Update: ITIL (Version 5) is now released. See ITIL 5 explained — what changed for the full picture.
ISO 20000 vs ITIL is the most common question in IT service management, and it rests on a category error. They are not competing options. One is an auditable standard an organisation can be certified against; the other is a body of guidance that describes how to do the work well. Most mature IT functions end up using both.
ISO 20000 vs ITIL: the fundamental difference
ISO/IEC 20000-1:2018 is a specification. It uses “shall”, it defines auditable requirements, and an accredited certification body can certify an organisation against it. That certificate is a thing you can put in a tender response.
ITIL is guidance. It describes practices in depth and explains why they work. No organisation is certified against ITIL — ITIL certification exists only for individuals. That distinction matters commercially: a customer asking for proof of your service management maturity cannot be satisfied by your staff’s personal ITIL certificates.
Where ISO 20000 vs ITIL overlap
ISO 20000 vs ITIL overlap heavily in clause 8. If you run ITIL practices well, much of the operational half of the standard is already evidenced: incident, service request and problem management map onto clause 8.6; change, service design and release map onto 8.5; availability, continuity and information security map onto 8.7; capacity and demand onto 8.4; service level and supplier management onto 8.3.
Clause 8 is where the standard becomes specific, and it is organised as one general requirement plus six practice areas:
- 8.1 Operational planning and control
- 8.2 Service portfolio — service planning, control of parties involved, the service catalogue and asset management.
- 8.3 Relationship and agreement — business relationship management, service level management and supplier management.
- 8.4 Supply and demand — budgeting and accounting, demand management and capacity management.
- 8.5 Service design, build and transition — change management, service design, build and the controlled transition into live operation.
- 8.6 Resolution and fulfilment — incident management, service request management and problem management.
- 8.7 Service assurance — service availability management, service continuity management and information security management.
Documentation for both, in one place.
The ISO 20000 Toolkit covers the certifiable SMS end to end, and the ITIL 4 Toolkit provides the practice-level documentation that sits underneath it — over 70 templates each.
Explore the ISO 20000 Toolkit →ISO 20000 vs ITIL: what ITIL does not give you
This is where ISO 20000 vs ITIL stops being academic. ITIL has no equivalent of the management system wrapper: context and interested parties, leadership and policy, planning of objectives and risks, competence and documented information, internal audit, management review and improvement. Nor does it have clause 6.3, the service management plan, which is the requirement most ITIL-mature organisations discover late and the most common reason a first certification attempt fails.
Put plainly: ITIL tells you how to run change management well. ISO 20000 asks who owns the SMS, how it is resourced, how it is audited, and how you prove any of it to a third party.
ISO 20000 vs ITIL: what the standard does not give you
Equally, the standard is deliberately thin on how. It requires problem management; it does not explain root cause technique, or how to structure a major incident process, or what good looks like in practice. That is exactly what ITIL supplies. An organisation that implements only the standard tends to produce a compliant but hollow system — processes that satisfy an auditor and irritate everyone who has to use them.
ISO 20000 vs ITIL: which one do you actually need?
If a customer, tender or regulator is asking for evidence, you need ISO 20000 certification, and ITIL is the fastest route to the operational content. If nobody is asking and you simply want better service delivery, ITIL alone is sufficient and cheaper. The mistake is pursuing certification purely as a badge: the standard rewards organisations that genuinely run their services well, and audits are conducted by people who can tell the difference.
See our guides to ISO 20000 certification, the ISO 20000 implementation guide and ISO 20000 alignment with other frameworks.
References
- ISO/IEC 20000-1:2018 — the service management system requirements on iso.org.
- ISO/IEC 20000-1:2018/Amd 1:2024 — the climate action amendment.
More on ISO 20000
- ISO 20000 certification
- ISO 20000 implementation guide
- ISO 20000 mandatory documents
- ISO 20000 internal audit checklist
- ISO 20000 vs ITIL — you are here
- ISO 20000 alignment
All of these are covered by the ISO 20000 Toolkit, with practice-level documentation in the ITIL 4 Toolkit.