Compliance · Certifiable standard
The certification that says your IT service delivery is managed, not improvised.
ISO/IEC 20000-1 is the international standard for a service management system (SMS). It certifies that you plan, deliver, measure, and improve IT services deliberately — the difference between a service desk and a managed service.
SMS
Service mgmt system
ITIL-aligned
Practice fit
3 yr
Certification cycle
It certifies the system that runs your services, not the tooling you bought.
Service planning, catalogue, levels, and the governance loop around them — plus the measurement that proves you're meeting what you promised.
Incident, request, problem, change, configuration, release, capacity, availability, continuity, and supplier management — defined, operating, and evidenced.
SLAs mean something only if measured and reported. The standard expects targets, actual performance, and action when you miss.
Providers whose product is service delivery itself.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We compare your current delivery against 20000-1 and find what's genuinely missing versus merely undocumented.
We build the service management system — catalogue, levels, roles, and the governance cadence.
We define and operationalize incident, change, problem, and the rest without drowning your team in ceremony.
We instrument SLAs and service reporting so performance is provable, not asserted.
We bring your subcontractors and vendors into scope, which is where multi-tier providers usually fail.
We prepare for Stage 1 and Stage 2 and support surveillance audits.
Define services in scope and assess against 20000-1.
Catalogue, service levels, roles, governance.
Stand up and operate the core service processes.
Report performance and act on misses.
Stage 1 and Stage 2 audit, then surveillance.
No. ITIL is a body of best-practice guidance you can adopt however you like; ISO/IEC 20000-1 is an auditable standard you can certify against. ITIL practices map well onto 20000 requirements, so ITIL-mature organizations usually have a shorter path.
They answer different questions — 20000 is about service delivery, 27001 about information security. Many MSPs hold both because customers ask for both. The management-system clauses overlap substantially, so the second certification is far cheaper than the first.
Yes — you define the scope, by service, site, or business unit. Scoping deliberately is how you keep a first certification achievable, provided the scope is coherent and honestly stated on the certificate.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.