Back to Frameworks
Frameworks

ISO/IEC 20000

Framework Name

‍ISO/IEC 20000 (IT Service Management family)

Type

‍Voluntary

Region / Jurisdiction

‍Global

Enforcing Body / Certifying Party

‍International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Only Part 1 is certifiable, assessed by independent, accredited certification bodies. The other parts are guidance documents, not something an organization is audited against

Penalty / Consequence of Non-Compliance

‍No legal penalty. The consequence is commercial: losing out on contracts or tenders, particularly for managed service providers and IT outsourcing companies, where clients increasingly require formal proof of a mature service management system

What It Is & Why It Matters

ISO/IEC 20000 is a family of documents covering IT Service Management, built around a single certifiable core:

  • Part 1 sets the actual requirements for a Service Management System (SMS), a structured way to plan, deliver, and continually improve IT services, and it's the only part an organization can be certified against. The rest of the family supports that core document rather than adding new requirements.
  • Part 2 helps interpret and apply Part 1's requirements with examples.
  • Part 3 helps an organization define what should fall inside its certification scope.
  • Part 10 defines shared terminology across the whole family
  • Part 11 maps ISO 20000-1 directly onto ITIL, the widely used best-practice framework it's built on.

A 2024 amendment to Part 1 added a requirement to consider climate change as a factor affecting service delivery, the same update ISO applied across several of its management system standards around the same time.

It matters because ITIL itself, despite being the more widely recognized name, isn't something an organization can be certified against, only individuals earn ITIL certifications. ISO 20000-1 is what turns those same practices into a formal, auditable, organization-level certification, and the supporting parts exist specifically to make that certification process less ambiguous, telling an implementation team not just what the requirement says, but how to interpret it and what to include.

Who Needs It

  • You are a managed service provider or IT outsourcing company and clients require proof of a certified service management system
  • You run an internal IT department and want a formal, recognized way to demonstrate service reliability to the rest of the business
  • You are bidding on a contract or tender that explicitly lists ISO 20000-1 as a requirement
  • You already hold ISO 27001 or ISO 9001 and want to extend your management system to cover service delivery specifically, not just security or quality

Note on the Certification Path

Only Part 1 leads to certification, and it follows the same Stage 1/Stage 2 audit structure as ISO 27001, with certification requiring renewal every three years alongside annual surveillance audits. The other four parts are worth having on hand during implementation and internal audit prep, but they never appear on a certificate and a customer will never ask whether you're "compliant" with Part 2 or Part 10 specifically, only whether you hold Part 1 certification.

Book A Demo