All frameworks
ISOCertification · ITSM

ISO 20000 compliance

Run IT services you can prove are under control.

ISO/IEC 20000-1 is the international standard for a Service Management System (SMS) — the way you plan, design, transition, deliver and improve IT services so they meet agreed requirements and deliver value. It is the certifiable, auditable companion to ITIL practice, built on the same management-system spine (clauses 4–10) as ISO 27001, ISO 22301 and ISO 9001, with a rich operational Clause 8 that covers the full service lifecycle.

Start from the basics

The standard

ISO/IEC 20000-1:2018 — IT Service Management System (SMS)

Who needs it

Any organisation that runs IT services for customers or users and is asked to prove it does so reliably — managed service providers, IT outsourcers and BPOs, SaaS and cloud operators, and internal IT functions answering enterprise RFPs, framework agreements or regulators that ask 'are your IT services ISO 20000 certified?'.

4–10

ITSM lifecycle, audited

The basics

What is ISO 20000?

A management system, not a tool: you set the SMS scope, a service management policy and objectives, and a service management plan, then run the operational core of Clause 8 — the service portfolio (service catalogue, asset and configuration management), relationships and agreements (business relationship, service level and supplier management), supply and demand (budgeting, demand and capacity), service design/build/transition (change, release and deployment), resolution and fulfilment (incident, service request and problem management), and service assurance (availability, continuity and information security).

The ITSM processes are its heart: a service catalogue and SLAs define what you deliver; incident, service request and problem management keep it running; change and release management keep it safe to evolve; availability, capacity and continuity management keep it dependable.

The 2018 third edition adopts the Annex SL high-level structure, so it integrates cleanly with ISO 27001, 22301 and 9001. It is certified through an initial Stage 1 and Stage 2 audit, then annual surveillance and three-yearly recertification.

Why it matters

What ISO 20000 does for your business

It's asked for by name

ISO 20000 is a standard line item in managed-services and outsourcing tenders. A certificate answers the service-management question in one attachment.

It turns practice into proof

Running ITIL-style processes is good; ISO 20000 is the audited evidence that incidents, changes, problems and service levels are actually managed and improving.

It reuses what you have

If you already run ISO 27001 or 22301, the clause 4–10 spine transfers directly, and 27001's information-security and 22301's continuity controls map into the SMS.

What it covers

Define & agree

SMS scope, service catalogue, and SLAs that set service level targets, workload limits and exceptions.

Run & resolve

Incident, service request and problem management — with major-incident handling and a known-error base.

Change safely

Change, release and deployment management with risk-based approval, back-out plans and post-implementation review.

Assure & improve

Availability, capacity and continuity management, service reporting, internal audit, management review and continual improvement.

The hard way

An SMS is a lot to stand up by hand: a service catalogue and SLAs, live incident/request/problem/change registers, a CMDB, capacity and availability plans, a service continuity plan, supplier contracts, and a full audit trail across clauses 4–10 — all kept current as services change.

The easier way, with Compliance One

  • Ships the full ISO/IEC 20000-1:2018 clause 4–10 requirement library (66 controls across 14 domains), enabled by default with an applicability register — no Annex A, no Statement of Applicability.
  • Includes native IT service management registers — incident (with major-incident handling), service request, problem & known error, and change (RFC) — with auto-numbered references and lifecycle status.
  • Pre-fills the mandatory documents (Clause 7.5.4): SMS scope, service management policy and plan, change and information-security policies, service continuity plan, service catalogue, SLA and supplier-contract templates, capacity and availability plans, risk register, internal audit, management review and service report.
  • Cross-maps to ISO 27001 (information security, via ISO/IEC 27013), ISO 22301 (service continuity) and ISO 9001 (shared Annex SL backbone), so one evidence set drives an Integrated Management System.

Do it once, reuse it everywhere. Evidence you collect for ISO 20000 is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Is ISO 20000 the same as ITIL?
No — ITIL is a best-practice framework of guidance; ISO/IEC 20000-1 is the certifiable standard an accredited body audits you against. They work together: you adopt ITIL-style practices and certify the management system to ISO 20000.
Is it certifiable like ISO 27001?
Yes — a certification body runs a Stage 1 and Stage 2 audit, then annual surveillance audits and a three-yearly recertification.
We already have ISO 27001 — how much extra work?
Less than you'd expect. Clauses 4–10 are shared Annex SL text, and ISO 20000's information-security clause (8.7.3) maps to ISO 27001. Compliance One cross-maps the overlap so you extend rather than restart.
Can we outsource all our IT and still certify?
No — ISO 20000 requires the organisation to retain accountability and demonstrate control; other parties cannot operate all of the in-scope services, components or processes. The platform helps you record and control what each party operates.

Ready to tackle ISO 20000?

See exactly how Compliance One maps ISO 20000 to your environment in a 30-minute walkthrough — and how much of it we handle for you.