distribution, retail, catering, and the companies that supply equipment, packaging, cleaning chemicals and ingredients.
The standard combines three things that many plants already do separately. It takes hazard analysis and critical control point thinking, wraps it in a management system with policy, objectives and review, and requires prerequisite programs to be defined, applied and verified rather than assumed.
The practical effect is that informal practice has to become documented practice. A supervisor who “always checks the metal detector at start-up” needs a check record with a rejection test, a result and a name.
Who IAS is, and who accredits IAS
Integrated Assessment Services (IAS) is the certification body that carries out the audit and issues the certificate. IAS is accredited by UQAS. That accreditation is an independent assessment of IAS — of its impartiality arrangements, auditor competence, audit time decisions, decision-making separation and record control.
Say that plainly, because it is often misunderstood: accreditation is an assessment of the certification body, not an endorsement of any certified organization. UQAS does not audit your plant, does not review your hazard analysis and does not vouch for your product. It assesses whether IAS is competent to make certification decisions and consistent in how it makes them.

You can read more about the organization on the IAS about us page, and about how certification decisions are structured in the certification process.
What ISO 22000 certification covers on your site
A certificate is a statement about a system, on a defined scope, at a point in time. It is worth being precise about the boundary, because customers sometimes read more into it than it carries.
| The certificate does say | The certificate does not say |
|---|---|
| A documented FSMS was audited against ISO 22000 | That every product shipped is safe |
| The listed sites and activities were sampled | That unlisted sites or activities were assessed |
| Hazard analysis and controls were reviewed for adequacy | That no hazard will ever be missed |
| Prerequisite programs existed and were verified | That they were applied perfectly on every shift |
| Nonconformities found were closed | That no nonconformity exists today |
| Surveillance will continue during the cycle | That the certificate cannot be suspended |
Certification is not a guarantee of product safety, and it is not a substitute for your own controls, your own testing or your own recall readiness. An audit samples. It looks at selected records, selected lines, selected shifts. A clean audit means nothing contradicting the standard was found in that sample.
Prerequisite programs: where most gaps show up
Prerequisite programs (PRPs) are the basic conditions that make hazard control possible. Cleaning and sanitation. Pest control. Personal hygiene and gowning. Water and air quality. Maintenance and lubricant control. Glass and brittle plastic. Allergen segregation. Waste handling. Supplier approval. Chemical storage.
The common failure is not absence. It is that PRPs exist as documents nobody verifies. There is a sanitation schedule, but no record of a completed verification swab or a visual sign-off by someone other than the person who cleaned. There is a pest control contract, but no review of trend data and no action on a device that catches repeatedly.
Auditors look for the loop: the program, the monitoring, the verification by a second party, and evidence that findings changed something. A program without that loop is a leaflet. Sites that want supervisors to understand the hygiene conditions underneath these programs often send them to GMP training or cGMP internal auditor training before the system work starts.
Verification records an auditor will ask for
This is the section worth rehearsing before an audit. The difference between a smooth audit and a difficult one is usually record quality, not intent.
| Element | What strong evidence looks like | What weak evidence looks like |
|---|---|---|
| CCP monitoring | Signed readings at defined frequency, with the limit printed on the form | A logbook with gaps and no limit stated |
| Corrective action | Product disposition, cause analysis, and a check that the fix held | A note saying “adjusted” with no product decision |
| Calibration | Traceable certificates, in-use checks, and a rule for out-of-tolerance results | A sticker with a date and nothing behind it |
| Sanitation verification | Swab results trended, with action limits and follow-up | Pass or fail with no limit and no trend |
| Allergen control | Changeover cleaning validated, label reconciliation records | A statement that lines are dedicated, unverified |
| Supplier approval | Specifications, certificates of analysis checked against spec | Certificates filed but never compared |
| Traceability exercise | A mock recall with times, quantities reconciled, gaps listed | An exercise with no reconciliation of quantities |
| Management review | Inputs, decisions, owners and due dates | Minutes recording attendance only |
Two details reliably cause findings. First, certificates of analysis that arrive and are filed without anyone comparing the result to the agreed specification. Second, traceability exercises that trace forward but never reconcile quantity — what was made, what shipped, what remains.
The ISO 22000 certification pathway, from application to certificate
The route is predictable. Knowing the order helps you avoid the classic mistake of booking a stage 2 audit before internal audits have actually run.

Stage 1 is a readiness review. The assessor looks at documented information, scope, hazard analysis, PRP list, internal audit and management review, and confirms the site is ready to be audited properly. It is diagnostic. Findings here are normal and are cheaper to fix than findings at stage 2.
Stage 2 is the implementation audit on site. Assessors follow processes, interview operators, watch a start-up check, pull records at random and test whether the system described on paper is the system running on the floor.
Nonconformities are then closed with evidence, not promises. An independent reviewer inside IAS — someone who did not audit you — checks the file before the certification decision is made. How the stages connect is described on the ISO audit procedure page.
Choosing between the schemes around ISO 22000
Customers name different schemes, and they are not interchangeable. Pick against the request you received, not against what sounds strongest.
| If your customer asks for | Usually the right route | Worth knowing |
|---|---|---|
| A recognized FSMS certificate | ISO 22000 | Management system standard, sector-neutral |
| A GFSI-benchmarked scheme | FSSC 22000 | Builds on ISO 22000 plus sector PRPs and additional requirements |
| A retailer-driven UK or EU spec | BRC | Prescriptive, product-focused, graded outcome |
| Hazard plan verification only | HACCP | No surrounding management system required |
| Manufacturing practice conditions | cGMP | Focused on facility and process hygiene conditions |
| Religious dietary assurance | Kosher | Separate scheme with its own supervision model |
FSSC 22000 also moves on its own schedule, and version 7 changed what sites report on food loss, waste and packaging — the note on FSSC 22000 version 7 sets out what that means in practice.
If you already run ISO 9001, the management clauses will feel familiar and internal audit planning can often be combined. Our ISO 9001 certification page covers that side, and auditors moving across both standards usually take ISO 9001 internal auditor training. The same combining logic applies if you hold ISO 14001 certification or ISO 45001 certification: one audit program can cover several systems without auditing the same evidence three times. For food fraud and authenticity controls, which increasingly appear in customer questionnaires, see the note on auditing food fraud and authenticity.
The three-year ISO 22000 certification cycle
Certification is not a single event. The certificate runs on a cycle, with surveillance audits between the initial audit and recertification.

Surveillance is narrower than the initial audit but not a formality. It typically looks at internal audit results, management review, complaints and corrective actions, changes to product or process, use of certification marks, and a sample of CCP and PRP records since the last visit. Recertification looks at the whole system again and considers performance across the full cycle.
Changes matter between visits. A new production line, a new allergen on site, a new high-risk ingredient or a move to a second facility should be reported rather than revealed at the next audit.
Getting the scope wording right
Scope is the most commercially important sentence on the certificate, and the one most often rushed. It names the activities, the product categories and the sites covered.
Write it the way your customer will read it. If the certificate says “manufacture of bakery products” but the customer buys frozen dough from a second site that was never audited, the certificate does not cover the purchase. Excluding a site to save time creates a problem later when a supplier questionnaire asks which facility produced the lot.
Certification marks have rules too. They belong on stationery and marketing, not on product or packaging in a way that implies product certification. What you may display is set out in the logo usage guideline.
Where ISO 22000 certification audits usually go wrong
Four patterns come up repeatedly.
- Internal audits run late or shallow. A single audit covering everything, a week before stage 2, with no findings. Auditors read that as a system nobody tested.
- Management review as a formality. Attendance recorded, decisions absent. The standard expects inputs, outputs, owners and dates.
- Hazard analysis copied from a template. Generic hazards for a generic plant, not the hazards of your ingredients, your layout and your flow.
- Validation confused with verification. Validation shows a control can work. Verification shows it did work. Both are needed, and they are separate records.
A fifth, quieter one: no evidence that the food safety team meets. The standard expects a multidisciplinary team, and an audit will ask who is on it and when they last sat down together.
Building internal capability
Two roles matter. Someone has to run internal audits competently, and someone has to understand the standard well enough to design the system rather than copy it.
Internal auditor training covers audit planning, evidence gathering, writing findings that identify a cause, and reporting in a way management can act on. Lead auditor training goes further into audit program management and team leadership. Both are available for ISO 22000 — internal auditor and lead auditor — and for FSSC 22000, at lead auditor and internal auditor level, where a GFSI-benchmarked scheme is required. Sites building hygiene fundamentals first often start with HACCP training before layering the management system on top.
Dates for public courses sit on the training schedule, and the wider ISO training range covers the other standards a food safety team is likely to meet.
A note on legal duties
Nothing on this page asserts what any country’s law requires. It describes a voluntary international standard and how a certification audit against it is run. Food businesses in the United States and elsewhere sit under their own statutory and regulatory obligations, and those obligations are not decided by a certificate. Whether ISO 22000 certification helps you meet any legal duty is a question for your own legal and regulatory advisers, who know your products, your sites and your markets. Nothing here is legal advice.
Frequently asked questions
Is ISO 22000 the same as HACCP?
No. HACCP is a hazard analysis method. ISO 22000 includes HACCP principles but adds a management system: leadership, planning, competence, communication, internal audit and review. A HACCP plan can sit inside an ISO 22000 system.
Does ISO 22000 certification satisfy a GFSI requirement?
Not on its own. Customers asking specifically for a GFSI-benchmarked scheme generally need FSSC 22000, which adds sector prerequisite programs and additional requirements on top of ISO 22000.
Who accredits IAS?
IAS is accredited by UQAS. That accreditation assesses IAS as a certification body. It is not an assessment or endorsement of any organization IAS certifies.
Can a small plant get ISO 22000 certification?
Yes. The standard scales. A small processor with three products and one line still needs hazard analysis, PRPs, monitoring records and a review, but the documentation is proportionate to the operation.
Do we need a consultant?
No. Many companies build the system with internal staff who have been through internal auditor training. If you do use a consultant, the same firm cannot both consult on your system and audit it for certification.
What happens if a nonconformity is found?
You submit correction, cause analysis and corrective action with evidence. Major nonconformities usually need verified closure before a certificate is issued. Minor ones may be verified at the next audit, depending on the finding.
How long is the certificate valid?
It runs on a defined cycle with surveillance audits in between, then a recertification audit before expiry. Validity depends on surveillance being completed on schedule and the system remaining effective.
Can the certificate be suspended?
Yes. Missed surveillance, unreported major changes, misuse of marks or a serious unresolved breakdown in the system can lead to suspension or withdrawal.
Does the certificate cover our co-packer?
Only if that site and activity are named in the scope. A separate legal entity producing on your behalf needs its own certification or explicit inclusion in yours.
What records should we have ready before stage 2?
Hazard analysis, PRP list with verification evidence, CCP and OPRP monitoring records, calibration, corrective actions, internal audit reports, management review minutes, a completed traceability exercise and complaint records.
Can multiple sites go on one certificate?
Sometimes, depending on how similar the activities are and how central the management system is. Discuss it at application, because it changes how the audit is planned.
Where do we start with ISO 22000 certification?
Define the scope, list your prerequisite programs honestly, and run one real internal audit. Then apply. More detail sits on the frequently asked questions page.
Ready to scope an ISO 22000 certification audit? Send your product list, sites and the food safety certification requirement your customer has set to IAS, or browse the wider range of system certification services and ISO certification in USA.
