Login Register

Access the GIFSQ Portal

Select your user type to log in or register a new account.

Student Portal

Access your food safety courses, certifications, and exams.

Instructor Portal

Manage courses, view student submissions, and grade quizzes.

Company Portal

Manage corporate setup, view employee logs, and access QA services.

A buyer emails: “Please confirm your GFSI certification.” Your plant runs solid HACCP, your people are trained, your audits are clean — but no certificate with one of those three names hangs on the wall. Months of work lie ahead, and the first decision is which scheme to pursue. Choose wrong and you spend a year building a system your customers don’t recognize.

SQF, BRCGS, and ISO 22000 are the three names that come up most. They aren’t interchangeable. Here’s what each one is, where each wins, and how to pick.

First: what GFSI is (and isn’t)

GFSI — the Global Food Safety Initiative — certifies nobody. It benchmarks certification programs: scheme owners submit their standards, and GFSI judges whether they meet its benchmarking requirements. Schemes that pass are “GFSI-recognized.” When buyers ask for “GFSI certification,” they mean certification under a GFSI-recognized scheme.

SQF and BRCGS both hold that recognition. ISO 22000, on its own, does not — a distinction that trips up plenty of companies. More on that below.

SQF: the North American workhorse

The Safe Quality Food program is run by SQFI, the Safe Quality Food Institute, a division of FMI, the US food industry association. Developed in Australia, it took root most strongly in North America, where it’s now widely used by manufacturers supplying retail and foodservice.

The current edition is SQF Edition 9. The code covers the full supply chain — primary production through manufacturing, storage, and distribution — combining HACCP-based food safety and quality elements in one system. Audits score sites on a percentage scale, and the scheme aligns tightly with GFSI benchmarking requirements.

SQF fits when your customers are North American retailers, manufacturers, or foodservice buyers, or when you export into the US and Canadian markets. Its farm-to-fork scope also suits companies wanting one scheme across multiple supply-chain steps.

BRCGS: the retail-driven standard

BRCGS — Brand Reputation Compliance Global Standards — began in the UK, developed by British retailers who wanted a single audit their suppliers could pass instead of a dozen different retailer inspections. That retail DNA still defines it: prescriptive, audit-focused, and built around what supermarket technical teams want to see.

The current version is Issue 9. Audits grade sites AA, A, B, or C, with unannounced audit options available — the top AA grade requires the unannounced route. GFSI-recognized like SQF, BRCGS dominates wherever UK and European retail supply chains run: Britain, much of continental Europe, the Middle East, and global private-label sourcing.

Choose BRCGS when you supply UK or European retailers, or when buyer specifications name it outright. If British supermarkets sit in your customer list, this is usually the expected certificate.

ISO 22000: the management-system standard

ISO 22000 comes from ISO, the International Organization for Standardization in Geneva — the same body behind ISO 9001. The current version is ISO 22000:2018. It’s a food safety management system standard: it describes how to build and run the system (management commitment, hazard analysis, prerequisite programs, continual improvement) without prescribing every detail.

That flexibility is the point — and the catch. ISO 22000 applies to any organization in the food chain, integrates cleanly with other ISO management standards, and is widely accepted in government tenders and institutional buying. But standalone, it is not GFSI-recognized. A buyer demanding GFSI-recognized certification won’t accept an ISO 22000 certificate alone.

Yeah, but actually: the FSSC 22000 bridge

Read this part carefully, because it’s where companies get confused. FSSC 22000 — run by the Foundation FSSC in the Netherlands, currently at Version 6 — is built directly on ISO 22000:2018. It takes the full ISO 22000 standard, adds sector-specific prerequisite programs (ISO/TS 22002-1 for manufacturing) plus extra scheme requirements — food fraud vulnerability assessment, food defense, allergen management, environmental monitoring — and submits the package for GFSI benchmarking. FSSC 22000 passes. It’s GFSI-recognized; plain ISO 22000 isn’t.

The practical consequence: if you’ve built an ISO 22000 system and a customer starts demanding GFSI recognition, you don’t start over — you upgrade to FSSC 22000. Most of the work is already done, which is why the migration path is well traveled.

Side-by-side comparison

SQF BRCGS Food Safety ISO 22000
Run by SQFI / FMI (US) BRCGS (UK) ISO (Geneva)
Current version Edition 9 Issue 9 2018
GFSI-recognized Yes Yes No — FSSC 22000 (built on it) is
Audit grading Percentage score AA / A / B / C grades Pass / fail
Audit frequency Annual Annual, announced or unannounced Annual surveillance, 3-year recertification
Geographic strength North America, Asia-Pacific UK, Europe, Middle East Global, especially ISO-system users
Best for US/Canada market access, farm-to-fork scope UK/EU retail suppliers Government tenders, ISO-integrated companies
Prescriptiveness Moderate High (retail-driven detail) Low (management-system framework)

What the audit feels like

The three audits run differently, and the difference matters if your team has to live through one.

A BRCGS audit reads like an inspection. The auditor works clause by clause through detailed, prescriptive requirements — senior management commitment, the food safety plan, site standards, process control — checking each against what they see on the floor. Expect depth over breadth: they’ll follow one product trail end to end and pull every record it touches. Unannounced audits are a real option here, and the top AA grade requires one, so some sites live in permanent audit-readiness.

An SQF audit scores. Sites earn a percentage, and the scoring has teeth — a critical nonconformity can sink the result regardless of how clean everything else looks. The food safety fundamentals carry the weight; the quality elements sit on top for sites pursuing the quality code.

An ISO 22000 audit runs in the standard ISO two-stage pattern: a Stage 1 document review, then the Stage 2 on-site assessment, with annual surveillance and full recertification every three years. Less theatrical than a retail audit, more focused on whether the management system actually steers decisions — auditors will ask how management review changed something real, not just whether the meeting happened.

How to choose

Start with your customers, not your preferences. The decision tree is short.

A specific buyer names a scheme? Get that one. Arguing costs more than complying.

Selling into North American retail or foodservice? SQF is the default expectation.

Supplying UK or European supermarkets? BRCGS, in most cases.

Government contracts, institutional buyers, or an existing ISO 9001 system? ISO 22000 fits — and if GFSI recognition enters the picture later, FSSC 22000 is the upgrade path.

Exporting to several retail markets at once? Ask your three largest buyers what they accept. One GFSI-recognized certificate often satisfies all of them. That’s the entire point of benchmarking.

On cost: none of the schemes publish fixed prices. Licensed certification bodies quote in auditor man-days, which scale with headcount, product lines, processes, and sites. Get two or three quotes — and remember the cheapest auditor is rarely the best value when a failed audit means paying for a re-audit.

Can you hold more than one?

Yes, and some companies do — typically FSSC 22000 (or ISO 22000) alongside a retailer-driven scheme. But each additional certificate means more audit days, more fees, and more corrective-action cycles. One well-maintained certification beats two neglected ones. Add a second scheme when a contract requires it, not before.

—

Ask your buyers what they require before you build anything. The most expensive certification is the one your customers don’t recognize.