Skip to main content
Category: Certification and Accreditation

Accreditation Scope

Also known as: Scope of Accreditation
Simply put

An accreditation scope is the official, detailed statement of the specific activities that an organization has been accredited to perform. It defines exactly what is and is not covered by an accreditation, so that anyone relying on it understands its boundaries. The scope is granted and recognized by an accreditation body rather than being open-ended.

Formal definition

An accreditation scope is the formal, documented statement issued by an accreditation body specifying the precise activities for which an organization is accredited and, by extension, the technical competence being recognized. In the laboratory context (ISO/IEC 17025), it is defined per ILAC G18 as the official and detailed statement of activities for which the laboratory is accredited, demonstrating technical competence for a defined scope alongside operation of a quality management system. More broadly, accreditation is structured around defined scopes: the IAF Multilateral Recognition Arrangement (MLA) currently organizes recognition into main scopes including Management Systems Certification, Product Certification, Certification of Persons, and Validation and Verification. Any accreditation applies only within its stated scope; activities outside the documented scope are not covered by the accreditation.

Why it matters

Accreditation scope matters because accreditation is never open-ended: it recognizes competence only for the specific activities documented in the scope statement. For anyone relying on an accredited outcome, whether a certification, a test result, or a calibration, the scope defines the boundary of what has actually been assessed. Activities that fall outside the documented scope are not covered, even if the accredited body appears otherwise qualified to perform them. Misreading this boundary can lead an organization to place trust in an outcome that was never within the accreditation's remit.

In the compliance context, this distinction affects how much weight a stakeholder can reasonably assign to an accredited certification body's work. For example, an ISO 27001 certificate is issued by a certification body whose accreditation is itself defined by a scope, typically within the IAF Multilateral Recognition Arrangement's Management Systems Certification main scope. Understanding that accreditation applies only within its stated scope helps clarify why a certificate covers only the defined ISMS and why the credibility of that certificate depends on the certification body operating within its own accredited scope.

Because the precise scope is granted and recognized by an accreditation body rather than self-declared, it provides a verifiable reference point. In most engagements, checking the documented scope is the appropriate way to confirm that a given activity was genuinely within the accredited competence, rather than assuming coverage from a body's general reputation or from a related but distinct activity.

Who it's relevant to

Compliance managers relying on third-party certifications
When evaluating an ISO 27001 certificate from a certification body, compliance managers should confirm that the body is accredited within the relevant scope, typically Management Systems Certification under the IAF MLA. The accreditation scope indicates whether the certification work falls within recognized competence, which is distinct from, and does not replace, checking the scope of the ISMS covered by the certificate itself.
Auditors and certification bodies
Certification bodies operate within their own accredited scope, and their outputs carry recognized weight only for activities inside that documented boundary. Auditors assessing a supplier's credentials benefit from understanding that accreditation applies only within its stated scope, so that activities outside the documented scope are treated as uncovered rather than assumed to be within competence.
GRC professionals managing vendor and laboratory assurance
For those relying on accredited laboratories or verification bodies, the scope of accreditation, defined under ISO/IEC 17025 per ILAC G18 for laboratories, is the reference point for confirming that a specific test, calibration, or verification activity was genuinely within recognized competence. GRC teams should verify the documented scope rather than infer coverage from an accreditation's general existence.

Inside Accreditation Scope

Certification Body Accreditation
The formal recognition, granted by a national accreditation body, that a certification body is competent to issue ISO/IEC 27001 certifications within specified boundaries. Accreditation scope defines the range of activities the certification body is authorized to perform.
Sectors and Technical Areas
The industry sectors, technical fields, or economic activities for which the certification body has demonstrated competence. A certification body accredited for one set of sectors may not be accredited to certify organizations operating in others.
Standard(s) Covered
The specific standard(s) against which the certification body is accredited to certify, for example, ISO/IEC 27001 for information security management systems, which should be distinguished from related standards such as ISO 27002, ISO 27017, or ISO 27018 that serve as guidance rather than certifiable requirements.
Geographic and Jurisdictional Boundaries
The regions or jurisdictions in which the accreditation is recognized, which may depend on mutual recognition arrangements among accreditation bodies. Scope in this sense reflects where a certification carries recognized weight.
Relationship to ISMS Certification Scope
Accreditation scope (what the certification body is authorized to do) is distinct from the scope of a certified organization's ISMS, which is defined by the organization under clauses 4 through 10 and documented alongside its Statement of Applicability. The two should not be conflated.

Common questions

Answers to the questions practitioners most commonly ask about Accreditation Scope.

Does an ISO 27001 certificate mean the entire organization is certified?
No. An ISO 27001 certificate covers only the defined scope of the ISMS, not necessarily the whole organization. The scope may be limited to specific business units, locations, services, or systems as documented during the engagement. Reviewing the scope statement on the certificate is essential to understand exactly what is and is not covered, since areas outside the defined boundary are not addressed by the certification.
Is a SOC 2 report's scope the same concept as an ISO 27001 accreditation scope?
Not exactly. A SOC 2 report attests only to the controls and the period covered by the examination, while ISO 27001 certification covers the defined scope of the ISMS. These are related ideas about boundaries, but they arise from different frameworks, a SOC 2 attestation performed by a CPA firm versus a certification issued by an accredited certification body, and their scope definitions are not interchangeable. Satisfying the scope of one does not automatically satisfy the other, as mapping between the frameworks is only partial.
How do I determine what should be included in the scope?
Scope is typically set through scoping decisions that consider the services, systems, locations, and business functions relevant to the intended audience or objective. For ISO 27001, the ISMS requirements in clauses 4 through 10 guide how the organization defines its scope, informed by its context and risk assessment. For SOC 2, scope decisions determine which Trust Services Criteria categories apply beyond the required Security (Common Criteria) category. In most engagements, the scope is documented and agreed before fieldwork begins.
Can the scope be expanded after an initial engagement?
Yes, scope can typically be adjusted in subsequent engagements or certification cycles, depending on the certification body, auditor, and the organization's decisions. Expanding scope may involve additional systems, locations, or services, and for SOC 2 may involve adding optional Trust Services Criteria categories such as Availability, Processing Integrity, Confidentiality, or Privacy. The specifics of how and when scope changes are handled vary by engagement, so confirming the process with the relevant certification body or auditor is advisable.
Where can I verify the scope that was actually assessed?
For ISO 27001, the scope is stated on the certificate and in supporting documentation such as the Statement of Applicability, which records which Annex A reference controls were selected. For SOC 2, the scope is described within the report itself, including the controls and period covered. Reviewing these documents directly is the reliable way to confirm boundaries rather than relying on general summaries.
Does a well-defined scope guarantee there will be no security incidents in those areas?
No. A defined scope establishes what was assessed but does not guarantee freedom from breaches. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined ISMS scope; neither provides an assurance that incidents will not occur. Outcomes depend on the controls in place, how effectively they operate, and factors outside the assessed boundary.

Common misconceptions

Any certification body can issue a valid ISO 27001 certificate for any organization in any sector.
A certification body typically operates within a defined accreditation scope covering particular standards, sectors, and jurisdictions. Certification obtained outside a body's accreditation scope may carry less recognition, so verifying that the body is accredited for the relevant standard and sector is advisable.
Accreditation scope and the scope of the certified ISMS are the same thing.
They are separate concepts. Accreditation scope describes what the certification body is authorized to certify, while the ISMS scope describes the boundaries of the organization's management system as defined under the ISO 27001 requirements clauses and its Statement of Applicability. An ISO 27001 certificate covers only the defined scope of the ISMS.
An accredited ISO 27001 certification is equivalent to, or interchangeable with, a SOC 2 report.
The two outcomes differ fundamentally: ISO 27001 is a certification issued by an accredited certification body against a management system standard, whereas SOC 2 is an attestation examination performed by a licensed CPA firm resulting in a report. Mapping between them is possible but partial, and holding one does not automatically satisfy the other.

Best practices

Before engaging a certification body, verify that its accreditation scope covers ISO/IEC 27001 and includes your industry sector and relevant jurisdiction, rather than assuming universal coverage.
Keep the certification body's accreditation scope conceptually separate from your own ISMS scope, and define the ISMS boundaries clearly under the requirements clauses alongside your Statement of Applicability.
Confirm the accreditation body backing the certification body, and check whether that accreditation is recognized in the jurisdictions where you need the certificate to carry weight.
Specify the standard edition when documenting or discussing certification, since Annex A was restructured in the 2022 revision and control references depend on the version in effect.
Where stakeholders request assurance beyond the defined ISMS scope, communicate that an ISO 27001 certificate covers only that scope, and consider whether complementary standards or a separate SOC 2 attestation are needed for other objectives.
Document how any mapping between ISO 27001 and SOC 2 was performed, noting that such mapping is typically partial and that satisfying one framework does not automatically satisfy the other.