ISO 27001 scope: how to define your ISMS boundary, with examples

How to define and write your ISO 27001 scope under clause 4.3: a six-dimension decision matrix, three worked ISMS scope statement examples, a template outline, what auditors check, and the scope-too-small trap that gets certificates rejected.

The short answer: Your ISO 27001 scope is the written boundary of the information security management system: the services, sites, teams, systems and suppliers the ISMS covers, and the ones it does not. Clause 4.3 of ISO 27001 requires you to define that boundary, document it, and account for the interfaces with whatever you leave outside it. The scope statement is then printed on your certificate, so it has to cover the service your customers actually buy.

Scope is the first decision in an ISO 27001 project and it sets the price of every decision after it: how many assets go in the risk register, how many controls you justify in the Statement of Applicability, how many audit days the certification body quotes. Buyers have also got better at reading scope statements, and a certificate covering "the Bristol office" when the platform runs from three countries no longer gets waved through.

{{snapshot}}

ISO 27001 scope at a glance

  • Clause 4.3 owns it. Determine the boundaries and applicability of the ISMS, consider your 4.1 and 4.2 context and the interfaces with other organisations, and keep it as documented information.
  • It goes on the certificate. The scope statement is public. Customers and auditors read it, so write it for them.
  • Six dimensions to decide. Locations, business units, services, systems, people and suppliers: each in or out, with a written reason.
  • Too small is the expensive mistake. A scope that excludes the thing you sell produces a certificate your customers reject.
  • Everything downstream inherits it. Risk assessment, SoA and audit days follow the boundary you draw.

{{/snapshot}}

What clause 4.3 actually asks for

Clause 4.3 is four sentences long. You determine the boundaries and applicability of the ISMS, considering the external and internal issues from clause 4.1, the requirements of interested parties from 4.2, and the interfaces and dependencies between activities you perform and activities other organisations perform for you. The scope must be available as documented information. That is the whole clause, and the clause 4.3 hub takes it line by line.

Notice what it does not say: not the whole company, no prescribed format. The auditor has no checklist beyond those three considerations, which is why the rest of clause 4 matters.

The phrase people skip is "interfaces and dependencies": every point where an in-scope process touches something outside the boundary. The cloud provider hosting your platform. The payroll bureau. You need not pull them inside the scope, but you must name the boundary and manage the relationship, which is what the Annex A supplier controls (5.19 to 5.22) exist for. The full text is at iso.org.

How to decide what sits inside the scope

Work through six dimensions, decide in or out for each, and write down why. The rule for most organisations: scope to the service customers are asking about, add the functions that support it and anything sharing infrastructure or an identity provider with them. Stop there.

DimensionTypically in scopeTypically out of scopeJustification to write down
LocationsOffices where in-scope staff work; hosting regions; remote workingA sales office with no access to in-scope dataWhich locations process, store or can access in-scope information
Business unitsEngineering, support, operations, IT, HR (for joiner and leaver controls)A subsidiary with its own IT and legal identitySeparate systems, separate identity provider, no shared data flows
ServicesThe product or service named in customer contractsA legacy product being retired; an internal tool with no customer dataWhat customers buy and what handles their data
SystemsProduction, code repositories, identity provider, ticketing, corporate laptopsA marketing website with no customer data; a standalone lab networkWhether it holds, processes or grants access to in-scope information
PeopleEmployees and contractors with access to in-scope systems or dataStaff in an excluded entityAccess, not job title, decides inclusion
SuppliersManaged as interfaces: hosting provider, MSP, payroll bureau, outsourced developmentTheir internal controls (their certification, your contract)Named as a dependency, controlled through supplier management

The last column is the one that matters at audit. "Out of scope" with no reason gets questioned at stage 1. Valid reasons: separate legal entity with separate systems, no access to in-scope information, service delivered by a supplier with its own assurance. "Too hard" is not one, however carefully phrased.

The fastest way to find your real boundary is to list the assets. If you cannot say which systems hold in-scope data and who administers them, you do not yet know your scope, whatever the draft says. An information asset register that feeds the risk register does that job once, then keeps doing it as systems get added, so drift gets caught before an auditor catches it.

Three ISMS scope statement examples

Scope statements are short: two to five sentences, usually referencing the SoA version. Three you can adapt, with the reasoning that makes each defensible.

Example 1: a SaaS company

"The ISMS covers the design, development, hosting, support and operation of the Acme platform, delivered to customers from AWS eu-west-2, together with the corporate information systems used by Acme Ltd staff working from its London office and remote locations, in accordance with the Statement of Applicability version 3.1."

This names the product, hosting region, legal entity and people. AWS's data centres are an interface, not in scope, managed through supplier controls and AWS's assurance reports. Remote working is named explicitly, because auditors will ask where the engineers actually sit.

Example 2: a managed service provider

"The ISMS covers the provision of managed IT, cloud and cyber-security services to clients, including service desk, remote monitoring and management, backup and privileged access to client environments, delivered from Acme's Manchester operations centre and by remote engineers, in accordance with the Statement of Applicability version 2.0."

Clients ask managed service providers for ISO 27001 because the MSP holds privileged access to their environments. A scope that leaves out the service desk or the RMM tooling leaves out the exact risk the client worries about. Client-owned systems stay outside; the MSP's access to them is inside.

Example 3: a single-site professional services firm

"The ISMS covers the handling of client information in the delivery of consulting services by Acme Advisory LLP from its office at 12 Example Street, Leeds, including the information systems and staff supporting those engagements, in accordance with the Statement of Applicability version 1.2."

One site, one entity, one service line, so the boundary is simple. What matters for a consulting firm is subcontractors and the client-owned systems staff log into. Both are interfaces: the scope document names them, supplier and access controls manage them.

A scope statement template you can fill in

Keep the statement to one paragraph and put the detail in a scope document it references. The certificate carries the paragraph; the auditor reads the document, which needs these sections:

  1. Organisation and legal entities covered.
  2. Products and services in scope, using the names customers see in contracts.
  3. Locations: offices, hosting regions, and whether remote working is included.
  4. Organisational units and roles inside the boundary, with approximate headcount.
  5. Systems and networks, either listed or by reference to the information asset register.
  6. Exclusions, each with a one-line justification.
  7. Interfaces and dependencies: suppliers, group companies, customers, and how each is controlled.
  8. Context references: the 4.1 issues and 4.2 requirements the scope responds to.
  9. Control: owner, approver, version and review trigger.

Write section 6 as if a sceptical customer will read it, because one will. Do not skip the review trigger in section 9, or the scope goes on naming an office you left two years ago.

The scope-too-small trap

It is tempting to certify one team or office to get the badge quickly. The certificate then reads "the information security management system supporting the Bristol office". Your customer buys a platform built by engineers in Bristol, Kraków and a contractor in Lisbon. Procurement compares scope with contract and either rejects the certificate or sends back the questionnaire it was supposed to replace. The scope must cover the service the customer buys end to end, including every team and system that touches its data. Anything narrower was drawn for the convenience of the project, and the market will notice.

The opposite failure is real too. Scoping the whole group, including entities with no connection to the service, doubles audit days and fills the risk register with orphan assets. HealthBoxHR, an HR and payroll SaaS holding sensitive employee data, drew the boundary around the platform and the people running it. In their CTO's words: "Starting without anything in place, we were able to achieve ISO/IEC 27001:2022 certification in 12 weeks." That speed came from a boundary decided in week one and not re-litigated in week eight.

What auditors check about scope

At stage 1 the auditor confirms a documented scope exists, traces back to your 4.1 and 4.2 context, identifies interfaces and dependencies, and agrees with the SoA and the risk assessment. They also settle the certificate wording.

At stage 2 they walk the boundary: an interview with an in-scope engineer about a named system, a trace of customer data to the supplier hosting it, a check that the supplier is actually managed. They also look for in-scope data leaking into out-of-scope places, such as a group file server used by everyone when only one unit is certified, or a shared Active Directory that makes the "separate entity" exclusion untrue.

The findings we see most often are boring and avoidable: a scope naming a location that closed, a scope that says "all systems" while the SoA excludes physical controls, a business unit excluded on paper that shares the in-scope identity provider. An ISO 27001 gap analysis before stage 1 catches all three, because it starts by asking whether the scope, the asset register and the SoA describe the same organisation.

How scope drives the SoA and risk assessment, and how to change it later

Scope is the input to everything that follows. The risk assessment covers the assets inside the boundary and nothing else. The Statement of Applicability justifies each Annex A control against the risks inside that boundary, and a control marked not applicable is defensible only if the scope explains why the risk cannot arise. Change the scope and both change with it.

Changing scope after certification is routine. Extend it at a surveillance or recertification audit: update the scope document, assess the new assets, update the SoA, and tell the certification body, which may add audit days. Reducing scope is possible too, and customers notice.

The same boundary can serve more than one standard. Blue-i Group, an event technology company, certified to ISO 9001, 14001 and 27001 in under two years on one platform, with the context and boundary written once and reused across three management systems.

{{snapshot}}

Hicomply's take

We have read a lot of scope statements and the bad ones fail the same way: they describe the project team rather than the service. Draw the boundary around what customers buy, name every interface honestly, and let the asset register decide the rest. The mistake to avoid is treating scope as a paragraph you write on day one and never open again. Keep it version-controlled next to the SoA with a review trigger, because the moment you add a site or a supplier, the certificate describes a company that no longer exists.

{{/snapshot}}

Draw the boundary once and stop redrawing it

Most scope problems are record-keeping problems: the asset register, the scope document and the SoA drift apart because they live in three places. Keeping them in one system, with the asset register feeding the risk register and the SoA generated from the control set, removes the drift.

Start with the free ISO 27001 readiness assessment to see whether your scope, context and asset list hold together, then book a demo and bring your draft scope statement. We will tell you whether an auditor, or a customer, will accept it.

Ready to Take Control of Your Privacy Compliance?

Hicomply’s platform provides an all-in-one solution to streamline, automate, and centralise your compliance activities, ensuring complete control and efficiency.

Book a demo
Last updated
September 18, 2026
Category
ISO 27001 Implementation
Topics
No items found.
Lucy Murphy
Head of Customer Success

Lucy works closely with customers to help them get the most out of the Hicomply platform, from onboarding to audit success. She brings a user-focused mindset to everything she does, making her well-placed to write about day-to-day challenges, shortcuts, and success strategies. Her content is grounded in what real InfoSec and compliance teams need to know — and how to get there faster.Expect helpful walkthroughs, product tips, and practical insights.

Popular ISO 27001 Scope queries, answered!

What is the scope of an ISMS in ISO 27001?

The ISMS scope is the documented boundary of your information security management system: the legal entities, services, locations, systems, people and supplier interfaces it covers. Clause 4.3 of ISO 27001 requires you to define it using your organisational context and interested-party requirements, record the interfaces with anything outside it, and keep it as documented information. The scope statement is printed on your certificate.

How do you write an ISO 27001 scope statement?

Write one paragraph naming the legal entity, the products or services covered, the locations and hosting regions, the people included, and the Statement of Applicability version it refers to. Keep exclusions and their justifications, plus interfaces such as hosting providers or group IT, in a longer scope document the statement references. Use the service names your customers see in contracts.

Can the ISO 27001 scope cover only part of a company?

Yes. ISO 27001 allows a scope covering one service, site or business unit, provided the exclusion of everything else is justified and the interfaces are managed. The practical limit is commercial: if the scope leaves out the service a customer buys, or a team that handles its data, the certificate will not satisfy their procurement checks and you will face the same questionnaire anyway.

Do suppliers like AWS have to be inside the ISO 27001 scope?

No. A hosting provider is an interface and dependency, not part of your ISMS. You name it in the scope document, manage it through the supplier controls in Annex A (5.19 to 5.22), and rely on its contract and assurance reports for the physical and infrastructure controls it operates. Your responsibility is the configuration, access and data you control on top of their service.

Can you change the ISO 27001 scope after certification?

Yes, and it is routine. Extending the scope to a new product, site or entity is normally handled at a surveillance or recertification audit: update the scope document, assess the new assets, revise the Statement of Applicability and notify the certification body, which may add audit days. Reducing the scope is also possible, though customers who read the certificate will notice.

Unlock Your Path to ISO 27001 Success

Download our Ultimate ISO 27001 Compliance Checklist for clear, step-by-step guidance to fast-track your certification.

End to end ISO 27001 compliance documentation

Your hub for the fundamentals of ISO 27001 compliance, curated best practices, and resources for GRC professionals.

ISO 27001 Overview

Achieve ISO 27001 Certification

ISO 27001 is the globally recognised standard for building a structured Information Security Management System (ISMS) that protects the confidentiality, integrity and availability of information. This article explains what ISO 27001 is, how it works, the core principles behind it, and what organisations must do to achieve certification. You’ll learn the standard’s structure, its key requirements, how the certification process unfolds, and the practical steps needed to implement an ISMS that is both compliant and effective.

Learn more about Achieve ISO 27001 Certification

Benefits Of ISO 27001 For Businesses

ISO 27001 certification is one of the most credible ways for businesses to prove they protect sensitive information with structure, consistency, and internationally recognised best practice. This guide explains what ISO 27001 certification is, why companies pursue it, the core business benefits, the costs involved, and how organisations of any size can achieve and maintain certification. Whether you're preparing for your first audit or strengthening your security posture, this article gives you the clarity, detail, and practical steps to move forward with confidence.

Learn more about Benefits Of ISO 27001 For Businesses

History And Evolution Of ISO 27001

ISO 27001 is now recognised as the world’s leading standard for managing information security, but its journey spans decades of technological change, emerging cyber threats, and global collaboration. This article traces the origins of ISO 27001, from its earliest foundations to the modern 2022 revision. You’ll learn how the framework developed, why it became globally adopted, how ISO 27002 fits into the picture, and how ISO standards evolved more broadly over time.

Learn more about History And Evolution Of ISO 27001
ISO 27001:2022 Requirements

Actions To Address Risks And Opportunities | Clause 6.1

Clause 6.1 of ISO 27001 defines how organisations must identify, assess, and treat information security risks — and how they must uncover opportunities to strengthen their Information Security Management System (ISMS). This clause acts as the engine of the ISO framework: it drives risk-based thinking, aligns controls to real-world threats, and ensures continual improvement. In this guide, we break down Clause 6.1 line by line, explain its relationship with Annex A, show you what documentation is required, and provide examples and best practices to help you implement it correctly and confidently.

Learn more about Actions To Address Risks And Opportunities | Clause 6.1

ISO 27001 Awareness | Clause 7.3

In this article, we explore everything you need to know about ISO 27001 Clause 7.3—its purpose, what the standard requires, how awareness strengthens your ISMS, and how to build a practical, auditor-ready awareness program that supports continuous security improvement.

Learn more about ISO 27001 Awareness | Clause 7.3

ISO 27001 Communication | Clause 7.4

In this guide, we break down exactly what ISO 27001 Clause 7.4 requires, why structured communication is essential to an effective ISMS, and how organisations can build a clear, compliant communication process supported by practical, real-world examples.

Learn more about ISO 27001 Communication | Clause 7.4

Internal Audit | Clause 9.2

Understanding the intricacies of ISO 27001:2022 is crucial for organisations aiming to enhance their information security management systems. Clause 9.2, which focuses on internal audits, plays a pivotal role in this context.

Learn more about Internal Audit | Clause 9.2
Information Security Management System (ISMS)

ISO 27001 ISMS Audit And Review Process

The audit and review process is one of the most important pillars of ISO 27001. It ensures your Information Security Management System (ISMS) is working as intended, risks are managed effectively, controls are operating correctly, and continual improvement is actively taking place. This guide explains every component of the ISO 27001 audit lifecycle — internal audits, external audits, certification audits, surveillance audits, and management reviews — and shows you how to prepare, what evidence auditors expect, and how to maintain long-term compliance.

Learn more about ISO 27001 ISMS Audit And Review Process

ISO 27001 ISMS Continuous Improvement Cycle

In this end-to-end guide, you’ll learn how continual improvement works in ISO 27001, why it’s essential for long-term security maturity, how the PDCA cycle operates inside an ISMS, and what processes, documentation, and actions are required to maintain compliance year after year.

Learn more about ISO 27001 ISMS Continuous Improvement Cycle
Annex A Controls — Organizational

Acceptable Use Of Assets | Annex A 5.10

Information security policies serve as the foundation of any robust cybersecurity program. Without clearly defined rules for acceptable use of information assets, organizations face increased vulnerability to data breaches, compliance violations, and operational disruptions. Control 5.10 of ISO 27001:2022 specifically addresses this critical aspect of information security management, requiring organizations to establish formal guidelines for how information and associated assets should be handled.

Learn more about Acceptable Use Of Assets | Annex A 5.10

Access Control Policies | Annex A 5.14

Information rarely stays still. Every organisation transfers data daily—between teams, systems, partners, customers, cloud platforms, and suppliers. Emails are sent, files are shared, storage media is moved, meetings are held, and conversations take place across calls and video conferences. Each transfer represents a moment of heightened risk.

Learn more about Access Control Policies | Annex A 5.14

Access Rights Management | Annex A 5.16

ISO 27001 Annex A 5.16 focuses on how organisations manage access rights by governing the full lifecycle of identities. This control ensures that only authorised users, systems, and services can access information assets, and that access is removed when no longer required.

Learn more about Access Rights Management | Annex A 5.16
Annex A Controls — People

Confidentiality And NDA Management | Annex A 6.6

Confidentiality obligations sit at the very core of information security. Without enforceable confidentiality controls, even the strongest technical safeguards can be rendered ineffective by human behaviour, contractual gaps, or unclear responsibilities. ISO 27001:2022 Annex A 6.6 formalises this reality by requiring organisations to define, implement, communicate, and enforce confidentiality and non-disclosure obligations across employees, contractors, suppliers, and other relevant parties.

Learn more about Confidentiality And NDA Management | Annex A 6.6

Disciplinary Process And Enforcement | Annex A 6.4

Establishing a fair disciplinary process is essential for organizations that want to effectively manage security violations while maintaining employee trust. When security breaches occur, organizations often struggle to respond consistently, which can lead to resentment, legal complications, or ineffective deterrence. Consequently, ISO 27001 includes specific requirements under Annex A 6.4 to ensure disciplinary processes are both fair and effective.

Learn more about Disciplinary Process And Enforcement | Annex A 6.4

Employee Screening And Background Checks | Annex A 6.1

In this guide, we explain everything organisations need to know about ISO 27001:2022 Annex A 6.1 — Employee Screening and Background Checks. You’ll learn what the control requires, why it exists, how auditors assess compliance, what evidence is expected, and how to design a screening process that is legally compliant, proportionate, and effective across different roles and risk levels.

Learn more about Employee Screening And Background Checks | Annex A 6.1
Annex A Controls — Physical

Access Control To Premises | Annex A 7.2

Physical security remains one of the most underestimated components of information security. While organisations invest heavily in cybersecurity tools, a single uncontrolled door, shared workspace, or unlogged visitor can undermine even the most mature digital controls. ISO 27001 Annex A 7.2 exists to address this exact risk by requiring organisations to establish and maintain effective access control to premises where information and information-processing facilities are located.

Learn more about Access Control To Premises | Annex A 7.2

Cabling And Electrical Security | Annex A 7.12

Modern technologies rely heavily on fiber, network, and power cables to function correctly. When we focus on ISO cyber security, we often overlook these critical components' physical vulnerabilities. Power and information cables face risks of damage and interception. Cyber criminals who gain access to fiber cables can disrupt all network traffic with simple techniques like 'bending the fiber.' This makes data and information unavailable.

Learn more about Cabling And Electrical Security | Annex A 7.12
ISO 27001 by Industry

ISO 27001 for Small Businesses

A practical guide to ISO 27001 for small businesses in the UK: how to scope the ISMS small, what certification really costs, how long it takes, the four mistakes small firms make, and when Cyber Essentials is enough instead.

Learn more about ISO 27001 for Small Businesses

ISO 27001 for Healthcare Companies

How UK health-tech firms, care providers and NHS suppliers use ISO 27001 to answer procurement security questions, and how it sits alongside the NHS DSPT, DTAC and Cyber Essentials Plus without duplicating the work.

Learn more about ISO 27001 for Healthcare Companies

ISO 27001 for Consulting Firms

How consultancies get ISO 27001 certified when their assets are people, laptops and client system access. Scoping by service line, the people and supplier controls auditors sample, and whether you need a consultant.

Learn more about ISO 27001 for Consulting Firms

ISO 27001 for Managed Service Providers

How UK MSPs certify to ISO 27001: what belongs in scope when you hold privileged access to client estates, the Annex A controls auditors focus on, and how CE+, ISO 27001 and SOC 2 fit together.

Learn more about ISO 27001 for Managed Service Providers

Your ISO 27001 Compliance Newsletter

Stay ahead with the latest expert insights, news, and updates on compliance.
Decorative