Compliance · Certifiable standard

ISO/IEC 20000 — IT service management

The certification that says your IT service delivery is managed, not improvised.

ISO/IEC 20000-1 is the international standard for a service management system (SMS). It certifies that you plan, deliver, measure, and improve IT services deliberately — the difference between a service desk and a managed service.

SMS

Service mgmt system

ITIL-aligned

Practice fit

3 yr

Certification cycle

What ISO 20000 requires

It certifies the system that runs your services, not the tooling you bought.

A service management system

Service planning, catalogue, levels, and the governance loop around them — plus the measurement that proves you're meeting what you promised.

Core processes

Incident, request, problem, change, configuration, release, capacity, availability, continuity, and supplier management — defined, operating, and evidenced.

Measured commitments

SLAs mean something only if measured and reported. The standard expects targets, actual performance, and action when you miss.

Who needs ISO 20000

Providers whose product is service delivery itself.

  • Managed service providers and outsourcers
  • Internal IT organizations proving service maturity
  • Providers bidding into public sector or enterprise RFPs
  • Companies standardizing delivery across regions or acquisitions

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

Gap assessment

We compare your current delivery against 20000-1 and find what's genuinely missing versus merely undocumented.

SMS design

We build the service management system — catalogue, levels, roles, and the governance cadence.

Process implementation

We define and operationalize incident, change, problem, and the rest without drowning your team in ceremony.

Measurement

We instrument SLAs and service reporting so performance is provable, not asserted.

Supplier management

We bring your subcontractors and vendors into scope, which is where multi-tier providers usually fail.

Certification support

We prepare for Stage 1 and Stage 2 and support surveillance audits.

How the engagement runs

1

Scope & gap

Define services in scope and assess against 20000-1.

2

Design the SMS

Catalogue, service levels, roles, governance.

3

Implement processes

Stand up and operate the core service processes.

4

Measure

Report performance and act on misses.

5

Certify

Stage 1 and Stage 2 audit, then surveillance.

Frequently asked questions

Is ISO 20000 the same as ITIL?

No. ITIL is a body of best-practice guidance you can adopt however you like; ISO/IEC 20000-1 is an auditable standard you can certify against. ITIL practices map well onto 20000 requirements, so ITIL-mature organizations usually have a shorter path.

Do we need ISO 20000 and ISO 27001?

They answer different questions — 20000 is about service delivery, 27001 about information security. Many MSPs hold both because customers ask for both. The management-system clauses overlap substantially, so the second certification is far cheaper than the first.

Can we certify only part of our business?

Yes — you define the scope, by service, site, or business unit. Scoping deliberately is how you keep a first certification achievable, provided the scope is coherent and honestly stated on the certificate.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

ISO 20000 for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.