HomeServices
Corporate Training Security Compliance Guide VAPT as a Service
AboutRecent Trends Get Started
ISO 20000-1

ISO 20000-1
Compliance, Quantum-Ready Consultation

ISO/IEC 20000-1 is the international standard for an IT Service Management System (SMS), governing how IT services are planned, designed, delivered and continually improved. QSECS provides end-to-end ISO/IEC 20000-1 consulting and implementation, applying rigorous change and configuration disciplines to make post-quantum cryptographic migration a controlled, low-risk service change rather than a disruptive overhaul. We prepare and implement your SMS, readying you for certification by an accredited body — QSECS consults and implements; it does not certify. The result is quantum-ready compliance delivered with the same predictability your business expects from every other managed service.

ISO 20000-1 compliance illustration
2018
ISO/IEC 20000-1 Published
4
Plan-Do-Check-Act Phases
35+
ITSM Implementations
2031
EO 14412 Signature Deadline
The Framework

Understanding ISO 20000-1

ISO/IEC 20000-1 defines the requirements for establishing, operating and improving a Service Management System that delivers IT services aligned to business and customer needs.

At its heart, ISO/IEC 20000-1 establishes a Service Management System: a coordinated set of policies, objectives, processes and resources that an organisation uses to direct and control its IT services. It frames service management around a full lifecycle — planning and design of new or changed services, transition into the live environment, day-to-day delivery, and continual improvement — so that every service is governed consistently from concept through retirement.

The standard codifies the core processes that keep services reliable, including incident, problem, change, configuration, release and service-level management. These disciplines align closely with widely adopted ITIL practices, giving organisations a recognised, auditable way to manage risk and maintain service quality. By integrating measurement, control and feedback at every stage, ISO/IEC 20000-1 assures that IT services remain dependable, predictable and genuinely aligned to the customers and business outcomes they support.

What ISO 20000-1 Covers

The Service Management System and its governing policy, objectives and leadership commitments

Service design, transition and delivery across the full service lifecycle

Incident and problem management to restore service and eliminate root causes

Change, configuration and release management for controlled, traceable service changes

Service-level management and continual service improvement of performance and quality

Cryptography Is Now a Service-Management Problem

An SMS treats every certificate, key, library and protocol as a configuration item, and the quantum threat turns crypto migration into a service-management programme spanning change, configuration and release management. U.S. Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks," sets legally binding federal post-quantum deadlines — key establishment by December 31, 2030 and digital signatures by December 31, 2031. Without crypto-agility tracked in your CMDB, swapping algorithms later becomes an unmanaged, high-risk change, while "Harvest Now, Decrypt Later" exposes data in transit today.

Staying Current

How QSECS Keeps Your ISO 20000-1 Future-Proof

QSECS manages your post-quantum transition through proven service management discipline, treating cryptographic modernisation as a planned, controlled change within your existing SMS.

We track every cryptographic asset — certificates, keys, libraries and protocols — as configuration items in your configuration management database (CMDB), giving full visibility of what must be migrated

We run PQC migration to NIST standards (FIPS 203, 204 and 205) as governed change and release management, with defined approvals, testing and rollback plans so live services stay protected

We sequence the migration roadmap as a managed release schedule so high-risk systems are remediated first and the transition completes well before the NIST 2030-2035 deadline

We protect SLA continuity throughout the transition, scheduling cryptographic changes within agreed maintenance windows so availability and performance targets are upheld

We embed continual service improvement, reviewing metrics and feeding lessons back into your SMS so quantum readiness becomes part of ongoing, auditable service management

Prerequisites

What You Need Before You Start

Recommended Readiness

A defined service catalogue and the scope of services you want the SMS to cover

A CMDB or asset inventory and named service owners for the processes the SMS will govern

Management commitment to the programme — no prior cryptography or audit experience required

What QSECS Implements

The SMS processes, with crypto assets tracked as configuration items in your CMDB

Change and release controls that turn cryptographic migration into a governed, low-risk service change

Readiness hand-off to the accredited certification body — QSECS consults and implements; it does not certify

Who Should Plan for ISO 20000-1

Is an ISO 20000-1 SMS Right for Your Team?

If your organisation runs IT services that customers or the business depend on, a managed SMS turns quantum readiness into routine, controlled work.

IT Service Management Leads

The owners accountable for service quality, SLAs and the maturity of the SMS itself.

Get a certification-ready SMS implemented end-to-end by QSECS, with PQC migration built into governance.

IT Operations & Infrastructure

The teams running live services who must keep availability and performance targets intact.

Migrate cryptography within agreed maintenance windows, so SLAs hold throughout the transition.

Change & Configuration Managers

The people who keep the CMDB accurate and every change traceable and approved.

Track every key, certificate and library as a configuration item so algorithm swaps stay governed.

Sample Agenda

A Sample ISO 20000-1 Consulting Engagement

An illustrative path through implementation — every engagement is scoped to your services before work begins.

Phase 1

Service & Scope Definition

Confirm the service catalogue, SMS boundary and the objectives the management system must meet.

Phase 2

SMS Process Design

Design incident, problem, change, configuration, release and service-level processes to the standard.

Phase 3

CMDB & Crypto-Asset Implementation

QSECS populates the CMDB and tracks every key, certificate and library as a configuration item for PQC migration.

Phase 4

Internal Audit & Management Review

Run the internal audit and management review to confirm the SMS operates and is ready for certification.

Certification

External Audit by the Accredited Body

The accredited certification body performs the external audit and issues the certificate — not QSECS.

Timelines vary with scope and team availability. QSECS provides consulting and implementation up to the external audit — the accredited certification body issues the certificate itself.

FAQ

ISO 20000-1 Questions

What teams usually ask before starting an ISO/IEC 20000-1 consulting and implementation engagement.

No. QSECS provides the consulting and implementation — SMS design, process build-out, CMDB and crypto-asset tracking, and internal audit support. The certificate itself is issued by an accredited certification body following its independent external audit, which we ready you for and hand off to.

ISO/IEC 20000-1 is the auditable standard against which a Service Management System is certified, while ITIL is a body of best-practice guidance. The two align closely: ITIL practices are a common way to implement the processes the standard requires, but only ISO 20000-1 can be certified.

It depends on the breadth of services in scope and your current process maturity. Our consulting and implementation runs in phases through to internal audit and management review, after which the accredited body schedules its external audit. We agree a realistic timeline during scoping.

We design and implement the SMS processes, populate the CMDB, build change and release controls, and prepare the audit evidence; your team provides system access, service knowledge and approvals. We embed alongside your service owners so the SMS is owned internally once the engagement ends.

We record every certificate, key, library and protocol as a configuration item in your CMDB, giving full visibility of what must migrate. Algorithm swaps to the NIST PQC standards (FIPS 203/204/205) then run as governed change and release management with approvals, testing and rollback — keeping you ahead of the Executive Order 14412 deadlines.

Yes. Engagements run onsite, remote or hybrid, and we tailor the SMS processes, CMDB and controls to your service catalogue, tooling and existing ITSM platform under NDA. Scope and tailoring are agreed during the requirement-analysis call.