What it includes
The organisational units, locations, products and services, processes, information, technology and people inside the boundary, and the interfaces with what lies outside it, such as other departments, cloud providers and outsourced services. A typical SaaS company scopes the platform, the teams that build and run it, and supporting functions such as HR and IT.
How it is defined
ISO 27001 requires the scope to take into account the internal and external issues facing the organisation, the requirements of interested parties such as customers and regulators, and the dependencies on activities performed by others (clause 4.3). It must be available as documented information, and the auditor reviews it at stage 1.
Too narrow, too broad
A scope limited to a small team or a single office makes certification easier, but customers who read the certificate may find that the service they buy is not covered. A scope that tries to include everything from the start can stall the project. The right scope covers what customers and contracts actually care about, and it can grow over time.
How it connects
The scope frames the asset inventory, the risk assessment and the Statement of Applicability. Under the ENS, the equivalent is the set of information systems covered by the declaration or certification of conformity. Our article on what a certification audit actually tests explains how auditors check it.




