Home/Services/Certification/ISO/IEC 20000-1:2018

ISO/IEC 20000-1:2018

International standard for IT Service Management Systems (ITSMS).

Overview
What is ISO/IEC 20000-1?

ISO/IEC 20000-1:2018 is the international standard for IT service management systems. It specifies requirements for establishing, implementing, maintaining, and continually improving a service management system — a structured framework for the planning, delivery, control, and improvement of technology-enabled services.

The standard helps organizations manage service quality, customer expectations, service performance, operational controls, and the continual improvement of IT services. It adopts the same high-level management system structure used across major ISO standards, enabling straightforward integration with ISO/IEC 27001, ISO 9001, and other management system frameworks an organization may already operate.

ISO/IEC 20000-1 is applicable to organizations of any size that design, deliver, manage, or support technology-enabled services — whether those services are provided internally to other parts of the same organization, or externally to customers under contractual service arrangements. The standard is technology-neutral and sector-independent, applying equally to cloud services, managed services, enterprise IT operations, and outsourced service delivery.

Key Themes
What does the standard focus on?
Service Delivery
Organizations must plan, implement, and control the processes required to deliver services that meet agreed requirements. This includes service capacity, availability, continuity, and the fulfillment of service requests and incidents within defined targets.
Service Quality
The standard requires organizations to establish quality objectives for services, measure performance against those objectives, and implement controls that drive consistent, reliable service outcomes for customers and users.
Service Lifecycle Management
Organizations must manage the design, transition, and operation of services through a structured lifecycle, ensuring that changes to services and supporting systems are controlled and that new or modified services can be delivered without disruption.
Customer Satisfaction
The standard emphasizes understanding customer requirements, managing customer relationships, handling complaints, and measuring customer satisfaction to ensure that services deliver the outcomes customers need.
Operational Control
Organizations must define and operate the processes that support service delivery, including incident management, problem management, change control, release management, and configuration management.
Continual Improvement
The standard requires organizations to monitor service performance, conduct internal audits, carry out management reviews, and drive continual improvement across the service management system and the services it supports.
Applicability
Who typically implements ISO/IEC 20000-1?
Managed Service Providers
Organizations providing outsourced IT operations, infrastructure management, helpdesk services, or end-user support under contractual service level agreements.
Cloud Service Providers
IaaS, PaaS, and SaaS providers where customers expect evidence that service management processes underpin the reliability, performance, and support of hosted services.
Data Centers
Colocation and managed infrastructure providers where structured incident, change, and availability management processes are fundamental to service commitments.
Technology Companies
Software and platform organizations managing the operational delivery and support of technology products and services to enterprise customers with formal service expectations.
Software Development Organizations
Development and DevOps teams responsible for the ongoing delivery, operation, and improvement of software services requiring structured service management disciplines.
IT Outsourcing Providers
Organizations contracted to deliver IT services on behalf of client organizations, where certification provides independently verified assurance of service management maturity.
Government Technology Departments
Public sector IT functions and shared service centers delivering technology services to government agencies, citizens, or other public bodies subject to service quality obligations.
Telecommunications Providers
Network operators and communications service providers managing technology-enabled service delivery to large enterprise and consumer customer bases.
Financial Institutions
Banks, insurers, and financial services organizations where the availability and reliability of technology services is subject to regulatory operational resilience and continuity requirements.
Internal IT Organizations
Enterprise IT departments and shared service functions delivering technology services to business units within the same organization, seeking to formalise and improve service management practices.
Benefits
Why organizations pursue certification
Improved Service Quality
Structured service management processes reduce incident rates, improve resolution times, and deliver more consistent outcomes for customers and users.
Better Service Governance
Defined policies, roles, and accountabilities for service management create clear ownership and oversight across the service lifecycle.
Enhanced Customer Satisfaction
Systematic management of customer requirements, service level targets, and complaint resolution improves customer experience and retention.
More Consistent Service Delivery
Documented processes and operational controls reduce variability in service outcomes, enabling repeatable delivery across teams, sites, and service lines.
Improved Operational Efficiency
Process standardisation and performance measurement identify inefficiencies, reduce rework, and improve the productivity of service delivery teams.
Stronger Service Performance Monitoring
Defined metrics, reporting, and review mechanisms provide meaningful visibility into service performance and the basis for data-driven improvement decisions.
Greater Business Confidence
Independently verified certification provides customers, partners, and procurement teams with assurance of service management maturity without requiring individual audit access.
Continual Improvement
Built-in monitoring, audit, review, and corrective action processes ensure service management keeps pace with changing customer requirements and operational environments.
Regulatory Context
Is ISO/IEC 20000-1 certification required?

ISO/IEC 20000-1 certification is generally voluntary. However, customer requirements, outsourcing arrangements, public sector procurement requirements, service level agreements, and broader operational excellence expectations frequently encourage organizations to adopt structured service management practices — and certification provides the most credible, independently verified form of that demonstration.

In public sector and government procurement contexts, ISO/IEC 20000-1 certification is increasingly specified as a prerequisite or evaluation criterion for IT service contracts. Procurement frameworks in multiple jurisdictions reference the standard as evidence of service management capability. Organizations tendering for managed services, cloud services, or outsourcing contracts with government or regulated entity clients are often expected to demonstrate certification as a condition of qualifying.

Regulatory frameworks governing operational resilience in financial services — including DORA and equivalent national requirements — create indirect demand for structured IT service management by requiring organizations to demonstrate control over technology services and the third parties delivering them. ISO/IEC 20000-1 certification provides a recognized framework for meeting these expectations, both as a direct service provider and as evidence of service management governance in supplier assurance programs.

Certification Journey
The certification lifecycle
01
Application
The organization submits an application for certification. Exelera reviews the proposed scope of IT services, delivery locations, applicable standard version, and any specific certification requirements.
02
Application Review
Exelera evaluates the application, confirms scope boundaries and audit complexity, and prepares the certification proposal and audit program.
03
Stage 1 Audit
Review of service management system documentation, service scope definitions, process documentation, and organizational readiness for the Stage 2 conformance assessment.
04
Stage 2 Audit
On-site assessment of the implementation and effectiveness of the service management system against all applicable ISO/IEC 20000-1:2018 requirements.
05
Certification Decision
Independent review of the audit report and findings by a Certification Decision Maker not involved in the audit, followed by a formal certification decision.
06
Certificate Issuance
Following a positive certification decision, Exelera issues the certificate and publishes the organization on the public certification register.
07
Surveillance Audit — Year 1
Scheduled surveillance visit conducted no later than 12 months after the certification decision to verify continued conformance and system effectiveness.
08
Surveillance Audit — Year 2
Continued verification of service management system implementation, performance, and the effectiveness of corrective actions from prior audits.
09
Recertification Audit
Comprehensive reassessment of the full service management system scope before renewal of the certification cycle at the end of year three.
10
Certification Renewal
Following a successful recertification audit and positive certification decision, a new three-year certification cycle commences.
FAQ
Common questions
ISO/IEC 20000-1 and ITIL serve different but complementary purposes. ISO/IEC 20000-1 is a certifiable standard that specifies requirements for a service management system — it defines what an organization must have in place and provides the basis for independent third-party certification. ITIL is a framework of best practice guidance that describes how to design and operate IT service management processes. Many organizations use ITIL practices as the implementation approach for meeting ISO/IEC 20000-1 requirements, but ITIL adoption alone does not result in certification.
Yes. ISO/IEC 20000-1 explicitly applies to internal IT service providers — departments or shared service functions that deliver technology services to other parts of the same organization. The standard does not require services to be delivered commercially or under external contracts. Many large enterprises certify their internal IT operations to provide assurance to business stakeholders and to drive service management maturity across the organization. The scope is defined to reflect the services being provided, regardless of whether they are internal or external.
No. ISO/IEC 20000-1 is designed for any organization that designs, delivers, manages, or supports IT services — including technology product companies, software development teams, enterprise IT functions, and shared service centers. The standard does not require an organization to be a commercial service provider or to have external customers. What matters is that the organization is responsible for delivering defined services to identified parties and wishes to manage that delivery through a structured, auditable framework.
The timeline depends on the scope of services, the size and complexity of the organization, and the maturity of existing service management processes. Organizations with established ITIL-based or process-managed environments often require less implementation effort than those building service management disciplines from a lower baseline. Exelera can advise on the expected scope and timeline following an initial review of the organization’s current practices and certification objectives.
Yes. ISO/IEC 20000-1:2018 follows the same harmonized high-level structure used by ISO/IEC 27001 and ISO 9001, enabling straightforward integration of documentation, processes, and audit programs. Organizations commonly pursue integrated management system certifications covering service management, information security, and quality management within a single program. Exelera conducts combined audits across multiple standards, reducing the overall audit burden for organizations managing integrated systems.
The certification scope defines the specific IT services, organizational units, and locations covered by the service management system. The scope must be clearly documented and its boundaries justified. It can cover a specific service line, customer segment, or operational unit rather than the entire organization. Auditors assess whether service management interactions at the scope boundary are appropriately managed. Many organizations begin with a focused scope and expand coverage in subsequent certification cycles.
Nonconformities identified during an audit are formally documented. Major nonconformities must be closed — through verified corrective action — before certification can be granted or maintained. Minor nonconformities require a corrective action plan within an agreed timeframe, with verification of effectiveness at the next scheduled audit. Exelera auditors assess the quality and effectiveness of corrective actions, not only their documentation, when verifying closure.
Certification transfers are possible in most cases. Exelera will review the existing certification, audit history, and current conformance status as part of the transfer assessment. Transfer audits are typically shorter than initial certification audits, reflecting the documented history of conformance. Contact Exelera for specific guidance on the transfer process and the information required to initiate a review.
Applications can be submitted through the Exelera website or by contacting the certification team directly. The application process involves providing information about the services in scope, the organizations and sites involved, and the current state of service management documentation. Exelera will review the application and prepare a certification proposal covering the applicable audit scope, program, and fee structure.
Related Standards
Standards commonly pursued alongside ISO/IEC 20000-1