Home | News | How to complete a Scope for ISO 27001?

News

How to complete a Scope for ISO 27001?

How To Complete A Scope For Iso 27001?

How to complete a Scope for ISO 27001?

Completing the scope for ISO 27001 means defining exactly where your Information Security Management System applies. The scope sets the boundary for certification and tells employees, customers, management and auditors which business activities, information, systems, people, locations and external dependencies fall within the ISMS.

Getting this right matters because almost everything else in ISO 27001 follows from the scope. Your risk assessment needs to cover it. Your controls need to protect it. Your internal audit needs to examine it. Your Statement of Applicability needs to support it. The external certification audit will also assess whether your organisation operates the ISMS effectively within the stated boundary.

ISO/IEC 27001:2022 requires organisations to establish, implement, maintain and continually improve an ISMS. ISO explains that organisations should adapt the management system and its risk management processes to their objectives, processes and organisational structure.

UK Cyber Compliance helps organisations manage this work through an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. Its platform supports ISO 27001 through guided workflows, risk assessment, control tracking and audit-ready documentation.

Why the ISO 27001 scope matters so much

The scope tells everyone what your ISMS protects.

Without a clearly defined boundary, your organisation may assess the wrong risks, overlook important suppliers or apply controls inconsistently.

Imagine a software company that states its customer platform sits inside the ISMS but excludes the cloud service that hosts the platform. That boundary would raise obvious questions because the customer service depends on that cloud provider.

The same problem could arise if a business includes customer data but excludes the employees who access it, or includes a service but ignores the third party responsible for maintaining an essential system.

A strong scope reflects how your organisation actually operates.

ISO guidance increasingly emphasises defining scope around commercially meaningful products, services, processes and interfaces, while keeping that scope under review as the organisation changes.

What is ISO 27001 Certification?

ISO 27001 certification provides independent assurance that an organisation operates an Information Security Management System that meets ISO/IEC 27001 requirements.

An ISMS gives your organisation a structured approach to protecting information. It connects risk management with leadership, employees, suppliers, technology, physical security, policies, objectives, monitoring, internal audit and continual improvement.

ISO describes ISO/IEC 27001 as an international standard for information security management systems and highlights its role in risk management, cyber resilience and operational excellence.

Certification does not guarantee that a cyber incident will never occur. Instead, it demonstrates that the organisation identifies information security risks, selects appropriate controls, assigns responsibilities and reviews whether its arrangements remain effective.

The scope defines where that assurance applies.

A customer reading an ISO 27001 certificate should therefore pay attention to the certification scope, not simply the presence of the certificate.

A company might hold ISO 27001 for its managed cloud service, for example, rather than every activity conducted by the organisation.

what is iso 27001

ISO 27001 is the commonly used name for ISO/IEC 27001:2022, the international requirements standard for information security management systems.

It helps organisations protect confidentiality, integrity and availability.

Confidentiality means information remains available only to authorised people and systems.

Integrity means information remains accurate and trustworthy.

Availability means authorised users can access information and services when they need them.

The ISMS scope determines which information, processes and services the organisation manages through this framework.

ISO explains that organisations should consider their own objectives, processes and organisational structure when establishing the management system.

That flexibility means a small consultancy and a large technology provider can both implement ISO 27001 without creating identical ISMS boundaries.

The important point is that the scope needs to make sense.

Start with the services your business provides

A useful scope exercise begins with business services rather than with computers.

Ask:

What does the organisation provide to customers?

Which services need information security assurance?

Which activities support those services?

Which information does the business process?

Which systems support delivery?

Which people perform the work?

Which external organisations support those activities?

This creates a business-focused starting point.

For example, a managed service provider might identify its managed IT support service, security monitoring service and customer service desk as important activities.

A software company might begin with its cloud application and supporting development and customer support processes.

A consultancy might focus on client engagement, document management and professional service delivery.

Once you know what you want the ISMS to cover, you can identify everything that supports it.

Decide whether to cover the whole organisation

Some organisations certify their entire operation.

This can make the scope easier to explain because every department, service and location falls inside the ISMS.

Whole-organisation certification can also provide strong customer assurance because customers do not need to determine whether a particular team sits inside or outside the boundary.

However, some organisations have legitimate reasons to use a more focused scope.

A large company might initially certify one business division. A group of companies might certify one legal entity. A technology provider might focus certification on a particular service.

A focused scope can work when the organisation defines it accurately and includes the dependencies that genuinely support the service.

The boundary should follow business reality rather than convenience.

Identify the legal entities involved

Start by confirming which legal organisation or organisations sit inside the ISMS.

A group may operate several businesses with shared employees, technology and suppliers.

Ask:

Which legal entity owns the service?

Which entity employs the staff?

Which entity signs customer contracts?

Which entity owns or controls the information?

Do shared services support the entity?

Does another company within the group provide IT, finance or HR services?

These questions matter because a seemingly simple organisational boundary can contain several dependencies.

Record the entity clearly in your scope documentation.

Avoid wording that could make customers believe several companies hold certification when only one actually sits inside the ISMS.

Identify the locations involved

Next, identify where the in-scope activities take place.

This may include:

Head offices

Regional offices

Home working locations

Data centres

Shared business premises

Customer sites

Warehouses

Operational facilities

Cloud environments

The physical office does not always define the ISMS boundary.

A modern organisation may have few physical premises but rely heavily on remote employees and cloud platforms.

Ask where staff access sensitive information and where essential services operate.

If most employees work remotely, your ISMS needs to recognise that working arrangement and the related security risks.

Remote working still belongs in the scope

Remote working can affect access control, endpoint protection, physical security, confidentiality and incident reporting.

The organisation should understand:

Which employees work remotely?

Which devices they use?

Which information they access?

Which cloud systems support them?

How they authenticate?

How they report security incidents?

How the business protects confidential information away from company premises?

You do not need to list every employee’s home as though it were a company office.

You do need to recognise remote working as an operating environment where it affects information security.

The scope should describe the arrangement clearly enough for risk assessment and control selection.

Identify the people who support the scope

The scope should account for the people involved in delivering and supporting the in-scope services.

Consider:

Permanent employees

Directors

Temporary workers

Contractors

External consultants

Support personnel

System administrators

Developers

Finance staff

Human resources

Customer service teams

You do not necessarily need to name every individual in the scope statement.

Instead, identify the organisational functions and roles that affect the ISMS.

A customer platform may depend on developers, technical support, operations and senior management. Those functions contribute to the security of the service even if only one department faces customers directly.

Map your information

Information forms the heart of ISO 27001.

Identify what information your in-scope services create, receive, store, process, transfer and destroy.

Examples include:

Customer records

Employee information

Contracts

Authentication information

Service records

Business plans

Supplier information

Financial records

Source code

Security information

Incident records

Audit evidence

Intellectual property

Ask where this information travels throughout the business.

A customer document might enter through email, move into cloud storage, pass to an employee device and later become part of an archived record.

Understanding that journey helps define both the scope and the risks.

Identify the systems that support the service

Once you understand the information and processes, identify the technology that supports them.

This may include:

Cloud platforms

Email

Identity services

Customer relationship management systems

Document storage

Finance systems

Human resources platforms

Customer portals

Business applications

Laptops

Mobile devices

Servers

Routers and firewalls

Backup services

Security monitoring systems

Development platforms

Source code repositories

Avoid creating a scope based solely on a list of technical assets.

Technology supports the service. The service should drive the ISMS boundary rather than the other way around.

Do not forget cloud services

Many organisations rely heavily on cloud platforms.

A cloud provider may host your applications, customer information, email, backups or identity services.

Using an external platform does not mean that the service falls outside your information security responsibilities.

Instead, determine what the supplier manages and what your organisation controls.

For example, a cloud provider may manage physical infrastructure while your business controls accounts, authentication, permissions and information.

Your supplier management process should address those responsibilities.

The scope should recognise critical cloud dependencies so the risk assessment can examine them properly.

Suppliers can sit outside your organisation and still affect your scope

ISO 27001 asks organisations to consider interfaces and dependencies between their own activities and activities performed by other organisations when establishing the ISMS boundary.

This means a supplier may sit outside the formal organisational boundary while still creating an important dependency.

Consider:

Managed IT providers

Cloud hosting companies

Software vendors

Payroll services

Security monitoring providers

Data processors

Telecommunications providers

Professional advisers

Backup providers

Development partners

The scope statement does not need to pretend that you control a supplier’s entire organisation.

Instead, recognise the dependency and manage the associated risk.

Your supplier controls, contracts and assurance activity can then address the relationship.

Understand internal and external issues

The ISMS boundary should reflect the context in which your organisation operates.

Internal considerations might include:

Business structure

Technology

Employee arrangements

Existing processes

Leadership priorities

Business strategy

Internal capability

Operational dependencies

External considerations could include:

Customer expectations

Regulation

Contractual requirements

Cyber threats

Supplier relationships

Technology changes

Market requirements

Legal obligations

ISO 27001 expects the scope decision to take account of the organisation’s context and relevant interested party requirements.

This prevents businesses from creating a scope without considering the reasons why information security matters in the first place.

Understand your interested parties

Interested parties can influence the ISMS boundary because they may impose requirements that your organisation needs to meet.

These may include:

Customers

Employees

Regulators

Government bodies

Shareholders

Suppliers

Partners

Insurers

Certification bodies

Contracting organisations

For example, a major customer may require ISO 27001 certification for the service you provide.

If that service depends on customer support, cloud hosting and development, a scope that excludes those important activities may not provide meaningful assurance.

Review customer contracts and security questionnaires when defining the scope.

They often reveal exactly what customers expect certification to protect.

Draw the boundaries clearly

Once you understand services, people, systems, information and suppliers, define the boundary.

A practical scope should answer:

Which organisation does the ISMS cover?

Which business services does it cover?

Which locations does it cover?

Which organisational functions contribute?

Which important technology supports it?

Which external dependencies affect it?

What falls outside the ISMS?

You do not need to write pages of detail into the final scope statement.

The supporting records can hold the deeper information.

The scope statement itself should remain concise and understandable.

Write the scope statement in plain language

A useful scope statement might follow this structure:

“The Information Security Management System applies to the provision and support of [service], including the people, processes, information systems, cloud services and business functions required to deliver that service from [relevant locations], in accordance with the Statement of Applicability.”

Adapt this wording to your organisation.

Do not copy a generic statement without checking whether every word accurately reflects your business.

Avoid vague wording such as:

“All information security activities.”

“Relevant company systems.”

“IT services.”

These phrases give auditors and customers very little understanding of the actual boundary.

Keep the scope available as documented information

ISO 27001 requires the ISMS scope to remain available as documented information.

That means you should maintain an approved scope statement within your compliance records.

The document should have clear ownership and version control.

Useful supporting records may include:

Organisation charts

Service diagrams

Asset records

Process maps

Location information

Supplier registers

System diagrams

Interested party records

Customer requirements

Risk records

You do not need to put all of this information inside the scope statement itself.

Keep enough supporting evidence to explain how management determined the boundary.

Make the scope match the risk assessment

Once the organisation approves the scope, the risk assessment should cover it.

This relationship sounds obvious, but organisations often create inconsistencies.

For example, the scope may include remote workers while the risk register contains no remote working risks.

A cloud service may appear in the scope while the organisation never assesses supplier failure or unauthorised cloud access.

Customer information may form part of the service while the risk assessment focuses only on internal IT.

Review the scope and risk register together.

Ask whether each important component of the boundary receives appropriate risk consideration.

Make the scope match the Statement of Applicability

The Statement of Applicability records the controls your organisation has determined are necessary and the reasoning behind those decisions.

The control selection should make sense in the context of the scope.

For example, a scope containing extensive remote working may require relevant people, access and endpoint controls.

A service relying heavily on cloud providers should have appropriate supplier and cloud-related controls.

A software development service will normally need relevant development security controls.

Weak alignment between scope, risk treatment and the Statement of Applicability can create audit findings and make the ISMS harder to manage. Current ISO committee guidance highlights strong traceability between these elements as a feature of effective ISMS operation.

Avoid exclusions made only to make certification easier

A business may legitimately exclude activities that have no meaningful connection with the in-scope service.

However, excluding a difficult system or department solely because it creates security work can cause problems.

Auditors may ask:

Does the excluded activity access in-scope information?

Does it support the certified service?

Does it manage critical systems?

Could failure affect the in-scope operation?

Does the service depend on its employees?

Would customers reasonably expect it to fall inside the certificate?

If the answer to several of these questions is yes, the exclusion may be difficult to justify.

Make scope decisions according to business relationships and risk rather than convenience.

Watch for shared systems

Shared systems can complicate a focused scope.

Imagine that the organisation certifies one division but every division uses the same Microsoft 365 environment.

Can you realistically exclude other parts of that environment?

The answer depends on access, configuration and technical separation.

Similar issues can arise with:

Shared networks

Central HR systems

Group finance systems

Identity platforms

Backup platforms

Security monitoring

Shared administrator teams

Central IT services

Understand these relationships before finalising the scope.

A diagram can often make shared dependencies easier to explain.

Scope should support customer confidence

The certification scope appears on, or relates directly to, the certification information that customers rely upon.

Clear wording helps customers understand exactly what assurance they receive.

A scope such as “Information Security Management System supporting the provision of managed cyber security services” gives useful context.

A vague statement such as “information systems” tells the reader much less.

Consider how a procurement professional would interpret the wording.

Would they understand whether the service they buy falls within the ISMS?

If not, improve the statement.

Current UK cyber risk makes clear scope important

The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months. Phishing affected 38 per cent of businesses.

The survey also found that medium businesses reported a higher incidence than the overall business population, while large organisations reported an even higher incidence.

These figures reinforce the need to understand where security risk exists across an organisation.

A poorly defined ISMS boundary can leave significant dependencies without appropriate risk assessment.

A clear boundary helps the business decide which people, processes, information and systems need attention.

Who needs iso 27001 certification

ISO 27001 certification can benefit organisations that hold important information or need to demonstrate structured information security management.

Technology providers, software companies, managed service providers, consultancies, professional firms, manufacturers, healthcare suppliers, financial organisations, charities and government suppliers may all benefit.

ISO states that its information security management framework can adapt to an organisation’s objectives, processes and structure.

Customer requirements often drive certification.

A larger organisation may ask suppliers to prove that they manage customer information systematically.

Public procurement, contractual requirements, corporate governance and supply-chain assurance can also influence the decision.

The scope becomes particularly important in these situations because customers need to know whether certification actually covers the service they purchase.

Small businesses can keep the scope straightforward

A small organisation should avoid making the process unnecessarily complicated.

Start with the business service.

List who supports it.

Identify the information involved.

Record the technology it depends on.

Identify the relevant suppliers.

Confirm where employees work.

Review customer and legal requirements.

Then write the boundary in plain language.

A business with ten employees may end up with a whole-organisation scope because separating departments would create little practical benefit.

This can make certification easier to understand and maintain.

Complex organisations may need more detailed boundary decisions.

The right answer depends on the business rather than employee numbers alone.

Review acquisitions and organisational changes

Your scope should change when the business changes significantly.

For example, review it after:

Acquiring another company

Launching a major service

Moving to a new cloud platform

Opening another location

Changing critical suppliers

Restructuring departments

Changing remote working arrangements

Taking on substantially different customer requirements

Changing major technology

Merging business functions

Current ISO committee guidance recommends treating scope as an active management item and reviewing it when acquisitions, cloud migration, new markets or major supplier changes affect the organisation.

Review the scope after incidents

A security incident can reveal that the actual operating boundary differs from the documented one.

Suppose an incident involving a supposedly excluded supplier affects the certified customer service.

That may indicate that the supplier represents an important dependency that the ISMS should consider more explicitly.

After significant incidents, ask:

Did the event affect something inside scope?

Did an excluded system contribute?

Did we misunderstand a dependency?

Does the risk assessment need updating?

Do we need to change the scope?

Does the Statement of Applicability need review?

An ISMS should learn from real events.

Internal audit should test the boundary

Your internal audit should examine whether the documented scope reflects reality.

An internal auditor may ask:

Does the scope cover the service customers believe is certified?

Are important locations included?

Do remote workers fit the stated boundary?

Are critical suppliers recognised?

Does the risk register cover all major dependencies?

Does the Statement of Applicability reflect the scope?

Are shared systems handled properly?

Have business changes affected the boundary?

This review provides an opportunity to correct weaknesses before the external certification assessment.

Management should approve and understand the scope

The ISMS scope should not become a technical document that only the compliance manager understands.

Senior management needs to understand what the organisation plans to certify.

Leaders should know:

Which services sit inside the ISMS

Which parts of the organisation support them

What sits outside

Which critical suppliers create dependencies

What customers will believe the certificate covers

Which risks follow from the boundary

Management involvement matters because the boundary influences resources, responsibilities and customer commitments.

A scope decision can also affect future growth.

If the organisation expects to expand the certified service quickly, consider whether the proposed boundary can support that growth.

ISO 27001 Certification Levels

ISO 27001 does not use formal achievement bands such as bronze, silver or gold.

An organisation either achieves certification for the stated ISMS scope or it does not.

Businesses do move through practical stages before certification.

These commonly include:

Understanding organisational context

Defining the ISMS scope

Identifying interested parties

Assessing information security risks

Treating unacceptable risks

Selecting controls

Preparing the Statement of Applicability

Operating the ISMS

Gathering evidence

Completing internal audit

Holding management review

Undergoing external certification assessment

The certification scope remains central throughout these stages because it tells everyone where the ISMS requirements apply.

How the Certification Works

The organisation starts by understanding its business context and interested parties.

It then defines the ISMS boundary.

Risk assessment identifies the information security scenarios that could affect the in-scope services, people, information, technology and suppliers.

Risk treatment determines what action the organisation needs.

The business selects controls and compares them with Annex A. It records its control decisions in the Statement of Applicability.

The organisation then operates the controls and gathers evidence.

Internal audit examines whether the ISMS meets requirements and works effectively.

Management review allows senior leadership to assess the system, major risks, audit findings, objectives and improvement activity.

An independent certification body then carries out the external certification process. ISO committee material describes certification auditing as a systematic and independent process for obtaining evidence and evaluating whether the ISMS fulfils ISO/IEC 27001 requirements.

The organisation needs to demonstrate that the ISMS works across the declared boundary.

Scope questions an auditor may ask

An auditor may ask:

Why did you choose this boundary?

Which services does it cover?

Which legal entity holds certification?

Which locations sit inside the ISMS?

Which employees support the service?

Which information falls inside the boundary?

Which technology supports it?

Which cloud platforms do you rely on?

Which suppliers create significant dependencies?

Why have you excluded certain activities?

How does the risk register reflect the scope?

How does the Statement of Applicability support it?

When did management last review the scope?

What changed since the previous review?

Clear supporting evidence makes these questions much easier to answer.

Common mistakes when defining scope

One common mistake involves making the boundary too vague.

Another involves focusing only on technology.

Some organisations exclude suppliers without examining dependencies.

Others forget remote workers or shared services.

Further weaknesses can include:

Ignoring customer requirements

Leaving important cloud services out

Using outdated organisation information

Excluding support teams that affect the service

Creating a scope that does not match the risk assessment

Using wording that customers cannot understand

Ignoring shared infrastructure

Failing to review the scope after change

Copying another organisation’s wording

Trying to reduce audit work by creating an artificial boundary

A well-written scope should reflect reality.

Which UK-based firms offer ISO 27001 consultancy services?

UK organisations can obtain ISO 27001 support from information security consultancies, compliance specialists, managed service providers and platform-led services.

UK Cyber Compliance provides ISO 27001 support through an automated and AI-driven platform. Its current service includes structured workflows, risk analysis, control coverage and audit-ready documentation.

A capable provider should help you understand:

Business context

Interested parties

ISMS scope

Organisational boundaries

Dependencies

Risk assessment

Annex A controls

The Statement of Applicability

Evidence

Internal audit readiness

Management review

The organisation should remain responsible for the final scope decision.

An external adviser can guide the process, but management needs to understand and approve what certification will cover.

How UK Cyber Compliance helps with ISO 27001 scope

Managing scope through disconnected documents can make dependencies harder to see.

UK Cyber Compliance provides a central platform that connects ISO 27001 activity with risk assessment, control management and audit readiness.

Its current platform describes real-time compliance visibility, intelligent risk assessment and structured guidance through ISO 27001 requirements.

This can help organisations connect the scope with:

Business activities

Information assets

People

Risk

Controls

Actions

Evidence

Audit preparation

A centralised approach can also make later changes easier to manage.

When a new system or supplier enters the ISMS, the organisation can review related risk and controls rather than updating several unrelated spreadsheets.

A practical ISO 27001 scope checklist

Before approving the scope, ask:

Which legal organisation does certification cover?

Which business services sit inside the ISMS?

Which locations support those services?

Which employees and business functions contribute?

Which information needs protection?

Which systems support the service?

Which cloud platforms do we rely upon?

Which suppliers create dependencies?

Have we considered remote working?

Have we considered shared systems?

Have we identified internal and external issues?

Have we considered interested party requirements?

Do customer expectations align with the scope?

Can we justify every significant exclusion?

Does the risk register cover the boundary?

Does the Statement of Applicability support the boundary?

Can senior management explain what is being certified?

Would a customer understand the wording?

Is the scope recorded as controlled documented information?

Do we have a process for reviewing the scope after change?

If several answers remain unclear, continue refining the boundary before the external audit.

Make the scope useful beyond the audit

A good ISO 27001 scope does more than satisfy a certification requirement.

It gives the organisation clarity about which information security responsibilities matter most.

It helps risk owners understand what they manage.

It helps employees understand where security processes apply.

It helps suppliers understand expectations.

It helps customers see what certification protects.

It helps internal and external auditors test the right activities.

Most importantly, it creates a solid foundation for the entire ISMS.

Start with the service your organisation wants to protect. Identify the people, information, processes, technology, locations and suppliers that support it. Consider customer requirements and external dependencies. Define the boundary clearly and document it.

Then connect that scope with risk assessment, Annex A controls, the Statement of Applicability, internal audit and management review.

UK Cyber Compliance provides an automated and AI-driven platform that helps organisations bring these elements together and maintain visibility throughout the ISO 27001 certification journey.

A clear and defensible scope gives your organisation a better foundation for certification and a much clearer understanding of what its Information Security Management System actually protects.

UK Cyber Compliance is here to help

For more information, please do get in touch.

Please check out our Free Cyber Insurance

Other blog posts, Your ISO 27001 Questions AnsweredGet ISO 27001 Certified ,

If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.