📞 +91 8882 213 680  |  ✉ [email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
Home›Standards›ISO/IEC 20000-1

Get Your ISO/IEC 20000-1 Quote

A specialist responds within 2 business hours ·

ISO/IEC 20000-1:2018 · IT Service Management

ISO/IEC 20000-1 backs up the service levels you promise

You sell managed services against agreed availability and response times, and a customer now wants proof the discipline exists. SIS audits how you run incidents, problems, changes, capacity and continuity, and how you report performance against the agreement.

  • !A managed services tender requires ISO/IEC 20000-1 alongside ISO/IEC 27001 at pre-qualification.
  • !Change-related outages keep hitting production and the post-incident reviews all say the same thing.
  • !Service credits are being claimed and the availability figures are disputed line by line.
  • !Your team holds ITIL qualifications but the organisation has nothing certifiable to show a buyer.
  • !A client wants evidence that your subcontracted support and cloud suppliers are managed, not just contracted.
  • !The service desk closes tickets fast and the same fault returns every fortnight without a problem record.
What it is

ISO/IEC 20000-1 is the international standard for a service management system. It defines what an organisation must have in place to plan, deliver, operate, measure and improve IT-enabled services against agreed service levels.

Who issues it

A certification of the organisation. An accredited certification body audits and issues it. ITIL by contrast is guidance, and ITIL qualifications certify individuals, not the service provider.

Validity

Three-year certificate with annual surveillance audits and recertification before expiry; service performance data is sampled at each visit.

Who can apply for ISO/IEC 22000 Certification?

Managed service providers, cloud and application support firms, outsourcers, and internal IT functions delivering services to the rest of a group.

5of 25 industries

Industries that require ISO 22000 Certification

ISO/IEC 20000-1 is applicable across 5 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Defence IndustryPublic SectorTelecommunication IndustryInformation Technology IndustryBanking and Finance

What ISO/IEC 20000-1 Actually Requires

An organisation must understand the requirements for ISO 22000 certification to implement it effectively.

1
Service scope and portfolio

The services covered, who receives them, which components are delivered by other parties, and the demand and capacity assumptions behind each one.

2
Governance of the system

Management ownership of service performance, a service management plan, objectives with measures, and accountability retained where parts of the service lifecycle sit with suppliers.

3
Service level management

A service catalogue and agreements with defined targets, measurement method and reporting frequency, agreed with customers rather than published at them.

4
Resolution processes

Incident and service request handling with prioritisation and escalation, major incident procedure, and problem management that finds underlying causes and removes them.

5
Control and continuity

Change control with assessment, approval and back-out, configuration information kept accurate, release and deployment discipline, and availability, capacity and service continuity planned and tested.

6
Reporting and improvement

Service reporting against targets, supplier performance reviewed, internal audits and management review conducted, and improvements recorded, prioritised and closed with evidence.

How ISO/IEC 20000-1 Certification Works

A clear, step-by-step process from your first call to a completed engagement.

Application & Proposal

We scope by service: which services and delivery sites are covered, customer count and type, and which components run on subcontracted or cloud platforms you do not operate.

1–2 days

Gap Review & Readiness

Configuration data drifts, and it drifts quietly. The tool says a server is on the supported list; it was decommissioned in the last migration and the change record was closed anyway.

1–2 weeks

Stage 1 + Stage 2 Audit

Stage 1 reviews scope, the service management plan and readiness. Stage 2 samples live tickets, change records, major incident reviews, capacity data and service reports against the agreements themselves.

Scheduled around operations

Certificate Issued

What the certificate lists - services, delivery locations - is what a managed services buyer compares against the contract. Surveillance is annual and samples live tickets rather than last year’s reports.

Valid 3 years
Six to ten weeks for an established service operation, and the pacing item is evidence: auditors need several months of service reports, change records and management review to sample, so early tool discipline matters more than documentation.

Industries That Need ISO/IEC 20000-1

🛡️
Defence Industry
Open full page →
Why it applies hereDefence networks, simulators and command support systems are increasingly run under long-term managed service contracts. ISO/IEC 20000-1 evidences the incident, change, capacity and service continuity disciplines needed to hold agreed availability on mission-critical systems, and gives the customer a contractual measure of service performance beyond an uptime percentage.Typical trigger: Managed service and AMC contracts
🏛️
Public Sector
Open full page →
Why it applies hereDepartments running shared services, helpdesks and citizen portals need measurable service performance. ISO/IEC 20000-1 formalises incident, change, capacity and continuity management, and gives a contractual basis for holding outsourced IT partners to agreed service levels.Typical trigger: Shared services; IT outsourcing
📡
Telecommunication Industry
Open full page →
Why it applies hereManaged connectivity, hosted voice and enterprise network services are sold on service level commitments. ISO/IEC 20000-1 formalises incident, change, capacity and continuity management so those commitments are met consistently, and gives enterprise buyers an auditable basis for service performance beyond monthly reports.Typical trigger: Managed service SLAs
💻
Information Technology Industry
Open full page →
Why it applies hereManaged services, cloud operations and application support are sold on service levels. ISO/IEC 20000-1 formalises incident, problem, change, capacity and continuity management so commitments are met consistently, and gives customers an auditable basis for service performance.Typical trigger: Managed service and SLA contracts
🏦
Banking and Finance
Open full page →
Why it applies hereCore banking, payments and digital channels are operated as services with hard availability expectations. ISO/IEC 20000-1 formalises incident, change, capacity and continuity management, reducing change-related outages that regulators require institutions to report and explain.Typical trigger: Change-related outage reduction

Commonly taken alongside

Service management, information security and continuity share change control, incident handling, supplier management and recovery testing, so an integrated audit samples that common evidence once instead of three times in the same year.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

Your evidence history may be thinner than you think

Six months of service reports tell us more than any questionnaire. If your change and problem records are too thin to sample, we would rather say so now than at Stage 2.

Get My Free Quote →

What ISO/IEC 20000-1 Changes for Your Business

More than a certificate — a testimony that you have raised the bar and built customer confidence.

📜

Tender requirements answered

Managed services and government IT tenders that name ISO/IEC 20000-1 stop being closed to you, and the certificate covers the service management section outright.

🛑

Fewer change-caused outages

Assessment, approval and back-out planning on every change removes the largest single cause of avoidable production incidents in most service operations.

🔁

Repeat faults actually removed

Problem management separate from incident closure means the recurring fault is investigated and eliminated instead of restored quickly again and again.

📊

Service reports customers trust

Agreed measurement methods and consistent reporting shorten the monthly service review and take most of the heat out of service credit conversations.

🔗

Suppliers held to account

Cloud and subcontracted components come under defined targets and periodic review, so responsibility does not evaporate at the boundary of your own infrastructure.

🔐

Pairs with security certification

ISO/IEC 27001 shares the change, incident, supplier and continuity ground, so the two certificates are commonly held together and audited together.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to ISO/IEC 20000-1.

How is ISO/IEC 20000-1 different from ITIL?
ITIL is a body of guidance describing practices you may adopt; its qualifications certify individuals. ISO/IEC 20000-1 is an auditable standard against which an organisation is certified. Most ITIL-based operations already meet a good part of it, but the standard adds management system requirements - planning, internal audit, management review, improvement - that ITIL treats as optional practice.
Can we certify if our infrastructure runs on a public cloud?
Yes, and most providers now do. The standard requires you to identify components delivered by other parties and to demonstrate control over them: defined requirements, agreed targets, monitored performance and accountability retained by you. Auditors will not audit the hyperscaler; they will test how you govern that dependency and what happens when it degrades.
Do we need ISO/IEC 27001 as well?
Not as a prerequisite, though buyers often ask for both and the pairing is common. ISO/IEC 20000-1 governs service delivery and performance; ISO/IEC 27001 governs the confidentiality, integrity and availability of information. They overlap on change, incident, supplier and continuity management, so the second certificate typically costs far less effort than the first.
What evidence does the auditor sample?
Live and closed tickets across priorities, change records including at least one emergency change and one back-out, major incident reviews, problem records with cause and closure, capacity and availability data, service reports issued to customers, supplier review minutes, internal audit results and management review outputs. Several months of history are needed, not a prepared sample.
Can an internal IT department certify, or only external providers?
Both. An internal IT function delivering services to business units under agreed service levels can be certified, and the customer in the standard’s language is then internal. What has to exist either way is a real agreement with measured targets and reporting, rather than an implicit expectation that systems will simply be available.
How long does certification take?
Six to ten weeks for a service operation already using a ticketing tool with reasonable discipline. The constraint is evidence history: the auditor needs enough months of change records, service reports and at least one management review to sample. Organisations that tidy the process tomorrow but have no record of yesterday end up waiting for the data to accumulate.
💬 WhatsApp Us
📞 CallGet Quote