HomeFrameworksCloud & Government AuthorizationISO 20000-1

Framework  Cloud & Government Authorization

ISO 20000-1

ISO/IEC 20000-1:2018 is the international standard for a service management system (SMS). It sets requirements for how an organization plans, designs, delivers and improves IT and other services: service catalog and service level management, incident and problem handling, change and release control, capacity, continuity and availability, supplier management, and measurement and improvement.

It follows the same high-level structure as ISO 27001 and ISO 9001, so it is often certified alongside them.

Certification requires a documented SMS: scope, service management policy and objectives, a service catalog and SLAs, documented processes for each clause 8 area, records of incidents, changes and reviews, internal audit results and management review minutes. The auditor checks that the written processes exist, are followed and are measured.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedSMS policy v2by name, on record
Clause 7.5 Handledwith AllyMatter
Serve It the Modern WayEvery service management policy, acknowledged by the people on call
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every engineer on record
Who read which version, and when
03
Hand the registrar the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Voluntary. IT service providers, managed service providers, outsourcers and internal IT functions adopt it when customers or tenders require a certified SMS, especially in public sector and telecom procurement. No statutory trigger.

What the assessor asks to see

SMS scope and service management policy; service catalog and SLAs; process documentation for incident, problem, change, release, configuration, capacity, continuity, availability and supplier management; risk and opportunity register; roles and competence records; service reports and SLA performance data; internal audit program and results; management review minutes; corrective action records; supplier agreements.

Where the requirement sits: ISO 20000-1 7.5 documented information

What AllyMatter does here

Document control layer.

AllyMatter publishes this site.

Assessors

Who assesses ISO 20000-1

An accredited certification body (registrar) operating under ISO/IEC 17021-1 with a scope covering ISO/IEC 20000-1, using ISO/IEC 20000-6 for its own competence requirements. Accredited by National accreditation bodies that are IAF MLA signatories, such as ANAB (US), UKAS (UK) and their peers.

Public register of assessors: https://www.iafcertsearch.org/

No firm has claimed a ISO 20000-1 assessor listing yet. Claim yours →

Consultants

Who helps with ISO 20000-1

Yes. ITSM and ISO consultants run gap assessments, write the SMS documentation, tune tooling (ticketing, CMDB) to the process requirements and prepare for the certification audit. Engagements typically run three to nine months before the Stage 1 audit.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

ArchlightMinneapolis, MN, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
BEMOUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Coral EsecureNew Jersey, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
CycoreMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Genius GRCWoodstock, GA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
IllumenPacific Northwest, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Neutral PartnersMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Securis360Pittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Soter AdvisoryUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TestprosReston, VA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TrustedCISORemote, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. ISO 20000-1 IT service management certificationA certification body explains what a service management system has to demonstrate and how the audit cycle runs.DQS
  2. ISO 20000-1 certification: IT service managementCovers the two-stage assessment, surveillance visits and the documented service commitments an auditor samples.NQA

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for ISO 20000-1

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of ISO 20000-1 in AllyMatter

Approve the policies ISO 20000-1 asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.