ISO 20000-1 for manufacturing IT: services underneath a physical business
Manufacturing IT teams run ERPs, MES, OT bridges and site services that the shop floor cannot run without. ISO 20000-1 formalises how that IT is delivered — a natural companion to a mature ISO 9001 quality system.
Michael McCarroll— Founder, ISO-STANDARD.app · 20+ yrs GRC 15 min read Updated June 2026
Why ISO 20000-1 matters for manufacturers
For a 20–200 person UK or EU manufacturer turning over £2m–£20m, ISO 20000-1 has moved from a nice-to-have to a deal-shaping requirement. Tier-one customers, insurers and regulated purchasers now ask for it by name in RFPs, and the absence of a credible answer is enough to lose the deal before a technical conversation ever happens.
The ICP this guide is written for: a 20–200 person B2B tech business turning over £2m–£20m, pursuing ISO 20000-1 (often alongside one or more of ISO 27001, ISO 20000-1, ISO 9001 and ISO 42001) without a dedicated full-time compliance manager. The founder, CTO, COO or Head of Ops usually owns it in practice.
You are past the stage where 'we take security seriously' answers a questionnaire
Your average enterprise sales cycle now includes an infosec assurance step
You cannot justify a £120k head to own compliance — but the work is real
Where firms in this sector typically start
Most manufacturing firms we speak to are somewhere between two familiar states: an experienced team who genuinely do the right things but cannot prove it to a buyer, and a team with a folder of policies written by someone external three years ago that no one has opened since.
Neither passes a modern audit or a modern buyer review. The starting point isn't 'implement everything' — it's a short, honest gap analysis against the standard, mapped to what already exists.
A 60–90 minute internal walkthrough of what already exists
A gap register scoped to the standard's mandatory clauses first, then Annex controls
An owner and a target certification window — 4–6 months is realistic for this sector
The minimum viable programme
Without a full-time compliance manager, the trap is trying to do everything. A minimum viable ISO 20000-1 programme for a 20–200 person UK or EU manufacturer turning over £2m–£20m is scoped, owned, and evidenced — not exhaustive.
The essential ingredients are the same across sectors: a defined scope, a leadership team that has signed off, a live risk register, the controls the standard requires, policies people actually read, and evidence produced as a by-product of doing the work rather than a separate reporting task.
Scope statement (single page, signed by the CEO)
Risk register with owners, treatment plans and review dates
Controls / Annex mapping showing what applies, what doesn't, and why
Policies drafted for adoption, not for a shelf
Evidence store linked directly to controls and audits
A calendar of internal audit, management review and improvement actions
Sector-specific pitfalls in manufacturing firms
Manufacturers typically try to certify every site at once. Start with corporate IT plus one representative site; add sites in scheduled surveillance visits. Trying to certify five sites in year one is how manufacturing programmes stall.
The second pattern to avoid is treating the standard like a shopping list. The clauses that talk about leadership, planning, evaluation and improvement matter more than the controls themselves — those are what auditors actually test for maturity.
How ISO-STANDARD.app changes the economics
The reason a 20–200 person UK or EU manufacturer turning over £2m–£20m without a compliance manager historically failed to certify wasn't will — it was cost. A traditional consultancy-plus-spreadsheet programme runs £30k–£45k in year one. Most of that pays for policy drafting, spreadsheet maintenance and evidence chasing that a modern platform simply removes.
ISO-STANDARD.app ships a ready-to-adopt ISO 20000-1 workspace with the risk register, controls catalogue, policies, evidence store, internal audit programme and audit-ready exports already wired together. What remains is your organisation's genuinely unique work — scope, risk decisions, and evidence — which is where a founder or ops leader's time actually adds value.
Consultancy-led baseline: ~£30k–£45k in year one
Templates + spreadsheets baseline: ~£20k–£25k with heavy internal hours
ISO-STANDARD.app: from £39/month plus focused internal effort
A 90-day path to readiness
For a 20–200 person UK or EU manufacturer turning over £2m–£20m, a credible 90-day readiness path exists and is well-worn. Certification itself lands in months 4–6 depending on registrar availability.
Days 1–14 · Scope, leadership sign-off, gap analysis, register the workspace
Days 15–45 · Populate the risk register, adopt policies, assign control owners, close top-priority gaps
Days 46–75 · Collect evidence for each control, run the first internal audit, remediate findings
Days 76–90 · Management review, Stage 1 documentation submission, book Stage 2
Frequently asked questions
Do we really need ISO 20000-1 to sell into enterprise?
For a 20–200 person UK or EU manufacturer turning over £2m–£20m, yes — increasingly so. It's the fastest way to get through the infosec section of an RFP or vendor onboarding without a bespoke justification. Firms that don't have it either lose deals or spend disproportionate founder time answering questionnaires that a certificate would answer once.
Can we certify ISO 20000-1 without hiring a compliance manager?
Yes, and most firms in this ICP do exactly that. What you need is a nominated owner (typically the COO, CTO or Head of Ops) with 4–6 hours a week for the programme, an executive sponsor, and a platform that removes the spreadsheet and drafting work. A part-time fractional practitioner for 4–8 days total is often enough.
How long does it realistically take?
For a 20–200 person B2B tech firm with a tight scope and an integrated platform: 90 days to readiness, 4–6 months to certificate (governed by UKAS registrar availability). Longer programmes almost always suffer from over-scoping, not from complexity of the standard.
How much will it cost in year one?
All-in with ISO-STANDARD.app: roughly £8k–£15k for a small scope (registrar + platform + focused internal time). Traditional consultancy-plus-spreadsheet programmes for the same scope typically run £30k–£45k. Recertification and surveillance run £4k–£8k a year afterwards.
How does ISO 20000-1 fit if we're also pursuing ISO 27001 / ISO 9001 / ISO 42001?
Well, if you use one integrated management system. The clauses on leadership, planning, support, operation, evaluation and improvement are near-identical across ISO management system standards. Duplicated risk registers, audit programmes and policies are the biggest source of wasted effort — an integrated workspace collapses them into one.
Ship ISO 20000-1 without a full-time compliance manager
ISO-STANDARD.app packages the whole ISO 20000-1 programme — risk register, controls, policies, evidence, audits — into one workspace priced for a 20–200 person UK or EU manufacturer turning over £2m–£20m.
ISO-STANDARD.app ships a ready-to-adopt ISO 20000-1 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.