Spring special ends 15 September: 30% off qualifying HACCP and FSSC 22000 courses. Code SPRING30 at checkout. See qualifying courses

HACCP, TACCP and VACCP: Which Assessments Each Certification Scheme Actually Requires

Home / Guides / Which assessments does your scheme require?

HACCP Β· TACCP Β· VACCP

You need three separate assessments, not one document with three headings. HACCP for accidental hazards, TACCP for deliberate harm and VACCP for fraud. This guide maps them clause by clause across FSSC 22000, BRCGS, SQF, IFS and GFSI, with the two transitions that are live right now: FSSC Version 7, published May 2026, and SQF Edition 10, effective 1 September 2026.

Key facts

  • FSSC 22000 V7 published May 2026, food defence 2.5.3, food fraud 2.5.4
  • FSSC V6 sunset audits permitted until 30 April 2027
  • FSSC upgrade window 1 May 2027 to 30 April 2028
  • BRCGS Food Issue 9 food defence 4.2, food fraud section 5.4
  • BRCGS Issue 10 in development, no publication date
  • SQF Edition 10 effective 1 September 2026, 2.7.1 and 2.7.2
  • IFS Food v8 food fraud 4.20, food defence 4.21, neither a knock out
  • GFSI Benchmarking Requirements version 2024, dated 13 November 2024

Three questions, three assessments

The reason these cannot be merged is not bureaucratic. It is that each one asks a question the others cannot answer, and the answers come from different people.

HACCP TACCP VACCP
The question What can go wrong by accident, and where do we control it? Who would want to harm us, and how would they get in? Who would want to make money out of us, and how would the chain let them?
Intent None assumed To cause harm To gain economically
Scored on Likelihood and severity of a hazard Attractiveness, vulnerability of the access point, impact Opportunity across seven vulnerability factors, and severity
Who is in the room Process and technical Engineering, HR, IT, security, production, quality Procurement, technical, quality, logistics, legal
Controls look like Critical control points and limits Deter, deny, detect, respond Preventive and detection measures on the supply chain
Method reference Codex HACCP principles PAS 96:2026 ISO 22002-100:2025 clause 16.3

A HACCP plan will never find a person who intends to cause harm, because HACCP assumes nobody is trying. That single sentence is why TACCP exists, and the same logic, pointed at money instead of harm, is why VACCP exists.

FSSC 22000, and the version change most material has not caught up with

FSSC has moved, and the move changed what you cite. Version 7.0 was published in May 2026. Version 6 audits are permitted until 30 April 2027, and upgrade audits against Version 7 run from 1 May 2027 to 30 April 2028. Both versions are therefore live in the market right now, and you may be audited against either.

Version 6 Version 7
Food defence 2.5.3 2.5.3
Food fraud 2.5.4, with sub-clauses 2.5.4.1 vulnerability assessment and 2.5.4.2 mitigation plan 2.5.4, a single clause with lettered points, opening with the words in addition to ISO 22002-100:2025, clause 16.3
Where the method lives In the clause itself In ISO 22002-100:2025 clause 16.3
Competence Implied Explicit: the assessment and plan must be developed and maintained by personnel having appropriate knowledge and competence
Suppliers Food chain category FII organisations must ensure suppliers have a food fraud mitigation plan Same requirement, worded as food chain subcategory FII

The trap in Version 7 is quiet. Clause 2.5.4 no longer contains the requirement to conduct a vulnerability assessment at all. If you audit or train from 2.5.4 alone under Version 7, you will miss the requirement, because it now lives in ISO 22002-100:2025 clause 16.3 and 2.5.4 carries only the additions.

Both transitions, taught properly

The two coordinator courses are built on the current position rather than the position of two years ago: FSSC Version 6 and Version 7 side by side, SQF Edition 10 with the Edition 9 differences for sites still transitioning, and BRCGS and IFS mapped alongside.

Food Defence Coordinator Course, R1750, 10 hours
Food Fraud Coordinator Course, R1750, 8 hours
Self-paced, graded practical marked by a person, no VAT charged.

BRCGS Global Standard Food Safety Issue 9

Issue 9 is the current issue. Issue 10 is in development and has no publication date and no audit start date, so nobody can be audited against it and nobody can honestly sell you Issue 10 training today.

Food defence sits at clause 4.2. Food fraud sits in section 5.4, product authenticity, claims and chain of custody. Two things about section 5.4 are worth knowing before you build for it.

First, the vulnerability assessment has to consider a defined set of factors. BRCGS drafting names historical evidence of substitution or adulteration, economic factors that make adulteration or substitution more attractive, ease of access to products, the sophistication of routine testing to identify adulterants, and the nature of the product. If your assessment cannot show all five being considered, expect a question.

Second, BRCGS confines section 5.4 to food raw materials and ingredients. Its own published frequently asked questions state that packaging does not need to be considered under section 5.4. That is narrower than IFS, which explicitly requires packaging.

A note on sub-clause numbers. Numbering inside 5.4 is easy to get wrong, the standard is not published free, and practitioners routinely quote each other’s mistakes online. If you are writing a procedure or an internal audit checklist, open your own licensed copy and read section 5.4 before you commit a number to paper. In a cross reference table, section 5.4 on its own is both correct and safe.

SQF Edition 10

Edition 10 is current, with an effective date of 1 September 2026, so most sites are only now moving onto it. Food defence remains at element 2.7.1 and food fraud at clause 2.7.2, sitting directly alongside each other in Module 2, System Elements.

The Edition 10 food fraud wording requires that the methods, responsibility and criteria for identifying the site’s vulnerability to food fraud, including susceptibility to inputs substitution, finished product mislabelling, dilution or counterfeiting, shall be documented, implemented and maintained, and that a food fraud mitigation plan shall be developed and implemented specifying how the identified vulnerabilities are addressed.

Edition 9, which sites are transitioning off, carried four sub-clauses under 2.7.2: identify vulnerability through all inputs, mitigate what you identify, provide instruction on mitigation strategies covering risk identification, receiving procedures, approved suppliers and access to raw materials, ingredients, labels and finished product, and review the plan documentation annually.

Do not delete your food fraud awareness training because a sub-clause disappeared. Edition 9 had a standalone training sub-clause and Edition 10 condenses the section. The requirement has not gone away, it will be assessed through the general competence and training clauses, and the auditor will still expect goods receiving and procurement to know what they are looking for.

IFS Food version 8

Food fraud is section 4.20 and food defence is section 4.21, so the pair sit next to each other the way they do in FSSC. The four requirements in 4.20 cover clearly defined responsibilities held by people with appropriate specific knowledge, a documented vulnerability assessment including its assessment criteria, a documented mitigation plan referencing the assessment and covering testing and monitoring methods, and review at least once within a twelve month period or whenever significant changes occur.

Three things make IFS the one to build to.

  • It has the widest scope. The assessment must cover all raw materials, ingredients, packaging materials and outsourced processes, where BRCGS puts packaging outside section 5.4.
  • It is the only one of the four that names a review interval in the requirement itself, at twelve months.
  • None of the 4.20 requirements is a knock out. IFS Food version 8 has ten knock out requirements and food fraud is not among them. Worth knowing accurately in both directions: not a knock out, and still a requirement you will be written up against.

GFSI sits above all of them

GFSI does not certify anybody. It benchmarks the schemes, so its requirements tell you what every benchmarked scheme has to demand of you. The current version is the Benchmarking Requirements version 2024, dated 13 November 2024.

Note the vocabulary shift: GFSI now says food fraud management plan rather than mitigation plan. Its food safety management requirements ask for a documented food fraud management plan specifying the measures implemented to mitigate the public health risks from the identified vulnerabilities, for that plan to be developed, implemented, verified, maintained and reviewed regularly or when a new vulnerability is established, and for appropriate knowledge and expertise to be used in developing and maintaining it.

That last one is the useful one. Every scheme now requires competence for this work and not one of them prescribes a course, a syllabus, a competency level or a number of hours. The requirement is real and how you meet it is left to you and your certification body, which is why a training record specific to the method is worth more in that file than a general food safety certificate.

The one page map

Scheme Food defence, TACCP Food fraud, VACCP Worth knowing
FSSC 22000 Version 7 2.5.3 2.5.4 plus ISO 22002-100:2025 clause 16.3 Current from May 2026. Explicit competence requirement.
FSSC 22000 Version 6 2.5.3 2.5.4.1 and 2.5.4.2 Auditable to 30 April 2027.
BRCGS Food Safety Issue 9 4.2 Section 5.4 Packaging outside 5.4. Issue 10 not published.
SQF Edition 10 2.7.1 2.7.2 Effective 1 September 2026, fewer sub-clauses than Edition 9.
IFS Food version 8 Section 4.21 Section 4.20 Widest scope, twelve month review named, neither is a knock out.
GFSI Benchmarking v2024 Food defence requirements FSM 8 series Sets what every benchmarked scheme must require. Calls it a management plan.

Build one threat assessment and one vulnerability assessment, each to the widest scope, and put a one page cross reference table at the front of each mapping it to every scheme you are audited against. It is fifteen minutes of work and it changes the tone of an audit, because an auditor who can see where your single assessment satisfies each clause spends their time verifying rather than searching.

Where sites actually lose marks

Across the assessments we are asked to review before an audit, the same faults come up.

  • A risk register wearing a different title. A severity times likelihood table presented as a vulnerability assessment fails on the methodology itself, and nothing in the rest of the document repairs it.
  • Two files that disagree. Sites certified to more than one scheme keep separate food fraud files, they drift apart, and the auditor reads the one nobody updated.
  • Scoring the intended state. Scoring the site as it will be after the capital project rather than as it is this morning, including the door propped open in summer.
  • Residual scores that collapse. Every rating dropping into the green after mitigation is the clearest signal that the document was written backwards from the answer somebody wanted.
  • Packaging, labels and traded goods left out. Especially traded goods, which carry your name and which nobody at your site makes.
  • A merged TACCP and VACCP document. Neither assessment is then complete, and the auditor will say so.

Where to go from here

If the food fraud side is what sits on your desk, the method is worked end to end with every score shown in how to do a food fraud vulnerability assessment. If it is food defence, the role and what it actually owns is set out in what a food defence coordinator actually does.

Understand the clauses, then prove you can build to them

Knowing which clause asks for what will get you through a conversation. Producing an assessment that survives the audit is a different skill, and it is the one both coordinator courses are built to test.

Compare all three food fraud and food defence courses
Start with the overview course, R1450
Introduction first, then the coordinator course for whichever side of the work is yours.

Frequently asked questions

What is the difference between HACCP, TACCP and VACCP?

HACCP controls hazards that arrive by accident and assumes nobody is trying. TACCP assesses deliberate threats intended to cause harm. VACCP assesses vulnerability to fraud committed for economic gain. Different logic, different people in the room, and every GFSI benchmarked scheme requires all three as separate assessments.

Can I combine my TACCP and VACCP into one assessment?

No, and an auditor who finds them merged will treat neither as complete. The factors are different, the teams are different and the mitigation is different. What you can and should combine is the cross reference table at the front of each, so one threat assessment serves every scheme you are certified to, and one vulnerability assessment does the same.

Which FSSC 22000 version will I be audited against?

Version 6 until 30 April 2027, then an upgrade audit against Version 7 between 1 May 2027 and 30 April 2028. Ask your certification body which applies to your next audit date, because the food fraud clause structure differs between the two.

Is BRCGS Issue 10 published?

No. Issue 9 is the current issue and is what your certification body audits against. Issue 10 is in development, with no publication date and no audit start date announced. Prepare against Issue 9.

Does packaging have to be in the food fraud vulnerability assessment?

It depends which scheme, which is why you build to the wider scope. IFS Food version 8 section 4.20 explicitly requires packaging materials and outsourced processes. BRCGS states that packaging does not need to be considered under section 5.4. Build to IFS and you have covered both, with no extra file to maintain.

What method should a TACCP assessment use?

PAS 96:2026 is the publicly available specification most auditors expect behind a food defence clause. None of the schemes prescribes a method, which is exactly why having a named, defensible one matters: a method you can point to is the difference between a scored assessment and a collection of opinions.

Do these requirements apply if I am not certified?

The assessment requirements do not, because they come from the schemes. The liability does. Adulteration, substitution and misdescription are offences under ordinary food law in every market you sell into, certified or not, which is usually the version of the argument that gets the programme funded.

About the author. Mthokozisi Nkosi is a food scientist, a registered Lead Auditor with Exemplar Global and IRCA, an HPCSA registered Environmental Health Practitioner, and one of four SAATCA registered R638:2018 Lead Implementers. He holds an MSc in International Public Health, an MSc in Data Science, an MBA and a BSc in Agriculture (Food Science and Technology), and is completing a PhD in Public Health. He founded ASC Food Safety Consultants, a SAATCA registered training centre (TC No. 065) and FoodBev SETA accredited provider, and prepares South African manufacturers for certification against FSSC 22000, BRCGS, SQF and IFS. Connect on LinkedIn.

ASC Food Safety Training Β· Leading with Science. Ensuring Food Safety. Β· Fully online, serving all of South Africa and beyond Β· info@ascfoodsafety.com Β· WhatsApp +27 61 483 0381 Β· SAATCA registered training centre (TC No. 065) Β· FoodBev SETA accredited provider No. 587/00337/1900 Β· B-BBEE Level 1 Β· Registered Lead Auditor (Exemplar Global and IRCA) Β· Consulting and document toolkits at ascfoodsafety.com