Service
The two documents that quietly decide what your certification costs, how long it takes, and whether an auditor believes the rest of it.
The scope decides what your management system covers. The Statement of Applicability records which controls apply, why, and what you have actually done about them. Between them they set the size of your audit, the volume of documentation you maintain every year, and whether the whole thing reads as considered or assembled.
They are also, routinely, the two documents produced last and fastest, by adapting a template someone had lying around. An auditor reads them first, and reads everything else in their light.
A scope has to state which organisational units, locations, services and information systems are covered, and be explicit about what is left out and on what grounds. It has to name the interfaces and dependencies that cross the boundary, because that is where most of the real risk sits: cloud platforms, group IT, outsourced development, managed service providers.
Scoping fails in two directions. Too narrow, and you end up with a certificate that does not answer the question your customer asked, which is the expensive discovery of finding out at renewal that the service they care about was never inside the boundary. Too broad, and a small team is carrying an audit built for a large one, every year, forever.
The right scope is the smallest one that honestly covers what you need it to cover. Finding it is a business conversation before it is a technical one.
A credible Statement of Applicability accounts for all 93 Annex A controls of ISO/IEC 27001:2022 and, for each one, records whether it applies, the justification for including or excluding it, its implementation status, and where in your organisation it is actually realised. Where your risks call for controls beyond Annex A, those belong in it too.
The part that separates a real Statement of Applicability from a spreadsheet is traceability. Every inclusion should be traceable to something in your risk assessment or to an obligation you carry. The document is an output of your risk work, not a starting point for it. When it is produced first, the risk assessment gets quietly reverse-engineered to match, and an experienced auditor recognises that immediately.
Organisations at the start of an ISO 27001 project who want the foundation right, and organisations already certified who suspect their scope no longer matches what they sell. It is also a sensible standalone engagement when NIS2 is the driver and the certification route depends on the scope covering the regulated services.
If you already have a Statement of Applicability where every control is marked applicable and implemented, and nothing links back to a risk assessment, you have a list rather than a decision record. That is fixable, and it is worth fixing before an auditor makes it a finding.
Yes, provided the exclusion is justified and the boundary is genuinely controlled. What you cannot do is exclude something in order to hide a risk that reaches into the scope anyway. Auditors test exclusions precisely because that is where people hide things.
You can exclude a control that does not apply to you. You cannot exclude a control that does apply because implementing it is inconvenient. If the honest position is that you accept the risk instead, that is a legitimate decision, but it is recorded as an accepted risk with an owner, not as an exclusion.
Often, yes. The usual tell is that everything is applicable, everything is implemented, and no line traces back to a risk. It passes a glance and fails a conversation, because an auditor only has to ask why one particular control is there.
Considerably. If you are using ISO 27001 as your route to demonstrating conformity, the scope has to cover the regulated services, and your Statement of Applicability has to show measures equivalent to the CyberFundamentals level that applies to you. A certificate whose scope excludes the regulated activity does not answer the question the supervisor is asking.
For a typical SME, one to two weeks of focused work, including the conversations needed to settle the boundary. Measured against what an ill-chosen scope costs over a three-year certification cycle, it is the cheapest week in the project.
Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.
Request an intro call