ISO/IEC 20000-1 is the international standard for an IT Service Management System (SMS), governing how IT services are planned, designed, delivered and continually improved. QSECS provides end-to-end ISO/IEC 20000-1 consulting and implementation, applying rigorous change and configuration disciplines to make post-quantum cryptographic migration a controlled, low-risk service change rather than a disruptive overhaul. We prepare and implement your SMS, readying you for certification by an accredited body — QSECS consults and implements; it does not certify. The result is quantum-ready compliance delivered with the same predictability your business expects from every other managed service.
ISO/IEC 20000-1 defines the requirements for establishing, operating and improving a Service Management System that delivers IT services aligned to business and customer needs.
At its heart, ISO/IEC 20000-1 establishes a Service Management System: a coordinated set of policies, objectives, processes and resources that an organisation uses to direct and control its IT services. It frames service management around a full lifecycle — planning and design of new or changed services, transition into the live environment, day-to-day delivery, and continual improvement — so that every service is governed consistently from concept through retirement.
The standard codifies the core processes that keep services reliable, including incident, problem, change, configuration, release and service-level management. These disciplines align closely with widely adopted ITIL practices, giving organisations a recognised, auditable way to manage risk and maintain service quality. By integrating measurement, control and feedback at every stage, ISO/IEC 20000-1 assures that IT services remain dependable, predictable and genuinely aligned to the customers and business outcomes they support.
The Service Management System and its governing policy, objectives and leadership commitments
Service design, transition and delivery across the full service lifecycle
Incident and problem management to restore service and eliminate root causes
Change, configuration and release management for controlled, traceable service changes
Service-level management and continual service improvement of performance and quality
Cryptography Is Now a Service-Management Problem
An SMS treats every certificate, key, library and protocol as a configuration item, and the quantum threat turns crypto migration into a service-management programme spanning change, configuration and release management. U.S. Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks," sets legally binding federal post-quantum deadlines — key establishment by December 31, 2030 and digital signatures by December 31, 2031. Without crypto-agility tracked in your CMDB, swapping algorithms later becomes an unmanaged, high-risk change, while "Harvest Now, Decrypt Later" exposes data in transit today.
QSECS manages your post-quantum transition through proven service management discipline, treating cryptographic modernisation as a planned, controlled change within your existing SMS.
We track every cryptographic asset — certificates, keys, libraries and protocols — as configuration items in your configuration management database (CMDB), giving full visibility of what must be migrated
We run PQC migration to NIST standards (FIPS 203, 204 and 205) as governed change and release management, with defined approvals, testing and rollback plans so live services stay protected
We sequence the migration roadmap as a managed release schedule so high-risk systems are remediated first and the transition completes well before the NIST 2030-2035 deadline
We protect SLA continuity throughout the transition, scheduling cryptographic changes within agreed maintenance windows so availability and performance targets are upheld
We embed continual service improvement, reviewing metrics and feeding lessons back into your SMS so quantum readiness becomes part of ongoing, auditable service management
A defined service catalogue and the scope of services you want the SMS to cover
A CMDB or asset inventory and named service owners for the processes the SMS will govern
Management commitment to the programme — no prior cryptography or audit experience required
The SMS processes, with crypto assets tracked as configuration items in your CMDB
Change and release controls that turn cryptographic migration into a governed, low-risk service change
Readiness hand-off to the accredited certification body — QSECS consults and implements; it does not certify
If your organisation runs IT services that customers or the business depend on, a managed SMS turns quantum readiness into routine, controlled work.
The owners accountable for service quality, SLAs and the maturity of the SMS itself.
Get a certification-ready SMS implemented end-to-end by QSECS, with PQC migration built into governance.
The teams running live services who must keep availability and performance targets intact.
Migrate cryptography within agreed maintenance windows, so SLAs hold throughout the transition.
The people who keep the CMDB accurate and every change traceable and approved.
Track every key, certificate and library as a configuration item so algorithm swaps stay governed.
An illustrative path through implementation — every engagement is scoped to your services before work begins.
Confirm the service catalogue, SMS boundary and the objectives the management system must meet.
Design incident, problem, change, configuration, release and service-level processes to the standard.
QSECS populates the CMDB and tracks every key, certificate and library as a configuration item for PQC migration.
Run the internal audit and management review to confirm the SMS operates and is ready for certification.
The accredited certification body performs the external audit and issues the certificate — not QSECS.
Timelines vary with scope and team availability. QSECS provides consulting and implementation up to the external audit — the accredited certification body issues the certificate itself.
What teams usually ask before starting an ISO/IEC 20000-1 consulting and implementation engagement.
No. QSECS provides the consulting and implementation — SMS design, process build-out, CMDB and crypto-asset tracking, and internal audit support. The certificate itself is issued by an accredited certification body following its independent external audit, which we ready you for and hand off to.
ISO/IEC 20000-1 is the auditable standard against which a Service Management System is certified, while ITIL is a body of best-practice guidance. The two align closely: ITIL practices are a common way to implement the processes the standard requires, but only ISO 20000-1 can be certified.
It depends on the breadth of services in scope and your current process maturity. Our consulting and implementation runs in phases through to internal audit and management review, after which the accredited body schedules its external audit. We agree a realistic timeline during scoping.
We design and implement the SMS processes, populate the CMDB, build change and release controls, and prepare the audit evidence; your team provides system access, service knowledge and approvals. We embed alongside your service owners so the SMS is owned internally once the engagement ends.
We record every certificate, key, library and protocol as a configuration item in your CMDB, giving full visibility of what must migrate. Algorithm swaps to the NIST PQC standards (FIPS 203/204/205) then run as governed change and release management with approvals, testing and rollback — keeping you ahead of the Executive Order 14412 deadlines.
Yes. Engagements run onsite, remote or hybrid, and we tailor the SMS processes, CMDB and controls to your service catalogue, tooling and existing ITSM platform under NDA. Scope and tailoring are agreed during the requirement-analysis call.