Information and technology
ISO/IEC 20000-1:2018
Service management systems
ISO/IEC 20000-1 sets out requirements for a service management system.
A certified organisation plans, designs, transitions, delivers and improves its services in a controlled way, so that they meet agreed requirements and provide value to customers and users. The standard grew out of IT service management, but its requirements can apply to any organisation that delivers services.
Who it suits
Internal IT departments, managed service providers, cloud and hosting companies, outsourcers and shared service centres: any organisation that delivers services to customers under agreed service levels and wants to show that it manages them consistently. It is often combined with ISO/IEC 27001.
What certification involves
ISAO, or a certification body accredited for ISO/IEC 20000-1, audits the system in two stages: first the scope (the services covered and the organisation delivering them), the service catalogue, agreements and readiness; then whether service management processes work in practice, from incidents and service requests to changes, capacity and suppliers. Where other parties operate part of a service, the organisation must show that it keeps control of those parts. The certificate names the services and locations covered. Certificates are normally valid for three years, with surveillance audits at least once a year and a recertification audit before expiry. ISAO carries out this certification itself, and also accredits certification bodies to do it. Every certificate ISAO issues, and every certificate issued under ISAO accreditation, is recorded on the public register.
Key themes
- A defined service portfolio and catalogue, with agreed service levels
- Managing relationships with customers and with suppliers who contribute to services
- Planning the capacity, availability, continuity and information security of services
- Controlling changes, releases and deployments
- Resolving incidents, fulfilling service requests and removing the causes of problems
- Reporting on service performance and improving services
Edition
- Current edition
- ISO/IEC 20000-1:2018
ISO/IEC 20000-1:2018, the third edition, was published in September 2018 and replaced ISO/IEC 20000-1:2011, which has been withdrawn. ISO confirmed the 2018 edition at its most recent periodic review. An amendment published in February 2024 asks the organisation to consider whether climate change matters to it when it reviews its context, and adds a note that interested parties may have expectations about climate change. ISO/IEC 20000-1:2018 is the current edition.
Check a certificate for ISO/IEC 20000-1:2018
- Enter the certificate number or verification code at Verify a certificate, or scan the QR code on the certificate. The record shows the certificate's status today, for example valid, suspended, withdrawn or expired.
- Compare the organisation name, scope and sites on the record with the copy you were given. Check that the named services, not just the organisation, match the services you receive.
- Check who issued the certificate, as named on the record. Where a certification body accredited by ISAO issued it, the record shows the status of that accreditation and its accreditation number, and says so if the accreditation did not cover ISO/IEC 20000-1:2018 when the certificate was issued.
- If the certificate is not on the register, ISAO cannot confirm it: it may have been issued under another accreditation, or a detail may be wrong. Ask the issuing body, and report a concern if something does not look right.
Related standards
This is ISAO’s own summary, not the text of the standard. Copies of ISO/IEC 20000-1:2018 can be bought from ISO or from national standards bodies.
