ISO/IEC 20000-1:2018 IT Service Management System Certification
ISO 20000-1 is the certifiable standard for IT service management — the audited proof that the ITIL practices you claim to follow actually operate, with evidence tied to your service levels.
4.9/5 average client rating · 1200+ engagements delivered
What the standard covers
ISO 20000-1 requires a service management system that plans, delivers, operates and improves services against agreed levels. It is the only ITSM standard against which an organisation can be certified — ITIL provides practice guidance but offers organisational certification for neither ITIL v3 nor ITIL 4.
The 2018 revision adopted the Annex SL structure, strengthened service portfolio and demand management, and clarified requirements where services are delivered through third parties — which matters if you subcontract any part of delivery.
- Service portfolio, service catalogue and demand and capacity planning
- Service level management with measurable SLAs, OLAs and underpinning contracts
- Incident, service request, problem, change, release and configuration management
- Service continuity and availability management aligned to agreed targets
- Information security within service management, and supplier and partner management
- Service reporting, internal audit, management review and continual improvement
Key facts
| Standard | ISO/IEC 20000-1:2018 |
|---|---|
| Relationship to ITIL | ITIL is guidance and cannot be certified organisationally; ISO 20000-1 is the certifiable standard |
| Core processes | Service level, incident, problem, change, configuration, release, capacity, continuity and supplier management |
| Typical timeline | 10–16 weeks |
| Integrates with | ISO 27001, ISO 22301, ISO 9001 |
Implementation components
We work inside your existing ITSM tool so the standard is enforced by the workflow, not by a separate document set.
Service catalogue & SLAs
Defined services, service levels, measurement method and reporting cadence agreed with customers.
Incident & request management
Categorisation, prioritisation, escalation matrices, major incident procedure and SLA-driven workflow.
Problem management
Root cause analysis discipline, known error database and proactive problem identification from incident trends.
Change & release
Change advisory board, risk-based approval, standard change catalogue, release planning and rollback criteria.
Configuration management
CMDB scope, CI relationships, verification and audit routines that keep the data trustworthy.
Capacity & continuity
Capacity plan tied to demand forecasts, availability targets and service continuity aligned with ISO 22301.
Who certifies
Service providers whose customers buy against SLAs, and internal IT functions that need to demonstrate maturity.
- Managed service providers, NOC and SOC operators
- IT outsourcing and application maintenance vendors
- Cloud, hosting and infrastructure service providers
- Government IT service contractors where ISO 20000-1 is a tender requirement
- Large internal IT departments running a shared service model
SLA performance improves
Structured incident and problem management reduces repeat incidents and drives measurable MTTR reduction.
Tender qualification
Frequently mandatory for government and large enterprise IT outsourcing contracts.
ITIL made auditable
Turns ITIL practices into evidenced processes with owners, metrics and audit trails.
Fewer escalations
Clear service boundaries and OLAs remove the ambiguity that generates customer escalations.
How the engagement runs
Service definition
Service catalogue, scope boundary, customer commitments and current SLA performance baseline.
Process design
Process definitions, RACI, workflow configuration in your ITSM tool and reporting design.
Deployment & training
Rollout to service desk and delivery teams, CAB establishment and CMDB population.
Measurement & audit
Service reporting cycle, internal audit against every clause, corrective actions and management review.
Certification
Stage 1 and Stage 2 audit support and non-conformity closure.
What you receive
- SMS scope, service catalogue and service level agreements
- Process definitions and RACI for all clause 8 service management processes
- ITSM tool workflow configuration guidance and reporting dashboards
- Change management framework, CAB charter and standard change catalogue
- CMDB scope, configuration baseline and verification routine
- Capacity plan, availability targets and service continuity plan
- Internal audit programme, management review pack and certification support
ISO 20000-1 — frequently asked questions
No. ITIL certification applies to individuals, not organisations. If a tender asks for organisational ITSM certification, ISO/IEC 20000-1 is the standard that satisfies it, and it accommodates ITIL 4 practices comfortably.
No. The standard is tool-agnostic. That said, evidencing SLA measurement, change approvals and CMDB accuracy manually is painful — we implement inside whatever tool you use, or advise on selection if you are between platforms.
They complement each other directly: ISO 20000-1 clause 8.7.3 addresses information security within service management, and both share Annex L structure. Integrated certification is common for managed service providers and reduces audit days substantially.
Yes, but you must demonstrate governance over those suppliers — the 2018 revision is explicit that you cannot claim conformity for processes wholly controlled by another party. Supplier agreements, performance monitoring and escalation rights are audited closely.
CMDB accuracy and change management discipline. Auditors sample changes and trace them to approvals, testing and configuration records. We run a change audit during internal audit specifically to catch this before the certification body does.
Still not sure what applies to you?
Ask an assessor directly — we answer scoping questions before anyone talks about a fee.
Get a realistic timeline and a fixed fee
A 30-minute call is usually enough to scope ISO 20000-1 accurately. You will leave with a timeline, an evidence checklist and a number — whether or not you engage us.