Certification Scope
What is Certification Scope?
The defined boundaries of what a certification covers, including the organizational units, processes, locations, and standards included.
Frameworks that govern certification scope
What the standards actually require on certification scope
Requirements naming certification scope across 3 standards, quoted from the control text.
The certification scope must include the whole organisation or a clearly defined sub set with documented network and trust boundaries, and the scope must be reaffirmed at each annual cycle.
CEP-SCP-01 · Scope Definition and Whole Organisation Boundary →Apply documented criteria for suspending, withdrawing or reducing ISMS certification scope.
27006-8.2 · Suspension, Withdrawal, Reduction →Providers shall conduct annual information security risk assessments covering assets within the certification scope, with risks treated through controls or formally accepted by management, and the risk register reviewed periodically.
CSAP-RIA-18 · Risk assessment and management →Questions people ask about certification scope
What is Certification Scope?
Why is Certification Scope important for compliance?
Which compliance frameworks address Certification Scope?
Where can I learn more about Certification Scope?
See how Certification Scope applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.