One Step BackKnow where you stand
Standards

FSSC 22000 v7: the biggest change is in a document you have to buy

I work in quality in UK food manufacturing. This is information, not advice. Always check the source document before making decisions that matter.

Version 7 was published in May 2026 with a twelve month transition. You can download the scheme document from the FSSC website for nothing, read the eighty pages, and come away with a reasonable idea of what changed.

You would still be missing most of it.

FSSC gives five reasons for the revision: incorporating the new ISO 22002-x series on prerequisite programmes, aligning with the GFSI benchmarking requirements 2024, strengthening requirements supporting the Sustainable Development Goals, providing a more defined structure for the division of food chain categories, and editorial improvement.

The first of those is doing far more work than the others, and it is the one that costs money.

Two standards where there used to be one

Version 6 pointed each food chain category at a sector prerequisite programme drawn from the ISO/TS 22002-x technical specifications and, for some categories, the BSI publicly available specifications. Category C manufacturers worked to ISO/TS 22002-1.

ISO restructured the whole series and published it in July 2025. Both the technical specifications and the BSI documents are gone.

Look at Table 1 in version 7. Almost every category now lists two: ISO 22002-100:2025 alongside a sector-specific standard.

ISO 22002-100:2025 is Part 100, "Requirements for the food, feed and packaging supply chain". It is the cross-sector layer that now sits underneath everything. For food manufacturing in categories C0, CI, CII, CIII and CIV, you need it plus ISO 22002-1:2025, Food manufacturing. Catering pairs it with Part 2. Packaging manufacturing with Part 4. Transport and storage with Part 5. Feed with Part 6. Retail and wholesale with Part 7.

Only subcategory FII, brokering and trading without physical handling, is exempt from prerequisite programmes entirely.

These are published standards bought from national standards bodies, not free downloads. Your gap analysis needs both of them, they are new documents rather than revisions you can skim, and you cannot do the work without them.

Where food defence and food fraud went

This is the part worth sitting up for.

In version 6, food defence and food fraud mitigation were FSSC additional requirements standing on their own. They told you to do a threat assessment, do a vulnerability assessment, and have plans.

In version 7 they read differently. Clause 2.5.3 begins: in addition to ISO 22002-100:2025, clause 16.2. Clause 2.5.4 begins: in addition to ISO 22002-100:2025, clause 16.3.

The substance has moved into the ISO standard. What FSSC now adds on top is narrower and sharper:

  • The threat assessment, the vulnerability assessment and both plans must be developed and maintained by personnel with appropriate knowledge and competence.
  • The plans must be implemented and supported by the food safety management system, comply with applicable legislation, cover the processes and products in scope, and be kept up to date.
  • For brokers and traders in subcategory FII, you must also ensure your suppliers have plans in place.

So if you want to know what your food defence obligation actually is under version 7, the scheme document will not tell you. It tells you what FSSC adds. The requirement itself is in a standard you have to purchase.

Note the competence requirement, incidentally. It is the same theme as the BRCGS position statements that landed this month: the person doing the vulnerability assessment now has to be demonstrably capable of doing it.

What actually changed in the FSSC requirements

Plenty, and some of it is more demanding than the summaries suggest.

Food loss and waste, clause 2.5.16. All categories except packaging. A documented policy and objectives setting out your strategy to reduce food loss and waste in your organisation and the related supply chain, and the objectives must be supported by clear and measurable targets with defined timelines. Plus controls over donated product to make sure it is safe to consume, and management of surplus and by-products going to animal feed.

A policy with measurable targets and timelines is not a statement of intent. It is an auditable commitment, and this is the clause where the sustainability push becomes a real requirement rather than a preamble.

Quality control, clause 2.5.9. Now all food chain categories. A quality policy and quality objectives. Quality parameters in line with finished product specifications for every product or product group in scope, including product release addressing quality control and testing. Analysis and evaluation of those results as an input to management review. Quality elements inside the scope of internal audit. Quantity control for unit, weight and volume with a calibration and verification programme.

And a specific one that will find things: line start-up and change-over procedures must include controls ensuring labelling and packaging from the previous run have been removed from the line.

Equipment management, clause 2.5.15. A documented purchase specification addressing hygienic design, legal and customer requirements and intended use, and the supplier must provide evidence of meeting that specification before installation. Plus a risk-based change management process for new or modified equipment, documented, including evidence of successful commissioning.

If your engineering team currently buys equipment and the technical team sees it when it arrives, that is now a nonconformity waiting to happen.

Allergen management, clause 2.5.6. Where more than one product with different allergen profiles is made in the same production area, verification testing is required at a risk-based frequency, with surface testing, air sampling and product testing all named. Precautionary labels may only be used where the risk assessment identifies cross-contamination as a residual risk despite effective controls, and applying a warning label does not exempt you from control measures or verification testing. Annual review, with verification data trended and used as an input.

Environmental monitoring, clause 2.5.7, applies to BIII, C, I and K. The review triggers are worth reading in full, because one of them is counterintuitive: you must review the programme when no positive testing results have been obtained over an extended period of time. A clean sheet is not evidence that the programme works. It may be evidence that you are swabbing the wrong places.

Foreign matter, clause 2.5.11(d). A risk assessment determines the need and type of detection equipment, and where you decide none is necessary, the justification must be maintained as documented information. Deciding you do not need a metal detector is now a documented decision rather than an absence.

Packaging design, clause 2.5.13(g). Organisations that design primary packaging must consider effective containment and protection, preserving and extending shelf life, minimising food loss and waste, and clear consumer communication on handling, storage and preparation. FSSC says these are the Save Food Packaging design principles, developed by the Australasian Institute of Packaging and globalised by the World Packaging Organisation. Worth knowing the provenance, because it tells you where to look for guidance on what good looks like here.

Culture, clause 2.5.8, is food safety and quality culture. Objectives, a documented plan with targets and timelines, and it goes into management review and continuous improvement.

Laboratories, clause 2.5.1(a). Where analysis is used for verification or validation of parameters critical to food safety, it must be done by a competent laboratory and performed in accordance with the applicable requirements of ISO/IEC 17025. Accreditation is given as an example of demonstrating competence, but the analysis itself has to meet 17025.

Things that changed around the audit rather than in it

Worth knowing even though they sit in the certification body's half of the scheme.

At least half of total audit duration must be spent auditing operational food safety planning and the implementation of prerequisite programmes and control measures, including time on the floor, traceability exercises and the related records. Development, training, internal audit and management review do not count toward that half.

No reductions to the calculated audit duration are allowed beyond the specific exemptions listed. For categories C, D and K the minimum audit duration is never less than two days.

Multi-site certification with sampling is only available for BIII, catering, retail and wholesale, brokering, and transport and storage. Manufacturing sites are not eligible.

The scheme does not allow opportunities for improvement. A finding is a nonconformity or it is nothing.

Auditors rotate out after two three-year cycles, or six years if they started mid-cycle.

The artificial intelligence clause, which is not about you

Several summaries of version 7 list artificial intelligence governance among the new requirements, in a way that suggests sites need an AI policy. Read the clause and it says the opposite.

Section 9 of Part 3 opens by stating that where artificial intelligence is being used in the certification process, the certification body shall meet the requirements that follow. It sits in the part of the scheme governing certification bodies. The obligations are theirs: a defined AI governance framework meeting principles of fairness, accountability, reliability, accuracy, transparency, confidentiality and security; a documented risk assessment for each AI system covering development, deployment and use; testing and validation for applicability, accuracy, repeatability and safety before deployment, with continuous monitoring afterwards.

Two provisions in it are worth knowing as a certified site, because they are effectively rights rather than duties.

Artificial intelligence may be used as an aid or support tool, but cannot replace human judgment, oversight and key decision-making activities, and specifically shall not replace the certification functions defined in Annex C, Table C.1 of ISO 22003-1:2022. Nobody's certificate is being decided by a model.

And its use must be transparent, explainable in terms of scope and applicability, and communicated to relevant stakeholders, explicitly including the certified organization. If your certification body is using artificial intelligence anywhere in your audit or certification process, you are entitled to be told. Most sites will not think to ask. It is a reasonable question at your next contract review.

The transition

Twelve months, and the dates are firmer than most of the coverage suggests.

Audits against version 6 are permitted until 30 April 2027. Upgrade audits against version 7 are conducted from 1 May 2027 until 30 April 2028.

Note what that means in practice. The transition period is not a year in which you can upgrade whenever you like. It is a year in which you prepare, followed by a separate year in which the upgrade audits happen. Your certification body has to be ready too, and every certified site in the scheme is booking into the same window.

The scheme document itself does not carry these dates. Part 3 says only that the Foundation will issue instructions when upgrade audits are required. The detailed requirements sit in a separate document, Upgrade Process Requirements V7, published alongside the scheme, and that is what to read before booking anything.

The Monday morning list

  1. Find your category in Table 1 and write down both normative standards it now names. For most food manufacturers that is ISO 22002-100:2025 and ISO 22002-1:2025.
  2. Get a budget line for buying them. You cannot do a gap analysis against a standard you have not read, and this is the step most likely to stall the whole project.
  3. Read clauses 16.2 and 16.3 of ISO 22002-100:2025 first. Your food defence and food fraud requirements now live there, and the scheme document only tells you what FSSC adds on top.
  4. Write down who does your threat assessment and vulnerability assessment, and what makes them competent. Same evidence the BRCGS position statements now ask for, so do it once.
  5. Draft the food loss and waste policy early. It needs measurable targets and timelines, which means it needs data you may not currently collect.
  6. Take the equipment purchase specification requirement to your engineering lead this month, not next year. It changes a purchasing process, and purchasing processes move slowly.
  7. Put the two dates in the plan now: version 6 audits stop on 30 April 2027, upgrade audits run 1 May 2027 to 30 April 2028. Book early. Everyone certified to this scheme is booking into the same window, and your certification body has to retrain its auditors on two new standards before it can deliver any of them.
Share LinkedIn
Know where you stand

Briefings on what's coming, how to be ready for it, and what it actually means for your site. Free.