ISO/IEC 20000-1
Information technology — Service management system requirements. Updated: September 29, 2026.
ISO/IEC 20000-1 is the certifiable standard for IT service management. It is frequently confused with ITIL, and the distinction is simple and useful: ITIL is a body of guidance and good practice that cannot be certified at organisational level — individuals take ITIL exams, organisations do not get ITIL certificates. 20000-1 is a requirements standard an organisation can be certified against. They are complementary: many organisations use ITIL as the implementation guide and 20000-1 as the certification target.
What It Covers
- Service portfolio and service levels — what you provide, to whom, and what you have committed to.
- Incident and service request management, which is the daily work — see incident handling and responsive support.
- Problem management, meaning the pursuit of underlying causes rather than repeated fixes — root cause diagnosis.
- Change and release management, and configuration management.
- Capacity and availability management, which is capacity trending with a governance wrapper.
- Continuity of service, overlapping with ISO 22301.
- Supplier management, including sub-contracted parts of your own service.
Who Needs It
Primarily service providers: managed service providers, outsourcing firms, internal IT departments that operate as a service function, and anyone bidding for contracts where the buyer wants assurance about how service is run rather than only about security. In some public procurement it appears alongside ISO 9001 and ISO 27001 as a standard trio.
For a product company that does not sell an operated service, it is usually not the right target — the effort is better spent on 27001.
Getting Certified
Shares the management system structure, so the internal audit, management review and improvement machinery is reusable from any other ISO certification you hold. The distinctive demand is records of the service management processes actually running: real incident tickets, real change approvals, real service reviews with the customer. A well-run service desk is most of the evidence; a service desk that exists but is bypassed whenever anyone is busy is where this certification exposes the gap.
Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice. Standards are revised on a cycle — confirm the current edition before you commit.