What Is ISO 20000 and Does Your IT Business Need It?

You run an IT business in Australia. Chances are you've heard the name ISO 20000 before. Maybe a client asked about it. Maybe you saw it in a tender. Maybe a competitor's got it plastered on their homepage. Here's what it actually is. ISO/IEC 20000-1:2018 is a standard for running IT services properly. Work out what your customers need. Set service levels you can actually keep. Handle incidents and changes the right way. Keep improving instead of standing still.
What's Actually In It
This thing's been around since 2004. The current version, ISO/IEC 20000-1:2018, is what everyone means when they say "ISO 20000" now. ISO and IEC built it jointly, and it's now the standard reference point for IT service management worldwide. What it actually demands is a working system - something that lets you plan, deliver, keep an eye on, and improve your services over time. It won't dictate your software stack. It won't force one rigid process on your team. It just needs to genuinely fit how your business operates.
ITIL gets mentioned in the same breath a lot, understandably, since there's real overlap. One key difference though: you can't get a company "ITIL certified." That's a personal qualification. ISO 20000 flips that - the organisation itself gets audited and certified, not an individual. Plenty of businesses run both anyway. ITIL's more the how; ISO 20000 is what an auditor actually checks your system against.
Why This Actually Matters Right Now
Treating IT service management as background admin is a mistake. It's the thing that decides how fast an incident gets sorted, how well a client's kept informed mid-outage, whether they renew with you next year or quietly start shopping around. Run it loosely and you'll probably be fine - for a while. Then a big outage hits. Or a client asks to see your processes and you've got nothing solid to hand over. Or a tender goes to the competitor who already has the certificate and you don't.
That last scenario's showing up more often these days. Doesn't mean every tender demands ISO 20000 though - some government and enterprise buyers in Australia list it, plenty don't. State and territory tenders swing the same way. Read the actual document. Don't assume either way.
When It's Worth Looking Into
You don't need to be a big operation for this to matter. Worth thinking about if any of this sounds familiar:
The same incidents keep resurfacing and nobody's actually nailed the root cause
Clients keep asking about service levels or how things are governed on your end
Government or enterprise contracts are somewhere on your radar
Your team's past the point where "everyone just knows the drill" actually holds up
A competitor nearby already has the certificate and is using it
None of that gets fixed by a certificate sitting in a drawer. It gets fixed by actually building the system. The certificate is just the proof afterward.

What It Looks Like in Practice, Not Just on Paper
Forget the certificate for a minute. What matters more is whether the system reflects how the business genuinely runs day to day.
Take an IT provider where people already deal with incidents and change requests - but everyone's got their own approach. One tech logs everything properly. Another barely bothers. A third invented a shortcut nobody else knows about. A real system kills that inconsistency. Clear ownership, the same steps every time, and proof things happen the way they're meant to - not just an assumption that they do.
That's usually where a gap assessment comes in first. Rather than dumping a pile of templates on a business straight away, a decent consultant looks at what's already solid and puts effort only where it's genuinely missing.
Getting Certified, Step by Step
This isn't one audit and you're done - it's a sequence.
Gap assessment first, comparing what you already do against what the standard actually expects. Then building the real system out: incident, problem and change procedures, a service catalogue, SLA and OLA templates, a record of your setup. After that, you run it for real - long enough that it generates genuine evidence, not paperwork cobbled together the week before an audit. Only then does the external audit happen: Stage 1 as a readiness check, Stage 2 as the actual certification, both run by an accredited body.
In Australia, JAS-ANZ accredits whoever's doing these audits. A specific tender might still stack extra requirements on top of that baseline though. And there's genuinely no fixed timeframe - it comes down to your scope, how far along your existing setup already is, and how much distance is left before you're audit-ready.
When Outside Help Actually Pays Off
Reading the standard yourself? Not hard. Turning it into something that actually functions while you're still running the business day to day - that's the real challenge. This is generally where ISO consulting earns its keep, and not by dumping generic paperwork on you either. It's about finding what your team's already doing well, closing the actual gaps, and shaping something that fits how you genuinely work rather than a template someone's recycled a dozen times.
A good consultant also catches the expensive mistakes before they happen: scoping things too broadly, writing documentation that has nothing to do with how work actually gets done, or walking into Stage 2 underprepared and scrambling to fix it afterward.
Start from the business, not the paperwork. Work out what you deliver, who receives it, what's actually been promised, and how incidents and risks get handled right now. Build the documentation to match that - not the reverse. Skip that step and you end up with procedures that read beautifully during an audit and get ignored by everyone the moment the auditor leaves.
For current information on Australian Government procurement, contract reporting and SME participation, see the Australian Government Department of Finance’s AusTender procurement statistics. Australian Government procurement statistics – Department of Finance

Picking the Right Consultant
Not every quality consultant actually understands IT environments. When you're weighing up a business transformation consultant for ISO 20000 work specifically, check they've genuinely worked inside ITSM teams before - not just general quality management from a different industry. A decent one will be upfront about timelines and how much internal effort it'll actually take, rather than pitching some unrealistic fast-track. Worth asking what a typical engagement looks like, who's actually doing the hands-on documentation, and how they run internal audits before the real one lands.
Looking to prepare for your next ISO audit? Explore our guide, ISO 27001 Audit Readiness: A Simple Guide for Businesses, for a clear, practical approach to getting audit-ready.
Final Thoughts
ISO 20000 was never really about a framed certificate. It's a way of making IT service delivery something you can actually measure and prove, whether that's for a tender, for cutting down repeat problems, or just tidying things up as the business grows. Understanding what the standard genuinely requires is what lets you decide whether it's worth the effort.
At 6 Sigma Consulting, we work with Australian IT businesses on exactly this - gap assessment through to certification readiness, part of our broader ITSM and process management work. If ISO/IEC 20000-1 is something you're weighing up, we can help you figure out where you actually stand and what a realistic path forward looks like.
Considering ISO/IEC 20000-1 certification for your IT business?
Reach out to 6 Sigma Consulting for a practical gap assessment and a clear roadmap towards certification readiness.
Frequently Asked Questions
What is ISO 20000 and does my IT business need it?
The international standard for IT service management. Worth a look if incidents keep repeating, clients keep asking about your service levels, or bigger and government contracts are somewhere on your horizon.
What's the difference between ISO 20000 and ITIL?
ITIL shapes how your team works day to day - but individuals get certified in it, not companies. ISO 20000's the reverse: your whole organisation can be audited and certified.
How long does ISO 20000 certification take?
Genuinely no fixed answer. Depends on your scope, how mature your current setup already is, and how much documentation and work sits between here and audit-ready.
Does ISO 20000 certification help with government tenders?
Sometimes, when a tender specifically names it. Read the individual tender rather than assuming either way.
Can a small IT company realistically get certified?
Yes. The standard scales to the business - a small operation can set its scope around exactly what it delivers.


Comments