[email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
HomeStandardsISO/IEC 20000-1

Get Your ISO/IEC 20000-1 Quote

Takes 30 seconds · a specialist responds within 2 business hours
Step 1 of 2
CertificationTrainingCompliance Audits
Not sure - guide me
ISO/IEC 20000-1
No spam. No obligation. A clear quote.
15,000+Certified Clients
30+Countries Served
IAS · IAFAccredited
ISO/IEC 20000-1:2018 · IT Service Management

ISO/IEC 20000-1 IT Service Management Certification that backs your service levels

You sell managed services against agreed availability and response times, and a customer now wants proof the discipline behind them exists. ISO/IEC 20000-1 certifies the service management system: how incidents, problems, changes, capacity and service continuity are run, and how performance against the agreement is measured and reported.

You need ISO/IEC 20000-1 if…

  • !A managed services tender requires ISO/IEC 20000-1 alongside ISO/IEC 27001 at pre-qualification.
  • !Change-related outages keep hitting production and the post-incident reviews all say the same thing.
  • !Service credits are being claimed and the availability figures are disputed line by line.
  • !Your team holds ITIL qualifications but the organisation has nothing certifiable to show a buyer.
  • !A client wants evidence that your subcontracted support and cloud suppliers are managed, not just contracted.
  • !The service desk closes tickets fast and the same fault returns every fortnight without a problem record.
What it is

ISO/IEC 20000-1 is the international standard for a service management system. It defines what an organisation must have in place to plan, deliver, operate, measure and improve IT-enabled services against agreed service levels.

Who issues it

A certification of the organisation. An accredited certification body audits and issues it. ITIL by contrast is guidance, and ITIL qualifications certify individuals, not the service provider.

Validity

Three-year certificate with annual surveillance audits and recertification before expiry; service performance data is sampled at each visit.

Who gets asked for it

Managed service providers, cloud and application support firms, outsourcers, and internal IT functions delivering services to the rest of a group.

5of 25 industries

Where this certification is demanded

ISO/IEC 20000-1 is applicable across 5 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Defence IndustryPublic SectorTelecommunication IndustryInformation Technology IndustryBanking and Finance

What ISO/IEC 20000-1 Actually Requires

The backbone an implementer has to build, in the order it usually gets built.

1
Service scope and portfolio

The services covered, who receives them, which components are delivered by other parties, and the demand and capacity assumptions behind each one.

2
Governance of the system

Management ownership of service performance, a service management plan, objectives with measures, and accountability retained where parts of the service lifecycle sit with suppliers.

3
Service level management

A service catalogue and agreements with defined targets, measurement method and reporting frequency, agreed with customers rather than published at them.

4
Resolution processes

Incident and service request handling with prioritisation and escalation, major incident procedure, and problem management that finds underlying causes and removes them.

5
Control and continuity

Change control with assessment, approval and back-out, configuration information kept accurate, release and deployment discipline, and availability, capacity and service continuity planned and tested.

6
Reporting and improvement

Service reporting against targets, supplier performance reviewed, internal audits and management review conducted, and improvements recorded, prioritised and closed with evidence.

How ISO/IEC 20000-1 Certification Works

No black box. A defined, time-bound route from first call to certificate in hand.

Application & Proposal

We scope by service: which services and delivery sites are covered, customer count and type, and which components run on subcontracted or cloud platforms you do not operate.

1–2 days

Gap Review & Readiness

Configuration data drifts, and it drifts quietly. The tool says a server is on the supported list; it was decommissioned in the last migration and the change record was closed anyway.

1–2 weeks

Stage 1 + Stage 2 Audit

Stage 1 reviews scope, the service management plan and readiness. Stage 2 samples live tickets, change records, major incident reviews, capacity data and service reports against the agreements themselves.

Scheduled around operations

Certificate Issued

What the certificate lists - services, delivery locations - is what a managed services buyer compares against the contract. Surveillance is annual and samples live tickets rather than last year’s reports.

Valid 3 years
Six to ten weeks for an established service operation, and the pacing item is evidence: auditors need several months of service reports, change records and management review to sample, so early tool discipline matters more than documentation.

Industries That Need ISO/IEC 20000-1

🛡️
Defence Industry
Open full page →
Why it applies hereDefence networks, simulators and command support systems are increasingly run under long-term managed service contracts. ISO/IEC 20000-1 evidences the incident, change, capacity and service continuity disciplines needed to hold agreed availability on mission-critical systems, and gives the customer a contractual measure of service performance beyond an uptime percentage.Typical trigger: Managed service and AMC contracts
🏛️
Public Sector
Open full page →
Why it applies hereDepartments running shared services, helpdesks and citizen portals need measurable service performance. ISO/IEC 20000-1 formalises incident, change, capacity and continuity management, and gives a contractual basis for holding outsourced IT partners to agreed service levels.Typical trigger: Shared services; IT outsourcing
📡
Telecommunication Industry
Open full page →
Why it applies hereManaged connectivity, hosted voice and enterprise network services are sold on service level commitments. ISO/IEC 20000-1 formalises incident, change, capacity and continuity management so those commitments are met consistently, and gives enterprise buyers an auditable basis for service performance beyond monthly reports.Typical trigger: Managed service SLAs
💻
Information Technology Industry
Open full page →
Why it applies hereManaged services, cloud operations and application support are sold on service levels. ISO/IEC 20000-1 formalises incident, problem, change, capacity and continuity management so commitments are met consistently, and gives customers an auditable basis for service performance.Typical trigger: Managed service and SLA contracts
🏦
Banking and Finance
Open full page →
Why it applies hereCore banking, payments and digital channels are operated as services with hard availability expectations. ISO/IEC 20000-1 formalises incident, change, capacity and continuity management, reducing change-related outages that regulators require institutions to report and explain.Typical trigger: Change-related outage reduction

Commonly taken alongside

Service management, information security and continuity share change control, incident handling, supplier management and recovery testing, so an integrated audit samples that common evidence once instead of three times in the same year.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

Your evidence history may be thinner than you think

Six months of service reports tell us more than any questionnaire. If your change and problem records are too thin to sample, we would rather say so now than at Stage 2.

Get My Free Quote →

What ISO/IEC 20000-1 Changes for Your Business

Certification is not a certificate on the wall. It is a working system that pays for itself.

📜

Tender requirements answered

Managed services and government IT tenders that name ISO/IEC 20000-1 stop being closed to you, and the certificate covers the service management section outright.

🛑

Fewer change-caused outages

Assessment, approval and back-out planning on every change removes the largest single cause of avoidable production incidents in most service operations.

🔁

Repeat faults actually removed

Problem management separate from incident closure means the recurring fault is investigated and eliminated instead of restored quickly again and again.

📊

Service reports customers trust

Agreed measurement methods and consistent reporting shorten the monthly service review and take most of the heat out of service credit conversations.

🔗

Suppliers held to account

Cloud and subcontracted components come under defined targets and periodic review, so responsibility does not evaporate at the boundary of your own infrastructure.

🔐

Pairs with security certification

ISO/IEC 27001 shares the change, incident, supplier and continuity ground, so the two certificates are commonly held together and audited together.

Knowledge Base - Downloads

Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.

TEMPLATE

Service level agreement and reporting structure

Targets, measurement method, exclusions and reporting cadence written so both parties calculate the same availability figure from the same raw data.

CHECKLIST

Change control audit checklist for service providers

Assessment, approval authority, back-out plan, verification and post-implementation review, with the evidence auditors sample at each point and the usual gaps.

PDF GUIDE

ITIL practices mapped to ISO/IEC 20000-1 clauses

Where existing ITIL-based processes already satisfy the standard, and which clauses ITIL adopters most often miss because the guidance treats them as optional.

WHITEPAPER

Problem management that removes repeat incidents

Separating restoration from cause removal, and how to get the permanent fix funded once the ticket is already closed and the customer has moved on.

🔒 Documents are locked. Fill the form once to unlock every download.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to ISO/IEC 20000-1.

How is ISO/IEC 20000-1 different from ITIL?
ITIL is a body of guidance describing practices you may adopt; its qualifications certify individuals. ISO/IEC 20000-1 is an auditable standard against which an organisation is certified. Most ITIL-based operations already meet a good part of it, but the standard adds management system requirements - planning, internal audit, management review, improvement - that ITIL treats as optional practice.
Can we certify if our infrastructure runs on a public cloud?
Yes, and most providers now do. The standard requires you to identify components delivered by other parties and to demonstrate control over them: defined requirements, agreed targets, monitored performance and accountability retained by you. Auditors will not audit the hyperscaler; they will test how you govern that dependency and what happens when it degrades.
Do we need ISO/IEC 27001 as well?
Not as a prerequisite, though buyers often ask for both and the pairing is common. ISO/IEC 20000-1 governs service delivery and performance; ISO/IEC 27001 governs the confidentiality, integrity and availability of information. They overlap on change, incident, supplier and continuity management, so the second certificate typically costs far less effort than the first.
What evidence does the auditor sample?
Live and closed tickets across priorities, change records including at least one emergency change and one back-out, major incident reviews, problem records with cause and closure, capacity and availability data, service reports issued to customers, supplier review minutes, internal audit results and management review outputs. Several months of history are needed, not a prepared sample.
Can an internal IT department certify, or only external providers?
Both. An internal IT function delivering services to business units under agreed service levels can be certified, and the customer in the standard’s language is then internal. What has to exist either way is a real agreement with measured targets and reporting, rather than an implicit expectation that systems will simply be available.
How long does certification take?
Six to ten weeks for a service operation already using a ticketing tool with reasonable discipline. The constraint is evidence history: the auditor needs enough months of change records, service reports and at least one management review to sample. Organisations that tidy the process tomorrow but have no record of yesterday end up waiting for the data to accumulate.
Email Us
✉ EmailGet Quote