ISO/IEC 20000-1 Certification: IT Service Management

Develop and improve processes for the design, creation, delivery, support and management of IT services.

Journey continues on Veracity, DNV's trusted digital platform.

ISO/IEC 20000-1 Certification: IT Service Management

Certification of your IT service management system to ISO/IEC 20000 1 demonstrates your commitment to deliver reliable, well controlled and customer focused IT services. It shows that your organization manages service performance in a structured manner, have processes in place to resolves incidents, control changes and maintain service quality across the full service lifecycle. It strengthens stakeholder trust, supports competitiveness in national and international markets and helps you manage risks while continually improving.

The ISO/IEC 20000 1 standard provides specific requirements for implementing, maintaining and continually improving and IT service management system. A compliant IT Service Management System enhances your ability to consistently deliver services that meet customer, regulatory and contractual requirements.

What is the ISO/IEC 20000-1 standard?

ISO/IEC 20000 1 is the international standard for IT service management systems. The standard is applicable to any organization that provides IT services, whether internally or externally. Its scope can be limited to defined parts of the organization or expanded to cover all service management activities and customer needs.

As part of the broader ISO/IEC 20000 IT service management family, it is the only certifiable standard. Its requirements define how organizations plan, design, transition, deliver and improve their IT services.

In essence, ISO/IEC 20000 1 ensures organizations manage service performance in a structured way, align service delivery with customer and business needs, and maintain predictable and reliable service outcomes over time. It helps organizations identify, assess and address risks and opportunities that may affect service performance, the customer experience or the achievement of service objectives.

ISO/IEC 20000 1 helps you achieve:

  • Consistent and reliable delivery of IT services
  • Higher customer confidence in service performance
  • Improved control of service design, transition and delivery
  • Effective management of incidents, problems and changes
  • Clear handling of legal, regulatory and contractual obligations
  • Objective measurement of service performance
  • Increased competitiveness and credibility in the market
  • A built in culture of continual improvement

ISO/IEC 20000 1 promotes the adoption of risk based thinking from planning to operations. The standard is built on ISO’s Harmonized Structure (HS), which ensures a consistent approach and enables smoother integration with other ISO management system standards such as ISO 9001, ISO/IEC 27001 and ISO/IEC 27701.

Value of ISO/IEC 20000-1 certification

Certification to ISO/IEC 20000 1 by an independent third-party demonstrates that your IT service management system meets the requirements of the standard. It also shows your ability to manage service performance in a consistent and well controlled way. This proves that your organization can deliver effective and resilient IT services, maintain control across the service lifecycle and operate with a level of reliability that builds trust in technology driven markets. It can also support you in gaining a competitive market position and adhere to regulatory requirements.

As a result, you achieve:

  • Increased customer trust through a structured approach to reliable and predictable service performance
  • Competitive edge in national and international markets where recognized certification supports credibility
  • Ability to compete when certification is required in contracts or procurement processes
  • Objective insights from independent auditors to identify gaps and improvement opportunities

Why partner with DNV?

DNV is one of the world’s leading certification bodies. Through management system certification, supply chain assurance and training services, we help companies manage risks, assure compliance and build competence in organizations, supply chains and people.

Trusted

A global partner locally before, during and after the audit

Knowledge

Solid auditor competence and industry experience

Innovation

Value adding services, solutions and digital tools

Experience

Commitment to a superior customer experience

80000

Customers

90000

Certificates

20000

People trained annually

180 +

Countries

How to get ISO/IEC 20000-1 certified

To be certified, you first need to implement an effective IT service management system complying with the requirements of the standard. DNV is an accredited third-party certification body and can help you with relevant training, GAP-analysis and the certification itself.

As a DNV customer, you also get access to a suite of digital tools that can help you ensure compliance, continually improve and manage your entire certification journey with us.

Learn how to get started and be certified

    • Obtain the standard:

    Get a licensed copy of the relevant standard and familiarize yourself with the requirements to decide if certification/registration to this standard makes good sense for your organization.

    • Review available literature and apply digital tools

    Explore available literature, guidelines from the standard owners (e.g. ISO/TS 9002 for ISO 9001, ISO 14004 for ISO 14001)   and digital sources and tools that can assist with implementation. Note that as a DNV customer you get access to tailored tools that can assist you.

    • Assemble a team and define strategy:

    To implement a management system should be a strategic decision for the entire organization. Senior management must be involved in the decision, committed and involved in shaping the system. They decide the business strategy the management system should support. In addition, you need a dedicated team to develop and implement your management system.

    • Determine competence needs:

    First, your team implementing and maintaining the management system needs a thorough understanding of the chosen standards. Later on, the wider organization needs awareness training. DNV offers a variety of public and in-house courses worldwide that meets your competence training needs at all levels within your organization.

    • Review consultant options:

    Independent consultants can advise on a workable, realistic, and cost-effective strategy plan for implementation if you do not have this competence or capacity already.

    • Develop management system documentation: 

    Decide on an appropriate platform for your documented information (e.g. software, process map- or SharePoint-based). The right platform is important to ensure effective management, communication and implementation.

    • Determine, manage and document processes:

    First identify key processes – what they are, how they work, and how they interact. Each process should have a clear purpose, defined responsibilities, and expected outputs. The level of documented information needed depends on the organization’s size, complexity, and the importance of each process, but must include relevant processes and other documented information needed to deliver on intended outcomes and comply with the chosen standard’s requirements.

    • Implement management system:

    Clear communication and necessary competence training are essential elements. During the implementation phase, you will work to ensure that your organization is working according to defined and documented processes. Once successful, you can prove system’s compliance and effectiveness.

    • Select a certification body/registrar:

    Selecting the right certification body/registrar can make a difference throughout your certification journey. DNV offers a trusted partnership approach, a risk-based approach and range of free digital tools that help you manage your certification journey before, during and after the audit.

    • Consider a pre-audit gap analysis:

    Consider a preliminary evaluation by your certification body/registrar to identify and correct nonconformities before starting the official certification process. The purpose is to identify areas of non-conformance or weaknesses, allowing you to correct these before you begin the official certification process.

FAQ – ISO/IEC 20000-1

  • ISO 20000 or ISO/IEC 20000 refers to the international family of standards for IT service management. It provides guidance and requirements for how organizations design, deliver and improve IT services in a structured and consistent way. Within this family, ISO/IEC 20000 1 contains the formal requirements and is the only standard that organizations can certify against.

  • ISO 20000 1 or ISO/IEC 20000-1, which is its formal name, defines the requirements for designing, implementing, operating and continually improving an IT service management system. It applies to any organization that provides IT services, whether internally or externally. Its scope can be limited to defined parts of the organization or expanded to cover all service management activities. The standard ensures that IT services are planned, designed, transitioned and delivered in a controlled and reliable way that meets customer, regulatory and contractual requirements.

  • To achieve ISO/IEC 20000 1 certification, your organization must implement a service management system that meets the requirements of the standard and demonstrate that it is implemented accordingly. Certification is carried out by an independent third party body such as DNV through a structured audit that verifies compliance with the standard’s requirements. When the management system is found compliant, the certification body issues an ISO/IEC 20000 1 certificate.

Information security and IT service management training

Information security and IT service management training

Information is a vital asset for any company, but which also harbours special obligations. Unauthorised access to important information and knowledge capital, or its loss, can have a significant negative impact.

Discover Information security and IT service management training
Technician working in computer server room

More information

Training

Relevant insight in an active learning environment.

Interested in how this service can support your organization?

Contact us