ISO 20000 certification cost is the one number every IT service provider wants before committing to the standard, and the one number no registrar will put on a website. That is not evasiveness. The certification audit fee is auditor days multiplied by a day rate, and the day count is set by a published table in ISO/IEC 20000-6 that nobody selling you a quote seems to mention. This guide walks through that table, the consultant and internal figures around it, and what a realistic three-year budget looks like for an IT department or managed service provider in 2026.
Why ISO 20000 certification cost is harder to find than it should be
Search for the price and half of what comes back is for something else. APMG, PECB and the training houses sell individual ISO/IEC 20000 Foundation, Practitioner and Lead Auditor courses, and their pages rank for the same words. A course costs a few hundred to a few thousand dollars per person and certifies a human, not a service management system. If the figure you found is under $3,000 and mentions an exam, it is a course, not a certificate for your organization.
The second problem is that ISO 20000 certification cost sits in four different budgets, usually owned by four different people: the registrar’s invoice, the consultant’s invoice, the tooling you may already pay for, and the staff hours nobody tracks. Most guides quote one of those and call it the total. Below, all four are broken out, with the certification body fee derived from the audit-time table rather than guessed.
What ISO 20000 certification actually is (and is not)
ISO/IEC 20000-1:2018 is the service management system (SMS) requirements standard, currently at its third edition, confirmed by ISO in 2023 with no revision in progress. The only change since 2018 is ISO/IEC 20000-1:2018/Amd 1:2024, the climate action amendment, which ISO distributes free. The standard itself lists at CHF 179 on the ISO Store, roughly US$220. That stability matters for budgeting: unlike ISO 9001 and ISO 14001, both of which moved to 2026 editions, there is no transition audit to price into an ISO 20000 cycle this year.
Certification is issued to the organization by an accredited certification body after a Stage 1 and Stage 2 audit, followed by annual surveillance and a recertification audit in year three. For the process itself, from application through surveillance, see our guide to how ISO 20000 certification works. This post is only about the ISO 20000 certification cost.
The four components of ISO 20000 certification cost
| Cost component | Who invoices it | Typical range (2026, USD) | What drives it |
|---|---|---|---|
| Certification audit (Stage 1 + Stage 2) | Accredited certification body | $4,000 to $25,000 | Effective personnel in scope, sites, services, suppliers |
| Annual surveillance (years 1 and 2) | Certification body | $1,500 to $9,000 per year | Roughly one-third of the initial audit time |
| Recertification (year 3) | Certification body | $3,000 to $17,000 | Roughly two-thirds of the initial audit time |
| Consultant or gap analysis | Consultancy | $5,000 to $45,000 | Maturity of existing processes, how much they write for you |
| Documentation templates | Template vendor | $99 to $2,000 | Whether you buy a pack or a consultant drafts from scratch |
| Training | Training provider | $500 to $5,000 | Internal auditor course, awareness sessions |
| Internal staff time | Your payroll | $10,000 to $30,000 equivalent | Process owners, evidence collection, internal audit |
| ISO/IEC 20000-1:2018 standard | ISO Store | CHF 179 (about $220) | Fixed |
The dollar ranges for consultants, training and internal time are typical figures aggregated from published 2026 guidance by accredited certification bodies and ITSM consultancies; they are not a survey and your quotes will land inside or outside them depending on maturity. The certification body share of ISO 20000 certification cost is different. It can be calculated, and the next section shows how.
How registrars calculate the audit fee: the ISO/IEC 20000-6 table
ISO/IEC 20000-6:2017 is the standard that accreditation bodies hold registrars to when they certify against ISO/IEC 20000-1. Clause 9.1.4.1 requires the certification body to use the effective number of client personnel, counted as full-time equivalents within the scope of the SMS, as the basis for initial audit time, and it publishes the table. Table 1 is based on 8-hour days and covers Stage 1 plus Stage 2 combined:
| Effective personnel in SMS scope (FTE) | Initial audit time, Stage 1 + Stage 2 (days) | Certification audit fee at $1,200 to $2,500 per day |
|---|---|---|
| 1 to 15 | 3.5 | $4,200 to $8,750 |
| 16 to 25 | 4.5 | $5,400 to $11,250 |
| 26 to 45 | 5.5 | $6,600 to $13,750 |
| 46 to 65 | 6 | $7,200 to $15,000 |
| 66 to 85 | 7 | $8,400 to $17,500 |
| 86 to 125 | 8 | $9,600 to $20,000 |
| 126 to 175 | 9 | $10,800 to $22,500 |
| 176 to 275 | 10 | $12,000 to $25,000 |
| 276 to 425 | 11 | $13,200 to $27,500 |
| 426 to 625 | 12 | $14,400 to $30,000 |
Source for the day counts: ISO/IEC 20000-6:2017, Table 1, “before adjustments”. The table continues to 1,175 personnel at 15 days, and registrars extrapolate above that. Three rules from the same clause matter for a small provider:
- The minimum initial audit time is 2.5 days after adjustments, whatever your headcount. A five-person MSP does not get a one-day audit.
- The audit delivered must not be less than 80 percent of the calculated audit time. A registrar quoting well under the table is either miscounting your personnel or not accredited for ISO 20000.
- Audit time includes off-site planning, document review and report writing, not only the days on your premises. Two quotes for the same headcount can look different because one lists the total and one lists the on-site days.
Accredited certification bodies in the US market typically charge between $1,200 and $2,500 per auditor day in 2026; UK registrars publish roughly £850 to £1,500. Multiply the day count by the rate, add the application fee and annual certificate fee most registrars charge ($500 to $2,000 combined), and you have the certification audit line. A registrar that will not show you its day calculation is hiding the only number that matters.
The adjustments that move ISO 20000 audit days up or down
The table is the starting point, not the quote. Registrars add time for multiple sites, a large or unusual service catalogue, and delivery that depends on outsourced suppliers, because the SMS has to demonstrate control over parties it does not employ. That last factor weighs more heavily in ISO 20000 than in most standards, and it is the usual reason two MSPs with identical headcount are quoted a day apart.
Time comes off for an existing certified management system. Clauses 4, 5, 6, 7, 9 and 10 of ISO/IEC 20000-1 share the harmonized structure with ISO 27001 and ISO 9001, so an integrated audit, which registrars run under IAF MD 11, avoids auditing leadership, planning, support and improvement twice. Clause 8, the service-management operation clause, is where almost all the SMS-specific audit time sits and does not shrink. Ask your registrar for the integrated quote in writing; it is routinely 15 to 25 percent lower than two standalone audits, though the reduction is the registrar’s call and is not guaranteed by the standard.
ISO 20000 certification cost by organization size in 2026
Putting the registrar table together with typical consultant and internal figures produces the ISO 20000 certification cost ranges below. They cover the initial certification year only; the three-year cycle follows.
| Organization profile | Certification body (initial audit + fees) | Consultant and templates | Internal time (equivalent) | Typical year-one total |
|---|---|---|---|---|
| Small MSP or IT team, 10 to 25 FTE in scope, one site | $5,000 to $12,000 | $3,000 to $15,000 | $8,000 to $15,000 | $16,000 to $42,000 |
| Mid-size provider, 50 to 125 FTE, one or two sites | $9,000 to $22,000 | $12,000 to $30,000 | $15,000 to $30,000 | $36,000 to $82,000 |
| Enterprise IT or multi-site MSP, 200 to 600 FTE | $14,000 to $35,000 | $25,000 to $60,000+ | $30,000 to $75,000 | $69,000 to $170,000+ |
Two things compress these numbers. A team that already runs ITIL-aligned incident, problem, change and release processes in a proper ITSM tool has most of clause 8 evidenced before the project starts, and the consultant line drops toward gap analysis and internal audit support only. And an organization already certified to ISO 27001 brings the management-system clauses, the internal audit programme and management review with it. For what transfers and what does not, see ISO 20000 vs ITIL.
Two things expand them. Multi-supplier delivery where a subcontractor runs part of a service in scope adds audit time and, more expensively, adds supplier-management work before the audit. And a service catalogue with dozens of loosely defined services in scope forces the auditor to sample across all of them. Trimming scope to the services customers actually contract for is the single cheapest cost control in the whole project.
ISO 20000 certification cost across the three-year cycle
The certificate is valid for three years, and the registrar bills every year of it. Certification bodies working under ISO/IEC 17021-1 plan surveillance at roughly one-third of the initial audit time and recertification at roughly two-thirds, with surveillance never under one day. For a 26-to-45 FTE scope at 5.5 initial days:
| Year | Audit | Auditor days (approx.) | Fee at $1,200 to $2,500 per day |
|---|---|---|---|
| Year 1 | Stage 1 + Stage 2 | 5.5 | $6,600 to $13,750 |
| Year 2 | Surveillance 1 | 2 | $2,400 to $5,000 |
| Year 3 | Surveillance 2 | 2 | $2,400 to $5,000 |
| Year 4 (new cycle) | Recertification | 3.5 to 4 | $4,200 to $10,000 |
Add the annual certificate fee and the rule of thumb holds: budget roughly two to two and a half times the initial audit fee for registrar costs across the first three-year cycle. The recurring internal cost is smaller but real. Someone has to run the internal audit, hold the management review, keep the service management plan current and maintain the records the standard requires; for a mid-size provider that is typically 0.2 to 0.5 of an FTE, often the existing service delivery manager.
Where ISO 20000 projects overspend
Paying a consultant to write documents you could template. The largest variable line in ISO 20000 certification cost is consultancy, and a large share of consultant hours on a first-time project go into drafting the SMS policy, the service management plan, the process documents and the record templates. That drafting is not specialist work; tailoring it to your services is. Buying a documentation pack and paying the consultant only for gap analysis and the internal audit is the usual way a small provider gets year-one cost into the low twenties rather than the forties. Our ISO 20000 mandatory documents list shows exactly what the auditor will ask for.
A failed Stage 2. Every major nonconformity raised at Stage 2 has to be closed before the certificate is issued, and a follow-up visit is billed at the full day rate. The most common causes are the ones the pillar guide lists: no service management plan under clause 6.3, service levels that no customer ever agreed to, and suppliers delivering part of a service in scope but sitting outside the SMS. A genuine internal audit two months before the registrar arrives is cheaper than any of them.
Buying an ITSM platform for the audit. Purpose-built management system software runs $2,000 to $10,000 a year and is sometimes sold as a certification requirement. It is not one. The standard requires evidence that processes operate; a ticketing tool you already run plus a controlled document set is sufficient for the vast majority of certifications. If a tool is justified, justify it on operations, not on the audit.
Scoping the whole company when only IT delivers services. Effective personnel counts the people in scope of the SMS, not the payroll. A 400-person software company whose IT service team is 30 people is audited at the 26-to-45 band, not the 276-to-425 band, if the scope is written that way. Get the scope statement right before requesting quotes.
How to get an accurate ISO 20000 quote
Request three quotes from bodies accredited for ISO/IEC 20000-1 by a recognized accreditation body (UKAS, ANAB, DAkkS or an equivalent IAF MLA signatory), and give each the same facts: FTE in scope, number of sites, the list of services, and every supplier that delivers part of one. Ask each to show the audit-time calculation against ISO/IEC 20000-6 Table 1 and to itemize application, certificate and travel fees. Ask separately for an integrated price if you hold ISO 27001 or ISO 9001. Then compare day counts, not totals, because the day count is what sets ISO 20000 certification cost; a low total with fewer days than the table allows is a quote from a body that is not accredited, and a certificate from it is not worth the paper.
If you are deciding whether ISO 20000 certification cost is worth paying at all, the honest answer is that ISO 20000 is usually a contractual requirement before it is a strategic one. Public-sector and enterprise procurement frameworks list it; if your pipeline does not, ITIL alignment without certification may be the better spend. If it does, the cost above is the price of the bids you are currently locked out of.
Cutting the consultant line: documentation
The ISO 20000 Toolkit ($99) contains over 50 editable templates aligned to ISO/IEC 20000-1:2018: the SMS policy and scope, the service management plan, service catalogue and SLA templates, the incident, problem, change, release, capacity, availability and continuity process documents, supplier agreements, and the internal audit and management review records the registrar will ask for. It replaces the drafting portion of a consultant engagement, which is typically the largest part of it. For the sequence of work around those documents, follow our ISO 20000 implementation guide.
ISO 20000 certification cost: frequently asked questions
How much does ISO 20000 certification cost for a small MSP?
For 10 to 25 people in scope at a single site, the accredited certification body typically charges $5,000 to $12,000 for Stage 1, Stage 2 and first-year fees, based on the 3.5 to 4.5 audit days ISO/IEC 20000-6 sets for that band. With a template pack instead of a full consultant engagement and realistic internal time, a year-one total of $16,000 to $25,000 is achievable; a full consultant build pushes it toward $40,000.
Is the ISO 20000 audit fee negotiable?
The day rate is; the day count largely is not. Accredited bodies must calculate audit time from the effective personnel table in ISO/IEC 20000-6 and deliver at least 80 percent of it. What you can legitimately reduce is the scope (services and people counted), the site count, and the integrated-audit reduction if you already hold another ISO certificate.
Does ISO 20000 certification cost more if we already have ISO 27001?
Less, not more. The management-system clauses (4, 5, 6, 7, 9, 10) are shared under the harmonized structure and an integrated audit under IAF MD 11 avoids auditing them twice. Expect the registrar to quote a combined audit at a noticeable discount to two standalone audits; clause 8 of ISO 20000, the service-management operation clause, still needs its full time.
Is there a transition cost for a new ISO 20000 edition in 2026?
No. ISO/IEC 20000-1:2018 was confirmed by ISO in 2023 and remains the current edition with no revision in progress. The only change since publication is the free 2024 climate action amendment, which adds a consideration to clauses 4.1 and 4.2 and does not require a transition audit.
What is the ongoing ISO 20000 certification cost after the certificate is issued?
Two surveillance audits at roughly one-third of the initial audit time each, an annual certificate fee, and a recertification audit at roughly two-thirds of the initial time when the cycle ends. Internally, plan on a fraction of an FTE to run the internal audit, management review and record maintenance. Budget about two to two and a half times the initial audit fee for registrar costs across the first three years.
References
- ISO/IEC 20000-1:2018 — service management system requirements, Edition 3, confirmed 2023; Amd 1:2024 climate action amendment, free of charge.
- ISO/IEC 20000-6:2017 — requirements for bodies providing audit and certification of service management systems; clause 9.1.4.1 and Table 1 (audit time by effective personnel).
- ISO 27001 certification cost — for comparison when planning an integrated audit.