Principles 3 and 4: critical limits and monitoring that hold up
How to set a measurable, validated critical limit for each critical control point, and build a monitoring routine that proves control while the work is happening rather than after it.
Chef Diego runs a real food plant. If this page didn't get you there, tell us — a person reads every message.
After this lesson you can put a defensible number under each of your critical control points — a critical limit you can stand behind as validated science, not a figure you carry in your head — and write the monitoring routine that proves, batch by batch and while the work is happening, that the CCP stayed inside that limit. You will know what to measure, how, how often, and who does it, and why continuous monitoring beats a spot check whenever you can get it.
From a critical control point to its number
Principle 2 left you with a short list of critical control points: the steps where control is genuinely essential and nothing else does the job. A CCP on that list is still just a step you have decided matters. Principle 3 gives it a number.
That number is the . FDA's HACCP Principles and Application Guidelines — the method US regulators publish, developed by the National Advisory Committee on Microbiological Criteria for Foods — define it as a maximum and/or minimum value to which a biological, chemical, or physical parameter must be controlled at a CCP to prevent, eliminate, or reduce a hazard to an acceptable level. It exists to distinguish safe operating conditions from unsafe ones, and nothing else.
The guidelines are blunt about one confusion worth heading off now. A critical limit is not the same as an . You might run your cook a few degrees hotter than the safety line so an operator has room to react before the real limit is ever threatened. That buffer is good practice, but it is not the critical limit. The critical limit is the safety boundary itself, and it is the only one an auditor holds you to.
What a critical limit measures
A critical limit is always something you can measure. The guidelines list the parameters it can be built on: temperature, time, physical dimensions, humidity, moisture level, , pH, titratable acidity, salt concentration, available chlorine, viscosity, preservatives, and even sensory checks such as aroma or appearance. If a parameter cannot be measured or observed, it cannot be a critical limit.
Two shapes come up again and again:
A process limit controls the hazard through the process itself — an internal temperature held for a time, a pH driven low enough, a metal detector's sensitivity. A thermal cook is the classic case: reach a temperature, hold it long enough, and the pathogens are reduced to a safe level.
A formulation limit controls the hazard through what the product is — a finished water activity low enough that pathogens cannot grow, or a pH low enough that they cannot survive. Here the number lives in the recipe, not the equipment.
A single CCP can carry more than one critical limit. The guidelines split them into a primary parameter — the one you actually monitor, such as internal temperature and hold time — and secondary parameters that let you reach it reliably, such as oven temperature, belt speed, or product thickness. When you write a limit, be explicit about which number is the safety line and which are the settings that get you there.
Set from validated science, not a number in your head
This is the part that separates a plan an auditor accepts from one they mark up. The guidelines state it plainly: critical limits must be scientifically based. A number you remember from a past job, or one that "feels safe," is not a critical limit — it is a guess wearing a decimal point.
is what turns a number into a defensible limit. The guidelines say a critical limit may be derived from regulatory standards and guidelines, published literature, experimental results, or experts — and that the evidence has to actually apply to your product and process. Under FDA's Preventive Controls rule, 21 CFR 117.160 makes this a written requirement: a preventive controls qualified individual must validate that a process control is adequate to control the hazard, by obtaining and evaluating scientific and technical evidence — or running studies where the evidence is thin — and must do it before the plan is relied on or within 90 calendar days of first production, and again whenever a change could affect control. Under the SQF Food Safety Code, Edition 9, clause 2.4.3.11 likewise requires the food safety team to validate every critical limit, and clause 2.5.1.1 requires those limits to be reviewed at least annually and re-validated when anything changes.
So where does the number come from? Name the authority for your product, and send yourself to its live source:
For meat and poultry, the USDA Food Safety and Inspection Service publishes the safe-harbor science directly. Its revised Cooking Guideline (Appendix A) and Stabilization Guideline (Appendix B), finalized December 14, 2021, give lethality tables for the cook and cooling curves for stabilization. They are guidance you may follow or depart from with your own validated support — not a ceiling, and not automatically a fit for your exact product.
For most other FDA-regulated foods, there is no federal table that hands you the number. The binding limit is the one your validated plan sets under 21 CFR 117. That is the whole point of validation: your process, your product, your evidence.
The FDA Food Code is a retail reference, not your rule
You will see the FDA Food Code two-stage cooling numbers everywhere — cool from 135°F to 70°F within 2 hours, then to 41°F or below within a total of 6 hours. Useful to know, but read the fine print: the Food Code is FDA's model code for restaurants and retail food service, adopted by state and local health departments. It does not bind a registered food manufacturer. Cite it as a reference if you like, but the limit that governs your plant is the one you validated for your process — do not paste a retail number into a manufacturer's HACCP plan and call it validated.
To see what "science-based" looks like in the guidelines' own worked example: for cooked beef patties, the committee concluded a thermal process equivalent to 155°F for 16 seconds was needed to reduce enteric pathogens such as E. coli O157:H7 and Salmonella to a safe level. One plant chose to monitor internal patty temperature and hold time directly as its critical limits; another controlled oven temperature, humidity, belt speed, and patty thickness — the secondary parameters — to guarantee the same result. Same science, two defensible ways to express the limit. That example is FDA's illustration, not a number to copy onto your own line; yours comes from evidence for your product.
Monitoring: proving control while it happens
A validated limit that no one watches proves nothing. Principle 4 is .
The guidelines give monitoring three jobs. First, it tracks the operation, so that a drift toward the edge can be caught and corrected before the limit is ever crossed. Second, it catches the moment control is lost — a — so an appropriate response can follow. Third, it produces the written record that proves, after the fact, that the CCP was under control. Those three jobs are why monitoring has to be designed, not improvised.
What, how, how often, and who
A monitoring procedure that holds up answers four questions in writing. SQF Edition 9 clause 2.4.3.12 requires exactly this — the personnel assigned, the method, and the frequency — and 21 CFR 117.145 requires written monitoring procedures that include the frequency, performed often enough to give real assurance the control is working.
What you measure — the primary parameter that is the safety line: the internal temperature and hold time, the finished pH, the detector reading. Not the buffer, the limit.
How you measure it — the instrument and the method, calibrated and specific. "Probe the thermometer into the thickest point of three units and record the lowest reading" is a procedure; "check the temp" is not.
How often — every unit, every batch, every 30 minutes, continuously. Frequent enough that if the limit were breached, you would catch it before that product left your control.
Who does it — a named, trained role. The guidelines stress that monitors must understand why the check matters, report honestly, and raise a failure immediately. Assigning monitoring to a role, not leaving it to whoever is nearby, is part of the procedure.
Answer those four for every CCP and you have a monitoring plan. Leave any of them vague and you have a gap an auditor will find.
Continuous or on an interval
The strongest monitoring is continuous — a chart recorder on a retort, an in-line pH meter, a metal detector that inspects every unit. The guidelines are clear that continuous monitoring is always preferred when it is feasible, because it watches every moment rather than sampling a few. Where you monitor continuously, calibration becomes the thing that keeps the record honest: an instrument reading the wrong number confidently is worse than no instrument.
When continuous monitoring is not possible, you set an interval instead — a check frequent and well-designed enough to give real confidence the CCP stayed in control between checks. The trap is treating an interval as a formality. If you probe one patty an hour, you are betting that the fifty-nine minutes you did not watch behaved like the one you did; the frequency has to be chosen so that bet is sound. And note what monitoring is usually not: microbiological testing. The guidelines point out that lab tests are seldom useful for real-time monitoring — the results come back long after the product has moved — which is exactly why fast physical and chemical measurements, temperature and time and pH, do the monitoring work instead.
The record, made as the work happens
Monitoring produces a record, and the record is only worth what its timing makes it. The guidelines require every monitoring record to be dated and signed or initialed by the person who did the check. The reason is the one auditors probe hardest: a log filled in at the end of the shift, or reconstructed the next morning, is not evidence that the CCP was in control — it is evidence that someone wrote numbers down. A monitoring record has to be made as the reading is taken, by the person taking it.
That is a design constraint on your log form, not an afterthought. A good form has a line for every scheduled check, the measured value, the time, and the monitor's initials, and it lives where the check happens so it gets filled in there. Design it so the honest thing and the easy thing are the same thing.
This is also where paper starts to strain. A clipboard log is only contemporaneous if someone is disciplined about it, and it tells no one anything until it is collected and read. Some operations close that gap by capturing the monitoring reading on the line as the batch runs, so the value, the time, and who recorded it are fixed at the moment of the check and a breach is visible immediately rather than at the next record review. Bettr Manager works this way for thermal CCPs — a production run carries its cooking and cooling logs, flags a red alert the moment a recorded temperature falls outside the limit, and will not let the run be finished until each batch's log is complete. It is one way to make the record contemporaneous by construction; a well-run paper log that is genuinely filled in at the check is another. What matters is that the record is made when the work happens, not that any particular tool makes it.
What a breached limit sets up
Do Principles 3 and 4 well and you have, for every CCP, a validated critical limit and a written monitoring routine that says what, how, how often, and who — with a record made at the moment of the check. That is control you can prove.
It also raises the question monitoring exists to force: when a reading comes back outside the limit — a deviation — what happens to the process, and what happens to the product that was running when it failed? A monitoring routine that catches a breach but has no answer for it is only half a control. That answer is Principle 5, the corrective action, and it is the next lesson.