Certification Scope
Certification scope is the official description of exactly what parts of an organization are covered by an ISO 27001 certificate, such as which teams, sites, cloud environments, processes, and partners are included. It appears on the certificate itself and tells readers what the certification does and does not cover. Anything outside this defined boundary is not certified, even if it belongs to the same company.
In ISO/IEC 27001, the certification scope is the formal boundary of the information security management system (ISMS), determined under Clause 4.3 by considering internal and external issues, interested parties, and interfaces and dependencies with other organizations. The scope is expressed as a concise scope statement identifying the activities, teams, sites, cloud services, processes, vendors, and partners included within the certified management system, and this statement appears on the ISO certificate issued by an accredited certification body. Because certification is limited to the defined boundary, controls, locations, or business functions outside the stated scope are not covered by the certificate; the scope can typically be changed over time through the certification body's processes. Per accreditation guidance, the certification scope should not reference a standard or normative document that falls outside the certification body's scope of accreditation.
Why it matters
Certification scope is the single most important qualifier on an ISO 27001 certificate, because it defines the exact boundary of what an accredited certification body has assessed. A certificate that appears impressive at first glance may in fact cover only a narrow slice of an organization, a single product line, one data center, or a specific team, while leaving other business functions entirely uncertified. Readers who rely on the certificate without examining its scope statement can badly misjudge how much of a vendor's operations are actually subject to the certified information security management system (ISMS).
For customers, procurement teams, and partners performing due diligence, the scope statement is where verification begins. Anything outside the defined boundary is not certified, even if it belongs to the same legal entity. This means a company can hold a valid ISO 27001 certificate while the specific service, cloud environment, or processing activity a customer cares about sits outside scope. Treating a certificate as blanket assurance across an entire organization is a common and consequential mistake; the scope must be read to understand what the certification does and does not cover.
Scope also carries integrity constraints imposed by accreditation guidance. A certification scope should not reference a standard or normative document that falls outside the certification body's own scope of accreditation, which helps prevent certificates from implying coverage the issuing body is not authorized to assess. Because of these boundaries, scope is not merely administrative wording, it is the load-bearing statement that determines the meaning and limits of the certificate.
Who it's relevant to
Inside Certification Scope
Common questions
Answers to the questions practitioners most commonly ask about Certification Scope.