20 certification schemes

ISO/IEC 20000-1:2018

ISO/IEC 20000-1 Certification

ISO/IEC 20000-1 sets the requirements for a service management system, governing how IT services are planned, delivered and improved.

Standard
ISO/IEC 20000-1:2018
Indicative timeline
12-20 weeks, depending on scope and readiness
Discipline
Specialised Standards
Assessment type
Independent third-party assessment

The standard

Overview

ISO/IEC 20000-1:2018 is the international standard for a service management system (SMS). It sets requirements for planning, designing, transitioning, delivering and improving services. Clauses 4 to 10 cover context, leadership, planning, support, operation, performance evaluation and improvement. Clause 8 holds the operational detail: service portfolio, relationship and agreement, supply and demand, service design, build and transition, resolution and fulfilment, and service assurance.

Certification shows that service delivery is governed by a defined system rather than individual effort. Service levels are agreed and measured, changes are assessed before release, and incidents, problems, capacity, availability and continuity are managed through set routes. Customers and procurement teams use the certificate as independent evidence.

UKCert assesses the SMS clause by clause. Stage 1 reviews documented information and readiness; Stage 2 tests the system in operation, using interviews, records and sampled service data. Findings cite the clause and the evidence behind them.

Who this is for

  • Managed service providers delivering IT services under contract
  • In-house IT functions supporting a wider organisation
  • Cloud, hosting and data centre operators
  • Software companies running the services they sell
  • Suppliers bidding for public sector or regulated contracts

What it gives you

Why organisations certify

What a certified ISO/IEC 20000-1:2018 assessment gives you once the certificate is issued.

Contract Eligibility

Many public sector and enterprise tenders ask for ISO/IEC 20000-1, so certification can remove a barrier at prequalification. Buyers set their own criteria, including whether accredited certification is specified.

Measured Service Levels

Service level targets are defined, monitored and reported. Performance discussions with customers rest on recorded data rather than recollection or dispute.

Fewer Repeat Incidents

Problem management separates fixing the symptom from removing the cause, so recurring faults are investigated and closed out rather than reopened each month.

Controlled Change

Changes are assessed, authorised and scheduled before release. Failed changes and unplanned outages become less frequent because the risk is examined first.

Clear Accountability

Roles, responsibilities and escalation routes are documented. Staff and suppliers know who owns each service and who decides when something goes wrong.

Supplier Oversight

Suppliers and internal groups are held to defined targets, so dependencies in the service chain are visible and managed rather than assumed.

Scope

What the assessment covers

The areas an assessor works through. Your final scope is confirmed in writing before any audit is booked.

  • Service management system scope and SMS plan
  • Service catalogue and service portfolio management
  • Service level management and service reporting
  • Incident, service request and problem management
  • Change management, release and deployment control
  • Capacity, availability and service continuity planning
  • Configuration and asset management
  • Supplier and business relationship management

How it runs

The assessment, stage by stage

From first enquiry to certificate. Each stage is agreed with you before it starts.

  1. Scope and Application

    We agree the services, sites and delivery teams covered by the SMS, confirm the wording of the certification scope, and set out the assessment programme and timings.

  2. Gap Assessment

    An optional review compares current practice against each clause of ISO/IEC 20000-1, identifying documentation, measurement and control gaps before the formal audit begins.

  3. Stage 1 Audit

    We examine the SMS documentation, scope, service reporting, internal audit results and management review records to confirm the system is ready for full assessment.

  4. Stage 2 Audit

    We test the system in operation across sites and teams, sampling incidents, changes, service reports and supplier records to confirm the requirements are met in practice.

  5. Certification Decision

    Nonconformities are closed with evidence. An independent reviewer who took no part in the audit then makes the certification decision, and the certificate is issued for three years.

  6. Surveillance and Recertification

    Surveillance audits in years one and two confirm the SMS is maintained and improving. A full recertification audit takes place before the three-year certificate expires.

Questions

ISO/IEC 20000-1:2018 — frequently asked

Anything here that does not cover your situation, put it to an assessor rather than guessing at it.

Ask a question

For most organisations the route runs from twelve to twenty weeks, depending on the number of services in scope, how many sites and teams deliver them, and how much of the system already exists. The standard requires records of internal audit, management review and service reporting before Stage 2, so organisations starting from nothing usually need longer to build that evidence.

Certificates are issued for three years. Surveillance audits are carried out in the first and second years to confirm the system is still operating and improving. A recertification audit covering the whole standard takes place before the third anniversary. If surveillance is missed or nonconformities are left open, the certificate can be suspended or withdrawn.

No. There is no law in the United Kingdom requiring ISO/IEC 20000-1 certification, and it remains voluntary. In practice it is often a contractual requirement. Public sector frameworks, enterprise procurement and managed service tenders frequently list it as a condition of bidding or as a scored criterion, which is why many suppliers pursue it.

Surveillance audits are shorter than the initial assessment and sample part of the system rather than all of it. We look at service performance reports, incident and change records, internal audit results, management review outputs, complaints, and any changes to scope or suppliers since the last visit. Open corrective actions are checked and closed.

ITIL is a body of guidance describing practices for service management. ISO/IEC 20000-1 is a standard containing auditable requirements, and it is the standard an organisation is certified against. ITIL practices can help meet those requirements, but adopting ITIL does not by itself achieve conformity, and the standard does not require any particular framework.

Certifying against more than one standard?

Where you hold several standards, shared clauses are assessed once in a combined visit rather than as separate audits. Talk it through with an assessor before you decide what ISO/IEC 20000-1:2018 should sit alongside.