Skip to main content
Category: Certification and Accreditation

Certification Scope

Also known as: ISMS Scope, Scope of Certification, Scope Statement
Simply put

Certification scope is the official description of exactly what parts of an organization are covered by an ISO 27001 certificate, such as which teams, sites, cloud environments, processes, and partners are included. It appears on the certificate itself and tells readers what the certification does and does not cover. Anything outside this defined boundary is not certified, even if it belongs to the same company.

Formal definition

In ISO/IEC 27001, the certification scope is the formal boundary of the information security management system (ISMS), determined under Clause 4.3 by considering internal and external issues, interested parties, and interfaces and dependencies with other organizations. The scope is expressed as a concise scope statement identifying the activities, teams, sites, cloud services, processes, vendors, and partners included within the certified management system, and this statement appears on the ISO certificate issued by an accredited certification body. Because certification is limited to the defined boundary, controls, locations, or business functions outside the stated scope are not covered by the certificate; the scope can typically be changed over time through the certification body's processes. Per accreditation guidance, the certification scope should not reference a standard or normative document that falls outside the certification body's scope of accreditation.

Why it matters

Certification scope is the single most important qualifier on an ISO 27001 certificate, because it defines the exact boundary of what an accredited certification body has assessed. A certificate that appears impressive at first glance may in fact cover only a narrow slice of an organization, a single product line, one data center, or a specific team, while leaving other business functions entirely uncertified. Readers who rely on the certificate without examining its scope statement can badly misjudge how much of a vendor's operations are actually subject to the certified information security management system (ISMS).

For customers, procurement teams, and partners performing due diligence, the scope statement is where verification begins. Anything outside the defined boundary is not certified, even if it belongs to the same legal entity. This means a company can hold a valid ISO 27001 certificate while the specific service, cloud environment, or processing activity a customer cares about sits outside scope. Treating a certificate as blanket assurance across an entire organization is a common and consequential mistake; the scope must be read to understand what the certification does and does not cover.

Scope also carries integrity constraints imposed by accreditation guidance. A certification scope should not reference a standard or normative document that falls outside the certification body's own scope of accreditation, which helps prevent certificates from implying coverage the issuing body is not authorized to assess. Because of these boundaries, scope is not merely administrative wording, it is the load-bearing statement that determines the meaning and limits of the certificate.

Who it's relevant to

Compliance and GRC Managers
These professionals draft and maintain the scope statement, ensuring it accurately reflects the teams, sites, cloud environments, processes, vendors, and partners that leadership will stand behind. They must balance a scope broad enough to satisfy stakeholders against one narrow enough to be defensible and manageable, and they coordinate with the certification body when scope changes are needed.
Auditors and Certification Bodies
Auditors assess whether the defined scope is appropriate given the organization's internal and external issues, interested parties, and interfaces and dependencies under Clause 4.3. Certification bodies issue the certificate reflecting the agreed scope and must ensure the scope wording does not reference standards or normative documents outside their own scope of accreditation.
Procurement and Vendor Risk Teams
Customers evaluating a vendor's ISO 27001 certificate must read the scope statement carefully to confirm that the specific service, environment, or processing activity they depend on falls within the certified boundary. Relying on a certificate without checking scope risks assuming coverage that does not exist, since anything outside the stated boundary is not certified.
Security Leadership and Executives
Leaders own the strategic decision of what to include in scope, since the scope statement represents the activities the organization is prepared to publicly stand behind. They weigh business priorities, customer expectations, and the operational cost of maintaining certification across the chosen boundary, and they authorize scope expansions or reductions over time.

Inside Certification Scope

ISMS Boundaries
The defined limits of the information security management system, including which organizational units, locations, business processes, and information assets are covered by the ISO/IEC 27001 certification.
Products, Services, and Activities
A statement of the specific services, products, or operational activities that fall within the certified ISMS, distinguishing what the certification body has assessed from what remains outside the assessment.
Physical and Organizational Sites
The locations, facilities, or legal entities included in the scope, which determines where the certification applies. Multi-site organizations may certify all or only a subset of their sites depending on scoping decisions.
Interfaces and Dependencies
The connections between the ISMS and external parties, third-party providers, or organizational functions outside the scope, along with how those dependencies are managed at the scope boundary.
Relationship to the Statement of Applicability
The scope informs, and is informed by, the Statement of Applicability, which documents the Annex A reference controls selected as applicable based on risk assessment. The scope and SoA together define what the ISMS addresses.
Justification for Exclusions
Where portions of the organization or activities are excluded from the scope, the reasoning is documented so that interested parties understand the boundaries of the certified ISMS.

Common questions

Answers to the questions practitioners most commonly ask about Certification Scope.

Does an ISO 27001 certificate mean my entire organization is certified?
No. An ISO 27001 certificate covers only the defined scope of the information security management system (ISMS), not necessarily the whole organization. The scope statement identifies which business units, locations, services, or processes the certification applies to. Activities, systems, or sites outside that defined boundary are not covered by the certificate, even if they belong to the same legal entity.
Is certification scope the same concept in SOC 2 as it is in ISO 27001?
They are related but distinct. ISO 27001 is a certification issued by an accredited certification body, and its scope defines the boundary of the certified ISMS. SOC 2 is an attestation examination performed by a licensed CPA firm, resulting in a report rather than a certificate, and its scope is defined by the system description, the applicable Trust Services Criteria selected, and, for a Type II, the review period. Because the frameworks differ in nature, their scoping mechanisms are not interchangeable, and defining scope under one does not define it under the other.
How do we decide what to include in the ISMS scope for ISO 27001?
Scope is typically determined by considering the internal and external issues relevant to the ISMS, the requirements of interested parties, interfaces and dependencies with other organizations, and the products or services you want to assure. The clause 4 requirements guide this determination. In most engagements, organizations align scope with the services or business functions where security assurance matters most to customers, while ensuring the boundary is defensible and that dependencies are addressed. The certification body will assess whether the stated scope is appropriate and supported by the ISMS.
How does scope affect which controls we need to address?
In ISO 27001, the defined ISMS scope informs the risk assessment, which in turn drives the selection of Annex A reference controls documented in the Statement of Applicability. Controls relevant only to activities outside the scope may be justified as not applicable. In SOC 2, scope determines which Trust Services Criteria categories apply, Security (the Common Criteria) is always included, while Availability, Processing Integrity, Confidentiality, and Privacy are added depending on the services and commitments in scope. Narrowing or broadening scope therefore changes the population of controls examined.
Can we expand the certification or report scope later?
Yes, scope can typically be adjusted over time. For ISO 27001, organizations may extend the ISMS boundary in subsequent surveillance or recertification cycles, subject to assessment by the certification body of the added areas. For SOC 2, the system description, criteria, or covered period can be adjusted in later examinations. In both cases, expanding scope generally means additional controls, evidence, and assessment effort, and the timing and process depend on the certification body or CPA firm and the applicable scope decisions.
What are the limitations of a defined scope when responding to customer due diligence?
A defined scope limits what the outcome assures. An ISO 27001 certificate demonstrates conformity only for the ISMS boundary stated on the certificate, and a SOC 2 report attests only to the controls, criteria, and period covered, it does not guarantee freedom from breaches or cover systems outside the described boundary. When responding to customer inquiries, it is important to confirm that the services the customer relies on fall within the stated scope, since a customer-facing system omitted from scope would not be covered by either the certificate or the report.

Common misconceptions

An ISO/IEC 27001 certificate means the entire organization is certified.
The certificate covers only the defined scope of the ISMS. An organization may certify a single business unit, service, or location, so the certificate applies solely to the boundaries stated on it, not necessarily to every part of the organization.
A broad certification scope is always better and demonstrates stronger security.
Scope is set by scoping decisions and risk considerations rather than by a rule that broader is better. A well-defined, appropriately bounded scope that the organization can genuinely manage and maintain is typically more meaningful than an overextended one, and the appropriate breadth depends on the organization's context.
The certification scope is the same concept as the SOC 2 scope, so the two can be treated interchangeably.
The ISO 27001 certification scope defines the boundaries of a management system assessed by an accredited certification body, whereas a SOC 2 examination scope defines the system and the selected Trust Services Criteria assessed by a CPA firm in an attestation report. Mapping between them is partial, and a scope defined for one framework does not automatically satisfy the other.

Best practices

Define the ISMS scope in terms of specific business processes, services, locations, and information assets so that the boundaries are unambiguous to auditors, the certification body, and interested parties.
Align the scope with the results of the risk assessment and the Statement of Applicability so that the controls selected as applicable correspond to what actually falls within the ISMS boundaries.
Document interfaces and dependencies with parties outside the scope, and clarify how risks at those boundaries are managed, to avoid gaps where responsibility is unclear.
Where portions of the organization or activities are excluded, record the justification for those exclusions so that the limits of the certified ISMS are transparent.
Ensure the scope stated on the certificate accurately reflects what was assessed, and communicate to stakeholders that the certificate covers only the defined scope rather than the whole organization.
Review the scope periodically and after significant organizational, service, or infrastructure changes, since scope that no longer matches operations can undermine the relevance of the certification.