- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Cloud & Government Authorization
ISO 20000-1
ISO/IEC 20000-1:2018 is the international standard for a service management system (SMS). It sets requirements for how an organization plans, designs, delivers and improves IT and other services: service catalog and service level management, incident and problem handling, change and release control, capacity, continuity and availability, supplier management, and measurement and improvement.
It follows the same high-level structure as ISO 27001 and ISO 9001, so it is often certified alongside them.
Certification requires a documented SMS: scope, service management policy and objectives, a service catalog and SLAs, documented processes for each clause 8 area, records of incidents, changes and reviews, internal audit results and management review minutes. The auditor checks that the written processes exist, are followed and are measured.
Who has to comply
Voluntary. IT service providers, managed service providers, outsourcers and internal IT functions adopt it when customers or tenders require a certified SMS, especially in public sector and telecom procurement. No statutory trigger.
What the assessor asks to see
SMS scope and service management policy; service catalog and SLAs; process documentation for incident, problem, change, release, configuration, capacity, continuity, availability and supplier management; risk and opportunity register; roles and competence records; service reports and SLA performance data; internal audit program and results; management review minutes; corrective action records; supplier agreements.
Where the requirement sits: ISO 20000-1 7.5 documented information
What AllyMatter does here
Document control layer.
AllyMatter publishes this site.
Assessors
Who assesses ISO 20000-1
An accredited certification body (registrar) operating under ISO/IEC 17021-1 with a scope covering ISO/IEC 20000-1, using ISO/IEC 20000-6 for its own competence requirements. Accredited by National accreditation bodies that are IAF MLA signatories, such as ANAB (US), UKAS (UK) and their peers.
Public register of assessors: https://www.iafcertsearch.org/
No firm has claimed a ISO 20000-1 assessor listing yet. Claim yours →
Consultants
Who helps with ISO 20000-1
Yes. ITSM and ISO consultants run gap assessments, write the SMS documentation, tune tooling (ticketing, CMDB) to the process requirements and prepare for the certification audit. Engagements typically run three to nine months before the Stage 1 audit.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for ISO 20000-1
Tools that name this framework in their own material.
Related reading
- ISO 20000-1 IT service management certificationA certification body explains what a service management system has to demonstrate and how the audit cycle runs.DQS
- ISO 20000-1 certification: IT service managementCovers the two-stage assessment, surveillance visits and the documented service commitments an auditor samples.NQA
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for ISO 20000-1
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of ISO 20000-1 in AllyMatter
Approve the policies ISO 20000-1 asks for, keep every version, and record a named acknowledgment from each person who has to read them.