Registrations

ISO 20000-1 Certification (ITSM)

ISO/IEC 20000-1:2018 certifies the IT service management system behind how you deliver, run and improve IT services — a standalone NABCB-accredited scheme IT vendors use to stand out in government and PSU tenders.

Why founders pick CapEasy

5.0★ across 335+ Google reviews

2,700+ founders served across India

Overview

ISO/IEC 20000-1:2018 is the international standard for an IT Service Management System (ITSM) — the set of processes that govern how an IT service provider plans, delivers, monitors and improves the services it runs for customers, whether those customers are internal teams or external clients. It covers service design and transition, incident and problem management, capacity and availability, service level management and continual improvement, all built around a Plan-Do-Check-Act cycle.

In India, NABCB (National Accreditation Board for Certification Bodies, under the Quality Council of India) runs ISO/IEC 20000-1 as its own standalone accredited management-system scheme, alongside ISO 9001, ISO 27001 and others. That means an Indian IT company can get certified through a NABCB-accredited certification body and hold a credential that carries the same accreditation weight as a 27001 or 9001 certificate — not a lesser or unofficial variant.

There is no Indian law or regulator that makes ISO 20000-1 mandatory. Where it earns its keep is in government IT procurement and PSU tenders: IT vendors bidding to run infrastructure, service desks or managed services for public-sector buyers use it to differentiate a proposal against competitors who cannot show the same process discipline. Treat any tender language claiming ISO 20000-1 is compulsory with caution; the honest framing is competitive edge, not legal floor.

Most IT vendors we work with already hold, or are pursuing, ISO/IEC 27001 for information security. ISO 20000-1 sits naturally alongside it: 27001 governs how you protect information, 20000-1 governs how you run the service around it, and the two systems share enough structure (documentation, internal audit, management review) that building them together beats doing them as separate projects a year apart.

Who it’s for

  • IT services, managed services and helpdesk/service-desk providers bidding for government or PSU IT contracts
  • Software and IT companies already ISO 27001-certified who want the service-management half of the story for a tender
  • Data centre, cloud and infrastructure-management vendors seeking to differentiate on process maturity, not just price
  • IT vendors whose government or PSU RFPs list ISO 20000-1 as a scoring criterion or preferred credential
  • IT vendors whose enterprise or PSU customers are asking, in due diligence, how incidents, changes and service levels are actually managed

Eligibility & requirements

  • A defined scope: which services, locations and customer accounts the ITSM system covers
  • Documented service management processes — service level management, incident/problem/change management, capacity and availability management, and continual improvement
  • A management review cycle and an internal audit programme covering the ITSM scope before the external audit
  • Evidence the processes are actually operating, not just written — logged incidents, tracked service levels, recorded management reviews
  • Commitment from leadership, since ISO 20000-1 (like every ISO management-system standard) requires demonstrable top-management involvement, not a delegated paperwork exercise
  • A NABCB-accredited certification body for the external audit — an unaccredited certificate does not carry the same recognition with government and PSU buyers

How CapEasy handles it

  1. Scoping and gap assessment — we map your current service delivery processes against the ISO/IEC 20000-1:2018 clauses and flag what is missing before you commit to an audit date
  2. Documentation — service level agreements, process definitions, the service catalogue and the records the standard expects, built to match how your team actually works rather than a generic template
  3. Process implementation support — helping the incident, problem, change and capacity processes function day to day, not just exist on paper
  4. Internal audit — a full internal audit of the ITSM system, the step every accredited certification body checks for before Stage 1
  5. Management review — facilitating the leadership review the standard requires, with real inputs (incidents, service levels, audit findings, improvement actions)
  6. Certification body selection — helping you choose a NABCB-accredited body suited to your scope and sector
  7. Stage 1 and Stage 2 audit support — documentation review, then the on-site (or remote) assessment of the system in operation, with corrective-action support if gaps surface
  8. Surveillance planning — ISO certifications run on a three-year cycle with annual surveillance audits; we set up the cadence so the certificate stays valid without a last-minute scramble

Documents you’ll typically need

  • Current service catalogue or list of IT services delivered to customers
  • Existing service level agreements (SLAs) or contracts with customers
  • Any incident, problem or change logs already maintained, however informal
  • Organisation chart showing who owns service delivery and IT operations
  • Details of any related certifications already held (ISO 27001, ISO 9001) so the systems can be integrated rather than duplicated
  • List of locations, data centres or delivery sites the certification scope should cover

CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.

Frequently asked

ISO 20000-1 Certification (ITSM) — questions founders ask

No. There is no statutory mandate requiring it. Government and PSU IT tenders that reference it treat it as a differentiator or scoring criterion, not a legal precondition to bid — though a specific tender’s own terms always govern, so read the RFP itself rather than assuming.

ISO 27001 certifies your information security management system — how you protect data and manage security risk. ISO 20000-1 certifies your IT service management system — how you design, deliver, monitor and improve the IT services themselves, including incidents, changes and service levels. Many IT vendors pursue both because a buyer wants assurance on security and on service delivery, and the two systems share enough structure to be built together efficiently.

NABCB, the National Accreditation Board for Certification Bodies under the Quality Council of India, runs ISO/IEC 20000-1 as a standalone accredited management-system scheme alongside ISO 9001, 27001 and others. Choosing a NABCB-accredited (or an equivalent IAF-MLA-signatory) certification body is what gives the certificate international and government-procurement recognition — an unaccredited certificate does not carry that weight.

No, the two are independent certifications and either can be pursued first. In practice most of our IT-vendor clients already hold or are working toward ISO 27001, and building ISO 20000-1 alongside it is more efficient because the documentation, internal audit and management review cycles overlap.

It depends on how mature your existing service management processes already are and how much documentation and evidence needs to be built before the external audit. We do not quote a fixed timeline upfront; we assess your starting point in the gap assessment and give you a realistic plan from there.

ISO/IEC 20000-1 certification runs on a three-year cycle with an annual surveillance audit by the certification body to confirm the system is still operating, followed by a recertification audit before the third year expires. Skipping a surveillance audit or letting the system lapse can put the certificate at risk.

Your CapEasy experts

Connect with us

Talk to the people who handle this work every day — no call centre, no hand-offs.

Ayush Joshi

Ayush Joshi

Co-Founder

Ex-OYO and Tenaciousfly. 7+ years in business development, strategic acquisitions, financing and debt syndication.

Aditya Jain

Aditya Jain

Co-Founder

Ex-Bank of America. 4+ years in investment banking, EU & Indian compliances, ESG compliances, and project management.

Manav Raval

Virtual CFO & Tax Specialist

Section 80-IAC, tax planning and startup compliance. Previously at Toyota Motor Corporation and Jaguar Land Rover.

Book a free consultation.

An honest assessment of where you are and what comes next — no cost, no pressure, no inflated promises.