The IT service-management challenge
Outages, slow incident resolution, unplanned changes and missed service levels all cost the business in the same way — customers and regulators want assurance that your IT services are run to a defined, repeatable standard. Most organisations have ITIL practices in pockets, but no consistent, measurable system across the service.
ISO/IEC 20000-1 is the international standard for a service management system. It moves you from informal ITSM habits to documented, audited processes with agreed service levels — and gives customers and enterprise buyers independent assurance that you can run their services reliably.
Who needs ISO/IEC 20000-1
ISO/IEC 20000-1 matters most where IT service quality is contractual or business-critical:
- Managed service providers and IT outsourcers whose contracts and RFPs require a certified SMS.
- SaaS, cloud and data-centre operators whose customers hold them to defined service levels.
- IT/ITES and BPO providers proving consistent, auditable ITSM to enterprise buyers.
- In-house IT functions that deliver services to the wider business under formal SLAs.
CyberSigma’s role
We are your implementation and readiness partner. We assess your gaps, design the service management processes, build the SMS, run the internal audit, and coordinate the certification-body audit — a single team from readiness through to a signed certificate.
The certification body’s role
The ISO/IEC 20000-1 certificate is issued by an accredited independent certification body, not by CyberSigma. Keeping implementation and certification separate is what makes the certificate credible. We prepare you for that audit and coordinate it; the body conducts it and issues the certificate.
How we deliver
Gap assessment
We assess your current IT service management against every ISO/IEC 20000-1 clause and give you a prioritised gap list — what exists, what is missing, and what needs to change before a certification audit.
Service management processes design
We design the ITSM processes the standard expects — incident, problem, change, service level, and capacity management — as workflows your service desk and operations teams can actually run, not generic diagrams.
SMS implementation
We build the service management system — the service management policy, the service catalogue and SLAs, and the documented process controls — sized to your organisation rather than a one-size template.
Internal audit & management review
We run the internal audit and a management review before the certification audit, close findings, and confirm you are ready — so the external audit holds no surprises.
Deliverables & evidence
- SMS policy and scope definition
- Service catalogue and service level agreements
- Process definitions for incident, problem, change, service level and capacity management
- Internal audit report and management review minutes
- A traceable evidence pack ready for the certification body audit
Indicative timeline
A typical mid-size SMS runs about 3–5 months from kickoff to the certification-body audit, depending on scope, the number of services in scope, and how mature your current ITSM processes are.
Timelines vary with scope and readiness; we confirm a schedule after the gap assessment.
Representative engagement
A managed service provider needed a certified SMS to satisfy enterprise-customer and RFP requirements. We mapped its services into a catalogue, agreed SLAs with the business, rebuilt its incident, problem and change processes on a single toolset, and took the organisation through internal audit to a successful certification-body assessment. Named client references are available under NDA on request.
Who leads your engagement
Your engagement is led by a senior ISO/IEC 20000-1 lead implementer and auditor — supported by ITSM specialists matched to your services. Every deliverable passes independent quality review before it reaches you or the certification body. We introduce your named lead on the first call.
