Direct Answer: ISO/IEC 20000 is the globally recognized standard for IT Service Management (ITSM), with over 7,500 certificates issued worldwide. Getting certified involves a 5-step process: Preparation (training, gap analysis, scope definition), Documentation (service management policies, procedures, service level agreements), Implementation (rolling out the system, training staff, process improvement), Internal Audit (self-assessment to verify compliance), and Certification Audit (two-stage audit by an accredited registrar, followed by certificate issuance). The process typically takes 6–12 months for a small to medium-sized organization, with costs ranging from $8,000–$20,000 for initial certification. This guide walks you through every step, with practical tips for a smooth certification journey for your IT services.
ISO/IEC 20000 is the world’s most widely recognized standard for IT Service Management (ITSM). Developed and published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it specifies requirements for an organization to establish, implement, maintain, and continually improve a Service Management System (SMS). With over 7,500 certificates issued globally, ISO 20000 is the foundational certification for organizations that take IT service delivery and support seriously.
For IT departments, managed service providers, cloud service providers, and organizations that rely on IT services, ISO 20000 certification demonstrates a commitment to delivering consistent, high-quality services that meet customer and business requirements. It provides a framework for aligning IT services with business objectives, improving operational efficiency, and managing service-related risks. This guide covers the complete certification process, from initial preparation through to the final certification audit, and provides practical, actionable advice for a smooth journey. See our related guides on ISO 9001 quality management and ISO 27001 information security to understand how ISO 20000 integrates with other management systems.
This guide is written for IT managers, service delivery managers, quality managers, IT directors, and anyone responsible for implementing or maintaining a Service Management System (SMS) in their organization. It covers both the DIY approach (using templates and internal resources) and the consultant-led route. It is equally relevant for internal IT departments seeking to improve service quality, and for service providers who need to demonstrate ITSM capability to their clients. For related partnership structures, see our guides on ISO 9001 and ISO 14001.
ISO/IEC 20000 is the international standard that defines the requirements for a Service Management System (SMS). It is part of the ISO 20000 family of standards, and is the only standard in the family that organizations can be certified against. The current version is ISO/IEC 20000-1:2018, which specifies requirements for an organization to establish, implement, maintain, and continually improve a service management system. The standard is based on the Plan-Do-Check-Act (PDCA) cycle and is aligned with the High-Level Structure (HLS) shared by other management system standards like ISO 9001 and ISO 27001. Certification demonstrates that your organization has a documented SMS that meets these requirements, and that you are committed to consistent service delivery, customer satisfaction, and continuous improvement.
ISO 20000 is recognized in over 170 countries, making it the most widely accepted IT service management certification globally. It provides a common framework for IT service excellence across international supply chains.
Many large corporations, government agencies, and international clients require ISO 20000 certification as a condition for doing business. It differentiates your IT services from non-certified competitors.
ISO 20000 provides a systematic framework for identifying and implementing improvements across your IT services, leading to reduced incidents, lower costs, and higher customer satisfaction.
Certification signals to your customers that you have robust service management controls and a commitment to meeting their requirements, building trust and strengthening business relationships.
ISO 20000 certification delivers tangible benefits across operational, commercial, and strategic dimensions. For IT service providers and internal IT departments, certification drives improvements that are recognized by customers, partners, and regulators.
ISO 20000 certification signals to customers, partners, and regulators that you have a validated system for managing IT services. This credibility opens doors to new business opportunities with clients who require certified service providers.
By systematically identifying and eliminating the root causes of service incidents and inefficiencies, certified organizations reduce rework, downtime, and operational costs. The process-focused approach drives operational excellence.
ISO 20000 provides a common framework for service management across supply chains, enabling smoother collaboration with IT partners, easier audits, and more consistent service delivery throughout the value chain.
The standard requires organizations to collect and analyze service performance data, enabling evidence-based decisions. This reduces reliance on intuition and improves the quality of service management decisions.
Clear processes, defined responsibilities, and documented procedures improve employee understanding of their roles and how their work contributes to service quality, increasing engagement and reducing ambiguity.
The risk-based thinking embedded in ISO 20000-1:2018 helps organizations proactively identify and mitigate service-related risks, reducing exposure to regulatory non-compliance and service disruptions.
A common question when exploring ISO 20000 certification is how it relates to ITIL (Information Technology Infrastructure Library). While both are essential frameworks in IT service management, they serve different purposes and are complementary rather than competitive. Understanding the distinction is crucial for a successful certification project.
ISO 20000 tells you WHAT to do: It provides the requirements for a certified Service Management System. It specifies the outcomes you must achieve, but does not prescribe exactly how to achieve them.
ITIL tells you HOW to do it: It provides detailed guidance, best practices, and process descriptions for implementing service management processes. Many organizations use ITIL practices to help them meet the requirements of ISO 20000.
Practical approach: Most successful ISO 20000 implementations use ITIL (or another best practice framework) as a reference model to design and operate their processes, while using ISO 20000 as the certification benchmark. They are complementary, not competing.
The preparation phase sets the foundation for your entire ISO 20000 certification project. The goal is to ensure you have the knowledge, resources, and support in place before beginning the detailed work of documentation and implementation. This phase typically takes 2–4 weeks for a small organization, longer for larger or more complex IT service operations.
If you are managing the certification process, you need to understand the standard’s requirements and how to apply them in your organization. Consider an ISO 20000 implementer training course, online or in-person, to build foundational knowledge. PECB and APMG offer accredited training programs from Foundation to Lead Implementer and Lead Auditor levels.
Top management commitment is critical. They must “walk the talk” by allocating resources, supporting the project, and communicating its importance. Provide executives with a concise overview of ISO 20000’s role in the business and the benefits certification will deliver, including improved service quality, reduced risk, and market differentiation.
Define the specific operational and commercial benefits you want from certification (e.g., reduced service incidents, improved SLAs, new customer acquisition). Clearly define the scope of your SMS: which services, departments, locations, or business units will be included? You can exclude certain areas, but consider the pros and cons of limiting the scope. See ISO 9001 for a framework that also applies to scope definition.
Assess how compliant your organization already is with ISO 20000 requirements and identify gaps. This helps you prioritize efforts and create a more accurate project plan. You can do this internally or with a consultant. For small organizations, multiple targeted mini-gap analyses during the documentation and implementation stages can be effective.
Plan your implementation steps, milestones, target dates, and responsibilities. For small and medium organizations, avoid complex Gantt charts; focus on a clear, simple plan that everyone understands. Define who will be the ISO 20000 point person (Management Representative) responsible for achieving and maintaining certification.
Inform your staff about the ISO 20000 project early to prevent rumors and build engagement. Explain how certification benefits the company and individual employees, addressing concerns about job security and work processes. This creates buy-in and transforms staff into stakeholders in the project’s success.
For organizations with multiple service lines or locations, consider a phased approach. Start with a pilot implementation for a single service or department, learn from the experience, and then roll out to the rest of the organization. This reduces risk and allows you to refine your approach based on real-world feedback. The same principle applies when implementing ISO 27001 or other management systems.
Documentation is often considered the most challenging phase of ISO 20000 certification. It requires aligning documents with the standard’s technical requirements while tailoring them to your company’s unique context and needs. The goal is to create a documentation set that is useful, practical, and compliant, not a bureaucratic burden.
| Document Type | Description | Key Consideration |
|---|---|---|
| Service Management Policy | A statement of your organization’s commitment to service management, approved by top management. It must be communicated to and understood by all employees. | Keep it concise and specific to your organization. It should provide a framework for setting service management objectives. |
| Service Management Objectives | Measurable goals aligned with the service management policy. They should be documented, monitored, and communicated. Examples: “improve service availability to 99.9% within 12 months.” | Objectives should be SMART (Specific, Measurable, Achievable, Relevant, Time-bound). |
| SMS Scope Statement | Defines the boundaries of your SMS: which services, locations, and business units are included and excluded. | Be clear about what is in scope and what is out. This is a key document for the auditor. |
| Service Catalog | A comprehensive list of services offered, including service descriptions, service levels, and delivery information. | This is a central reference for customers and service delivery teams. |
| Service Level Agreements (SLAs) | Formal agreements between service providers and customers defining service quality, availability, and performance targets. | SLAs must be measurable, monitored, and reviewed regularly. |
| Process Procedures | Documented processes that describe how service management activities are performed. ISO 20000 requires documented procedures for all core processes. | Create as many procedures as needed to address every requirement of the standard, but avoid unnecessary bureaucracy. Use your company’s vernacular. |
| Work Instructions | Detailed step-by-step guidance for specific tasks, especially where errors would be costly or where tasks are rarely performed. They should be written by the people who do the work. | Use any format that’s useful: text, flowcharts, checklists, or even visual media. Focus on the end user’s needs. |
| Forms & Records | Tools for recording data, capturing evidence, and guiding work. They can serve as both work instructions (before completion) and records (after completion). | Create forms where they save time and effort in meeting ISO 20000 requirements. Avoid creating forms for their own sake. |
| Process Maps (Flowcharts) | Visual representations of workflows, showing how processes interact, where bottlenecks exist, and how inputs become outputs. | Useful for understanding and improving processes during implementation. Can be created by staff mapping their own work on a whiteboard. |
DO: Look for the simplest way to meet a requirement and adapt it to your business. Use your company’s vernacular and avoid “ISO language.” Use diagrams and illustrations rather than long-winded text. Use a visually appealing and easy-to-understand layout. Consider integrating existing ITIL processes if you already use them.
DON’T: Include time-consuming references to other documents. Include bureaucratic requirements that are not suitable for your company’s circumstances or culture. Create documents that don’t add value to your operations.
Consider using documentation templates, pre-written documents designed to be tailored to your company’s needs. They save time, reduce errors, and provide a reliable starting point. Ensure they come with detailed customisation instructions. This approach is also effective when implementing ISO 14001 or other management systems.
Implementation is where your carefully designed Service Management System becomes a reality. This phase involves introducing your processes to the workforce, training them, and guiding them through adjustments to improve their work. The goal is seamless integration into daily IT operations, supported by a compelling incentive for adopting the new processes.
Top management should communicate the service management policy, explaining its significance and how the organization will put it into practice. Staff must understand the policy and connect it to their individual responsibilities, this is a mandatory requirement of ISO 20000.
Department managers and team leaders are critical to making the SMS an integral part of daily operations. Equip them with knowledge and skills to leverage ISO 20000 for tangible benefits and involve them actively in implementation. Targeted manager training is a high-leverage activity.
Start with incident management, then introduce other processes like change management, problem management, and service level management. The method of communication depends on your organization’s size: staff meetings, a trickle-down approach via department managers, or a combination.
Empower staff to redesign their work processes to align with ISO 20000 requirements. Teams can map existing processes on a whiteboard, identify bottlenecks and repetitions, and agree on improvements. The redesigned workflows should then be documented. This approach builds motivation and buy-in.
Detailed step-by-step guidance is essential for rarely performed or high-risk activities. Staff directly involved in the work should write these instructions, using any format (text, flowchart, visual) that is beneficial to the end user. This ensures practicality and accuracy.
As you integrate ISO 20000 requirements into operations, records are being created and kept on file. These records will be reviewed by auditors to assess compliance. Ensure records are complete, legible, and properly stored.
Even before certification, you can start marketing your commitment to service quality. Inform customers proactively about your pending accreditation, describe your SMS, and announce your intended certification date. This can help you secure new business earlier in the process.
Internal audits are a mandatory requirement of ISO 20000 and play a critical role in ensuring the effectiveness of your Service Management System. These self-inspections involve observing work processes, interviewing management and staff, and examining records. The objective is to verify compliance not only with ISO 20000 requirements but also with your own procedures and work instructions. Internal audits must be conducted before seeking certification and periodically thereafter. They can be performed by trained internal staff or outsourced to expert auditors.
Develop an audit schedule and methods for planning and preparing your audits. Create documents, forms, and checklists that support the audit process. Consider using lead auditor training that includes a module on managing the audit program.
Small organizations often rely on their ISO 20000 point person, quality manager, or IT manager. Larger companies may form an audit team. Auditors should be objective and impartial, they cannot audit their own work. Being an auditor is typically an additional responsibility, not a full-time role.
Auditors must be familiar with the ISO/IEC 20000-1:2018 standard, possess strong auditing skills, be capable of reporting findings and following up on corrective actions, and ideally, promote best practices and add operational value. Consider lead auditor training from PECB, GSDC, or APMG.
Use internal audits as training tools to support implementation. You can start auditing during Step 3, focusing on specific requirements or processes initially, and expanding the scope as the system matures. This early start helps identify and fix issues before the formal certification audit.
To be eligible for ISO 20000 registration, you must complete a comprehensive internal audit covering your entire SMS. The audit can be divided into multiple partial audits, focusing on specific departments or processes at a time. Address all identified nonconformities before proceeding to the certification audit.
If you lack internal audit expertise, you can outsource the pre-certification internal audit to experienced auditors. This ensures that all issues with your SMS are identified and addressed, increasing confidence in passing the certification audit.
Many organizations view internal audits purely as a certification requirement, but they are a powerful management tool. Use them to identify process improvements, uncover hidden inefficiencies, and engage employees in service quality thinking. A well-conducted internal audit provides valuable insights that go far beyond compliance. This same principle applies to information security audits and other management system audits.
The certification audit is the final step in obtaining ISO 20000 certification. It is conducted by an independent, third-party auditor from an accredited certification body (registrar). The audit is similar to your internal audits but with regulated scope and number of audit days. Successful completion results in the issuance of your ISO 20000 certificate, valid for three years.
| Audit Stage | What Happens | Key Focus |
|---|---|---|
| Stage 1 Audit (Documentation Review) | The auditor reviews your service management policy, procedures, and other documentation to ensure they meet ISO 20000 requirements and that your SMS is ready for the on-site audit. | Completeness and adequacy of documentation. Identification of any gaps or nonconformities that must be addressed before Stage 2. |
| Stage 2 Audit (On-Site Verification) | The auditor visits your site to verify that your SMS is effectively implemented and working in practice. They will interview employees, observe processes, and review records. | Effective implementation of the SMS. Evidence that processes are being followed and that the system is achieving its objectives. Verification that Stage 1 nonconformities have been addressed. |
| Audit Report & Decision | Following Stage 2, the auditor prepares a report detailing findings. If no major nonconformities are found, or if corrective actions are successfully implemented, the certification body issues your ISO 20000 certificate. | Overall conformity assessment. The certificate is valid for three years from the date of issue. |
| Surveillance Audits | During the three-year certificate validity period, the certification body conducts annual surveillance audits to ensure your SMS remains compliant and effective. | Ongoing compliance. The auditor checks that the SMS is being maintained and that continuous improvement is taking place. |
| Recertification Audit | After three years, you must undergo a recertification audit to renew your certificate. This is typically a more comprehensive audit than surveillance audits. | Full system re-assessment. You must demonstrate that your SMS remains effective and has evolved to meet changing business needs. |
Prepare your organization and staff: Ensure work areas are organized, outdated documents are removed, and staff are ready for the auditor. Explain what to expect, reduce anxiety, and rehearse typical questions like “How do you know you perform your work correctly?” and “How do you contribute to the service management policy objectives?” Staff should answer truthfully without volunteering additional information.
Select your registrar: Choose an accredited certification body that has experience in your industry. Compare quotes, check their reputation, and ensure they are recognised by your customers or industry bodies. See ISO 9001 for a framework that also applies to registrar selection.
The cost and timeline for ISO 20000 certification vary significantly based on organization size, complexity of IT services, existing processes, and the resources you allocate to the project. Understanding these variables upfront helps in planning and budget setting.
| Factor | Impact on Cost | Impact on Timeline |
|---|---|---|
| Organization Size (Employees) | Small (1–50): $8,000–$12,000 Medium (50–250): $12,000–$20,000 Large (250+): $20,000+ |
Small: 6–9 months Medium: 9–12 months Large: 12–18 months |
| Number of Services & Processes | More services and processes = more documentation, more audit days, higher cost | More complexity = longer implementation and audit schedule |
| Industry / Level of Risk | Higher-risk industries (e.g., financial services, healthcare) require more rigorous audits and often higher fees | Higher-risk = more audit days, potentially longer timeline |
| Complexity of Service Management System | Multiple sites, complex service portfolios, or integrated management systems increase cost | Complexity extends documentation, implementation, and audit phases |
| Use of Templates / Digital Tools | Reduces consultant fees and internal time, significantly lowering cost | Can cut timeline by 30–50% by streamlining documentation and implementation |
| Consultant Involvement | Full consultant support: adds $10,000–$30,000+ to cost; DIY with templates: lower cost | Consultant can accelerate timeline by providing expertise and templates |
| Existing ITSM Capability | Organizations with mature ITIL or ITSM processes require less investment | Mature processes can significantly shorten the timeline |
Several providers offer digital ISO 20000 certification platforms that significantly reduce cost and timeline. Subscription-based models can include the documentation tool, AI-assisted process mapping, training, and the certification audit itself. These digital solutions can bring certification within reach for small organizations that might otherwise find the traditional consultant-led route prohibitive. When evaluating such options, use the same partnership evaluation criteria you would apply to any B2B engagement.
The certification body (also called a registrar) is the independent organization that will conduct your audit and issue your ISO 20000 certificate. Choosing the right registrar is a critical decision that affects the cost, timeline, and market recognition of your certification.
Ensure the registrar is accredited by a recognized national accreditation body (e.g., UKAS, ANAB, DAKKS, JAS-ANZ). Accreditation ensures the registrar follows international standards for certification and is competent to audit.
Choose a registrar with auditors who have experience in your specific industry and IT service environment. They will understand your services, terminology, and risks, leading to a more relevant and valuable audit.
Consider whether your customers or industry bodies recognize the registrar’s certificate. In some industries, specific registrars are preferred or required. If you are exporting to a specific region, a registrar with local recognition may be advantageous.
Compare quotes from multiple registrars. The cheapest option is not always the best, consider the value of the audit, the auditor’s expertise, and the registrar’s reputation. Ensure you understand what is included in the quoted fee.
If you have or plan to have multiple sites in different countries, choose a registrar that can audit all sites consistently. This simplifies the management of your certification across locations.
Choose a registrar you feel comfortable working with. The relationship should be collaborative, not adversarial. A good auditor will help you improve your SMS, not just find faults. Assess their responsiveness and communication during the quoting process.
When evaluating registrars, ask: Are you accredited by a recognized national accreditation body? Do you have auditors with experience in my industry and IT environment? What is your audit process and how many days do you typically allocate for my organization type? What is included in your fee and are there additional costs? How do you handle nonconformities and what is the process for issuing the certificate? Can you provide references from clients in my industry? How do you conduct surveillance audits? Use this information alongside your partnership evaluation criteria to make an informed decision.
Creating excessive documentation that adds no operational value and makes the system difficult to maintain. This creates employee resentment and audit fatigue.
Avoid: Focus on what is necessary to control your processes and demonstrate compliance. Use the simplest approach that meets the requirements. Ask: “Does this document add value?”
When leadership does not actively support the SMS, it becomes a compliance exercise for employees rather than a strategic initiative, leading to poor implementation and audit failures.
Avoid: Secure top management commitment from the start. Ensure they understand the business case for certification and communicate their support visibly to the organization.
Using standard-specific jargon instead of your company’s natural language makes procedures confusing and difficult for employees to follow and maintain.
Avoid: Write procedures in your company’s everyday language. Use diagrams and illustrations. Make them user-friendly and practical for the people who will use them.
Focusing solely on passing the audit rather than building an SMS that improves services. This leads to a system that is maintained only for the auditor, not for business performance.
Avoid: Design your SMS to solve real operational problems. Use the internal audits and management reviews for genuine improvement, not just audit readiness.
Employees who do not understand the SMS or how their role contributes to it will not follow procedures consistently, leading to nonconformities and audit findings.
Avoid: Invest in training at all levels. Explain the “why” behind the processes. Make training engaging and relevant to employees’ daily work. Consider using PMP project management principles for structured training programmes.
Failing to address internal audit findings before the certification audit, or treating internal audits as a tick-box exercise without taking corrective action.
Avoid: Use internal audits as a genuine check on your system. Address all findings promptly. Conduct root cause analysis and implement corrective actions that prevent recurrence.
ISO 20000 certification is a powerful tool for demonstrating IT service quality to customers and partners. GTsetu complements your certification by connecting you with verified IT service providers, technology partners, and suppliers who meet rigorous quality standards. Our platform provides:
Related Compliance Standards
ISO 9001 Certification
Quality Management Systems
ISO 14001 Certification
Environmental Management Systems
ISO 13485 Certification
Medical Device Quality Management
ISO 27001 Certification
Information Security Management
ISO 45001 Certification
Occupational Health & Safety
PMP Certification
Project Management Professional
NSF Sanitation Certification
Food Equipment Safety Standards
HIPAA Certification
Healthcare Data Privacy
LEED Certification
Green Building Standards
HACCP Certification
Food Safety Management
UL Certification
Product Safety Standards
B Corp Certification
Sustainability & Impact Standards
USDA Organic Certification
Organic Food Standards
Connect with verified IT service providers, technology partners, and suppliers on GTsetu, compliance-backed verification, anonymous discovery, built-in NDA workflows, and zero broker commissions. Find partners who share your commitment to service quality.
Find Verified Partners Free → Browse Verified Companies
They represents the product, and research team behind GTsetu, a global B2B collaboration platform built to help companies explore cross-border partnerships with clarity and trust. The team focuses on simplifying early-stage international business discovery by combining structured company profiles, verification-led access, and controlled collaboration workflows.
With a strong emphasis on trust, and disciplined engagement, Team GTsetu shares insights on global trade, partnerships, and cross-border collaboration, helping businesses make informed decisions before entering deeper commercial discussions.