ISO/IEC 20000-1:2018IT service management systems
ISO/IEC 20000-1 sets out what a service provider needs in place to plan, deliver, support and improve the services it has agreed with its customers. It is the certifiable standard for service management: ITIL describes good practice, and ISO/IEC 20000-1 states requirements that an auditor can check. It is used mainly by providers of IT services, for outside clients or for their own organization.

01At a glance
- Standard
- ISO/IEC 20000-1:2018
- Subject
- IT service management systems
- Certificate
- Issued by AQC Group. Valid for three years, with a surveillance audit each year.
- Often combined with
- ISO/IEC 27001, ISO 9001
- Sectors
- IT companies
- Facts checked
- 9 October 2026, against iso.org
Who it is for
- Managed service providers and IT outsourcing firms
- Hosting, cloud and data centre operators
- Internal IT departments that serve a large organization
- Telecom and network service providers
- Software companies that run and support what they build
- Service desks and shared service centres
02What you gain
What certification to ISO/IEC 20000-1 gives you
A requirement in service tenders
Contracts for outsourced IT, hosting and support often ask for ISO/IEC 20000-1 certification or evidence of an equivalent system. The certificate is that evidence.
Service levels you can prove
Targets are agreed, measured and reported to the customer on a schedule. A dispute about whether the service was delivered is settled by the record.
Changes that break less
Changes are assessed, approved, tested and scheduled before they go live, with a way back if they fail. That removes a frequent cause of outages.
Problems fixed at the cause
Recurring incidents are analysed as problems and the cause is removed, so the service desk stops answering the same call.
Clear lines with suppliers
Where other companies or internal teams deliver part of the service, their obligations are written down and measured against what you promised the customer.
03What it asks of you
What ISO/IEC 20000-1 asks you to have in place
In plain terms and in our words, not the standard's. The standard itself is the authority, and you will need a copy.
Scope, policy and a service management plan
State which services the system covers, for which customers and from which locations. Top management sets a service management policy and objectives and approves a plan: the services you provide, the resources, the roles, the tools and the known limits. You remain accountable for the whole system even where others run parts of it. A provider that hands every service and process in the scope to other parties cannot be certified.
Service catalogue, assets and configuration
Keep a catalogue of the services you offer, written so that customers can understand it. Know which assets deliver each service. Record the configuration items that matter, such as servers, applications, network devices and licences, and how they depend on each other, and keep those records accurate as things change.
Customers, service levels and suppliers
Agree service levels with each customer in writing, measure performance against them and review the results with the customer at planned intervals. Record complaints and manage each one to a close. Hold agreements with suppliers, external or internal, whose targets support what you promised the customer, and monitor how they perform.
Budget, demand and capacity
Budget and account for the cost of services, so that decisions about them are made on figures. Forecast demand. Plan the people, technology and information needed to meet it, and monitor actual use against the plan.
Change, release and deployment
Have a change management policy that says which changes are controlled and how they are classified, emergency changes included. Assess, approve, schedule and review each change. New or significantly changed services are planned, designed, built and tested against agreed acceptance criteria. Releases are deployed in a controlled way, with a plan for reversing one that fails.
Incidents, service requests and problems
Record every incident and service request, classify and prioritize it, resolve or fulfil it and close it, with a defined route for major incidents. Analyse incident data to find problems and their root causes. Record known errors and workarounds until a permanent fix is in place.
Availability, continuity and information security
Agree availability targets, monitor them and investigate unplanned downtime. Assess the risks to service continuity, keep a continuity plan and test it. Set an information security policy for the services, apply controls that match the risks, and handle security incidents by a defined procedure.
Measuring, auditing and improving
Report on the performance of the services and of the system itself. Run internal audits and management reviews. Keep a list of opportunities for improvement, decide which to act on using set criteria, and check afterwards whether each one delivered what was expected.
04The audit
How certification to ISO/IEC 20000-1 works
Application and quotation
You tell us your scope, sites and headcount. We quote the audit days the standard's rules require.
Stage 1 audit
A review of your documented system and your readiness. You get a list of anything to settle before stage 2.
Stage 2 audit
The auditor follows your processes on site and samples records, to see that the system is in use and works.
Decision
Nonconformities are answered, the file is reviewed independently of the audit team, and AQC Group issues the certificate.
Surveillance and recertification
A shorter audit in each of the next two years, then a full recertification audit in the third.
What the auditor looks at
- The scope statement, and how other parties that deliver part of the service are controlled
- Service level agreements, the reports sent to customers and what was done about missed targets
- A sample of changes followed from request to the review after implementation
- Incident, major incident and problem records, and whether known errors lead to fixes
- Configuration records compared with what is actually running
- Availability and continuity plans, the last test and its results
What affects audit time
- The number of people who work within the service management system
- The number and variety of services in the scope, and how many customers they serve
- The number of sites, and whether the service desk or operations run around the clock
- How much of the service is delivered by suppliers or by other internal teams
05Often combined with
Standards audited alongside ISO/IEC 20000-1
Standards that share a structure can be audited together, in one visit and against one set of documents.
06Questions
Questions about ISO/IEC 20000-1
We follow ITIL. Why would we need ISO/IEC 20000-1?
ITIL is a framework of recommended practices. People study it and take examinations in it, and an organization adopts as much of it as suits its work. It is not a standard that an organization is audited and certified against. ISO/IEC 20000-1 is a set of requirements. A certification body can audit your service management system against them and issue a certificate.
The two fit together. Processes built on ITIL cover much of what the standard asks for. What the standard adds is the management system around those processes: a defined scope, a policy and objectives, internal audit, management review and documented evidence. ISO also publishes guidance on how ISO/IEC 20000-1 and ITIL relate.
How is it different from ISO/IEC 27001?
ISO/IEC 27001 is about protecting information. It starts from the risks to confidentiality, integrity and availability and covers everything within its scope. ISO/IEC 20000-1 is about delivering services as agreed: service levels, changes, incidents, capacity, continuity. It includes information security, but as one part of managing the service and in less depth.
The two standards share the same management system structure, so the policy framework, internal audit, management review and corrective action can be run once for both. A provider that holds one already has part of the other in place.
Is the 2018 edition still current?
Yes. ISO reviewed ISO/IEC 20000-1:2018 in 2023 and confirmed it, which means the edition remains current. Amendment 1, published in February 2024, asks organizations to consider whether climate change is a relevant issue for their system.
Does it apply only to IT services?
No. The standard was developed in the IT field and its vocabulary of incidents, changes, releases and configuration comes from there. Its requirements are generic, though, and are meant to apply to a service provider of any size and with any kind of service. What matters is that you deliver a defined service to a customer under agreed terms.
Can an internal IT department be certified?
Yes. The provider can be a department that serves the rest of its own organization. The scope then names the internal customers, and documented service levels agreed with them take the place of a contract. They are measured and reviewed in the same way.
Ask about ISO/IEC 20000-1 for your organization.
Tell us your scope, your sites and how many people work in them. We will tell you what the audit involves.