ISO 27001 Scope Statement Explained + Template

Stuart And Fay High Table

In this guide, you will learn what an ISO 27001 Scope Statement is, how to write it yourself and I give you a template you can download and use right away.

ISO 27001 Scope Explained

ISO 27001 scope is the scope of the information security management system. 

We are going to build an information security management system with the information security policies and apply it to something to get ISO 27001 certified. 

The ‘something’ that we are going to apply it to is the scope.

We document the scope in an ISO 27001 Scope Statement.

ISO 27001 Scope Statement Explained

The ISO 27001 Scope statement is the statement that will appear on your ISO 27001 certificate. It is the public document that you share with customers and potential customers. They will use this information to assess if the ISO 27001 certificate covers what they are buying from you and therefore if they can place reliance on it for their needs.

The scope statement shows which parts of your business are certified and it shows them that you are doing the right thing for information security.

If the ISO 27001 scope statement does not cover the products or services that they are buying from you then they cannot place reliance on it and it will not be valid for them.

Consider an extreme example where your ISO 27001 scope statement covers the company stationary cupboard (I know, I know, it is an example) and the customer is buying an online SAAS Platform from you. Does the fact that you have ISO 27001 certification for your stationary cupboard give them assurances that the online SAAS Platform is secure and managed to the standard of ISO 27001?

If you are struggling with this one, let me help you, the answer is no.

Template

Doing so many ISO 27001 certifications over the years led to the creation of the ISO 27001 Scope Document Template that people can use as part of their own ISO 27001 certification.

ISO 27001 Scope Document Template

ISO 27001 Scope Examples

When considering the what of ISO 27001 scope we can look at examples where we might want to apply the standard and gain ISO 27001 certification.

Common examples include

  • A Product: Focus the ISMS and certification on a specific software or hardware product line to provide robust security assurance to end-users.
  • A Service: Apply the standard to a particular service offering to ensure data protection and operational resilience for client-facing activities.
  • A Location: Define the scope by the physical boundaries of a single office or site where specific high-risk operations are conducted.
  • A Geography: Set the boundaries of the management system based on a specific region or territory to align with local jurisdictional requirements.
  • A Team: Scope the certification to a high-performing group, such as an engineering team, to secure critical internal development workflows.
  • A Department: Formalise the security boundaries for an entire functional area, such as IT or Operations, to manage department-specific risks.

ISO 27001 Scope Statement Examples

Entity TypeExample Scope Statement TextImplementation Guidance
High Table (Specialist)Information security consultancy and virtual chief information security officer services in accordance with the statement of applicability version 2.Focuses on the specific service delivery and the Statement of Applicability version control.
General BusinessThe scope encompasses all employees, locations, technology, data assets and business processes that deliver [List the products and services in scope] in accordance with the statement of applicability version [version number].A broad baseline requiring the itemisation of products, services, and technical infrastructure.
Template ReferenceReusable framework available via the ISO 27001 Scope Document template.Best for organisations needing a pre-populated structure to ensure Clause 4.3 audit compliance.

A great ISO 27001 scope example is provided in the ISO 27001 Scope Document template and can be readily reused and adapted for your needs.

How to write an ISO 27001 Scope Statement Yourself

The scope for ISO 27001 is going to be based on two things:

  • the products and services you offer
  • which of those products and services your customers expect to be certified

To implement ISO 27001 Clause 4.3 effectively, you must define the precise boundaries of your Information Security Management System (ISMS). This involves inventorying products, auditing stakeholder requirements, and mapping the technical landscape to ensure security efforts are focused on high-value assets and customer expectations.

Step 1: Provision a Business Service Inventory

Action: Provision a comprehensive list of all organisational products and services using the specific terminology recognised and used by your customers. Result: A technical baseline of business offerings that allows for the accurate identification of the digital assets requiring protection.

Step 2: Define High-Value Certification Targets

Action: Analyse customer feedback, existing contracts, and sales team insights to choose the specific products that require certification. Result: A resource-efficient scope that focuses security efforts on necessary business units, which minimises documentation workload and reduces implementation costs.

Step 3: Identify Personnel, Technology, and Premises

Action: List the specific departments, technical infrastructure (such as IAM roles or cloud instances), and physical locations that deliver the chosen services. Result: Technical clarity on the human and physical resources that reside within the formal Information Security Management System (ISMS) boundary.

Step 4: Compose the ISO 27001 Scope Statement

Action: Compose a concise, formal statement that explicitly names the services, people, technology, and locations included in the certification. Result: A clear public-facing declaration that defines the precise reach of your security management system for auditors and clients.

Step 5: Formalise In-Scope and Out-of-Scope Details

Action: Formalise a detailed Scope Document that specifically encompasses systems in use, departments involved, and a justified list of exclusions. Result: A robust internal resource supported by architecture diagrams and network maps that clarifies absolute security boundaries for audit evidence.

ISO 27001 Scope – FREE Training Video

To watch a video of how to implement ISO 27001 scope and write an ISO 27001 scope statement watch the tutorial – Determining the Scope of the Information Security Management System.

ISO 27001 Scope Statement vs Document Comparison

A common audit failure is providing the auditor with a brief Scope Statement when they requested the Scope Document. While the statement is public-facing, the document is an internal technical blueprint required by Clause 4.3.

FeatureScope Statement (Public)Scope Document (Internal)
PurposePrinted on your ISO 27001 certificate for clients to see.Defines the technical and physical boundaries for the audit.
Detail LevelHigh-level summary of products and services.Granular lists of assets, IAM roles, and network segments.
VisualsText only.Includes architecture diagrams and logical network maps.
Audit UseVerification of the certificate’s reach.Evidence of “Determining the Scope” (Clause 4.3).
ISO 27001 Toolkit Business Edition

Climate Change Impact on ISO 27001 Scoping

Per the 2024 ISO 27001 Amendments, you must determine if climate change is a relevant issue. In the context of Clause 4.3, this means evaluating if environmental risks dictate the physical or logical boundaries of your certification.

Climate Factor (4.1)Impact on Scope (4.3)Required Audit Evidence
Extreme Weather RisksSpecific physical office sites or legacy data centres may be excluded or isolated due to high-risk flood or heat zones.Exclusion justification in the Scope Document citing environmental risk assessment.
Sustainability MandatesScope expands to include the Secure Disposal (Annex A 7.14) of hardware via green-certified e-waste partners.Inclusion of third-party recycling interfaces in the dependency map.
Geographical ResilienceScope shifts toward Multi-Region Cloud Redundancy to mitigate localised environmental outages.Logical boundary map showing failover data centre locations.

Lead Auditor Tip: If your Context Analysis (4.1) concludes that climate change is not a relevant issue for your business, your Scope Statement does not need to change. However, you must document that this determination was made. An auditor will ask: “How did your 4.1 climate review affect the boundaries defined in 4.3?” Be ready with a clear answer.

Scope Creep

This section addresses the most significant operational risk during an ISO 27001 project: Scope Creep. For CEOs and business owners, an undefined boundary is the primary cause of budget overruns (often exceeding 30-50% of the initial estimate) and audit failure. By formalising your “Out-of-Scope” list with technical justifications, you create an auditor-defensible barrier that protects your timeline and resources.

How to Prevent ISO 27001 Scope Creep

Preventing scope creep is not about avoiding security; it is about ensuring your certification boundaries match your business liabilities. Auditors naturally explore technical interfaces, and without a rigid, board-approved scope document, a 4-day audit can easily spiral into a 6-day investigation into non-critical systems.

  • Define a Minimum Viable Scope (MVS): Action: Identify the specific “Revenue-Generating Assets” your customers require to be certified. Result: A focused ISMS that excludes low-risk back-office functions, reducing documentation volume by up to 40%.
  • Formalise a Documented Exclusion Register: Action: List every department, site, or system NOT included in the ISMS and provide a technical justification for each. Result: A pre-emptive defense that stops auditors from “drilling down” into unvetted areas during the Stage 1 assessment.
  • Establish Audit Rules of Engagement (RoE): Action: Provision a formal RoE document for the auditor that explicitly states the technical boundaries. Result: Prevention of “Tangent Auditing” where investigators follow data flows into third-party or out-of-scope environments.
  • Enforce a Pre-Audit Change Freeze: Action: Revoke the ability to add new systems or services to the ISMS 60 days before the external audit. Result: A stable environment where the documentation matches the actual practices, eliminating last-minute “compliance gaps.”
  • Appoint a Single Point of Contact (SPOC): Action: Designate a “Scope Gatekeeper” who is the only individual authorised to provide evidence to the auditor. Result: Elimination of “accidental scope expansion” caused by staff providing evidence for systems that are technically out of scope.

Lead Auditor Tip: If an auditor asks to see evidence for a system you consider out of scope, do not just say “no.” Refer them to your Clause 4.3 Scope Document and point to the Justified Exclusion section. A justified “No” is a sign of management maturity, not a lack of compliance.

The Distinction: ISMS Scope vs. Statement of Applicability (SoA)

A common mistake is confusing the Scope Statement (Clause 4.3) with the Statement of Applicability (Clause 6.1.3). As a Lead Auditor, I define the difference simply: The Scope is the ‘What’ (your business boundaries), while the SoA is the ‘How’ (the specific controls applied within those boundaries).

Asset/FunctionStatusTechnical Justification for Auditor
Physical Data CentresExcludedOrganisational reliance on 100% Cloud Infrastructure (AWS/Azure). Physical security is managed via the Cloud Provider’s SOC 2/ISO 27001 reports.
Software DevelopmentIncludedInternal engineering teams maintain proprietary source code. Annex A 8.25 (Secure Development) is mandatory.
Off-shore SupportExcludedSupport is outsourced to a third party with a distinct ISMS; interfaces are managed via Clause 4.2 supplier requirements.
ISO 27001 Toolkit Business Edition

Advance Guidance

Aligning ISO 27001, 9001 and 14001 Scope

This technical guide addresses the strategic alignment of an Integrated Management System (IMS). For organisations seeking multi-standard certification, aligning the ISO 27001 scope with ISO 9001 (Quality) and ISO 14001 (Environmental) is the most effective way to reduce documentation redundancy and audit fatigue.

Integrated Management Systems (IMS): Aligning ISO 27001, 9001, and 14001

Aligning your ISO 27001 scope with other ISO standards is facilitated by Annex SL, the high-level structure shared by all modern ISO management systems. By unifying your Clause 4.3 definitions, you can achieve a 25% reduction in total audit duration and ensure that your security objectives support your quality and environmental goals simultaneously.

RequirementISO 27001 (Security)ISO 9001 (Quality)ISO 14001 (Environment)
Strategic FocusProtecting Confidentiality, Integrity, and Availability of data.Ensuring consistent quality and customer satisfaction.Managing environmental impact and sustainability.
Scope BoundaryLogical and physical data boundaries; technical assets.Entire production lifecycle and service delivery.Physical site boundaries and waste streams.
Shared Clause 4.3Unified Approach: Define the “Organisational Boundary” once. If the ISO 27001 scope is a subset (e.g. just the IT Dept), explicitly justify this within the IMS Scope Statement.
Audit EvidenceStatement of Applicability (SoA).Quality Manual / Process Maps.Aspects and Impacts Register.

How to Align Multi-Standard Scopes in 5 Steps

  • Step 1: Harmonise Terminology . Action: Use standard Annex SL definitions for “Context,” “Interested Parties,” and “Risks” to ensure all three systems speak the same language. Result: Simplified documentation that is easier for leadership to review.
  • Step 2: Create a Unified Context Register . Action: Provision a single register that captures security, quality, and environmental issues in one SWOT/PESTLE analysis. Result: A holistic view of organisational risk that satisfies three auditors at once.
  • Step 3: Define Core Physical Boundaries . Action: Formalise the physical locations (offices/data centres) that apply to all standards. Result: Elimination of conflicting site descriptions between your Security and Environmental manuals.
  • Step 4: Map Interdependent Interfaces . Action: Identify where security controls (e.g. data destruction) overlap with environmental controls (e.g. e-waste recycling). Result: Technical efficiency where one operational process satisfies multiple ISO requirements.
  • Step 5: Conduct an Integrated Management Review . Action: Sign off the scope for all three standards in a single board-level meeting. Result: Documented evidence of top management accountability across the entire IMS.

Lead Auditor Tip: When auditing an IMS, I check if the ISO 27001 scope is nested within the ISO 9001 scope. If you certify your entire company for Quality but only one department for Security, your Scope Statement must clearly define that technical boundary to prevent a non-conformity regarding misleading certification.

ISO 27001 Scope Revision Trigger

ISO 27001 Clause 4.3 is not a ‘set and forget’ requirement. Auditors will verify if your scope was updated following these specific triggers:

  • Mergers & Acquisitions: Integrating a new business unit requires an immediate logical and physical boundary review.
  • AI Deployment: Adopting Generative AI models often moves your logical boundary into third-party LLM environments.
  • New Jurisdictions: Opening operations in a new country requires updating your Clause 4.2 Legal Register and physical scope.

Scoping for Regulated Industries

ISO 27001 certification is no longer exclusive to IT. Regulatory frameworks like NIS2 and DORA have made Clause 4.3 scoping a legal necessity for manufacturing, healthcare, and infrastructure sectors.

IndustryCritical Boundary PointRequired Audit Evidence
HealthcareElectronic Health Record (EHR) logical interfaces.Traceability of patient data flows (HIPAA/GDPR alignment).
ManufacturingDemarcation between IT and OT (Operational Tech).Network segregation diagrams showing the “Air Gap.”
Legal ServicesPrivileged Client Document access roles.RBAC (Role-Based Access Control) matrix for legal staff.

Lead Auditor Tip: For regulated industries, your Scope Statement must mirror your Legal Register. If you are subject to NIS2 but your scope only covers one office, you will likely face a Major Non-Conformity for “Inadequate Determination of Requirements.”

ISO 27001 Shadow IT Scoping Matrix

A major scoping risk in modern environments is the omission of Shadow IT, unauthorised SaaS applications used by staff outside of IT oversight. To satisfy Clause 4.3, your scope must encompass the Logical Data Flow, regardless of whether the software is officially sanctioned.

ScenarioIn-Scope?Annex A Applicability
Shadow AI ToolsYES. If business data is processed, it is logically in-scope.Mandatory: Annex A 5.10 (Acceptable Use).
In-Scope AssetsYES. The primary asset is within the ISMS boundary.Varies: Only controls identified in the Risk Assessment apply.

Lead Auditor Tip: Do not mistake ‘In-Scope’ for ‘Every control applies.’ Being in scope means the asset is part of the Management System. You then use your Statement of Applicability (SoA) to define exactly which security controls are necessary to protect it.

If It’s In-Scope, Does Every ISO 27001 Control Apply?

The short answer is No. There is a critical distinction between the ISMS Scope (the boundaries of your system) and the Statement of Applicability (SoA) (the specific security controls you choose to implement). Just because an asset is in-scope does not mean you must apply all 93 controls from Annex A to it.

The Scoping PhaseThe Risk PhaseThe Result (SoA)
Defining the Boundary
(Clause 4.3)
Assessing the Asset
(Clause 6.1.2)
Selecting the Control
(Clause 6.1.3)
“Is this laptop part of the certified product team?”“What risks face this laptop (Theft, Malware, Data Leak)?”“We will apply MFA and Encryption, but exclude Physical Perimeter controls.”
Outcome: In-ScopeOutcome: Risk Profile IdentifiedOutcome: Proportionate Security

3 Key Rules for Control Applicability:

  • Risk is the Driver: You only apply a control if your risk assessment identifies a threat that requires that specific mitigation.
  • Technical Relevance: If your scope is 100% cloud-based, “Annex A 7.4 Physical security monitoring” is Not Applicable because you have no physical perimeter to monitor.
  • Documented Justification: For every control you decide not to apply, you must provide a technical justification in your Statement of Applicability.

Lead Auditor Tip: Auditors don’t want to see you ‘over-controlling’ your environment. We look for Proportionate Security. If you claim every control applies to every asset, it tells me you haven’t actually performed a granular risk assessment. The Scope tells me where I can audit; the SoA tells me what I should find there.

Cloud-Native Scoping & Demarcation Points

In a cloud-first world, your ISMS scope is defined by Logical Demarcation Points rather than physical walls. Clause 4.3 (c) requires you to document the interfaces between your activities and those of your cloud provider. Failure to define these “hand-off” points is a primary reason for audit delays and increased certification costs.

Cloud ModelDemarcation Point (The Boundary)In-Scope for YOUR ISMS
SaaS (e.g. M365)The Application Identity / API LayerIncluded: User access, data classification, and backup configurations.
PaaS (e.g. Azure SQL)The Database Configuration / Network ACLsIncluded: Encryption settings, connectivity rules, and audit logging.
IaaS (e.g. AWS EC2)The Guest Operating System / Virtual SwitchIncluded: OS patching, firewall rules, and internal networking.

ISMS Scope vs. Audit Scope

People often ask: “Is my ISMS scope the same as my Audit scope?” BLUF: No. Your ISMS Scope is the internal management of all security risks, while the Audit Scope is the specific subset defined on your public certificate. Misaligning these leads to “Certificate Value Gaps” where customers don’t see the services they actually use listed on your ISO 27001 certificate.

Lead Auditor Tip: To prevent “Scope Creep” in cloud environments, use the Data Flow Rule. If your organisation controls the encryption keys or the user access list for a cloud service, that interface is In-Scope. If you assume the provider handles it all, you will fail Clause 4.3 during your Stage 1 audit.

Regulatory Scoping: NIS2, EU AI Act, and DORA

ISO 27001 Clause 4.3 must serve as the foundation for your regulatory compliance. An inaccurate scope doesn’t just fail an audit; it can leave you exposed to significant fines under NIS2 or the EU AI Act if critical logical boundaries are omitted.

Lead Auditor Tip: When I review a scope for an enterprise firm, I check if the Legal Register (Clause 4.2) matches the Physical Boundaries (Clause 4.3). If you operate in the EU but exclude your EU-based data processing from the scope, you are creating a massive liability gap that an auditor must report.

ISO 27001 Remote Workforce Scoping

A major scoping debate is the inclusion of home offices. BLUF: For most certifications, individual home offices are excluded from the physical scope, but the Endpoint Device is always logically in-scope.

Asset TypeScoping StatusReasoning
Home/Coworking WiFiExcludedOrganisational control ends at the VPN/Tunnel layer.
Company LaptopsIncludedContains in-scope data and is managed via MDM (Logical Boundary).
Head Office / HubIncludedPhysical site where ‘Top Management’ decisions are recorded.

FAQ

What is an ISO 27001 Scope Statement?

An ISO 27001 Scope Statement is a mandatory document that defines the physical, organisational, and logical boundaries of your Information Security Management System (ISMS). It explicitly states which assets, locations, and services are covered by your certification to ensure targeted and effective risk management.

What is the purpose of ISO 27001 Clause 4.3?

The purpose of Clause 4.3 is to ensure your ISMS boundaries are accurately defined based on your business context and stakeholder requirements. By accurately narrowing the scope, organisations can reduce implementation costs by up to 40% and focus resources on protecting their most critical data assets.

How do you determine the boundaries of the ISMS?

To determine ISMS boundaries effectively, you should follow a structured four-step process to ensure all technical dependencies are captured:

  • List Products and Services: Identify exactly what products and services your customers purchase from you.
  • Identify Stakeholder Expectations: Review customer contracts and Clause 4.2 requirements to identify mandatory security obligations.
  • Map Physical and Logical Boundaries: Define data centre locations, cloud environments (such as AWS, Azure, or GCP), and physical office sites.
  • Review and Approve: Ensure top management formally approves the documented scope to evidence leadership commitment for the audit.

Can you exclude parts of the business from the ISO 27001 scope?

Yes, you can exclude specific departments or locations, provided those exclusions do not affect the organisation’s ability or responsibility to provide information security. Every exclusion must be technically justified and clearly documented within the Statement of Applicability (SoA) to satisfy Stage 1 audit requirements.

How long does it take to define the ISMS scope?

Defining a robust ISMS scope typically takes between 4 and 8 hours for most SMEs when using the High Table ISO 27001 Toolkit. While the final document is often only 2 to 5 pages long, the underlying analysis of third-party interfaces and dependencies is critical for a successful certification.

Who is responsible for the ISO 27001 Scope Statement?

The Information Security Manager is usually responsible for drafting the scope, but Clause 5.1 mandates that Top Management remain accountable for its approval. Auditors require documented evidence, such as management review minutes, proving that leadership has verified the scope against current business objectives.

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top