Skip to main content
Category: Certification and Accreditation

Certification Scope Statement

Also known as: ISO 27001 Scope Statement, ISMS Scope Statement
Simply put

A certification scope statement is a concise declaration that describes which parts of an organization, its activities, and its context are covered by its information security management system (ISMS). In an ISO/IEC 27001 certification, this statement typically appears on the certificate itself, telling readers exactly what the certification does and does not cover. Anything outside the stated scope is not addressed by the certification.

Formal definition

Within an ISO/IEC 27001 engagement, the certification scope statement is the formal expression of the ISMS boundaries defined under the standard's requirements clauses (scope determination is addressed in Clause 4). It concisely describes the organization's context, the activities, locations, assets, and business functions included in the ISMS, and by implication those excluded. The scope statement is typically reproduced on the certificate issued by an accredited certification body, so its wording directly governs what the certification attests to. Because ISO/IEC 27001 certification covers only the defined scope of the ISMS, controls, processes, or organizational units not captured by the scope statement fall outside the certification's assurance. Scope determination in most engagements is informed by risk assessment and organizational context, and the precise wording is set by scoping decisions rather than prescribed by the standard.

Why it matters

The certification scope statement is arguably the single most consequential sentence on an ISO/IEC 27001 certificate, because it defines the exact boundary of what the certification attests to. Since ISO/IEC 27001 certification covers only the defined scope of the ISMS, any organizational unit, location, activity, or system left outside the scope statement receives no assurance from the certificate. A customer, partner, or auditor reviewing the certificate must read the scope wording carefully rather than assume that a certified organization is certified in its entirety.

This matters because scope wording can either accurately reflect a robust, enterprise-wide ISMS or, if narrowly drawn, cover only a small function while the certificate still carries the organization's name. A scope that excludes a critical product line, data center, or business unit means that the excluded elements are not addressed by the certification's assurance at all. For GRC teams evaluating a vendor's certificate, misreading or overlooking the scope statement can lead to overestimating the coverage they are relying on.

Because the scope statement is typically reproduced verbatim on the certificate issued by the accredited certification body, its wording directly governs the meaning of the certification in the marketplace. Precise, honest scoping supports credibility with stakeholders, while vague or overly broad wording invites challenge during surveillance and recertification activities.

Who it's relevant to

Compliance and GRC Managers
Those responsible for pursuing ISO/IEC 27001 certification must define and document the ISMS scope under Clause 4 and craft a scope statement that accurately reflects the included activities, locations, and functions. Drawing the scope too narrowly may undermine stakeholder confidence, while drawing it too broadly can create unsupportable assurance claims during audit.
Vendor Risk and Procurement Teams
Professionals evaluating a supplier's ISO/IEC 27001 certificate should read the scope statement carefully, since the certification covers only the defined scope of the ISMS. A certificate bearing an organization's name does not necessarily cover every product, location, or business unit relevant to the engagement being assessed.
Certification Bodies and Auditors
Accredited certification bodies rely on the scope statement to bound their assessment and to determine what appears on the certificate. Because the wording governs what the certification attests to, auditors typically scrutinize scope during initial certification, surveillance, and recertification to confirm it remains accurate for the organization's context.
Security and ISMS Leadership
Those operating the ISMS use the scope statement to understand which assets, processes, and organizational units fall inside the managed system. Elements outside the stated scope are not addressed by the certification's assurance, so leadership should ensure the scope aligns with the organization's actual risk profile and business priorities.

Inside Certification Scope Statement

Boundaries of the ISMS
A definition of the organizational, physical, and logical boundaries of the information security management system, describing which business units, locations, and systems fall within the certified scope.
Products, Services, and Processes Covered
An identification of the specific products, services, and business processes to which the ISMS applies, so that readers understand exactly what activity the certificate addresses.
Interfaces and Dependencies
A description of interfaces and dependencies on activities performed by the organization and by other parties, as required when defining ISMS boundaries under the clause 4 requirements.
Version Reference
A reference to the standard against which certification is granted, typically ISO/IEC 27001, with the applicable edition (for example, the 2022 revision) noted so the scope statement remains unambiguous.
Relationship to the Statement of Applicability
An implicit link to the Statement of Applicability, since the controls selected from Annex A and justified through risk assessment are applied within the boundaries set by the scope.

Common questions

Answers to the questions practitioners most commonly ask about Certification Scope Statement.

Does an ISO 27001 certificate cover my entire organization once we're certified?
No. An ISO 27001 certificate covers only the defined scope of the ISMS as stated in the certification scope statement. This scope may be limited to specific business units, locations, services, or processes, and anything outside the documented boundaries is not covered by the certification. Reviewing the scope statement is essential to understand exactly what the certificate applies to.
Is the certification scope statement the same as a SOC 2 report's coverage description?
No, they are distinct. A certification scope statement defines the boundaries of an ISMS certified against ISO/IEC 27001 by an accredited certification body. A SOC 2 report, by contrast, is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, and its coverage is described in terms of the systems, Trust Services Criteria, and review period addressed. The two frameworks describe coverage differently and satisfying one does not establish the coverage of the other.
What should a certification scope statement typically include?
In most engagements, a scope statement identifies the boundaries of the ISMS, such as the products, services, locations, organizational units, and processes covered. It is informed by the organization's context (ISO 27001 clause 4) and interfaces with the Statement of Applicability, which documents the Annex A reference controls that have been selected or excluded. The exact content depends on the organization and the certification body.
How do we decide where to draw the boundaries of our ISMS scope?
Scope boundaries are typically determined by considering the organization's context, interested parties, and the interfaces and dependencies between activities performed by the organization and those performed by other parties (ISO 27001 clauses 4.1 through 4.3). Depending on scope, organizations may choose to limit certification to a specific service or location initially and expand later. Certification bodies expect the boundaries to be justified and consistent with the risk assessment.
Can we change the certification scope after we're certified?
Scope changes are generally possible but must be handled through the certification body, which may require review or reassessment before the change is reflected on the certificate. Expanding scope to new locations, services, or units typically triggers additional assessment activity, and the specific process depends on the certification body and the nature of the change.
Does a narrowly scoped certificate reduce its value to customers?
Not necessarily, but customers should review the scope statement to confirm the certificate covers the services or systems relevant to them. A certificate attests only to the defined ISMS scope, so a narrow scope is not inherently a weakness as long as it clearly covers what the customer relies on. Clear communication of scope boundaries helps avoid misunderstandings about what the certification does and does not cover.

Common misconceptions

An ISO 27001 certificate with a scope statement means the entire organization is certified.
The certificate covers only the defined scope of the ISMS. Business units, locations, or services outside the stated boundaries are not covered, so the scope statement should be read carefully to understand what the accredited certification body actually certified.
A scope statement is the same concept as the scope described in a SOC 2 report.
The two frameworks are distinct. ISO 27001 is a certification issued by an accredited certification body against the ISMS requirements in clauses 4 through 10, whereas SOC 2 is an attestation examination performed by a licensed CPA firm under SSAE 18 resulting in a report. The way scope is defined and the criteria applied differ between them, so the concepts should not be treated as interchangeable.
A broad scope statement guarantees a stronger security posture than a narrow one.
Scope reflects boundary decisions, not a guarantee of effectiveness. A certificate attests only that the ISMS within the defined boundaries met the requirements at the time of assessment; it does not guarantee freedom from breaches, and a wider scope is not inherently more assured than a well-defined narrower one.

Best practices

Define the boundaries explicitly by identifying the organizational units, locations, systems, products, and services included, and document any interfaces and dependencies on other parties as required under clause 4.
State the standard and its edition (for example, the 2022 revision of ISO/IEC 27001) in the scope statement to avoid ambiguity, since control structures and counts differ between editions.
Ensure the scope statement is consistent with the Statement of Applicability and the underlying risk assessment, so the controls selected from Annex A align with the boundaries being certified.
Draft the scope narrowly enough to be accurate and defensible during assessment, while broad enough to cover the activities stakeholders expect to be certified.
Communicate to customers and other readers that the certificate covers only the defined scope and does not extend to out-of-scope units or guarantee freedom from breaches.
Review and update the scope statement whenever the covered products, services, locations, or organizational structure change, and confirm changes with the certification body before relying on them.