WHAT IT IS
IT Service Management
Running IT services reliably and measurably
CURRENT VERSION
ISO/IEC 20000-1:2018
The certifiable part of the series
CERTIFIABLE?
Yes
Through an accredited certification body
BEST FOR
MSPs & IT providers
Internal IT teams too
STANDARD EXPLANATION
What is ISO 20000?
ISO/IEC 20000-1 is the international standard for IT service management — it defines a service management system, or SMS. It sets out what's needed to plan, deliver, and continually improve IT services so they reliably meet the needs of the people relying on them: things like service levels, incident and problem management, change control, and measuring whether you're actually delivering what you promised.
If you know ITIL, the concepts will feel familiar — but there's an important difference. ITIL is a library of good practices; it isn't something you can be certified against. ISO 20000 is a certifiable standard, so it lets you formally demonstrate the maturity of how you run services. The current version is ISO/IEC 20000-1:2018, which follows the same harmonised high-level structure as other ISO management standards.
It's particularly relevant for managed service providers and IT service businesses. When a client wants proof that you won't drop the ball on their systems, an ISO 20000 certificate is a recognised, independent way to show it.
This is an MSP's natural fit. If you're a managed service provider, ISO 20000 evidences service maturity in procurement — often alongside ISO 27001, which covers the security side of the same conversation.
WHY PEOPLE COME TO US FOR IT
Do you actually need ISO 20000?
It matters most when how you deliver IT services is itself the product, or close to it. The trigger usually looks like one of these.
01
A client contract wants evidence of maturity. A customer — often a larger one — wants proof that your service management is structured and reliable before they'll commit.
02
You want consistent delivery as you scale. Incidents and changes are handled differently depending on who's on shift, and you want that to stop as you grow.
03
You want to formalise your ITIL practices. You already work in an ITIL-ish way and want to turn that into something certifiable you can point to.
HOW WE HELP
Two ways in. Same principle throughout.
Whether we're independently auditing your SMS or helping you build it, you stay involved and walk away understanding it. Here's how that splits for ISO 20000.
Audit & Assessment · Independent
We check your system against the standard.
Impartial, evidence-based work — and kept separate from your certification body, so nobody's marking their own homework.
-
Gap analysis against ISO 20000 before you commit
-
Internal audits to satisfy clause 9.2 (required to certify)
-
Review of your Service Catalogue and delivery processes
-
Clear findings — conformities, nonconformities, observations
Implementation Support · Collaborative
We help you build the SMS — alongside you.
Hands-on help with the parts that genuinely need it, with your team driving the work so you can run it afterwards.
-
Scoping your SMS around the services you actually run
-
Defining service management processes that fit your team
-
Writing procedures with you, not for you
-
Preparing for the certification audit
COMMON QUESTIONS
ISO 20000 questions we hear a lot
Is ISO 20000 the same as ITIL?
No, though they're related. ITIL is a library of service management good practices — useful, but not something you certify against. ISO 20000 is a certifiable standard. Many organisations use ITIL practices to help meet ISO 20000, so they work well together.
Who is ISO 20000 actually for?
Most often managed service providers and IT service businesses, but also internal IT functions that want to run services in a structured, measurable, and efficient way. If delivering IT services reliably is core to what you do, it's relevant.
What's the current version?
ISO/IEC 20000-1:2018 is the current certifiable version of ISO 20000, setting out the requirements for an effective Service Management System (SMS), while the wider ISO 20000 family includes additional guidance and supporting standards.
Is an internal audit required?
Yes. Clause 9.2 requires you to run internal audits of your SMS at planned intervals. You need evidence of internal audits both to achieve certification and to keep it at each surveillance visit. Using an independent auditor keeps those findings credible — and is exactly the kind of work we do.
Can I run it alongside ISO 27001 or any other ISO standards?
Yes, and many do. Many ISO standards share the same high-level structure, so you can operate an integrated management system rather than two separate ones — less duplication, fewer audits. If done correctly, the standards can complement each other and help you grow your business in a mature and consistent way.
Do you issue the certificate?
No — and that separation matters. The certificate is issued by an accredited certification body after their own Stage 1 and Stage 2 audits. We're independent of that process. We help you get ready and run the internal audits the standard requires, but we don't mark our own work or yours.
RELATED STANDARDS
Often comes up alongside
ISO 27001
The security half of the MSP conversation - extremely common to run both together.
Information Security
ISO 9001
The same consistency mindset applied to your whole organisation, not just IT services.
Quality Management
SOC 2
Often requested by US customers of service providers as an alternative form of assurance.

