ISO Certifications

ISO/IEC 20000-1 — IT Service Management

Implementation and certification-readiness support for a service management system — evidence that your IT services are planned, delivered, measured and improved to a recognised standard.

Book a consultation
ISO/IEC 20000-1 IT service management system implementation
ISO/IEC Governing body / standard owner
Advisory Consulting, training & audit readiness
What this covers
ISO 20000-1SMSIT Service ManagementITSM

What ISO/IEC 20000-1 is and why buyers ask for it

ISO/IEC 20000-1 is the international standard for a service management system (SMS): the way an organisation plans, delivers, monitors and improves the IT services it provides. It covers the disciplines an IT service provider is judged on in practice — service levels, incident and problem management, change control, capacity and availability, service continuity, and how suppliers in the chain are managed.

Buyers ask for it because a service contract is a promise about behaviour under pressure. Anyone can commit to a response time in a proposal; ISO/IEC 20000-1 certification is independent evidence that the processes behind that commitment exist, are followed and are reviewed. It appears regularly in outsourcing, managed services and public-sector tenders, often alongside ISO 27001 for information security.

What the certification audit covers

Certification is granted by an independent certification body against the requirements of ISO/IEC 20000-1:2018. The audit looks at the service management system as a whole: the scope and the services within it, the service level agreements and how performance against them is measured, the processes for incidents, problems, changes and releases, the way capacity, availability and continuity are planned, supplier and customer relationships, and the internal audits and management reviews that keep the system honest.

As with other ISO management system standards, the assessment runs in two stages — a review of readiness and documentation, then an audit of the system in operation — followed by surveillance audits across the three-year certification cycle.

How ABS helps

ABS is a consulting firm. We agree the scope of the service management system with you, assess what you already have against the standard, and set out exactly what needs to change. From there we help you build or tidy the processes, put the measurement and reporting in place, run internal audits and the management review, and check that you are ready before the certification body arrives.

Where you already work to ITIL practices, most of the raw material is usually there: the work is often less about inventing processes than about evidencing, measuring and closing the loop on what your teams already do. Each engagement begins with a fixed-price scoping call and a proposal within 24 hours.

Timeline

There is no fixed timeline. It depends on the scope of services you certify, the size of your organisation, the number of sites and shifts involved, and how much of your service management is already documented and operating. You receive a firm timeline with your fixed-price quote, so you know what the path looks like before committing.

Common questions

What is a service management system (SMS)?

It is the set of processes, roles and controls through which you plan, deliver, monitor and improve your IT services — service levels, incident and problem management, change control, capacity, availability, continuity and supplier management among them. ISO/IEC 20000-1 sets the requirements for that system and lets an independent certification body assess it.

How does ISO/IEC 20000-1 relate to ITIL?

They work together and answer different questions. ITIL is a body of best-practice guidance on how to run IT service management, and there is no organisational certificate for it. ISO/IEC 20000-1 is the certifiable standard: it states what a service management system must include, so an organisation using ITIL practices can be certified against ISO/IEC 20000-1.

Who needs ISO/IEC 20000-1?

Organisations that deliver IT or managed services under contract, and internal IT functions that want to demonstrate disciplined service delivery. It is most often asked for by enterprise and public-sector buyers in outsourcing, managed services and support contracts, where the buyer wants evidence that service levels are managed rather than promised.

Can it be combined with ISO 27001 or ISO 9001?

Yes. ISO/IEC 20000-1 shares the harmonised structure of ISO management system standards, so it can run as one integrated system with ISO 27001 for information security or ISO 9001 for quality, and certification bodies can often audit them together. The overlap in documentation, internal audit and management review is considerable.

How long does ISO/IEC 20000-1 certification take?

There is no fixed timeline. It depends on the scope of services you certify, the size of your organisation, the number of sites and shifts involved, and how much of your service management is already documented and operating. You receive a firm timeline with your fixed-price quote.

What does ABS do, and what does the certification body do?

ABS prepares you for certification: we agree the scope of the service management system, assess the gaps, help you implement it, support your internal audit and management review, check readiness and support you through the audits. The certification body, an independent organisation you appoint, carries out the Stage 1 and Stage 2 audits, makes the certification decision and issues the certificate.

Which edition of ISO/IEC 20000-1 is current?

ISO/IEC 20000-1:2018, the third edition of the standard. ISO/IEC 20000-1 is supported by further parts in the 20000 series, such as guidance on applying the standard, but Part 1 is the one certification is granted against.

More services

Related services

ISO Certifications / 01 ISO 27001 information security management implementation

ISO 27001 — Information Security Management

Globally recognised certification for information security management systems (ISMS).

ISO 27001ISMSInformation Security
Get a quote
ISO Certifications / 02 ISO 9001 quality management system documentation review

ISO 9001 — Quality Management

The world's most widely adopted standard for quality management systems.

ISO 9001QMSQuality Management
Get a quote
ISO Certifications / 03 ISO 22301 business continuity management system implementation

ISO 22301 — Business Continuity Management

Implementation and certification-readiness support for a Business Continuity Management System — evidence that your organisation can keep critical operations running through disruption.

ISO 22301BCMSBusiness ContinuityResilience
Get a quote
CMMI & Process / 04 CMMI for Services process maturity improvement

CMMI for Services (CMMI-SVC)

Process maturity improvement for organisations that establish, manage and deliver services — benchmarked against the CMMI Services view.

CMMICMMI-SVCProcess ImprovementIT Services
Get a quote
Cyber Security / 05 SOC 2 controls readiness for a cloud service provider

SOC 2 — Type I & Type II Reports

Readiness and support for SOC 2 reports on security, availability and confidentiality controls, for SaaS and cloud providers.

SOC 2Type IType IITrust Services
Get a quote

Get started

Ready to get certified?

Get a free, fixed-price quote within one business day. No obligation, no sales pressure, no follow-up spam — just a clear path to certification.

Book a 30-min consultation
24-hour response time Fixed price, multi-currency Consulting & audit readiness Remote & on-site delivery
Call us