ISO 22000:2018 Maturity · Food Safety Management System
Your ISO 22000 practices scored by theme, with a costed trajectory to the level you target.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
ISO 22000:2018 Maturity · Food Safety Management System
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One ISO 22000:2018 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism, a level, the level above, and the action that links them, is what turns an audit finding into a trajectory of progress.
Are CCP critical limits validated, and is monitoring data used to steer the process?
- N1
No justification for the critical limits is available. The values applied come from long standing practice, with no documented reference.
- N2
Critical limits appear in the HACCP plan with a bibliographic or regulatory reference, but no validation specific to the process has been carried out, and readings are filed without analysis.
- N3
Each critical limit rests on a documented validation tied to the process and product. Monitoring is recorded, deviations are addressed, and records are reviewed by management.
- N4
Monitoring data is analysed for trends by CCP and by line. Drifts are detected before a deviation occurs and trigger action on the process.
- N5
Critical limits are revalidated at every recipe, equipment or supplier change and during a planned periodic review, with traceability of revisions and their justifications.
Action to move from L2 to L3
Conduct, CCP by CCP, a process specific validation study (scale trials, challenge test data or external expert opinion), record the conclusion in the HACCP plan, and set up a monthly review of monitoring records signed off by the production manager.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon ISO 22000.
What this framework covers
ISO 22000:2018 is the international standard for food safety management systems. It applies to any operator in the food chain, from primary production to distribution, including suppliers of packaging, ingredients and services. Its structure combines three elements: the high level structure common to ISO management standards, the HACCP principles from Codex Alimentarius, and prerequisite programmes. The 2018 version introduces two interlocking PDCA cycles, one for the management system and one for the hazard control plan, along with analysis of the organisation’s context and interested parties’ expectations.
In practice, the challenge is not writing the manual but sustaining the system over time, across multiple sites and lines. Is the hazard analysis reviewed whenever a recipe, a supplier or a piece of equipment changes, or simply carried over unchanged year after year? Are the critical limits for CCPs backed by a validated justification, or by inherited practice? Has a withdrawal exercise been carried through to the end, timed, with the quantities actually recovered checked? The answer to these questions is not binary: it describes a level of control, and that level needs to be measured.
A common confusion is worth clearing up: ISO 22000 is not a GFSI recognised scheme on its own. It is FSSC 22000 that combines the standard, the prerequisite programmes from the ISO/TS 22002 series and additional requirements to achieve that recognition. Another point worth clarifying is the distinction between PRPs, operational PRPs and CCPs, introduced by the 2018 version: many hazard control plans classify as CCPs measures that actually belong to oPRPs, which adds monitoring burden without strengthening hazard control. The assessment surfaces these reasoning gaps before the auditor does.
A certification audit concludes with a nonconformity or a conformity: the requirement is met, or it is not. A maturity assessment answers a different question: what level of control does each practice sit at, and what specific action moves it up to the next level. A system can be conformant and fragile, documented but not owned by production teams. Measuring maturity lets you prioritise investment and compare sites within the same group on a common basis, both before and after certification.
The ISO 22000 framework is ready to use in Datamensio. You can adapt it to your scope: the AI adjusts themes, questions and levels to your sector, dairy, beverages, meat, packaging or logistics, or builds a tailored version from your existing manuals, HACCP plans and audit reports.
Reference standard: ISO 22000:2018
The themes assessed
Organisational context and interested parties
Determining the system scope, internal and external issues, customer and authority requirements, expectations of relevant interested parties.
Leadership and food safety policy
Management commitment, a formalised and communicated policy, roles and responsibilities of the food safety team, authority of the appointed manager.
Planning, risks and objectives
Identifying risks and opportunities for the system, measurable food safety objectives, planning of changes.
Resources, competence and documentation
Infrastructure and work environment, competence and training, use of external experts, control of documented information and records.
Internal and external communication
Communication along the food chain, exchanges with suppliers and customers, information flow up to the food safety team, notification of authorities.
Prerequisite programmes (PRPs)
Premises and personal hygiene, cleaning and disinfection, pest control, maintenance, water and air management, prevention of cross contamination, allergen management.
Hazard analysis and control plan
Product descriptions and flow diagrams verified on site, identification and assessment of biological, chemical, physical and allergen hazards, determination of oPRPs and CCPs, critical limits and their validation.
Monitoring, measurement and nonconformities
Monitoring plans for CCPs and oPRPs, calibration of measuring equipment, corrections and corrective actions, control of nonconforming products.
Traceability, withdrawals and recalls
Upstream and downstream traceability, batch identification, withdrawal and recall exercises, timeframes and recovery rates, management of emergency situations.
Verification, management review and improvement
Internal audits, verification of the hazard control plan, analysis of verification results, management review, system updates and continual improvement.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Does this assessment deliver ISO 22000 certification?
No. Certification is granted by an accredited body following an audit. The assessment measures the maturity of your system, documents the gaps, and produces the action plan that prepares you for that audit.
How does this differ from a mock audit?
A mock audit reproduces the logic of the certification audit and concludes with gaps, met or not met. The assessment places each practice on a five level scale and identifies the action that moves it up to the next level. The two are complementary: the assessment prioritises the workstreams, the mock audit checks readiness for the day itself.
Is ISO 22000 enough to meet a customer’s GFSI requirement?
No, ISO 22000 is not GFSI recognised on its own. Recognition comes through FSSC 22000, which adds the prerequisite programmes from the ISO/TS 22002 series and additional requirements. The ISO 22000 assessment forms the foundation of this approach, with the remaining gap concerning the additional requirements.
How long does the assessment take?
The short version can be completed in a single session by the quality manager. The full version involves production, maintenance, procurement and logistics working collaboratively, and typically spans one to two weeks, most of the time going into gathering evidence on the ground.
Can the framework be adapted to our activity?
Yes. You can change the questions, levels and themes, or add your own. The AI tailors the framework to your sector, dairy processing, beverages, meat, packaging or logistics services, and can build a version from your existing manuals and HACCP plans.
How do we compare multiple sites within the same group?
Each site completes its assessment against the same framework. Scores by theme can be compared across business units and over time. The AI groups common gaps into a consolidated roadmap, which avoids funding the same action ten times over.
Does the assessment also cover EU regulatory requirements?
ISO 22000 is a voluntary standard that does not replace Regulation (EC) No 852/2004 or the traceability obligations of Regulation (EC) No 178/2002. Dedicated frameworks exist for these texts, and a cross-site roadmap lets you cross reference them with ISO 22000 without duplicating actions.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.




