Skip to content
Offer of the Day Free Billing Software with Company Registration. Valid today only Claim on WhatsApp
TaxhintAdvisors
Certification · IT service management

ISO 20000 Certification (ISO/IEC 20000-1:2018)

ISO/IEC 20000-1 is the international standard for running IT services through a documented service management system. Enterprise clients and government buyers often ask IT support, managed service and cloud providers for it. We build the system with your team and take you through the certification audit.

ISO/IEC 20000-1:2018Stage 1 & Stage 2 auditThree-year certificateAnnual surveillance
5000+ businesses served10+ years of practice · Pan-India
Get a free consultationWe reply within one working day

What it is

ISO 20000 certification is independent proof that you plan, deliver and improve your services in a controlled way. The standard behind it is ISO/IEC 20000-1:2018, “Service management system requirements”. It sets out what a service management system (SMS) must cover, from the service catalogue and service agreements to incidents, changes and continuity.

The current edition is the third, published in September 2018 and confirmed by ISO in 2023, with a 2024 amendment adding climate action changes. It uses the same ten-clause structure as ISO 9001 and ISO 27001. Certification is voluntary and comes from a certification body after an audit, not from any ministry or portal. In India, the National Accreditation Board for Certification Bodies (NABCB) accredits certification bodies for this standard under ISO/IEC 20000-6.

Who it applies to

You run IT services for clients

Help desks, infrastructure support teams, data centre and cloud hosting firms, and software companies that run applications for clients under a service agreement.

You bid for bank, PSU or government IT work

Some bank, PSU and government IT tenders list ISO 20000 as a qualifying or scoring criterion. If you sell through GeM or bid in RFPs, it can decide whether your bid is evaluated at all.

You run an in-house IT function

A shared-services centre or a group’s IT team can certify the services it delivers to the rest of the business.

Why it matters

Answer due-diligence questions in one page

Large clients ask how you log incidents, approve changes and recover from outages. Picture a Faridabad firm that supports plant IT for auto-component makers and now wants a bank’s help-desk contract. A current certificate and its scope statement answer most of the bank’s vendor questionnaire.

Stop depending on a few key people

Many small IT firms depend on two or three people who “just know” how things work. The SMS writes it down, so service does not collapse when one of them leaves.

Pair it with ISO 27001

Clients who ask for ISO 27001 certification often want service evidence too. Shared clauses allow one integrated system.

Documents required

About the organisation

  • Incorporation or registration certificate, PAN and GSTIN
  • Addresses of sites inside the scope
  • Organisation chart and list of people in service roles
  • List of services, customers and key suppliers

The service management system

  • SMS scope, policy and objectives
  • Service catalogue and SLAs
  • Incident, request, problem and change procedures
  • Capacity, availability and continuity plans
  • Supplier agreements and reviews

Evidence the system runs

  • Ticket and SLA performance reports
  • Change and release records
  • Internal audit report and management review minutes
  • Corrective action records

How it works

1

Fix the scope of services and sites

We agree which services, locations and customers go into the certificate. Here is the catch: too wide a scope fails at Stage 2, and too narrow a scope may not match the tender.

2

Check the gaps against each clause

We compare what your team already does against each clause of ISO/IEC 20000-1, especially clause 8 (operation), and list what is missing.

3

Write and roll out the documents

We draft the policy, catalogue and procedures around the ticketing tool you already use. No new software is needed.

4

Run the system, then audit it yourself

Auditors want live records, not fresh templates. Say a Noida hosting company adopts the new change procedure in April: by Stage 1 it should have real change tickets and approvals to show. We then help with the internal audit and the management review.

5

Choose the certification body and face the audit

We help you compare accredited certification bodies, prepare for Stage 1 and Stage 2, and close any nonconformities raised.

ISO 20000, ISO 27001 and ITIL compared

ISO/IEC 20000-1ISO/IEC 27001ITIL
What it isRequirements for a service management systemRequirements for an information security management systemA good-practice framework
FocusDelivering services to agreed levelsProtecting informationHow to design and run service practices
Can an organisation be certified?Yes, by an accredited certification bodyYes, by an accredited certification bodyNo; individuals take ITIL exams

In practice, ITIL is the “how” and ISO 20000 is the auditable “what”. ISO publishes a technical specification, ISO/IEC TS 20000-11:2021, that maps one to the other. ITIL-trained teams find the standard familiar.

Timelines

Clear a two-stage initial audit

Stage 1 reviews your documents and readiness. Stage 2 checks that the system works in practice. The certificate follows the certification body’s decision.

Face surveillance every calendar year

Surveillance audits happen at least once a calendar year, and the first must fall within 12 months of the certification decision.

Recertify before the three years end

The certificate runs on a three-year cycle. The recertification audit must be completed before expiry to keep it continuous.

What happens if the certificate lapses

Miss a surveillance and face suspension

If a surveillance audit is skipped or major nonconformities stay open, the certification body can suspend the certificate. You cannot use it in bids while suspended.

Restore it within six months, or start over

An expired certificate can be restored within six months if the pending recertification work is completed. After that, you start again with a full initial audit.

Lose bids and breach contracts

Many contracts require a valid certificate for the whole term. A lapse can cost you a bid or bring a breach notice from a client.

Frequently asked questions

Is ISO 20000 certification mandatory in India?

No, ISO 20000 certification is voluntary in India; no law requires it. It becomes necessary when a client or tender makes it a condition, as some banking, PSU and government IT tenders do. Some tenders want the certificate to cover the exact services you are bidding for, so read the eligibility clause closely. If it is in the RFP, start well before the bid date.

Which version of ISO 20000 is current?

ISO/IEC 20000-1:2018 is the current version, published in September 2018 as the third edition. ISO confirmed it in its 2023 review, and a 2024 amendment added climate action changes. The 2011 edition is withdrawn, so new certificates are issued against the 2018 standard, even where an old tender still names 2011.

Who issues the ISO 20000 certificate?

A certification body issues it, after auditing your service management system. ISO itself does not certify anyone. Pick a body accredited for ISO/IEC 20000-1, for example by NABCB, which accredits bodies under ISO/IEC 20000-6. Procurement teams look for that accreditation. We check the body’s accreditation scope with you before you sign up.

How long does ISO 20000 certification take?

It depends on how mature your processes are, because the standard expects live records, not just documents. A firm with a ticketing tool and change approvals already in place needs far less work. After the documents are ready, you need enough operating history for an internal audit and a management review before Stage 1. We give you a realistic plan after the gap check.

How long is the certificate valid?

The certificate runs on a three-year cycle from the certification decision. Surveillance audits take place at least once each calendar year, and the first must be within 12 months of the decision. A recertification audit before expiry starts a fresh three-year cycle. Keep the surveillance dates in your compliance calendar and the certificate stays valid without gaps.

Can a small IT company with ten people get ISO 20000?

Yes, there is no minimum size in ISO/IEC 20000-1. The standard asks for the processes, not for a large team, and one person can hold several roles if responsibilities are clear. The certification body sets audit time by headcount and scope, so a small firm also gets shorter audits. Keep the documents lean and true to how you work.

Can ISO 20000 and ISO 27001 be audited together?

Yes, many certification bodies offer combined or integrated audits when both standards cover the same scope. Both follow the same ten-clause structure, so policy, internal audit, management review and corrective action can be shared. You still get two certificates, each with its own scope. Planned together, the two projects take less of your team’s time.

What does Taxhint do, and what does the certification body do?

We handle scoping, the gap check, the SMS documents, internal audit support and liaison with the certification body. The certification body alone audits you and decides on the certificate; no consultant can promise the result. Technical changes in your tools and infrastructure stay with your IT team. This split keeps the audit independent, which is what makes the certificate worth having.

Pricing

What it costs

Our fee plus the government fee that applies to your case, quoted before you commit. Tell us the situation and we will price it exactly.

There is no government fee for ISO 20000. The certification body charges for each audit, based on the audit days your scope and headcount need. We help you compare quotes from accredited bodies.

Ready to begin?

Tell us which services you deliver and which tender or client is asking, and we will map your route to ISO 20000.