ISO/IEC 20000-1 backs up the service levels you promise
You sell managed services against agreed availability and response times, and a customer now wants proof the discipline exists. SIS audits how you run incidents, problems, changes, capacity and continuity, and how you report performance against the agreement.
- !A managed services tender requires ISO/IEC 20000-1 alongside ISO/IEC 27001 at pre-qualification.
- !Change-related outages keep hitting production and the post-incident reviews all say the same thing.
- !Service credits are being claimed and the availability figures are disputed line by line.
- !Your team holds ITIL qualifications but the organisation has nothing certifiable to show a buyer.
- !A client wants evidence that your subcontracted support and cloud suppliers are managed, not just contracted.
- !The service desk closes tickets fast and the same fault returns every fortnight without a problem record.
ISO/IEC 20000-1 is the international standard for a service management system. It defines what an organisation must have in place to plan, deliver, operate, measure and improve IT-enabled services against agreed service levels.
A certification of the organisation. An accredited certification body audits and issues it. ITIL by contrast is guidance, and ITIL qualifications certify individuals, not the service provider.
Three-year certificate with annual surveillance audits and recertification before expiry; service performance data is sampled at each visit.
Managed service providers, cloud and application support firms, outsourcers, and internal IT functions delivering services to the rest of a group.
Industries that require ISO 22000 Certification
ISO/IEC 20000-1 is applicable across 5 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What ISO/IEC 20000-1 Actually Requires
An organisation must understand the requirements for ISO 22000 certification to implement it effectively.
The services covered, who receives them, which components are delivered by other parties, and the demand and capacity assumptions behind each one.
Management ownership of service performance, a service management plan, objectives with measures, and accountability retained where parts of the service lifecycle sit with suppliers.
A service catalogue and agreements with defined targets, measurement method and reporting frequency, agreed with customers rather than published at them.
Incident and service request handling with prioritisation and escalation, major incident procedure, and problem management that finds underlying causes and removes them.
Change control with assessment, approval and back-out, configuration information kept accurate, release and deployment discipline, and availability, capacity and service continuity planned and tested.
Service reporting against targets, supplier performance reviewed, internal audits and management review conducted, and improvements recorded, prioritised and closed with evidence.
How ISO/IEC 20000-1 Certification Works
A clear, step-by-step process from your first call to a completed engagement.
Application & Proposal
We scope by service: which services and delivery sites are covered, customer count and type, and which components run on subcontracted or cloud platforms you do not operate.
1–2 daysGap Review & Readiness
Configuration data drifts, and it drifts quietly. The tool says a server is on the supported list; it was decommissioned in the last migration and the change record was closed anyway.
1–2 weeksStage 1 + Stage 2 Audit
Stage 1 reviews scope, the service management plan and readiness. Stage 2 samples live tickets, change records, major incident reviews, capacity data and service reports against the agreements themselves.
Scheduled around operationsCertificate Issued
What the certificate lists - services, delivery locations - is what a managed services buyer compares against the contract. Surveillance is annual and samples live tickets rather than last year’s reports.
Valid 3 yearsIndustries That Need ISO/IEC 20000-1
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
Your evidence history may be thinner than you think
Six months of service reports tell us more than any questionnaire. If your change and problem records are too thin to sample, we would rather say so now than at Stage 2.
Get My Free Quote →What ISO/IEC 20000-1 Changes for Your Business
More than a certificate — a testimony that you have raised the bar and built customer confidence.
Tender requirements answered
Managed services and government IT tenders that name ISO/IEC 20000-1 stop being closed to you, and the certificate covers the service management section outright.
Fewer change-caused outages
Assessment, approval and back-out planning on every change removes the largest single cause of avoidable production incidents in most service operations.
Repeat faults actually removed
Problem management separate from incident closure means the recurring fault is investigated and eliminated instead of restored quickly again and again.
Service reports customers trust
Agreed measurement methods and consistent reporting shorten the monthly service review and take most of the heat out of service credit conversations.
Suppliers held to account
Cloud and subcontracted components come under defined targets and periodic review, so responsibility does not evaporate at the boundary of your own infrastructure.
Pairs with security certification
ISO/IEC 27001 shares the change, incident, supplier and continuity ground, so the two certificates are commonly held together and audited together.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to ISO/IEC 20000-1.
How is ISO/IEC 20000-1 different from ITIL?
Can we certify if our infrastructure runs on a public cloud?
Do we need ISO/IEC 27001 as well?
What evidence does the auditor sample?
Can an internal IT department certify, or only external providers?
How long does certification take?
Certify your service management system with SIS
Assessors who have run service desks and sat through major incident reviews audit this scope. They will read your tickets, not your process documents.
Get My Free Quote → WhatsApp Us