Overview
ISO/IEC 20000-1:2018 is the international standard for an IT Service Management System (ITSM) — the set of processes that govern how an IT service provider plans, delivers, monitors and improves the services it runs for customers, whether those customers are internal teams or external clients. It covers service design and transition, incident and problem management, capacity and availability, service level management and continual improvement, all built around a Plan-Do-Check-Act cycle.
In India, NABCB (National Accreditation Board for Certification Bodies, under the Quality Council of India) runs ISO/IEC 20000-1 as its own standalone accredited management-system scheme, alongside ISO 9001, ISO 27001 and others. That means an Indian IT company can get certified through a NABCB-accredited certification body and hold a credential that carries the same accreditation weight as a 27001 or 9001 certificate — not a lesser or unofficial variant.
There is no Indian law or regulator that makes ISO 20000-1 mandatory. Where it earns its keep is in government IT procurement and PSU tenders: IT vendors bidding to run infrastructure, service desks or managed services for public-sector buyers use it to differentiate a proposal against competitors who cannot show the same process discipline. Treat any tender language claiming ISO 20000-1 is compulsory with caution; the honest framing is competitive edge, not legal floor.
Most IT vendors we work with already hold, or are pursuing, ISO/IEC 27001 for information security. ISO 20000-1 sits naturally alongside it: 27001 governs how you protect information, 20000-1 governs how you run the service around it, and the two systems share enough structure (documentation, internal audit, management review) that building them together beats doing them as separate projects a year apart.
Who it’s for
- IT services, managed services and helpdesk/service-desk providers bidding for government or PSU IT contracts
- Software and IT companies already ISO 27001-certified who want the service-management half of the story for a tender
- Data centre, cloud and infrastructure-management vendors seeking to differentiate on process maturity, not just price
- IT vendors whose government or PSU RFPs list ISO 20000-1 as a scoring criterion or preferred credential
- IT vendors whose enterprise or PSU customers are asking, in due diligence, how incidents, changes and service levels are actually managed
Eligibility & requirements
- A defined scope: which services, locations and customer accounts the ITSM system covers
- Documented service management processes — service level management, incident/problem/change management, capacity and availability management, and continual improvement
- A management review cycle and an internal audit programme covering the ITSM scope before the external audit
- Evidence the processes are actually operating, not just written — logged incidents, tracked service levels, recorded management reviews
- Commitment from leadership, since ISO 20000-1 (like every ISO management-system standard) requires demonstrable top-management involvement, not a delegated paperwork exercise
- A NABCB-accredited certification body for the external audit — an unaccredited certificate does not carry the same recognition with government and PSU buyers
How CapEasy handles it
- Scoping and gap assessment — we map your current service delivery processes against the ISO/IEC 20000-1:2018 clauses and flag what is missing before you commit to an audit date
- Documentation — service level agreements, process definitions, the service catalogue and the records the standard expects, built to match how your team actually works rather than a generic template
- Process implementation support — helping the incident, problem, change and capacity processes function day to day, not just exist on paper
- Internal audit — a full internal audit of the ITSM system, the step every accredited certification body checks for before Stage 1
- Management review — facilitating the leadership review the standard requires, with real inputs (incidents, service levels, audit findings, improvement actions)
- Certification body selection — helping you choose a NABCB-accredited body suited to your scope and sector
- Stage 1 and Stage 2 audit support — documentation review, then the on-site (or remote) assessment of the system in operation, with corrective-action support if gaps surface
- Surveillance planning — ISO certifications run on a three-year cycle with annual surveillance audits; we set up the cadence so the certificate stays valid without a last-minute scramble
Documents you’ll typically need
- Current service catalogue or list of IT services delivered to customers
- Existing service level agreements (SLAs) or contracts with customers
- Any incident, problem or change logs already maintained, however informal
- Organisation chart showing who owns service delivery and IT operations
- Details of any related certifications already held (ISO 27001, ISO 9001) so the systems can be integrated rather than duplicated
- List of locations, data centres or delivery sites the certification scope should cover
CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.



