FSSC 22000 - Food Safety System Certification
FSSC 22000: Additional Requirements (Food Defense + Food Fraud + Allergen + Environmental + Culture)

FSSC 22000 - Food Safety System Certification FSSC-Additional-Requirements-v6: FSSC 22000 Additional Requirements v6 (Food Defense + Food Fraud + Allergen + Environmental + Culture)

FSSC 22000 v6 Additional Requirements - FSSC-specific scheme additions beyond ISO 22000 + ISO/TS 22002-x (publicly available + downloadable from fssc.com). KEY REQUIREMENTS: (1) FOOD SAFETY AND QUALITY CULTURE - documented program with leadership behaviour + training + recognition + competence + retention + 4-pillar approach (Vision + Values + Behaviour + Performance) + measured via culture surveys + KPIs; (2) FOOD DEFENSE (TACCP - Threat Assessment Critical Control Points) - threat identification + threat assessment + critical control points + mitigation + monitoring + verification + against intentional + ideologically + economically motivated tampering + insider threats + cyber-attack on food safety systems; (3) FOOD FRAUD MITIGATION (VACCP - Vulnerability Assessment Critical Control Points) - vulnerability assessment per material + supplier + economic incentive + opportunity + adulteration history + mitigation + verification + supplier-management integration; (4) ALLERGEN MANAGEMENT - identification + risk assessment + segregation + cleaning validation + labelling + employee training + incident management + Codex + FDA + EU 1169/2011 alignment; (5) ENVIRONMENTAL MONITORING - microbiological monitoring of production environments + Listeria + Salmonella + Cronobacter + other pathogens + zoning + sampling plan + trending + corrective action; (6) PRODUCT LABELLING + CLAIMS - compliance with applicable regulations + nutritional + allergen + country-of-origin + organic + halal + kosher + others; (7) STORAGE + TRANSPORT - sanitary conditions + temperature + segregation + cross-contamination prevention; (8) FSSC LOGO USE; (9) HAZARD CONTROL + CROSS-CONTAMINATION; (10) MANAGEMENT OF SERVICES + PURCHASED MATERIALS supplier qualification; (11) PERSONAL HYGIENE + TRAINING; (12) v6 NEW: QUALITY CULTURE + LOSS REDUCTION + (anticipated v6.1) cybersecurity + AI use.

What else in your programme already covers this

This control maps to 87 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 3.1 Physical Security
  • 3.11 Encrypt Sensitive Data at Rest
  • 3.2 Establish and Maintain a Data Inventory
  • 3.4 Enforce Data Retention
  • 3.1 Physical Security
  • 3.2 Establish and Maintain a Data Inventory
  • 3.4 Enforce Data Retention

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO/IEC 29134:2023 · 3 controls

  • 2.1.3 Food Safety and Quality Culture
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

SWIFT CSCF · 3 controls

  • SWIFTCSCF-3 Physically Secure the Environment (Objective 3)
  • SWIFTCSCF-4 Prevent Compromise of Credentials (Objective 4)
  • SWIFTCSCF-7 Plan Incident Response (Objective 7)

API 1164 · 2 controls

ISO/IEC 27014:2020 · 2 controls

  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process

PCI DSS 4.0 · 2 controls

  • 2.1.1 All security policies and operational procedures that are identified in Requirement 2 are: • Documented. • Kept up to date. • In use. • Known to all affected parties
  • 2.1.2 Roles and responsibilities for performing activities in Requirement 2 are documented, assigned, and understood
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • 58.49 Laboratory Operation Areas
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • 8.5 Control effectiveness review
  • 4.3.1 Risk Assessment and Impact Analysis

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

ISO 13485 · 1 control

  • 8.5 Control effectiveness review

ISO 27005 · 1 control

  • 8.5 Control effectiveness review

ISO/IEC 27003:2017 · 1 control

  • 8.5 Control effectiveness review

ISO/IEC 27031:2011 · 1 control

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

India DPDP Act · 1 control

  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

South Korea PIPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 87 it maps to, and the evidence behind each claim, over MCP and REST.