Certification Scope Statement
A certification scope statement is a concise declaration that describes which parts of an organization, its activities, and its context are covered by its information security management system (ISMS). In an ISO/IEC 27001 certification, this statement typically appears on the certificate itself, telling readers exactly what the certification does and does not cover. Anything outside the stated scope is not addressed by the certification.
Within an ISO/IEC 27001 engagement, the certification scope statement is the formal expression of the ISMS boundaries defined under the standard's requirements clauses (scope determination is addressed in Clause 4). It concisely describes the organization's context, the activities, locations, assets, and business functions included in the ISMS, and by implication those excluded. The scope statement is typically reproduced on the certificate issued by an accredited certification body, so its wording directly governs what the certification attests to. Because ISO/IEC 27001 certification covers only the defined scope of the ISMS, controls, processes, or organizational units not captured by the scope statement fall outside the certification's assurance. Scope determination in most engagements is informed by risk assessment and organizational context, and the precise wording is set by scoping decisions rather than prescribed by the standard.
Why it matters
The certification scope statement is arguably the single most consequential sentence on an ISO/IEC 27001 certificate, because it defines the exact boundary of what the certification attests to. Since ISO/IEC 27001 certification covers only the defined scope of the ISMS, any organizational unit, location, activity, or system left outside the scope statement receives no assurance from the certificate. A customer, partner, or auditor reviewing the certificate must read the scope wording carefully rather than assume that a certified organization is certified in its entirety.
This matters because scope wording can either accurately reflect a robust, enterprise-wide ISMS or, if narrowly drawn, cover only a small function while the certificate still carries the organization's name. A scope that excludes a critical product line, data center, or business unit means that the excluded elements are not addressed by the certification's assurance at all. For GRC teams evaluating a vendor's certificate, misreading or overlooking the scope statement can lead to overestimating the coverage they are relying on.
Because the scope statement is typically reproduced verbatim on the certificate issued by the accredited certification body, its wording directly governs the meaning of the certification in the marketplace. Precise, honest scoping supports credibility with stakeholders, while vague or overly broad wording invites challenge during surveillance and recertification activities.
Who it's relevant to
Inside Certification Scope Statement
Common questions
Answers to the questions practitioners most commonly ask about Certification Scope Statement.