ISO 20000
IT Service Management Systems
ISO 20000:2018 at a glance
- Current edition
- ISO/IEC 20000-1:2018 - Information technology — Service management — Part 1: Service management system requirements
- Published
- 2018
- Status
- Published
- Type of standard
- Management system standard
- Certifiable
- Yes — organizations can be certified by an accredited body
- Previous edition
- ISO/IEC 20000-1:2011
- Official ISO page
- View ISO 20000:2018 on iso.org
- Last verified
Overview
The certifiable requirements standard for a service management system. The third edition, ISO/IEC 20000-1:2018, adopted the harmonized management system structure; Amendment 1:2024 added climate action wording.
ISO/IEC 20000-1:2018, Information technology — Service management — Part 1: Service management system requirements, is the standard organizations certify against for IT and other service management. It is the third edition, published in 2018, and cancels and replaces ISO/IEC 20000-1:2011, which it technically revised. It was reviewed and confirmed in 2023 and remains current.
The 2018 edition restructured the standard into the harmonized management system structure shared with ISO 9001, ISO/IEC 27001 and other management system standards. That introduced common requirements for context of the organization, leadership, planning to achieve objectives and actions to address risks and opportunities, support, operation, performance evaluation and improvement — and made integrated certification with ISO/IEC 27001 and ISO 9001 considerably more practical.
The service-specific requirements sit within the operation clause and cover the full service lifecycle. Service portfolio requirements cover service planning, control of parties involved in the service lifecycle (including internal groups, suppliers and customers acting as suppliers), service catalogue management, and asset and configuration management. Relationship and agreement requirements cover business relationship management, service level management and supplier management. Supply and demand requirements cover budgeting and accounting for services, demand management and capacity management.
Service design, build and transition requirements cover change management, service design and transition, and release and deployment management. Resolution and fulfilment requirements cover incident management, service request management and problem management. Service assurance requirements cover service availability management, service continuity management and information security management. These map recognisably onto ITIL practice, which is why organizations using ITIL often find ISO/IEC 20000-1 the natural way to make that practice auditable — but the standard is framework-neutral and does not require ITIL.
A notable feature is the treatment of parties involved in the service lifecycle. Where services are delivered through a chain of internal groups, external suppliers and subcontractors, the organization must demonstrate governance of those parties and cannot simply point at a supplier contract. This is a common source of findings in certification audits of managed service providers and outsourced operations.
Amendment 1:2024 added climate action wording to the context and interested-parties clauses, matching the change applied across ISO management system standards. It adds no new service management requirements.
Certification is available through accredited certification bodies using a two-stage initial audit, surveillance during the certificate cycle and recertification. Scope definition is commercially important: the certificate names the services and locations covered, and customers reading it will check whether the service they buy is inside the scope. Other parts of the series provide support without being certifiable — guidance on the application of the service management system (Part 2), guidance on scope definition and applicability (Part 3), and concepts and vocabulary (Part 10) — and ISO/IEC 27013 gives guidance on integrated implementation of ISO/IEC 20000-1 and ISO/IEC 27001.
Purpose
To specify requirements for an organization to establish, implement, maintain and continually improve a service management system, covering the planning, design, transition, delivery and improvement of services to meet service requirements and deliver value.
Key Benefits
- Provides a certifiable framework for IT and other service management
- Uses the harmonized structure, integrating cleanly with ISO/IEC 27001 and ISO 9001
- Makes ITIL-style practice auditable without mandating any particular framework
- Requires governance of internal groups, suppliers and subcontractors in the service chain
- Covers the full lifecycle from planning and design through transition, delivery and improvement
- Certification is widely used as assurance in managed service and outsourcing procurement
- Improves discipline in incident, problem, change and release management
- Links service continuity, availability and information security to service commitments
- Provides a defined basis for service level agreements and reporting
Key Requirements
- Determine the context of the organization and the needs and expectations of interested parties
- Define the scope of the service management system, including services and locations
- Demonstrate top management leadership, establish a service management policy and assign roles
- Address risks and opportunities, set service management objectives and plan the SMS
- Provide resources, ensure competence and awareness, and control documented information
- Plan services, control parties involved in the service lifecycle and manage the service catalogue
- Manage assets and configuration, including configuration items and their relationships
- Operate business relationship management, service level management and supplier management
- Budget and account for services, and manage demand and capacity
- Operate change management, service design and transition, and release and deployment management
- Operate incident management, service request management and problem management
- Manage service availability and service continuity, including testing continuity plans
- Manage information security within the service management system
- Monitor, measure, analyse and evaluate the SMS and the services, and report performance
- Conduct internal audits and management reviews at planned intervals
- Manage nonconformities and corrective action and continually improve the SMS and the services
- Address climate change as a context issue in accordance with Amendment 1:2024
Who Needs This Standard?
IT service providers and managed service providers, internal IT departments delivering services to a business, cloud and hosting providers, business process outsourcing providers, telecoms operators, and public sector shared service organizations. It concerns service delivery and operations managers, service desk and ITSM process owners, supplier and contract managers, and organizations that must evidence service management capability in tenders and outsourcing contracts.
Where to get ISO 20000
The full text of ISO 20000 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 20000 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.
Get our free implementation resources
Send me the implementation checklist for ISO 20000, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.
We'll only email you about this standard. Unsubscribe anytime.
Need help getting certified?
Certificates for ISO 20000 are issued by accredited certification bodies, not by ISO itself. Tell us what stage you are at and we will put you in touch with people who work with this standard — implementation support, audit or training. Free and no obligation.