Principle 2: which steps are truly critical control points
How to turn your significant hazards into a short, defensible list of critical control points — the steps where control is genuinely essential — and tell them apart from what a prerequisite program already handles.
Chef Diego runs a real food plant. If this page didn't get you there, tell us — a person reads every message.
After this lesson you can take the significant hazards your hazard analysis produced and decide, hazard by hazard, which steps in your process are true critical control points — the steps where control is essential and nothing else does the job better. You will also be able to tell a CCP apart from a step a prerequisite program already handles, and name each one correctly for the rule you operate under.
From significant hazards to the steps that control them
Principle 1 left you with a list. For each step of your verified flow diagram, you named the biological, chemical, and physical hazards, and you marked the ones significant enough that safety depends on controlling them. Principle 2 asks the next question: for each of those significant hazards, where does control actually land?
That word "where" is the whole job. A has to be controlled somewhere in your process — but not every step that touches it is the place. Most steps carry a , and that is exactly why this principle needs its own discipline. The step where control is merely helpful is not the step where control is essential.
A is the step where control is essential. The method US regulators publish — the National Advisory Committee on Microbiological Criteria for Foods method, in FDA's HACCP Principles and Application Guidelines — defines it as a step at which control can be applied and is essential to prevent or eliminate a hazard or reduce it to an acceptable level. FDA's Preventive Controls rule carries essentially the same definition in 21 CFR 117.3. "Essential" is the load-bearing word. If safety does not actually depend on the control at that step, it is not a CCP.
What makes a point "critical"
A CCP is the step that is the last, best line of defense against a hazard — the point where you either prevent it, eliminate it, or knock it down to a safe level, and after which nothing in your process will do so again. That is why a kill step is the classic example. Once the cook is done and the product moves on, no later step revisits the pathogens the cook was there to destroy.
The guidelines name the usual suspects: a thermal process, chilling, testing incoming ingredients for chemical residues, controlling a formulation such as pH, and screening finished product for metal. Two things are worth pinning down. First, a CCP exists only for safety. The guidelines are blunt that critical control points are used only for purposes of product safety — a step you watch to protect texture, color, or fill weight is a quality control point, not a CCP, and it does not belong in this list. Second, your CCPs are yours. Two plants making nearly the same food can land on different CCPs, because their layout, equipment, ingredients, and process differ. There is no universal list to copy; there is only the reasoning applied to your own process.
The decision tree: a sequence of questions, not an oracle
To keep the reasoning honest, the guidelines offer a tool: a . You run it at each step where a significant hazard is present, one hazard at a time. The logic every version walks through looks like this:
1
Is there a control measure at this step for the hazard?
If a significant hazard is present but no control measure exists here or anywhere else, safety has a gap. The answer is not to shrug — it is to change the process so a control exists. SQF Edition 9 states this plainly: where a significant hazard is identified at a step but no control measure exists, the food safety team must modify the process to add one (clause 2.4.3.10).
2
Is control at this step necessary for safety?
A control measure can be present and still not be essential here. If the step contributes to safety but is not where the hazard is actually held in check, it is not the CCP for that hazard.
3
Is this the step that eliminates or reduces the hazard to an acceptable level?
This is the heart of it. A CCP is the step designed to bring the hazard to a safe level. If it is, and nothing later revisits the hazard, this step is a strong CCP candidate.
4
Will a later step control it better?
A subsequent step may be the more effective place to control the hazard, and then that later step is the preferred CCP — not this one. This is the check the guidelines call out directly, and it is where over-eager plans go wrong: control gets pinned to an early step when a downstream kill step is the real CCP.
Two honest caveats keep the tool in its place. The guidelines call the decision tree merely a tool, not a mandatory element of HACCP, and warn that it is not a substitute for expert knowledge — they publish two different example trees precisely because there is no single official one. And a single control can span more than one hazard, while a single hazard can be split across more than one step. The tree structures your judgment; it does not replace it. Walk it, then read the result back and ask whether it matches what you know about your own line.
CCP, prerequisite program, or preventive control — name it right
Here is where plans get their vocabulary wrong, and where an auditor notices. The same hazard can be handled three different ways, and only one of them is a CCP.
Many significant hazards are held in check not by a CCP but by a . Sanitation between allergen changeovers, an approved-supplier program for spices, a glass-and-brittle-plastic policy — these control real hazards, but they run continuously across the whole plant rather than at one measurable step. The guidelines keep them separate: prerequisite programs are the foundation the HACCP plan stands on, managed apart from it, and the plan itself stays narrow. Deciding which significant hazards a prerequisite program already controls — and therefore should not become CCPs — is half the work of Principle 2.
The other trap is the word "preventive control," and it is not a synonym for CCP. Which rule you operate under decides your vocabulary:
Under classic HACCP — and under the mandatory HACCP regulations for meat and poultry (USDA FSIS, 9 CFR 417.2), seafood, and juice — the term is critical control point, and each CCP carries a critical limit. FSIS requires the plan to list the CCPs for every identified hazard and the critical limits to be met at each.
Under FDA's FSMA Preventive Controls rule, the umbrella term is preventive control. A is broader than a CCP, not equal to it. 21 CFR 117.135 spells out that required preventive controls include controls at CCPs, if there are any CCPs, and controls other than those at CCPs that are also appropriate for food safety. The rule then lists categories — process controls, food allergen controls, sanitation controls, supply-chain controls, and a recall plan. So under FSMA an allergen control or a sanitation control is a preventive control without ever being a CCP.
A CCP is a preventive control; a preventive control is not always a CCP
Calling every preventive control a CCP, or every CCP just "a preventive control," reads as not knowing which framework you are under. Under FSMA, a process control at a genuine critical step is a CCP; a sanitation or allergen control that runs plant-wide is a preventive control but not a CCP. Use the word the rule you operate under uses, and use it for the right thing.
Why over-designating is as risky as under-designating
The instinct, once you understand the stakes, is to mark everything a CCP to be safe. That instinct is wrong, and it is worth seeing why.
Every CCP drags a full apparatus behind it. The next five principles apply to each one: a validated critical limit (Principle 3), a monitoring routine (Principle 4), a corrective action for when it fails (Principle 5), verification (Principle 6), and records (Principle 7). Designate too few, and a real hazard goes uncontrolled — the gap Principle 1 existed to prevent. Designate too many, and you bury the CCPs that truly matter under monitoring and paperwork for steps that never needed it, dilute the attention of the people doing the checks, and drag quality steps or prerequisite-controlled steps into a plan that is supposed to be narrow. A plan with fifteen CCPs is usually not a safer plan; it is a plan whose author could not tell essential control from ordinary control.
The audit stakes are real, too. Under SQF Edition 9, a breakdown of control at a critical control point is treated as a critical non-conformance — the most serious kind. That cuts both ways: mislabel a routine step as a CCP and you have manufactured a critical finding out of thin air; miss a real one and you have left a genuine gap. Both come from the same failure to reason carefully about which steps are truly critical.
What your CCP list sets up
Done well, Principle 2 gives you something short and defensible: a small set of CCPs, each confirmed as a step where control is essential, where no earlier or later step controls the hazard better, and where a prerequisite program was not already doing the job. That short list is the spine of the plan. Everything after it hangs on these points.
What it does not yet give you is the number. A CCP without a boundary is just a step you have decided matters. The next question — how hot, how long, how low a pH, held to what value — is Principle 3, the critical limit: the measurable line between safe and unsafe, set from validated science rather than a figure carried in your head. That is the next lesson, and the CCP list you just built is what it acts on.