Get Your ISO/IEC 20000-1 Quote
ISO/IEC 20000-1 IT Service Management Certification that backs your service levels
You sell managed services against agreed availability and response times, and a customer now wants proof the discipline behind them exists. ISO/IEC 20000-1 certifies the service management system: how incidents, problems, changes, capacity and service continuity are run, and how performance against the agreement is measured and reported.
You need ISO/IEC 20000-1 if…
- !A managed services tender requires ISO/IEC 20000-1 alongside ISO/IEC 27001 at pre-qualification.
- !Change-related outages keep hitting production and the post-incident reviews all say the same thing.
- !Service credits are being claimed and the availability figures are disputed line by line.
- !Your team holds ITIL qualifications but the organisation has nothing certifiable to show a buyer.
- !A client wants evidence that your subcontracted support and cloud suppliers are managed, not just contracted.
- !The service desk closes tickets fast and the same fault returns every fortnight without a problem record.
ISO/IEC 20000-1 is the international standard for a service management system. It defines what an organisation must have in place to plan, deliver, operate, measure and improve IT-enabled services against agreed service levels.
A certification of the organisation. An accredited certification body audits and issues it. ITIL by contrast is guidance, and ITIL qualifications certify individuals, not the service provider.
Three-year certificate with annual surveillance audits and recertification before expiry; service performance data is sampled at each visit.
Managed service providers, cloud and application support firms, outsourcers, and internal IT functions delivering services to the rest of a group.
Where this certification is demanded
ISO/IEC 20000-1 is applicable across 5 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What ISO/IEC 20000-1 Actually Requires
The backbone an implementer has to build, in the order it usually gets built.
The services covered, who receives them, which components are delivered by other parties, and the demand and capacity assumptions behind each one.
Management ownership of service performance, a service management plan, objectives with measures, and accountability retained where parts of the service lifecycle sit with suppliers.
A service catalogue and agreements with defined targets, measurement method and reporting frequency, agreed with customers rather than published at them.
Incident and service request handling with prioritisation and escalation, major incident procedure, and problem management that finds underlying causes and removes them.
Change control with assessment, approval and back-out, configuration information kept accurate, release and deployment discipline, and availability, capacity and service continuity planned and tested.
Service reporting against targets, supplier performance reviewed, internal audits and management review conducted, and improvements recorded, prioritised and closed with evidence.
How ISO/IEC 20000-1 Certification Works
No black box. A defined, time-bound route from first call to certificate in hand.
Application & Proposal
We scope by service: which services and delivery sites are covered, customer count and type, and which components run on subcontracted or cloud platforms you do not operate.
1–2 daysGap Review & Readiness
Configuration data drifts, and it drifts quietly. The tool says a server is on the supported list; it was decommissioned in the last migration and the change record was closed anyway.
1–2 weeksStage 1 + Stage 2 Audit
Stage 1 reviews scope, the service management plan and readiness. Stage 2 samples live tickets, change records, major incident reviews, capacity data and service reports against the agreements themselves.
Scheduled around operationsCertificate Issued
What the certificate lists - services, delivery locations - is what a managed services buyer compares against the contract. Surveillance is annual and samples live tickets rather than last year’s reports.
Valid 3 yearsIndustries That Need ISO/IEC 20000-1
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
Your evidence history may be thinner than you think
Six months of service reports tell us more than any questionnaire. If your change and problem records are too thin to sample, we would rather say so now than at Stage 2.
Get My Free Quote →What ISO/IEC 20000-1 Changes for Your Business
Certification is not a certificate on the wall. It is a working system that pays for itself.
Tender requirements answered
Managed services and government IT tenders that name ISO/IEC 20000-1 stop being closed to you, and the certificate covers the service management section outright.
Fewer change-caused outages
Assessment, approval and back-out planning on every change removes the largest single cause of avoidable production incidents in most service operations.
Repeat faults actually removed
Problem management separate from incident closure means the recurring fault is investigated and eliminated instead of restored quickly again and again.
Service reports customers trust
Agreed measurement methods and consistent reporting shorten the monthly service review and take most of the heat out of service credit conversations.
Suppliers held to account
Cloud and subcontracted components come under defined targets and periodic review, so responsibility does not evaporate at the boundary of your own infrastructure.
Pairs with security certification
ISO/IEC 27001 shares the change, incident, supplier and continuity ground, so the two certificates are commonly held together and audited together.
Knowledge Base - Downloads
Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.
Service level agreement and reporting structure
Targets, measurement method, exclusions and reporting cadence written so both parties calculate the same availability figure from the same raw data.
Change control audit checklist for service providers
Assessment, approval authority, back-out plan, verification and post-implementation review, with the evidence auditors sample at each point and the usual gaps.
ITIL practices mapped to ISO/IEC 20000-1 clauses
Where existing ITIL-based processes already satisfy the standard, and which clauses ITIL adopters most often miss because the guidance treats them as optional.
Problem management that removes repeat incidents
Separating restoration from cause removal, and how to get the permanent fix funded once the ticket is already closed and the customer has moved on.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to ISO/IEC 20000-1.
How is ISO/IEC 20000-1 different from ITIL?
Can we certify if our infrastructure runs on a public cloud?
Do we need ISO/IEC 27001 as well?
What evidence does the auditor sample?
Can an internal IT department certify, or only external providers?
How long does certification take?
Certify your service management system with SIS
Assessors who have run service desks and sat through major incident reviews audit this scope. They will read your tickets, not your process documents.
Get My Free Quote → WhatsApp Us