Every year I sit across the table from a plant manager who has just been told, in the same quarter, that a customer wants ISO 22000 certification and that FDA expects full compliance with the Preventive Controls for Human Food rule. The reaction is almost always the same: dread, because it sounds like two homework assignments instead of one. It isn't. In my view, once you look at the actual clause language and the actual regulatory text side by side, ISO 22000 and FSMA turn out to be two dialects of the same underlying language — hazard analysis, preventive control, verification, and documented correction. Build the system once and you can speak both.
This article walks through what each framework actually requires, where the overlap is close enough to build one program instead of two, where the differences matter enough that you cannot skip a step, and how food companies structure a single food safety management system that satisfies a voluntary international standard and a mandatory U.S. federal regulation at the same time.
What ISO 22000 Actually Requires
ISO 22000:2018 is a voluntary, internationally recognized food safety management system standard published by the International Organization for Standardization. It is built on the ISO high-level structure shared across ISO 9001 and ISO 14001, which means it opens with context of the organization (clause 4), leadership (clause 5), planning (clause 6), and support (clause 7) before it gets to operational food safety content in clause 8.
Clause 8 is where the standard earns its keep. Clause 8.5.1 requires the preliminary steps that enable that analysis — characterizing raw materials, product characteristics, intended use, and process flow diagrams. Clause 8.5.2 requires the hazard analysis itself: identifying biological, chemical, and physical hazards, and — since the 2018 revision — explicitly considering radiological hazards and food fraud vulnerability. From there, clause 8.5.2.4 requires the organization to select and categorize control measures, and clause 8.5.4 requires classifying them into a hazard control plan as either operational prerequisite programs (OPRPs) or hazard analysis and critical control point (HACCP) plans, following the same critical-control-point logic Codex Alimentarius established in its General Principles of Food Hygiene (CXC 1-1969, revised 2020). ISO 22000 does not invent a new hazard control methodology — it wraps the Codex HACCP framework inside a full management system with document control, internal audit, management review, and continual improvement requirements under clause 10.
Certification to ISO 22000 is issued by an accredited third-party certification body following a two-stage audit and ongoing surveillance audits, typically annually. The standard itself carries no legal force in the United States — no regulator requires it — but most major retailers and branded manufacturers require it or its GFSI-recognized derivative from their suppliers as a condition of doing business.
What FSMA Actually Requires
The FDA Food Safety Modernization Act was signed into law on January 4, 2011, and it shifted FDA's food safety posture from responding to contamination after the fact to preventing it before it happens. The implementing regulation most directly relevant to manufacturers is 21 CFR Part 117, the Current Good Manufacturing Practice, Hazard Analysis, and Risk-Based Preventive Controls for Human Food rule.
Subpart C of Part 117 requires every covered facility to have a written food safety plan prepared, or overseen, by a preventive controls qualified individual (PCQI). That plan must include a hazard analysis under 21 CFR 117.130, identification of preventive controls under 117.135, and — where preventive controls are identified — monitoring, corrective actions, and verification procedures under 117.145 through 117.165. FDA and industry shorthand this as HARPC: Hazard Analysis and Risk-Based Preventive Controls. Unlike classic HACCP, HARPC preventive controls are not limited to critical control points; they extend to process controls, sanitation controls, allergen controls, supply-chain controls, and, where applicable, a recall plan under 117.139.
FSMA is not voluntary and it is not a certification. It is federal law enforced through FDA inspection, warning letters, and, in the most serious cases, mandatory recall authority and consent decrees. A company cannot opt out of FSMA the way it can decline to pursue ISO 22000 certification — if you manufacture, process, pack, or hold human food in a facility required to register under section 415 of the FD&C Act, Part 117 applies to you unless a specific exemption fits your operation.
Where They Overlap: Hazard Analysis Is the Shared Spine
Here is the realization that changes how most clients approach this: ISO 22000 clause 8.5.2's hazard analysis and 21 CFR 117.130's hazard analysis are asking the same question in almost the same order. Both require you to identify known or reasonably foreseeable hazards, evaluate the severity of illness or injury and the probability of occurrence, and determine which hazards require a control measure. Both require that determination to be documented, not just performed. Both require you to revisit the analysis when something changes — a new ingredient, a new supplier, a new piece of equipment, a new finding from your environmental monitoring program.
Where ISO 22000 splits controls into OPRPs and CCPs, 21 CFR 117.135 splits them into process, sanitation, allergen, supply-chain, and recall preventive controls — a different vocabulary, but a control measure identified through one lens rarely needs a second identification exercise under the other. I have found that clients who write their hazard analysis worksheet with both column sets built in from the start — CCP/OPRP classification next to preventive-control-type classification — never have to run the exercise twice.
Verification is the second point of near-total overlap. ISO 22000 clause 9.1.1 requires monitoring, measurement, analysis, and evaluation of the food safety management system's performance. 21 CFR 117.165 requires verification activities including validation, monitoring review, calibration, and — for certain facilities — environmental monitoring or product testing. The language differs; the intent, that you must prove your controls actually work rather than assume they do, is identical.
Supplier control is the third overlap point, though it is where the two frameworks start to diverge in mechanism. ISO 22000 clause 7.1.6 requires control of externally provided processes, products, or services relevant to food safety. FSMA addresses supplier verification two ways. The first is 21 CFR 117.410, the supply-chain program requirement built into Part 117 itself. The second is the Foreign Supplier Verification Programs rule at 21 CFR Part 1, Subpart L, which applies specifically to importers of food from foreign suppliers. A U.S. manufacturer sourcing internationally may need to satisfy all three at once — ISO 22000's supplier clause, Part 117's supply-chain program, and FSVP — but that's one supplier qualification file, not three, if it's built correctly the first time.
Where They Genuinely Differ
The overlap is real. But I would be doing you a disservice if I told you the two frameworks are interchangeable. They are not. Three differences matter enough to plan around.
First, scope of coverage. ISO 22000 is designed to apply across the entire food chain. Primary producers, feed producers, food manufacturers, transport and storage operators, retail, and even packaging manufacturers and equipment suppliers can all certify to it. FSMA's Part 117 rule is narrower: it applies specifically to facilities that manufacture, process, pack, or hold human food and are required to register with FDA. Farms covered by the Produce Safety Rule (21 CFR Part 112) and facilities exclusively engaged in certain low-risk activities fall under different rules entirely.
Second, food fraud and food defense sit in different places. ISO 22000:2018 clause 8.5.2 requires consideration of food fraud vulnerability as part of the hazard analysis itself. FDA addresses intentional adulteration separately, through the Mitigation Strategies to Protect Food Against Intentional Adulteration rule at 21 CFR Part 121, which requires a food defense plan with actionable process steps and mitigation strategies — a distinct document from the Part 117 food safety plan, prepared under a different qualified individual designation (the food defense qualified individual, not the PCQI).
Third, and most practically: one is a certification, the other is a legal obligation with inspection consequences. Passing an ISO 22000 audit gets you a certificate that customers may require. Passing an FDA inspection avoids a Form 483 observation, a warning letter, or in serious cases an import alert or consent decree. You can lose ISO 22000 certification and keep operating. You cannot lose FSMA compliance and keep operating legally.
Comparison at a Glance
| Dimension | ISO 22000:2018 | FDA FSMA (21 CFR Part 117) |
|---|---|---|
| Nature | Voluntary international standard | Mandatory U.S. federal regulation |
| Enforced by | Accredited third-party certification body | FDA (inspection, warning letters, recall authority) |
| Core methodology | Codex HACCP + PRPs/OPRPs within an ISO management system | Hazard Analysis and Risk-Based Preventive Controls (HARPC) |
| Hazard analysis clause/section | Clause 8.5.2 | 21 CFR 117.130 |
| Preventive control categories | CCP / OPRP | Process, sanitation, allergen, supply-chain, recall |
| Qualified person requirement | Food safety team leader (competence-based, no fixed credential) | Preventive Controls Qualified Individual (PCQI), FDA-recognized training or equivalent experience |
| Food fraud coverage | Built into clause 8.5.2 hazard analysis | Addressed separately (economically motivated adulteration guidance) |
| Intentional adulteration | Not a standalone requirement | Separate rule, 21 CFR Part 121 |
| Recognition path to GFSI | Not directly GFSI-recognized on its own | N/A — FSMA is not a GFSI benchmark |
| Geographic scope | Global | U.S. facilities and importers into the U.S. |
FSSC 22000: The Bridge That Already Exists
If ISO 22000 and FSMA are two dialects of the same language, FSSC 22000 is the certification scheme that was built to prove you're fluent in both. FSSC 22000 layers ISO 22000, a sector-specific technical specification such as ISO/TS 22002-1 for food manufacturing, and additional FSSC requirements covering food fraud mitigation, food defense, and allergen management on top of the base ISO 22000 standard. Because the Global Food Safety Initiative benchmarks FSSC 22000, certification against it is recognized by GFSI-aligned retailers worldwide — something ISO 22000 alone does not carry.
For a U.S.-based manufacturer, this matters directly: FSSC 22000's additional requirements on food defense and food fraud map closely to what Part 117 and Part 121 already require you to document, which means a well-built FSSC 22000 program produces most of the paperwork an FDA investigator will ask to see during a Part 117 inspection, and vice versa. I have seen clients build the food defense vulnerability assessment once, format it to satisfy FSSC 22000's additional requirement, and hand the same document to an FDA investigator asking about their Part 121 mitigation strategies. That's not a coincidence — it's what happens when you design the system around the hazard, not around the audit.
Building One System Instead of Two
The practical path I recommend to clients facing both obligations is straightforward, even if the documentation underneath it isn't:
- Start with a single hazard analysis worksheet that carries both classification schemes. For every hazard identified, record the CCP/OPRP determination alongside the FSMA preventive control category. This is a formatting decision, not extra work — you're running one hazard analysis, just tagging the output twice.
- Assign one qualified individual to own both roles where your operation allows it. The PCQI credential under Part 117 and the ISO 22000 food safety team leader role are not the same designation, but nothing prevents the same person from holding both, provided they've completed FDA-recognized PCQI training (commonly the standardized curriculum developed by the Food Safety Preventive Controls Alliance) and possess the competence ISO 22000 clause 7.2 requires of a team leader.
- Build your supplier program to satisfy the strictest requirement in the stack. If you import ingredients, that means FSVP's foreign supplier verification activities under 21 CFR Part 1 Subpart L become your baseline, and ISO 22000 clause 7.1.6's supplier control requirements and FSSC 22000's supply-chain requirements layer on top rather than requiring a separate file.
- Document verification and validation once, with dual references. Every internal audit finding, corrective action record, and management review minute should cite both the ISO clause and the CFR section it satisfies. When an FDA investigator or a certification auditor asks to see evidence, you pull the same record for either one.
- Treat food defense and food fraud as connected but distinct workstreams. They satisfy different clauses and different rules, and conflating them tends to produce a document that answers neither question well.
None of this is complicated in concept. It is tedious in execution, and the tedium is exactly where companies fall behind — not because the hazard analysis is hard, but because nobody assigned ownership of keeping two sets of references current when a process changes.
Frequently Asked Questions
Does ISO 22000 certification satisfy FDA FSMA requirements?
No. ISO 22000 is a voluntary certification with no legal standing under U.S. food safety law, and FDA does not accept ISO 22000 certification in place of Part 117 compliance. The two frameworks share a hazard-analysis structure closely enough that a well-built ISO 22000 system will already satisfy most of Part 117's documentation requirements, but a facility still must meet 21 CFR Part 117 independently, including the PCQI requirement, regardless of certification status.
Is FSSC 22000 the same as ISO 22000?
No. FSSC 22000 is a certification scheme built on top of ISO 22000, adding a sector-specific prerequisite program specification (such as ISO/TS 22002-1) plus additional FSSC requirements on food fraud, food defense, and allergen management. FSSC 22000 is recognized by the Global Food Safety Initiative; ISO 22000 alone is not GFSI-benchmarked.
Do I need a PCQI if I already have an ISO 22000 food safety team leader?
Yes, if your facility is subject to 21 CFR Part 117. The Preventive Controls Qualified Individual designation is a distinct regulatory requirement under 117.180, separate from the ISO 22000 food safety team leader competency requirement in clause 7.2. One person can hold both roles if they meet each set of qualifications, but the PCQI credential itself is not satisfied by ISO 22000 team leader status.
Does FSMA apply to facilities outside the United States?
Yes, indirectly. Foreign facilities that manufacture, process, pack, or hold food for consumption in the United States are subject to FDA facility registration and, for their U.S. importers, the Foreign Supplier Verification Programs rule at 21 CFR Part 1, Subpart L. Many foreign suppliers pursue ISO 22000 or FSSC 22000 certification specifically to give their U.S. customers documented evidence to support FSVP verification activities.
Which should a company pursue first, ISO 22000 or FSMA compliance?
FSMA compliance isn't optional for a covered U.S. facility, so it isn't really a choice — 21 CFR Part 117 compliance has to be in place regardless of certification plans. In my experience, the more useful sequencing question is whether to build the Part 117 food safety plan and the ISO 22000 hazard analysis as one integrated document from the outset, rather than building compliance first and retrofitting certification structure onto it later. The retrofit is always more expensive than the integration.
If you're weighing which certification path fits your supply chain and your customers' requirements, Certify Consulting's ISO 22000 team can walk through where your existing FSMA program already meets the standard's requirements — and where it needs a second look. For companies specifically targeting GFSI recognition, our FSSC 22000 consulting page covers how the additional requirements layer on top of what you've already built.
Last updated: 2026-08-24
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.