What is ISO/IEC 20000-1?
ISO/IEC 20000-1 sets out the requirements for a service management system — the policies, processes and responsibilities through which an organization delivers high-quality, reliable IT services.
The standard applies both to IT departments within organizations and to companies that provide IT services to external customers — for example support, hosting, cloud services, infrastructure management or software development as a service.
Its requirements help the organization build a structured approach to managing incidents, changes, service levels, suppliers and other key processes. The core of the standard follows the common structure of ISO management system standards, which is why ISO/IEC 20000-1 combines easily with ISO 9001 and ISO/IEC 27001 in a single integrated system.
How does ISO/IEC 20000-1 relate to ITIL?
ITIL and ISO/IEC 20000-1 complement each other: ITIL is a body of good practice for IT service management, while ISO/IEC 20000-1 is a standard with requirements, and conformity with them is verified in an audit.
ITIL
- A framework of good practice
- Describes how processes can be organized
- It is people who are trained, not the organization that is certified
ISO/IEC 20000-1
- An international standard with requirements
- Defines what the system must achieve
- The organization is certified after an audit
Many organizations use ITIL practices to build their processes and ISO/IEC 20000-1 to demonstrate to their customers that these processes work systematically.
Which processes does the standard cover?
The standard covers the processes across the entire service life cycle — from planning and agreeing services to delivering, supporting and improving them.
| Group | Example processes |
|---|---|
| Service portfolio | service planning, service catalogue, asset and configuration management |
| Relationships and agreements | business relationship, service level and supplier management |
| Supply and demand | budgeting and accounting for services, demand and capacity management |
| Design and transition | change management, service design and transition, release and deployment management |
| Resolution and fulfilment | incident, service request and problem management |
| Service assurance | availability, continuity and information security management |
- 1Plan
You define which services you provide, to whom and at what service levels.
- 2Design and transition
New and changed services are designed, tested and introduced in a controlled way.
- 3Delivery
Incidents, requests and problems are handled according to clear rules and timeframes.
- 4Measurement and improvement
Results are monitored, analysed and used to improve the services.
What are the benefits of ISO/IEC 20000-1 certification?
ISO/IEC 20000-1 certification improves the quality of IT services and demonstrates the organization’s commitment to reliability and customer focus.
- Better service qualityClearly defined processes and control over service delivery.
- More satisfied customersServices are delivered in a predictable and measurable way.
- Efficiency and lower costsBetter management of resources, incidents and changes.
- International recognitionThe certificate shows that the organization works according to established international practice.
- Competitive advantageOften a requirement or an advantage in public procurement and international projects.
- Continual improvementThe standard encourages systematic measurement, analysis and improvement of processes.
How does certification work?
Certification works in the same way as for other management system standards — with a two-stage audit and a three-year cycle.
- Stage 1 — a review of the documentation, the scope of services and readiness for the audit.
- Stage 2 — an on-site check of how the processes are applied in practice.
- Issue of a certificate valid for 3 years, with surveillance audits in the second and third years.
- A recertification audit before the certificate expires.
Audits are conducted in Bulgarian. If you want to certify several systems at the same time, see Certification to two or more standards.
Questions about ISO/IEC 20000-1
Who is ISO/IEC 20000-1 suitable for?
For IT departments within organizations and for companies that provide IT services to external customers — regardless of their size.
Can an organization be certified to ITIL?
No. ITIL is a framework of good practice in which people are trained. An organization demonstrates the systematic management of its IT services through ISO/IEC 20000-1 certification.
Can ISO/IEC 20000-1 be combined with ISO/IEC 27001?
Yes. Both standards follow the common structure of ISO management system standards and are often implemented and audited together.
How long is the certificate valid?
The certificate is valid for 3 years, with surveillance audits in the second and third years and recertification before it expires.