Management System Certification

ISO/IEC 20000-1 – IT Service Management System

Certifiable proof that your IT service delivery is managed, measured and improving.

  • ISO/IEC 20000-1
  • Recognised internationally

About ISO/IEC 20000-1

What is ISO/IEC 20000-1?

ISO/IEC 20000-1:2018 is the international standard for a Service Management System (SMS). It specifies requirements for planning, designing, transitioning, delivering and improving services to meet agreed service requirements — and it is the only IT service management standard organisations can actually be certified against.

The standard covers the service lifecycle in operational detail: service portfolio and planning, service level management, capacity and demand management, service continuity and availability, information security within service delivery, budgeting, supplier and partner management, incident and service request management, problem management, configuration management, change management, and release and deployment.

ITIL is a body of good practice; ISO/IEC 20000-1 is a certifiable requirement set. Organisations that have adopted ITIL usually find they have most of the process content already and need to add the management system layer — context, leadership, documented planning, internal audit and management review — plus the measurement discipline that turns "we follow ITIL" into demonstrable evidence.

Who needs this?

  • IT managed service providers and outsourcing organisations
  • Internal IT departments delivering services under formal SLAs
  • Cloud, hosting and data centre operators
  • Software product companies operating SaaS platforms with uptime commitments
  • Service desk and technical support operations
  • Organisations bidding for IT contracts where ISO 20000 is a tender requirement

Why organisations certify

Key benefits of ISO/IEC 20000-1

What certification actually returns, stated specifically rather than generically.

Credibility

Certification proves your service management is systematic and audited, not dependent on a handful of experienced individuals.

Market Access

Government, PSU and enterprise IT tenders frequently list ISO/IEC 20000-1 as a qualification criterion alongside ISO 27001.

Risk Reduction

Formal change, problem and configuration management directly reduce change-induced incidents — historically the largest single cause of unplanned downtime.

Operational Efficiency

Capacity planning, problem elimination and request automation reduce firefighting effort and the cost per ticket.

Customer Trust

Published, measured and reviewed service levels change the client relationship from dispute to data.

Regulatory Compliance

Provides a defensible framework for contractual SLA obligations and regulatory service-availability expectations.

How it works

Our process for ISO/IEC 20000-1

Every stage has a defined purpose, a realistic duration and a stated output.

  1. 01

    Application & Quotation

    2–3 working days

    You submit an application form covering scope, headcount, sites and shift pattern. We review complexity, confirm audit-day allocation against accreditation rules and issue a fixed quotation.

  2. 02

    Contract & Audit Planning

    1 week

    On acceptance we appoint a lead auditor with verified technical competence for your sector, agree audit dates and share the audit plan in advance.

  3. 03

    Stage 1 — Readiness Review

    1 day (typical)

    A documentation and readiness assessment: scope confirmation, review of your management system documents, internal audit and management review evidence, and identification of anything that would block Stage 2.

  4. 04

    Stage 2 — Certification Audit

    2–5 days (scope dependent)

    On-site assessment of the system in operation. We sample processes, interview staff, examine records and raise findings graded as major, minor or opportunity for improvement.

  5. 05

    Corrective Action & Decision

    2–4 weeks

    You close out any nonconformities with root-cause analysis and evidence. An independent certification decision-maker — not the audit team — reviews the file and grants certification.

  6. 06

    Certificate Issue

    3–5 working days

    A three-year certificate is issued and your organisation is listed on our public certified-client directory for verification by your customers.

  7. 07

    Surveillance & Recertification

    Annual

    Surveillance audits at 12 and 24 months confirm the system remains effective. A full recertification audit is completed before the three-year expiry.

Preparation

Documents required

What we will ask to see. Having these ready before Stage 1 is the single biggest factor in a certification that runs to schedule.

  • Completed and signed application form
  • Certificate of incorporation / business registration
  • Organisation chart and scope statement
  • Management system manual or equivalent documented information
  • Documented processes, procedures and work instructions
  • Internal audit reports covering the full scope
  • Management review minutes
  • Records of corrective actions and continual improvement
  • Applicable legal and regulatory licences for your activity
  • Service management policy, objectives and service management plan
  • Service catalogue and documented service level agreements
  • SLA performance reports and service review minutes
  • Incident, service request and major incident procedures with records
  • Problem management records with root-cause analysis and known-error database
  • Change management records including emergency change and post-implementation review
  • Configuration management database and verification records
  • Capacity and availability plans; service continuity plans and test results
  • Supplier and partner agreements with performance monitoring records

Not sure whether your scope is right?

Scope is the single thing most often got wrong, and it appears verbatim on your certificate. We will review yours before you apply, at no charge — it costs us less than fixing it at recertification.

Talk to a specialist

Common questions

ISO/IEC 20000-1 — frequently asked questions

Direct answers, including where the honest answer is inconvenient for us.

No. ITIL is a framework of good practice and its certifications are held by individuals. ISO/IEC 20000-1 is a standard that organisations are certified against. ITIL adoption is excellent preparation but is neither necessary nor sufficient on its own.

Yes, but the standard requires you to demonstrate governance of processes operated by other parties. You must show control of the outsourced services through defined requirements, monitoring and review. You cannot certify a scope whose processes you neither operate nor govern.

Very commonly, yes. The two share a management system structure and interlock at incident management, change management, capacity and continuity. An integrated audit programme reduces total audit days and prevents two systems drifting apart.

Question not answered here? Ask a certification specialist — we answer technical questions without requiring an enquiry first.

Talk to us

Talk to a certification expert

Tell us your scope and headcount and we will send a fixed quotation for ISO/IEC 20000-1 with the audit-day calculation shown.

  • Quotation within 2–3 working days
  • IAF MD 5 audit-day calculation included
  • Full three-year cycle cost, not just the first audit
  • Your details are used only to answer this enquiry

Including contractors and shift staff — this sets your audit days.

Tell us your scope, whether design is included, and any deadline you are working to.

Your details are used only to answer this enquiry. We do not sell or share them.

Next step

Ready to certify to ISO/IEC 20000-1?

We will scope it honestly, show you the calculation behind the price, and tell you plainly if the timeline you need is not achievable.