FSSC 22000 Version 7 was published in May 2026, and it comes with a hard stop. The last Version 6 audit may be conducted on 30 April 2027, and every certified site must then pass a full Version 7 audit at its next regular surveillance or recertification audit between 1 May 2027 and 30 April 2028. Certificates that are not upgraded are removed from the FSSC public register on 30 June 2028.
That is a compressed window for a scheme that has changed more than its version number suggests. This article walks through why the scheme changed, every Part 2 additional requirement clause by clause, the five changes that need new evidence rather than re-worded procedures, what changes about the audit itself, and a 90-day order of work. The free V6→V7 gap checklist at the end runs the whole transition as a tracked project.
A note on sources before we start. The clause-by-clause section paraphrases the FSSC 22000 Scheme Version 7.0 text (May 2026) in plain English; the dates, the comparison with Version 6 and the audit-process notes draw on the FSSC Foundation's published upgrade process and certification-body guidance. This is a planning aid, not the scheme. The Version 7 scheme documents are a free download from fssc.com — work from them, and from your licensed ISO 22000 and ISO 22002-x:2025 standards, before you close a gap.
Why Version 7 exists
Three outside forces drove the revision. The Global Food Safety Initiative updated its Benchmarking Requirements in 2024, and any scheme that wants continued retailer recognition has to re-align. The ISO 22002 series that defines prerequisite programmes was completely rewritten and republished in July 2025 as full international standards, and FSSC 22000 is built directly on them. And ISO 22000:2018 itself picked up Amendment 1 on climate change in early 2024. Add the growing weight of sustainability and food-waste expectations, and Version 6, published in 2023, was due for replacement.
The four dates that matter
- May 2026 — Version 7 published.
- 30 April 2027 — the last day a Version 6 audit may be conducted.
- 1 May 2027 to 30 April 2028 — the upgrade window: every site passes a full V7 audit at its next regular surveillance or recertification audit.
- 30 June 2028 — V6 certificates that were not upgraded are withdrawn from the public register.
Your site does not choose when to upgrade; the calendar does. Whichever surveillance or recertification audit falls inside the window becomes your upgrade audit. Certification bodies were required to inform certified organisations within three months of publication and to issue a new V7 contract or addendum, because audit duration is now calculated with a new formula. If you have not heard from your CB, ask.
The upgrade audit is a full audit against Version 7, not a delta audit that checks only the changes. It may be announced, or unannounced if that audit was already your unannounced one in the three-year cycle. FSSC does not prescribe additional duration for the upgrade, though a CB may add time. If you upgrade at a surveillance audit, the certificate keeps its original expiry date and a new certificate referencing V7 is issued.
The structural change: a new ISO 22002 family
This is the change that touches every site regardless of category.
Under Version 6, prerequisite programmes were audited against a sector technical specification: ISO/TS 22002-1:2009 for food manufacturing, -2:2013 for catering, -4:2013 for packaging, -5:2019 for transport and storage, -6:2016 for feed, and PAS 221 for retail. Version 7 replaces that with a two-layer model. The base layer is ISO 22002-100:2025, a single common PRP standard for the whole food, feed and packaging supply chain (it does not apply to primary production). On top of it sits a rewritten 2025 sector part: -1, -2, -4, -5, -6, and a new -7 for retail, wholesale and e-commerce. The old technical specifications remain valid for Version 6 audits only.
For food manufacturers, the practical question is what is new inside ISO 22002-1:2025:
- Site design must now consider both internal and external contamination sources.
- There is an explicit section on chemical contamination and a requirement for a system to manage recycled and re-used materials.
- Utilities maintenance and service activities are called out, and equipment requirements are strengthened.
- Personnel hygiene is expanded to include hazard awareness, controls for visitors and external providers, and more on facilities, clothing and behaviour.
- Two new sections cover food defence (16.2) and food fraud (16.3), which the Part 2 additional requirements now reference.
- Transport needs documented inspection and cleaning, dispatch gets its own requirements, and storage segregation is tightened.
- Two topics were removed: laboratory facilities, and product recall, which now lives only in ISO 22000.
Because the clause numbering changed throughout, every PRP procedure and the internal audit checklist need to be re-mapped. This is the largest single piece of transition work.
Version 7 also introduces a more granular sub-sub-category structure. Auditors must be qualified for your specific sub-sub-category, and the scope statement is re-checked at the upgrade audit. Mixed operations should confirm their category with the CB early.
The Part 2 additional requirements, clause by clause
2.5.1 Management of services and purchased materials. Laboratory analysis used to verify or validate parameters critical to food safety must come from a competent laboratory, internal or external, using validated methods and performed in accordance with the applicable requirements of ISO/IEC 17025 — accreditation is one way to demonstrate that, alongside proficiency testing and regulatory approval. An emergency procurement procedure is mandatory for categories BIII, C, D, I, FII, G and K, and animal-product categories (C0, CI, CIII, CIV) need a policy on the procurement of animals, fish and seafood subject to prohibited-substance control. The same manufacturing categories must run a review process for raw-material and finished-product specifications, with microbiological, physical, chemical and allergen limits based on scientific principles where legislation is silent. Category I gets criteria for recycled packaging inputs.
2.5.2 Product labelling and printed materials. Labels must comply with the legislation of the country of intended sale, including allergen and customer requirements; where product is unlabelled, the information needed for safe use must still reach the customer. Any claim — allergen, nutritional, method of production, chain of custody, raw-material status — needs validation evidence plus verification including traceability and mass balance. Artwork-control requirements that used to be aimed at packaging manufacturers now apply to any organisation that prints labels or printed materials in-house: master approval, change control, print-run sign-off, error detection, segregation of variants and reconciliation.
2.5.3 Food defence and 2.5.4 Food fraud. Both are now anchored to ISO 22002-100:2025 clauses 16.2 and 16.3 and aligned with GFSI 2024. Both add a competence requirement Version 6 did not have: the people performing the threat assessment (TACCP) or vulnerability assessment (VACCP) must be demonstrably competent. Plans must be integrated into the FSMS rather than kept as stand-alone documents. Brokers and traders (FII) must ensure their suppliers have documented plans.
2.5.5 Logo use. Marketing only — never on products, labels, packaging, certificates of analysis or conformance, or anything implying FSSC 22000 approves a product or service.
2.5.6 Management of allergens. The allergen list must cover raw materials and finished products. Where products with different allergen profiles share a production line or area, risk-based verification testing is explicitly required, so a validated clean-down alone no longer closes the topic. Precautionary "may contain" labelling is acceptable only after confirming a residual risk remains despite all controls; it cannot substitute for a control. All personnel need allergen awareness plus role-specific training. The plan must be reviewed at least annually and after a significant change, an allergen recall or withdrawal, or industry trends, using trended verification data as input. For feed and pet food the clause may be marked not applicable where the country of sale has no allergen legislation for it, unless an allergen claim is made.
2.5.7 Environmental monitoring. The risk-based programme for BIII, C, I and K now explicitly requires trend analysis, an annual review, and a defined set of triggers for adjusting the programme.
2.5.8 Food safety and quality culture. This is the clause that changes character most. Senior management still sets objectives across communication, training, employee feedback and engagement, and performance measurement. Version 7 adds that commitment must be demonstrable from all personnel with sufficient resources (2.5.8 a and c), that the plan needs documented targets and timelines, and that culture becomes a mandatory management-review input. Auditors will look for survey results, near-miss reporting, training completion and what people on the floor say and do — not a signed policy.
2.5.9 Quality control. A quality policy and objectives are formally required, quality parameters must align with finished-product specifications including product release, quality results become a management-review input, and quality falls inside the internal audit scope. Quantity control (unit, weight, volume) needs its own procedures and a calibration and verification programme for the equipment used. The practical item most sites miss is line clearance: start-up and changeover procedures must include controls that ensure labelling and packaging from the previous run have been removed from the line.
2.5.10 Transport, storage and warehousing. First-expired-first-out (FEFO) is required alongside FIFO. Bulk tankers need a risk-based cleaning plan, cleaning validation and supplier agreements on prior loads. C0 sites must define post-slaughter time and temperature limits.
2.5.11 Hazard control and cross-contamination. Foreign-matter management is formalised for every category except FII: a risk assessment that decides whether foreign-body detection equipment is needed and of what type (magnets, metal detectors, X-ray, filters, sieves), with documented justification if the answer is none; a documented procedure for the equipment chosen; and breakage-management controls for metal, ceramic and hard plastic. Category-specific additions cover packaging that provides a functional effect on food (BIII, C, I), lairage and evisceration inspection (C0), and ingredients with adverse animal-health potential (D).
2.5.12 PRP verification. Routine site inspections with a risk-based frequency and content, now extended to catering (E) and retail/wholesale (FI).
2.5.13 Product design and development. A documented procedure for new products and for changes to products or processes (BIII, C, D, E, F, I, K), covering the impact on the FSMS and hazard analysis including new allergens, the impact on the process flow, resource and training needs, and equipment and maintenance needs. Production and shelf-life trials with ongoing risk-based shelf-life verification apply to BIII, C, D and K, and ready-to-cook products need validated cooking instructions. Organisations that design primary packaging must consider four principles: containment and protection, shelf-life extension, minimising food loss and waste, and clear consumer communication — none of which may compromise food safety.
2.5.14 Traceability of edible carcass parts. New, and for C0 only: traceability of every edible part, including blood for human consumption, until the carcass is declared fit.
2.5.15 Equipment management. A hygienic-design purchase specification must exist before purchase or installation, and risk-based change management must produce documented commissioning evidence.
2.5.16 Food loss and waste. A documented policy and objectives for reducing food loss and waste in the organisation and its related supply chain, with clear, measurable targets and defined timelines; controls so that products donated to not-for-profits, employees or others are safe to consume; protection of surplus and by-products destined for animal feed from contamination; and legal compliance throughout. FSSC frames this as its contribution to SDG 12.3. Applies to all categories except I.
2.5.17 Communication requirements. Notify the CB within three working days of events affecting FSMS integrity, force majeure, public food-safety events, regulatory action, legal proceedings, fraud or corruption.
2.5.18 Multi-site organisations (BIII, E, F, G). The central function must resource and define the roles of management, internal auditors and technical reviewers, and run an internal audit programme that covers the system, the central function and every site at least annually with auditors independent of what they audit. Internal auditors must meet defined experience and education criteria and hold specific training: a 40-hour FSMS, QMS or FSSC 22000 lead auditor course for the internal lead auditor, a 16-hour internal auditor course for the other team members, and at least 8 hours of FSSC scheme training covering ISO 22000, the sector ISO 22002-x standard and the additional requirements. Audit reports get a technical review, and auditors and reviewers are calibrated annually. The certification body's own site-sampling formula, y = 20 + √(x − 20), sits in Part 3.
Five changes that need real work
If you only have capacity for five things before the upgrade audit, these are the five. Each needs evidence that most Version 6 systems do not yet hold.
Re-map every PRP. Buy ISO 22002-100:2025 and your sector part, build an old-to-new clause map, address the genuinely new topics (chemical contamination, recycling and re-use, visitors and contractors, utilities maintenance, dispatch, the food defence and fraud sections), renumber the PRP procedures and the internal audit checklist, and run one full internal audit against the new numbering before the CB arrives.
Allergen verification testing. Where allergen profiles share equipment or an area, define a risk-based testing programme with method (swab, rinse water or product test), frequency and acceptance limit. Keep validation (does the clean work?) separate from verification (is it still working?). Re-examine every "may contain" statement and record why a residual risk remains after all controls.
Culture, from policy to evidence. Convert the policy into a plan with numbers and dates. Use KPIs you already measure: hygiene-audit score trend, near-miss and hazard reports per month, training completion, gemba walk observations, a short annual survey. Show engagement at every level and put culture on the management-review agenda as a standing input. The auditor will spend more time talking to operators than reading the policy; make sure what they hear matches what you wrote.
Food fraud and defence competence. Name the people who perform the VACCP and TACCP and record what makes them competent. Integrate both plans into the FSMS with cross-references to supplier approval, hazard analysis and management review, and refresh the assessment against the current ingredient list and market conditions, because the auditor will check the date.
Food loss and waste objectives with numbers. Measure a baseline by stream for three months, set targets with dates, extend the policy to the supply chain, document surplus and donation controls, and link it to SDG 12.3 in a sentence. You need a number, a date and a monthly measurement — not a sustainability report.
What changes about the audit itself
Audit duration is now formula-driven (an ISO 22003-1:2022 Annex B base plus an FSSC allocation), which is why a new contract or addendum is coming. At least one surveillance audit per three-year cycle remains unannounced. Hybrid audits are formally embedded with a minimum of 50% on site and a maximum of 30 days between the remote and on-site parts, both against V7; brokers and traders may be audited fully remotely. Audit data is uploaded to the FSSC Assurance Platform within 28 days of the certification decision.
Version 7 also introduces an artificial-intelligence governance framework for the certification process: risk assessment, validation, monitoring, transparency and defined roles, with the principle that AI may assist but cannot replace human judgement or key decisions. It is aimed mainly at certification bodies, but if your own team uses AI to draft procedures or review data, have a one-page statement ready on how outputs are validated and who signs them off.
A 90-day order of work
- Weeks 1–2 — confirm your upgrade audit date and category with the CB; buy ISO 22002-100:2025 and your sector part; download the V7 scheme documents from fssc.com.
- Weeks 3–6 — PRP clause map and gap analysis; renumber procedures and the internal audit checklist.
- Weeks 5–8 — allergen verification testing programme; culture plan with KPIs; competence records for fraud and defence.
- Weeks 7–10 — food loss and waste baseline and targets; label and artwork control; equipment purchase specifications; foreign-matter risk assessment.
- Weeks 10–12 — full internal audit against V7; management review with the new inputs; close the gaps.
Then run the new system for at least a quarter before the audit, because the auditor wants records, not intentions. If you want the whole thing narrated, the free FSSC 22000 V7 masterclass walks this article's content in about eighteen minutes.
Six mistakes to avoid
- Treating the upgrade as a delta audit — it is a full audit.
- Leaving PRP procedures numbered to the 2009 technical specification.
- A culture plan with no numbers, or numbers with no dates.
- Using "may contain" as a control instead of a residual-risk decision.
- Waiting for the CB to tell you the audit date instead of asking.
- Closing gaps from a summary like this one instead of the scheme text.
Frequently asked questions
Is the upgrade audit longer than a normal surveillance audit?
FSSC does not add a fixed upgrade duration, but every V7 audit uses the new formula-driven duration calculation from 1 May 2027, so your CB will reissue the contract or add an addendum. Ask for the calculation — it is the first sign of how much of your site the auditor expects to see.
Can we be audited against V7 before 1 May 2027?
No. V6 audits run until 30 April 2027 and V7 audits start on 1 May 2027. Use the time to run the new system, not to wait for it.
Do we need to buy the ISO 22002 standards?
Yes — ISO 22002-100:2025 and your sector part (ISO 22002-1:2025 for food manufacturing). The FSSC scheme documents themselves are free from fssc.com, but the ISO standards are licensed documents and the auditor will expect you to hold them.
We are not a manufacturer — does this apply?
Yes. Every food chain category has a 2025 sector part, and the new ISO 22002-7:2025 opens a clearer FSSC pathway for retail, wholesale and e-commerce. The Part 2 requirements that are category-specific are marked as such in the gap checklist.
Our FSSC certificate expires inside the upgrade window — what happens?
Your recertification audit becomes the upgrade audit and is run in full against V7. If your next audit is a surveillance audit, the V6 certificate expiry date is kept and a new certificate referencing V7 is issued after a successful upgrade.
What does "demonstrable commitment from all personnel" actually look like?
Behaviour and data: hygiene-audit trends, hazard and near-miss reports raised by operators, training records with assessment results, survey or feedback results, and what people on the floor say when the auditor asks them why a control exists. A policy signed by the managing director is the starting point, not the evidence.
Free download: the FSSC 22000 V7 Gap Checklist
The checklist has 27 lines covering the framework change, every Part 2 clause and the audit-process changes. Each line gives the V6 position, what changed, the evidence the auditor will ask for and a priority, with status drop-downs, owners, target dates, overdue flags and a readiness score that calculates itself. Enter your email below and it is on its way.
Qlause is an independent training and templates provider. It is not an FSSC-licensed certification body or training organisation, and this article is not a substitute for the scheme documents. Sources: FSSC 22000 Scheme Version 7.0, Part 2 (May 2026); FSSC Foundation — Version 7 Upgrade Process and Version 7 key changes; ASC Food Safety — the complete V6→V7 change guide; Passionfruit, Bureau Veritas, Mérieux NutriSciences and SGS transition guides; IFSQN — ISO 22002-1:2025 change summary.