Certificates for Agricultural Suppliers to Israel
Phytosanitary, agrochemical, veterinary, food quality, kosher and environmental, six certificate families, three regulators, and a 2 to 6 month lead time.
HACCP is a management-system discipline, not a product certification. It is a method for identifying and controlling food safety hazards, codified by Codex Alimentarius in CXC 1-1969 and written into law in most markets, including the European Union under Regulation 852/2004 and the United States under the FSMA preventive controls rule. No authority certifies a product as HACCP compliant. What is sold as HACCP certification is certification of your management system against a scheme that embeds HACCP, meaning ISO 22000, FSSC 22000, BRCGS, IFS or SQF, and what retailers and importers actually specify is GFSI recognition, which ISO 22000 on its own does not carry.
Every other certification on this site attaches to a product: a sample is tested against a standard, a file is reviewed, and a document says that item may be sold in that market. HACCP does none of that. It attaches to a site and its processes, it certifies how you run them, and it says nothing about whether any individual product is legal in the destination. Buyers who arrive expecting a product certificate are the ones who discover late that they still need registration, labelling and a health certificate, and that none of those were ever in scope.
The legal obligation and the certificate are also separate things. Article 5 of Regulation (EC) 852/2004 requires food business operators in the European Union to put in place procedures based on HACCP principles; it does not require anyone to hold a certificate. In the United States the general obligation is the preventive controls rule at 21 CFR 117 rather than HACCP by name, with dedicated HACCP regulations surviving for seafood at 21 CFR 123 and juice at 21 CFR 120, and USDA FSIS running its own at 9 CFR 417 for meat and poultry. In all of them an inspector asks you to demonstrate the system. None of them asks to see a certificate.
The certificate exists because customers ask for it. A retailer cannot inspect four hundred suppliers, so it delegates that to an accredited certification body and writes the scheme into the supply agreement. That makes the certificate a commercial requirement sitting on top of a legal one, and the two can be satisfied and breached independently.
The Codex principles are conduct a hazard analysis, determine the critical control points, establish validated critical limits, establish monitoring, establish corrective actions, establish verification, and establish documentation and record keeping. Every consultancy site lists them. A list of the seven is a table of contents, not a plan, and an auditor treats it as one.
What the plan has to contain is specific to your process and cannot be borrowed. Which hazards are reasonably likely to occur in your raw materials and your layout. Why a given step is a critical control point and the next one is not, with the reasoning recorded. What the critical limit is and the scientific basis for it, which is the validation step and the one most often missing entirely. How often monitoring happens, by whom, and what they do when a limit is breached. Who verifies that the monitoring was actually performed, and how often the whole plan is reassessed.
A template HACCP plan downloaded and renamed fails at the second question. Auditors ask why, not what, and the answer has to come from the people who know the process.
HACCP assumes a hygienic operating environment already exists. That environment is the prerequisite programmes: cleaning and sanitation, pest control, maintenance and calibration, glass and hard plastic control, allergen management and segregation, personnel hygiene and training, water potability, waste handling, supplier approval, traceability and recall. In the ISO family they are specified in the ISO/TS 22002 series; BRCGS, IFS and SQF write them into their own clauses.
PRPs are where the non-conformities land, and there is a structural reason. The hazard analysis is written once by people who are paying attention. Prerequisite programmes have to be executed every shift by everyone, and they leave a paper trail that either exists or does not: a pest control report with open findings from three visits ago, calibration certificates expired, an allergen changeover with no verification swab, a supplier approved on a certificate that lapsed last year. The audit finds those in an afternoon.
There is a second effect worth knowing before the gap assessment. Weak prerequisite programmes push control upward, so hazards that a competent PRP would have handled routinely end up designated as critical control points instead. The plan then carries more CCPs than it should, each needing validated limits, monitoring and records, and the site has quietly given itself a heavier system to run forever.
A certification body, and only one that is accredited to ISO/IEC 17021-1 for the relevant scheme by a national accreditation body, and licensed by the scheme owner where the scheme requires it. Check the scope on the accreditation body register rather than the certificate: accreditation is granted per scheme and per sector, and a body accredited for ISO 22000 is not automatically accredited for BRCGS. A certificate from an unaccredited issuer is not wrong so much as it is not the thing your customer asked for, and it will be rejected on that basis.
A consultant cannot issue it, and the same organisation cannot both consult and certify. ISO/IEC 17021-1 bars a certification body from providing management system consultancy to a client it certifies and imposes a cooling-off period, normally two years, after any such work. The GFSI schemes enforce the same separation. That is why the honest shape of this engagement is that we build and rehearse the system and an independent body audits it, and any provider offering to do both is offering you a certificate your customer can dismiss.
From gap assessment to certificate is typically six to twelve months, and the binding constraint is almost never the audit. Gap assessment takes one to two weeks. Writing the plan and closing PRP gaps takes two to four months. Then the system has to run, because an auditor samples records, and a site cannot present three months of monitoring records it has only been keeping for three weeks. Internal audit and management review have to have happened at least once before the certification audit is bookable at all.
After that the cycle depends on the scheme, and the schemes genuinely differ. ISO 22000 and FSSC 22000 issue a three-year certificate with annual surveillance audits and a full recertification in year three, and FSSC requires at least one unannounced audit within each cycle. BRCGS, IFS and SQF do not work that way: they re-audit in full every year, and the certificate runs to the next audit due date rather than for three years. Under BRCGS the grade you achieve sets whether that interval is twelve months or six.
| Scheme | What it certifies | GFSI recognised? | Certificate and audit cycle |
|---|---|---|---|
| Codex HACCP (CXC 1-1969) | The method itself, applied to your process. It is a reference text, not a certifiable management system standard | No | Not applicable. Certificates issued against it are private attestations, not accredited management system certification |
| ISO 22000:2018 | Food safety management system built around HACCP, PRPs and interactive communication along the chain | No | Three years, with annual surveillance and recertification in year three |
| FSSC 22000 | ISO 22000 plus sector prerequisite programmes from the ISO/TS 22002 series plus scheme additional requirements | Yes | Three years, annual surveillance, at least one unannounced audit per cycle |
| BRCGS Food Safety | Site standard covering HACCP, the quality management system, site standards, product and process control and personnel | Yes | Full audit every year; certificate runs to the next audit due date, at six or twelve months depending on grade |
| IFS Food | Site standard written around retailer and brand-owner requirements, strongest on product and process control | Yes | Full audit every year; certificate valid roughly twelve months from the audit report |
| SQF Food Safety Code | Site code covering the food safety system, with a separate quality module available above it | Yes | Recertification audit every year; certificate valid twelve months |
GFSI recognition is what a retailer means when it says the certificate has to be GFSI approved, and it is the line ISO 22000 falls on the wrong side of. A site already certified to ISO 22000 usually moves to FSSC 22000 rather than starting again, because FSSC builds on it. All of these schemes are versioned and reissued every few years, so confirm the current issue before scoping.
Everything on the left is something to find before the project starts. Everything on the right is ours. Send what you have and we will tell you what is missing.
You provide
We provide
A certification body accredited to ISO/IEC 17021-1 by a national accreditation body for the specific scheme, and licensed by the scheme owner where one exists. A consultant cannot, and neither can the body that helped you build the system. ISO/IEC 17021-1 prohibits a certification body from certifying a client it has given management system consultancy to, with a cooling-off period normally of two years, and the GFSI schemes enforce the same separation. Verify the accreditation scope on the accreditation body register, because accreditation is granted per scheme rather than in general.
Six to twelve months is typical, and the audit is the short part. Gap assessment takes one to two weeks, writing the plan and closing prerequisite programme gaps two to four months, and after that the system has to run long enough to produce records, because auditors sample history rather than intent. Internal audit and management review must both have taken place before the certification audit can be booked. A site with functioning prerequisite programmes already in place can be at the faster end.
Legally, no. Regulation 852/2004 in the European Union and the preventive controls rule in the United States require you to operate a hazard-based system and to demonstrate it to an inspector; neither asks for a third-party certificate, and holding one does not discharge the obligation. The certificate is a commercial requirement that comes from customers, not regulators. Treat them as two separate obligations, because a certified site can still be non-compliant and a compliant site can still lose a listing for having no certificate.
No. ISO 22000 is a legitimate food safety management system standard but it is not GFSI recognised, so a buyer whose specification says GFSI will not accept it. The usual route is FSSC 22000, which takes ISO 22000, adds the sector prerequisite programmes from the ISO/TS 22002 series and a set of additional requirements, and is recognised. Because it builds on ISO 22000 rather than replacing it, an already certified site keeps most of the work it has done.
Phytosanitary, agrochemical, veterinary, food quality, kosher and environmental, six certificate families, three regulators, and a 2 to 6 month lead time.
Moroccan NM standards are largely harmonised with European ones, so ISO and CE do real work. Which certificates each sector needs, and four common mistakes.
Three authorities, Hebrew labelling that is mandatory rather than customary, and kosher status that is not legally required but commercially decisive.
One specialist owns your file from the first email to the registered certificate. Every one of them has recorded a briefing on their field.
Send the product name, HS code and technical data. You get back the applicable route, the document list and a timeline, before any commitment. For HACCP, the first reply says whether you need a certified system or a documented plan, and which scheme the buyer will accept.
Scoping is freeReply within one working day