You log the cook temp. You initial it. You move on. Two hundred times a month, maybe more, and every one of those entries says the same thing underneath: the number on that probe was real.
That's the part nobody writes down.
A CCP log is a claim about a reading. The calibration record is what makes the reading worth anything. Without it, a full year of signed, timestamped, perfectly filled-out temperature logs proves that somebody looked at a display, not that the product ever hit the target. And that is the thread an inspector pulls first, because it's the fastest way to find out whether the records in front of them are evidence or decoration.
01. The rule is one sentence, and it's aimed at you
The preventive controls rule doesn't bury this. 21 CFR 117.165(a)(1) lists, as the first verification activity a facility must perform, "calibration of process monitoring instruments and verification instruments (or checking them for accuracy)." Not "should." Must.
Then 117.165(b)(1) requires a written procedure covering "the method and frequency of calibrating process monitoring instruments and verification instruments (or checking them for accuracy)." Method and frequency, in writing. If your answer to "how often do you check the probe?" is "whenever it seems off," you don't have a procedure. You have a habit, and habits don't survive a records request.
And 117.190(a) puts "calibration of process monitoring and verification instruments" on the list of implementation records you have to establish and maintain, which drags it under the general records requirements in subpart F. Same standard as your batch records: accurate, indelible, legible, and created at the time you did the work, not reconstructed on Friday from memory.
Three short clauses. Together they say: check the instrument, write down how and how often you check it, and keep proof that you did.
02. What "checking for accuracy" looks like on a floor with one ice bucket
The regulation says "calibrating ... or checking them for accuracy" on purpose. It doesn't require a certified lab, a NIST-traceable reference, or a service contract. For most small producers the practical version is an ice-point check: crushed ice, a little water, stir, let it settle, read the probe. It should read 32°F / 0°C. Some operations add a boiling-point check at the top end, adjusted for altitude. If the probe is off, you adjust it if it's adjustable, or you tag it and pull it if it isn't.
That's the whole method. It takes about three minutes. The problem was never that it's hard. The problem is that it's invisible.
An ice-point check leaves no product behind, no batch number, no shift report line. It's the kind of task that gets done conscientiously for three weeks and then quietly stops because nothing downstream ever asks for it. And when it stops, nobody notices, because the CCP logs keep filling up exactly as before. The gap only shows up when someone asks the question the logs can't answer.
03. The question you can't answer without it
The probe drifts. Not dramatically, just a couple of degrees low. Every cook step for the next six weeks reads 165°F on the display, so every log says 165°F, so every batch gets released. Then the probe gets checked, or replaced, and the new one reads two degrees hotter on the same product.
Now you have a question: how many batches, going back how far, were logged as in spec but weren't?
If your last calibration record is dated, initialed, and shows the probe reading true, you have a bounded problem. Everything before that date is clean. Everything after it is the review window, and it's a finite list of batches you can name.
If there is no record, the window has no left edge. You cannot prove any batch since the probe was installed met the critical limit, because the only evidence you have was generated by the instrument you now know was wrong. That's a hold-and-evaluate on every lot you can't rule out, and it's the kind of thing that turns into a recall conversation with the owner that nobody on the floor wanted to be part of.
Nobody decided to run with a bad probe. But the person whose initials are on six weeks of logs is the one who gets asked about it.
04. A calibration record that will survive a review
The rule tells you what has to exist. It doesn't tell you what the form looks like. This is the minimum that holds up, sized for a two-person shift, not a QA department.
Per instrument, once: an ID that's physically on the device (a tape label works), what it's used for (which CCP, which step), the check method (ice point, boiling point, comparison against a reference), the acceptance tolerance (for example ±2°F), and the frequency. Daily before first use is common for a probe that touches a CCP. Whatever you pick, write it down, because that's the "method and frequency" in 117.165(b)(1).
Per check, every time: date and time, instrument ID, the reference value, the value the instrument read, pass or fail against the tolerance, what you did if it failed (adjusted, tagged out, replaced), and who did it. Real numbers, not a checkmark. 117.305 asks for "the actual values and observations obtained," and a column of ticks doesn't meet that.
The link most people skip: which batches used this instrument between this check and the last one. That's the piece that turns a calibration log from a standalone form into the left edge of the review window from section 03. If the probe fails today, the record should already tell you which lots are in play.
The review: 117.165(a)(4)(ii) puts calibration records on the list a preventive controls qualified individual reviews "within a reasonable time after the records are created." On the floor, that means someone other than the person doing the check should be looking at the log, and signing that they did. A calibration log nobody reviews is one more record that only proves it was filled in.
05. Why this is the record a spreadsheet loses first
A spreadsheet can hold a calibration log. Plenty do. It fails because the calibration tab lives in a different file from the batch record, on a different machine from the one you're standing next to, and the connection between "probe 3 was checked at 6:40 this morning" and "batch 0917 cooked at 9:15 on probe 3" exists only in someone's head.
That's fine until the day you need it, which is the one day nobody's head is a good enough place for it to be.
In FourFoxes, the instrument is a record of its own. The calibration check is logged from a phone, at the equipment, in the moment, with the reading you got, and it takes about as long as the ice takes to settle. When the CCP entry goes in, it's tied to the instrument that produced it. So when the question comes, in an audit or on the worst Tuesday of the quarter, "which batches ran on this probe since its last good check" is a lookup, not a reconstruction.
Every CCP log you've ever signed rested on an assumption. Make the record that proves it.
Your next audit is coming. Be ready. See how FourFoxes logs calibration alongside the CCP checks it backs up
References
All regulatory text quoted above was retrieved from the electronic Code of Federal Regulations on 2026-09-08.
- 21 CFR 117.165(a)(1): verification of implementation and effectiveness; calibration of process monitoring instruments and verification instruments (or checking them for accuracy). eCFR, current text, retrieved 2026-09-08. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-B/part-117/subpart-C/section-117.165
- 21 CFR 117.165(a)(4)(ii): review of calibration records by a preventive controls qualified individual "within a reasonable time after the records are created." Same source.
- 21 CFR 117.165(b)(1): written procedure for "the method and frequency of calibrating process monitoring instruments and verification instruments (or checking them for accuracy)." Same source.
- 21 CFR 117.190(a): implementation records, including calibration of process monitoring and verification instruments; (b) those records are subject to subpart F. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-B/part-117/subpart-C/section-117.190
- 21 CFR 117.305: general requirements applying to records; actual values and observations; accurate, indelible, legible; created concurrently with performance of the activity. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-B/part-117/subpart-F
- 21 CFR 117.315: retention; records "must be retained at the plant or facility for at least 2 years after the date they were prepared." Same source.
Not sourced from a regulation (practitioner method): the ice-point check in §02 and the "daily before first use" frequency and "±2°F" tolerance in §04 are common-practice examples, not CFR requirements. The rule sets no specific method, frequency, or tolerance; it requires that you write down yours.