How to complete a Scope for ISO 27001?
Completing the scope for ISO 27001 means defining exactly where your Information Security Management System applies. The scope sets the boundary for certification and tells employees, customers, management and auditors which business activities, information, systems, people, locations and external dependencies fall within the ISMS.
Getting this right matters because almost everything else in ISO 27001 follows from the scope. Your risk assessment needs to cover it. Your controls need to protect it. Your internal audit needs to examine it. Your Statement of Applicability needs to support it. The external certification audit will also assess whether your organisation operates the ISMS effectively within the stated boundary.
ISO/IEC 27001:2022 requires organisations to establish, implement, maintain and continually improve an ISMS. ISO explains that organisations should adapt the management system and its risk management processes to their objectives, processes and organisational structure.
UK Cyber Compliance helps organisations manage this work through an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. Its platform supports ISO 27001 through guided workflows, risk assessment, control tracking and audit-ready documentation.
Why the ISO 27001 scope matters so much
The scope tells everyone what your ISMS protects.
Without a clearly defined boundary, your organisation may assess the wrong risks, overlook important suppliers or apply controls inconsistently.
Imagine a software company that states its customer platform sits inside the ISMS but excludes the cloud service that hosts the platform. That boundary would raise obvious questions because the customer service depends on that cloud provider.
The same problem could arise if a business includes customer data but excludes the employees who access it, or includes a service but ignores the third party responsible for maintaining an essential system.
A strong scope reflects how your organisation actually operates.
ISO guidance increasingly emphasises defining scope around commercially meaningful products, services, processes and interfaces, while keeping that scope under review as the organisation changes.
What is ISO 27001 Certification?
ISO 27001 certification provides independent assurance that an organisation operates an Information Security Management System that meets ISO/IEC 27001 requirements.
An ISMS gives your organisation a structured approach to protecting information. It connects risk management with leadership, employees, suppliers, technology, physical security, policies, objectives, monitoring, internal audit and continual improvement.
ISO describes ISO/IEC 27001 as an international standard for information security management systems and highlights its role in risk management, cyber resilience and operational excellence.
Certification does not guarantee that a cyber incident will never occur. Instead, it demonstrates that the organisation identifies information security risks, selects appropriate controls, assigns responsibilities and reviews whether its arrangements remain effective.
The scope defines where that assurance applies.
A customer reading an ISO 27001 certificate should therefore pay attention to the certification scope, not simply the presence of the certificate.
A company might hold ISO 27001 for its managed cloud service, for example, rather than every activity conducted by the organisation.
what is iso 27001
ISO 27001 is the commonly used name for ISO/IEC 27001:2022, the international requirements standard for information security management systems.
It helps organisations protect confidentiality, integrity and availability.
Confidentiality means information remains available only to authorised people and systems.
Integrity means information remains accurate and trustworthy.
Availability means authorised users can access information and services when they need them.
The ISMS scope determines which information, processes and services the organisation manages through this framework.
ISO explains that organisations should consider their own objectives, processes and organisational structure when establishing the management system.
That flexibility means a small consultancy and a large technology provider can both implement ISO 27001 without creating identical ISMS boundaries.
The important point is that the scope needs to make sense.
Start with the services your business provides
A useful scope exercise begins with business services rather than with computers.
Ask:
What does the organisation provide to customers?
Which services need information security assurance?
Which activities support those services?
Which information does the business process?
Which systems support delivery?
Which people perform the work?
Which external organisations support those activities?
This creates a business-focused starting point.
For example, a managed service provider might identify its managed IT support service, security monitoring service and customer service desk as important activities.
A software company might begin with its cloud application and supporting development and customer support processes.
A consultancy might focus on client engagement, document management and professional service delivery.
Once you know what you want the ISMS to cover, you can identify everything that supports it.
Decide whether to cover the whole organisation
Some organisations certify their entire operation.
This can make the scope easier to explain because every department, service and location falls inside the ISMS.
Whole-organisation certification can also provide strong customer assurance because customers do not need to determine whether a particular team sits inside or outside the boundary.
However, some organisations have legitimate reasons to use a more focused scope.
A large company might initially certify one business division. A group of companies might certify one legal entity. A technology provider might focus certification on a particular service.
A focused scope can work when the organisation defines it accurately and includes the dependencies that genuinely support the service.
The boundary should follow business reality rather than convenience.
Identify the legal entities involved
Start by confirming which legal organisation or organisations sit inside the ISMS.
A group may operate several businesses with shared employees, technology and suppliers.
Ask:
Which legal entity owns the service?
Which entity employs the staff?
Which entity signs customer contracts?
Which entity owns or controls the information?
Do shared services support the entity?
Does another company within the group provide IT, finance or HR services?
These questions matter because a seemingly simple organisational boundary can contain several dependencies.
Record the entity clearly in your scope documentation.
Avoid wording that could make customers believe several companies hold certification when only one actually sits inside the ISMS.
Identify the locations involved
Next, identify where the in-scope activities take place.
This may include:
Head offices
Regional offices
Home working locations
Data centres
Shared business premises
Customer sites
Warehouses
Operational facilities
Cloud environments
The physical office does not always define the ISMS boundary.
A modern organisation may have few physical premises but rely heavily on remote employees and cloud platforms.
Ask where staff access sensitive information and where essential services operate.
If most employees work remotely, your ISMS needs to recognise that working arrangement and the related security risks.
Remote working still belongs in the scope
Remote working can affect access control, endpoint protection, physical security, confidentiality and incident reporting.
The organisation should understand:
Which employees work remotely?
Which devices they use?
Which information they access?
Which cloud systems support them?
How they authenticate?
How they report security incidents?
How the business protects confidential information away from company premises?
You do not need to list every employee’s home as though it were a company office.
You do need to recognise remote working as an operating environment where it affects information security.
The scope should describe the arrangement clearly enough for risk assessment and control selection.
Identify the people who support the scope
The scope should account for the people involved in delivering and supporting the in-scope services.
Consider:
Permanent employees
Directors
Temporary workers
Contractors
External consultants
Support personnel
System administrators
Developers
Finance staff
Human resources
Customer service teams
You do not necessarily need to name every individual in the scope statement.
Instead, identify the organisational functions and roles that affect the ISMS.
A customer platform may depend on developers, technical support, operations and senior management. Those functions contribute to the security of the service even if only one department faces customers directly.
Map your information
Information forms the heart of ISO 27001.
Identify what information your in-scope services create, receive, store, process, transfer and destroy.
Examples include:
Customer records
Employee information
Contracts
Authentication information
Service records
Business plans
Supplier information
Financial records
Source code
Security information
Incident records
Audit evidence
Intellectual property
Ask where this information travels throughout the business.
A customer document might enter through email, move into cloud storage, pass to an employee device and later become part of an archived record.
Understanding that journey helps define both the scope and the risks.
Identify the systems that support the service
Once you understand the information and processes, identify the technology that supports them.
This may include:
Cloud platforms
Identity services
Customer relationship management systems
Document storage
Finance systems
Human resources platforms
Customer portals
Business applications
Laptops
Mobile devices
Servers
Routers and firewalls
Backup services
Security monitoring systems
Development platforms
Source code repositories
Avoid creating a scope based solely on a list of technical assets.
Technology supports the service. The service should drive the ISMS boundary rather than the other way around.
Do not forget cloud services
Many organisations rely heavily on cloud platforms.
A cloud provider may host your applications, customer information, email, backups or identity services.
Using an external platform does not mean that the service falls outside your information security responsibilities.
Instead, determine what the supplier manages and what your organisation controls.
For example, a cloud provider may manage physical infrastructure while your business controls accounts, authentication, permissions and information.
Your supplier management process should address those responsibilities.
The scope should recognise critical cloud dependencies so the risk assessment can examine them properly.
Suppliers can sit outside your organisation and still affect your scope
ISO 27001 asks organisations to consider interfaces and dependencies between their own activities and activities performed by other organisations when establishing the ISMS boundary.
This means a supplier may sit outside the formal organisational boundary while still creating an important dependency.
Consider:
Managed IT providers
Cloud hosting companies
Software vendors
Payroll services
Security monitoring providers
Data processors
Telecommunications providers
Professional advisers
Backup providers
Development partners
The scope statement does not need to pretend that you control a supplier’s entire organisation.
Instead, recognise the dependency and manage the associated risk.
Your supplier controls, contracts and assurance activity can then address the relationship.
Understand internal and external issues
The ISMS boundary should reflect the context in which your organisation operates.
Internal considerations might include:
Business structure
Technology
Employee arrangements
Existing processes
Leadership priorities
Business strategy
Internal capability
Operational dependencies
External considerations could include:
Customer expectations
Regulation
Contractual requirements
Cyber threats
Supplier relationships
Technology changes
Market requirements
Legal obligations
ISO 27001 expects the scope decision to take account of the organisation’s context and relevant interested party requirements.
This prevents businesses from creating a scope without considering the reasons why information security matters in the first place.
Understand your interested parties
Interested parties can influence the ISMS boundary because they may impose requirements that your organisation needs to meet.
These may include:
Customers
Employees
Regulators
Government bodies
Shareholders
Suppliers
Partners
Insurers
Certification bodies
Contracting organisations
For example, a major customer may require ISO 27001 certification for the service you provide.
If that service depends on customer support, cloud hosting and development, a scope that excludes those important activities may not provide meaningful assurance.
Review customer contracts and security questionnaires when defining the scope.
They often reveal exactly what customers expect certification to protect.
Draw the boundaries clearly
Once you understand services, people, systems, information and suppliers, define the boundary.
A practical scope should answer:
Which organisation does the ISMS cover?
Which business services does it cover?
Which locations does it cover?
Which organisational functions contribute?
Which important technology supports it?
Which external dependencies affect it?
What falls outside the ISMS?
You do not need to write pages of detail into the final scope statement.
The supporting records can hold the deeper information.
The scope statement itself should remain concise and understandable.
Write the scope statement in plain language
A useful scope statement might follow this structure:
“The Information Security Management System applies to the provision and support of [service], including the people, processes, information systems, cloud services and business functions required to deliver that service from [relevant locations], in accordance with the Statement of Applicability.”
Adapt this wording to your organisation.
Do not copy a generic statement without checking whether every word accurately reflects your business.
Avoid vague wording such as:
“All information security activities.”
“Relevant company systems.”
“IT services.”
These phrases give auditors and customers very little understanding of the actual boundary.
Keep the scope available as documented information
ISO 27001 requires the ISMS scope to remain available as documented information.
That means you should maintain an approved scope statement within your compliance records.
The document should have clear ownership and version control.
Useful supporting records may include:
Organisation charts
Service diagrams
Asset records
Process maps
Location information
Supplier registers
System diagrams
Interested party records
Customer requirements
Risk records
You do not need to put all of this information inside the scope statement itself.
Keep enough supporting evidence to explain how management determined the boundary.
Make the scope match the risk assessment
Once the organisation approves the scope, the risk assessment should cover it.
This relationship sounds obvious, but organisations often create inconsistencies.
For example, the scope may include remote workers while the risk register contains no remote working risks.
A cloud service may appear in the scope while the organisation never assesses supplier failure or unauthorised cloud access.
Customer information may form part of the service while the risk assessment focuses only on internal IT.
Review the scope and risk register together.
Ask whether each important component of the boundary receives appropriate risk consideration.
Make the scope match the Statement of Applicability
The Statement of Applicability records the controls your organisation has determined are necessary and the reasoning behind those decisions.
The control selection should make sense in the context of the scope.
For example, a scope containing extensive remote working may require relevant people, access and endpoint controls.
A service relying heavily on cloud providers should have appropriate supplier and cloud-related controls.
A software development service will normally need relevant development security controls.
Weak alignment between scope, risk treatment and the Statement of Applicability can create audit findings and make the ISMS harder to manage. Current ISO committee guidance highlights strong traceability between these elements as a feature of effective ISMS operation.
Avoid exclusions made only to make certification easier
A business may legitimately exclude activities that have no meaningful connection with the in-scope service.
However, excluding a difficult system or department solely because it creates security work can cause problems.
Auditors may ask:
Does the excluded activity access in-scope information?
Does it support the certified service?
Does it manage critical systems?
Could failure affect the in-scope operation?
Does the service depend on its employees?
Would customers reasonably expect it to fall inside the certificate?
If the answer to several of these questions is yes, the exclusion may be difficult to justify.
Make scope decisions according to business relationships and risk rather than convenience.
Watch for shared systems
Shared systems can complicate a focused scope.
Imagine that the organisation certifies one division but every division uses the same Microsoft 365 environment.
Can you realistically exclude other parts of that environment?
The answer depends on access, configuration and technical separation.
Similar issues can arise with:
Shared networks
Central HR systems
Group finance systems
Identity platforms
Backup platforms
Security monitoring
Shared administrator teams
Central IT services
Understand these relationships before finalising the scope.
A diagram can often make shared dependencies easier to explain.
Scope should support customer confidence
The certification scope appears on, or relates directly to, the certification information that customers rely upon.
Clear wording helps customers understand exactly what assurance they receive.
A scope such as “Information Security Management System supporting the provision of managed cyber security services” gives useful context.
A vague statement such as “information systems” tells the reader much less.
Consider how a procurement professional would interpret the wording.
Would they understand whether the service they buy falls within the ISMS?
If not, improve the statement.
Current UK cyber risk makes clear scope important
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months. Phishing affected 38 per cent of businesses.
The survey also found that medium businesses reported a higher incidence than the overall business population, while large organisations reported an even higher incidence.
These figures reinforce the need to understand where security risk exists across an organisation.
A poorly defined ISMS boundary can leave significant dependencies without appropriate risk assessment.
A clear boundary helps the business decide which people, processes, information and systems need attention.
Who needs iso 27001 certification
ISO 27001 certification can benefit organisations that hold important information or need to demonstrate structured information security management.
Technology providers, software companies, managed service providers, consultancies, professional firms, manufacturers, healthcare suppliers, financial organisations, charities and government suppliers may all benefit.
ISO states that its information security management framework can adapt to an organisation’s objectives, processes and structure.
Customer requirements often drive certification.
A larger organisation may ask suppliers to prove that they manage customer information systematically.
Public procurement, contractual requirements, corporate governance and supply-chain assurance can also influence the decision.
The scope becomes particularly important in these situations because customers need to know whether certification actually covers the service they purchase.
Small businesses can keep the scope straightforward
A small organisation should avoid making the process unnecessarily complicated.
Start with the business service.
List who supports it.
Identify the information involved.
Record the technology it depends on.
Identify the relevant suppliers.
Confirm where employees work.
Review customer and legal requirements.
Then write the boundary in plain language.
A business with ten employees may end up with a whole-organisation scope because separating departments would create little practical benefit.
This can make certification easier to understand and maintain.
Complex organisations may need more detailed boundary decisions.
The right answer depends on the business rather than employee numbers alone.
Review acquisitions and organisational changes
Your scope should change when the business changes significantly.
For example, review it after:
Acquiring another company
Launching a major service
Moving to a new cloud platform
Opening another location
Changing critical suppliers
Restructuring departments
Changing remote working arrangements
Taking on substantially different customer requirements
Changing major technology
Merging business functions
Current ISO committee guidance recommends treating scope as an active management item and reviewing it when acquisitions, cloud migration, new markets or major supplier changes affect the organisation.
Review the scope after incidents
A security incident can reveal that the actual operating boundary differs from the documented one.
Suppose an incident involving a supposedly excluded supplier affects the certified customer service.
That may indicate that the supplier represents an important dependency that the ISMS should consider more explicitly.
After significant incidents, ask:
Did the event affect something inside scope?
Did an excluded system contribute?
Did we misunderstand a dependency?
Does the risk assessment need updating?
Do we need to change the scope?
Does the Statement of Applicability need review?
An ISMS should learn from real events.
Internal audit should test the boundary
Your internal audit should examine whether the documented scope reflects reality.
An internal auditor may ask:
Does the scope cover the service customers believe is certified?
Are important locations included?
Do remote workers fit the stated boundary?
Are critical suppliers recognised?
Does the risk register cover all major dependencies?
Does the Statement of Applicability reflect the scope?
Are shared systems handled properly?
Have business changes affected the boundary?
This review provides an opportunity to correct weaknesses before the external certification assessment.
Management should approve and understand the scope
The ISMS scope should not become a technical document that only the compliance manager understands.
Senior management needs to understand what the organisation plans to certify.
Leaders should know:
Which services sit inside the ISMS
Which parts of the organisation support them
What sits outside
Which critical suppliers create dependencies
What customers will believe the certificate covers
Which risks follow from the boundary
Management involvement matters because the boundary influences resources, responsibilities and customer commitments.
A scope decision can also affect future growth.
If the organisation expects to expand the certified service quickly, consider whether the proposed boundary can support that growth.
ISO 27001 Certification Levels
ISO 27001 does not use formal achievement bands such as bronze, silver or gold.
An organisation either achieves certification for the stated ISMS scope or it does not.
Businesses do move through practical stages before certification.
These commonly include:
Understanding organisational context
Defining the ISMS scope
Identifying interested parties
Assessing information security risks
Treating unacceptable risks
Selecting controls
Preparing the Statement of Applicability
Operating the ISMS
Gathering evidence
Completing internal audit
Holding management review
Undergoing external certification assessment
The certification scope remains central throughout these stages because it tells everyone where the ISMS requirements apply.
How the Certification Works
The organisation starts by understanding its business context and interested parties.
It then defines the ISMS boundary.
Risk assessment identifies the information security scenarios that could affect the in-scope services, people, information, technology and suppliers.
Risk treatment determines what action the organisation needs.
The business selects controls and compares them with Annex A. It records its control decisions in the Statement of Applicability.
The organisation then operates the controls and gathers evidence.
Internal audit examines whether the ISMS meets requirements and works effectively.
Management review allows senior leadership to assess the system, major risks, audit findings, objectives and improvement activity.
An independent certification body then carries out the external certification process. ISO committee material describes certification auditing as a systematic and independent process for obtaining evidence and evaluating whether the ISMS fulfils ISO/IEC 27001 requirements.
The organisation needs to demonstrate that the ISMS works across the declared boundary.
Scope questions an auditor may ask
An auditor may ask:
Why did you choose this boundary?
Which services does it cover?
Which legal entity holds certification?
Which locations sit inside the ISMS?
Which employees support the service?
Which information falls inside the boundary?
Which technology supports it?
Which cloud platforms do you rely on?
Which suppliers create significant dependencies?
Why have you excluded certain activities?
How does the risk register reflect the scope?
How does the Statement of Applicability support it?
When did management last review the scope?
What changed since the previous review?
Clear supporting evidence makes these questions much easier to answer.
Common mistakes when defining scope
One common mistake involves making the boundary too vague.
Another involves focusing only on technology.
Some organisations exclude suppliers without examining dependencies.
Others forget remote workers or shared services.
Further weaknesses can include:
Ignoring customer requirements
Leaving important cloud services out
Using outdated organisation information
Excluding support teams that affect the service
Creating a scope that does not match the risk assessment
Using wording that customers cannot understand
Ignoring shared infrastructure
Failing to review the scope after change
Copying another organisation’s wording
Trying to reduce audit work by creating an artificial boundary
A well-written scope should reflect reality.
Which UK-based firms offer ISO 27001 consultancy services?
UK organisations can obtain ISO 27001 support from information security consultancies, compliance specialists, managed service providers and platform-led services.
UK Cyber Compliance provides ISO 27001 support through an automated and AI-driven platform. Its current service includes structured workflows, risk analysis, control coverage and audit-ready documentation.
A capable provider should help you understand:
Business context
Interested parties
ISMS scope
Organisational boundaries
Dependencies
Risk assessment
Annex A controls
The Statement of Applicability
Evidence
Internal audit readiness
Management review
The organisation should remain responsible for the final scope decision.
An external adviser can guide the process, but management needs to understand and approve what certification will cover.
How UK Cyber Compliance helps with ISO 27001 scope
Managing scope through disconnected documents can make dependencies harder to see.
UK Cyber Compliance provides a central platform that connects ISO 27001 activity with risk assessment, control management and audit readiness.
Its current platform describes real-time compliance visibility, intelligent risk assessment and structured guidance through ISO 27001 requirements.
This can help organisations connect the scope with:
Business activities
Information assets
People
Risk
Controls
Actions
Evidence
Audit preparation
A centralised approach can also make later changes easier to manage.
When a new system or supplier enters the ISMS, the organisation can review related risk and controls rather than updating several unrelated spreadsheets.
A practical ISO 27001 scope checklist
Before approving the scope, ask:
Which legal organisation does certification cover?
Which business services sit inside the ISMS?
Which locations support those services?
Which employees and business functions contribute?
Which information needs protection?
Which systems support the service?
Which cloud platforms do we rely upon?
Which suppliers create dependencies?
Have we considered remote working?
Have we considered shared systems?
Have we identified internal and external issues?
Have we considered interested party requirements?
Do customer expectations align with the scope?
Can we justify every significant exclusion?
Does the risk register cover the boundary?
Does the Statement of Applicability support the boundary?
Can senior management explain what is being certified?
Would a customer understand the wording?
Is the scope recorded as controlled documented information?
Do we have a process for reviewing the scope after change?
If several answers remain unclear, continue refining the boundary before the external audit.
Make the scope useful beyond the audit
A good ISO 27001 scope does more than satisfy a certification requirement.
It gives the organisation clarity about which information security responsibilities matter most.
It helps risk owners understand what they manage.
It helps employees understand where security processes apply.
It helps suppliers understand expectations.
It helps customers see what certification protects.
It helps internal and external auditors test the right activities.
Most importantly, it creates a solid foundation for the entire ISMS.
Start with the service your organisation wants to protect. Identify the people, information, processes, technology, locations and suppliers that support it. Consider customer requirements and external dependencies. Define the boundary clearly and document it.
Then connect that scope with risk assessment, Annex A controls, the Statement of Applicability, internal audit and management review.
UK Cyber Compliance provides an automated and AI-driven platform that helps organisations bring these elements together and maintain visibility throughout the ISO 27001 certification journey.
A clear and defensible scope gives your organisation a better foundation for certification and a much clearer understanding of what its Information Security Management System actually protects.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

