+359 887 407 840 office@escert.com Stara Zagora · Sofia · Plovdiv
BGEN

ResourcesISO/IEC 20000-1Information security

ISO/IEC 20000-1 — IT service management system

Predictable, measurable and continually improving IT services

ISO/IEC 20000-1 is the international standard that sets out the requirements for an IT service management (ITSM) system. It defines how an organization plans, delivers, maintains and improves its IT services so that they meet the needs of the business and its customers.

Euro Standard CertificationThe ESCERT team Published
Updated
3 minread
A team with laptops and documents at a work table

What is ISO/IEC 20000-1?

ISO/IEC 20000-1 sets out the requirements for a service management system — the policies, processes and responsibilities through which an organization delivers high-quality, reliable IT services.

The standard applies both to IT departments within organizations and to companies that provide IT services to external customers — for example support, hosting, cloud services, infrastructure management or software development as a service.

Its requirements help the organization build a structured approach to managing incidents, changes, service levels, suppliers and other key processes. The core of the standard follows the common structure of ISO management system standards, which is why ISO/IEC 20000-1 combines easily with ISO 9001 and ISO/IEC 27001 in a single integrated system.

How does ISO/IEC 20000-1 relate to ITIL?

ITIL and ISO/IEC 20000-1 complement each other: ITIL is a body of good practice for IT service management, while ISO/IEC 20000-1 is a standard with requirements, and conformity with them is verified in an audit.

ITIL

  • A framework of good practice
  • Describes how processes can be organized
  • It is people who are trained, not the organization that is certified

ISO/IEC 20000-1

  • An international standard with requirements
  • Defines what the system must achieve
  • The organization is certified after an audit

Many organizations use ITIL practices to build their processes and ISO/IEC 20000-1 to demonstrate to their customers that these processes work systematically.

Which processes does the standard cover?

The standard covers the processes across the entire service life cycle — from planning and agreeing services to delivering, supporting and improving them.

Main process groups in ISO/IEC 20000-1:2018
GroupExample processes
Service portfolioservice planning, service catalogue, asset and configuration management
Relationships and agreementsbusiness relationship, service level and supplier management
Supply and demandbudgeting and accounting for services, demand and capacity management
Design and transitionchange management, service design and transition, release and deployment management
Resolution and fulfilmentincident, service request and problem management
Service assuranceavailability, continuity and information security management
  1. 1Plan

    You define which services you provide, to whom and at what service levels.

  2. 2Design and transition

    New and changed services are designed, tested and introduced in a controlled way.

  3. 3Delivery

    Incidents, requests and problems are handled according to clear rules and timeframes.

  4. 4Measurement and improvement

    Results are monitored, analysed and used to improve the services.

What are the benefits of ISO/IEC 20000-1 certification?

ISO/IEC 20000-1 certification improves the quality of IT services and demonstrates the organization’s commitment to reliability and customer focus.

  • Better service qualityClearly defined processes and control over service delivery.
  • More satisfied customersServices are delivered in a predictable and measurable way.
  • Efficiency and lower costsBetter management of resources, incidents and changes.
  • International recognitionThe certificate shows that the organization works according to established international practice.
  • Competitive advantageOften a requirement or an advantage in public procurement and international projects.
  • Continual improvementThe standard encourages systematic measurement, analysis and improvement of processes.

How does certification work?

Certification works in the same way as for other management system standards — with a two-stage audit and a three-year cycle.

  1. Stage 1 — a review of the documentation, the scope of services and readiness for the audit.
  2. Stage 2 — an on-site check of how the processes are applied in practice.
  3. Issue of a certificate valid for 3 years, with surveillance audits in the second and third years.
  4. A recertification audit before the certificate expires.

Audits are conducted in Bulgarian. If you want to certify several systems at the same time, see Certification to two or more standards.

ISO/IEC 20000-1 certificationQuote within two hours during business hoursRequest a quote

Questions about ISO/IEC 20000-1

Who is ISO/IEC 20000-1 suitable for?

For IT departments within organizations and for companies that provide IT services to external customers — regardless of their size.

Can an organization be certified to ITIL?

No. ITIL is a framework of good practice in which people are trained. An organization demonstrates the systematic management of its IT services through ISO/IEC 20000-1 certification.

Can ISO/IEC 20000-1 be combined with ISO/IEC 27001?

Yes. Both standards follow the common structure of ISO management system standards and are often implemented and audited together.

How long is the certificate valid?

The certificate is valid for 3 years, with surveillance audits in the second and third years and recertification before it expires.

Free preliminary assessment and quote

ISO/IEC 20000-1 certification with a quote within two hours

Describe your services, locations and the number of employees within the scope — you will receive a quote with the scope, the audit duration and an all-inclusive price.