ISO/IEC 20000-1:2018 — IT Service Management

The IT service management standard. Certifiable proof of disciplined service delivery, and the one buyers ask MSPs for by name.

ISO and IEC. Certification is issued by accredited certification bodies.

What it is

ISO/IEC 20000-1 is the international standard for a Service Management System — an SMS. It governs how IT and managed services are planned, delivered, measured and improved: the discipline behind service levels, incident and problem management, change control, capacity, availability and service continuity.

It is frequently confused with ITIL, and the distinction matters. ITIL is a body of good practice you can adopt selectively. ISO/IEC 20000-1 is a certifiable standard with auditable requirements. Organisations often use ITIL practices to satisfy 20000-1 requirements, but only the standard produces a certificate.

Like ISO 27001 it follows the Annex SL structure across Clauses 4 to 10, then adds service-specific requirements: service portfolio and catalogue, relationship and supply management, service level management, budgeting, demand and capacity, service continuity and availability, and the incident, request, problem, change, configuration and release processes.

Who it's for

Organisations whose product is a service delivered and supported over time.

Managed service providers

The clearest case. It differentiates on delivery discipline rather than price, which matters particularly against low-cost offshore competition where the buyer's real concern is reliability.

IT vendors bidding for government and enterprise panels

20000-1 alongside ISO 9001 and ISO 27001 is a recognised qualification set for ICT panel applications.

Internal IT functions

Under pressure to demonstrate service maturity to their own executive or to a parent organisation, where an external benchmark carries more weight than an internal assertion.

Software vendors offering hosted or supported products

Where customers are contracting for availability and response, not just a licence.

Why implement it

  • It proves service maturity to buyers. For an MSP it is the difference between claiming disciplined delivery and evidencing it. Government and enterprise buyers increasingly ask for it by name.
  • It reduces firefighting. Formal change and problem management are the two disciplines that most reliably cut repeat incidents, because problems get root-caused rather than repeatedly restored.
  • It makes SLAs defensible. Service levels backed by measurement and reporting stop being a negotiating position and become a managed commitment.
  • It supports continuity obligations. Clients subject to APRA CPS 230 must evidence the operational resilience of their material service providers — which is what a certified SMS demonstrates.
  • It pairs cheaply. Shared Annex SL clauses and heavy overlap in change, incident and supplier management with ISO 27001 and ISO 9001.

How implementation works

Five to eight months, faster for organisations already running a mature service desk where much of the work is formalising existing practice.

1. Gap assessment

Review the current service desk, change process, service catalogue and reporting against the standard.

2. Scope and service definition

Establish which services are in scope and build the service catalogue. Where services are delivered partly by subcontractors, the standard imposes specific governance requirements that must be settled here rather than discovered at audit.

3. Service level and measurement design

Define service levels measurable with data you actually collect, and establish the reporting that will be put in front of an auditor. Service levels you cannot measure are worse than none.

4. Build the processes

Incident, request, problem, change, configuration and release management, service continuity and availability planning, capacity and demand management, supplier and relationship management — configured in the service desk tooling you already run.

5. Operate the system

Two to three months. The SMS must produce a track record: incidents resolved against target, changes assessed and approved, problems root-caused, service reports issued and reviewed.

6. Internal audit and management review

7. Stage 1 and Stage 2 certification audit

How Soveriq helps

Soveriq configures the service management system in the tooling you already operate, so the processes an auditor examines are the processes your team actually uses day to day.

Where ISO 27001 or ISO 9001 are in scope, the shared clauses and the overlap in change, incident and supplier management make the combined programme substantially cheaper than three separate ones.

On internal audit. Where Soveriq has built your management system, we do not then audit it and present that as an independent internal audit. What we provide is readiness validation, labelled as such. Where an independent internal audit is needed after a Soveriq build, it is performed by someone independent of that build and disclosed to you in writing.

What we will not do. Soveriq does not issue certificates, is not a certification body, and does not promise a certification outcome.

What the engagement looks like

  • Module 01 — Gap analysis of the service desk, change process, catalogue and reporting.
  • Module 02 — Build. Service catalogue, SLA and measurement design, and the incident, request, problem, change, configuration and release processes configured in your existing tooling.
  • Module 03 — Internal audit, subject to the impartiality position above.
  • Module 04 — Audit representation through Stage 1 and Stage 2.
  • Module 05 — Continuous compliance and surveillance readiness.

Price floors are published on the pricing page. Certification body fees are separate and paid directly to that body.

Common questions

Is this the same as ITIL?

No, and the distinction matters commercially. ITIL is a body of good practice you can adopt selectively; there is no ITIL certificate for an organisation. ISO/IEC 20000-1 is a certifiable standard with auditable requirements. Organisations commonly use ITIL practices to satisfy 20000-1 requirements, but only the standard produces a certificate a buyer can ask for.

We are already certified to ISO 27001. How much extra is this?

Less than you would expect. They share Clauses 4 to 10, and there is heavy overlap in change management, incident management and supplier management. The additional work concentrates on the service-specific requirements — catalogue, service levels, capacity and service continuity.

What if subcontractors deliver part of our service?

The standard has specific governance requirements for that arrangement, and they need to be settled early in scoping. You remain accountable for services delivered on your behalf, which is precisely what your customers are trying to establish.

Do we need a particular service desk tool?

No. The standard specifies requirements, not products. What matters is that the processes operate and produce records, which most established service desk platforms support out of the box.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope