[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:the-iso-27001-scope-statement-why-a-certificate-that-says-head-office-does-not-cover-your-saas-what-clause-4-3-asks-for-what-a-buyer-under-dora-checks-and-three-that-pass":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","the-iso-27001-scope-statement-why-a-certificate-that-says-head-office-does-not-cover-your-saas-what-clause-4-3-asks-for-what-a-buyer-under-dora-checks-and-three-that-pass","The ISO 27001 scope statement: why a certificate that says head office does not cover your SaaS, what clause 4.3 asks for, what a buyer under DORA checks, and three scope statements that pass","The scope statement is the certificate's limit, and buyers now read it against a regulation: a financial customer may rely on your ISO 27001 certificate instead of auditing you only if its scope covers the systems it depends on. What ISO\u002FIEC 27001:2022 clause 4.3 requires, what ISO\u002FIEC 17021-1 makes the certificate show, the surveillance cycle that decides whether it is current, the 2013-edition deadline that has passed, one scope statement that fails and three that pass for a software company, and how the interfaces to your cloud provider stay inside the scope while the provider stays outside.","2026-09-12",{"who":10,"when":11,"do":12},"A certified software company whose certificate names an office, a department or a legal entity rather than the product and the systems a customer depends on; the buyer under DORA reads the scope before anything else, and a scope that does not cover the service is a certificate that does not count.","The certificate is current only inside its three-year cycle, with a surveillance audit at least once a calendar year and the first within 12 months of the decision; a certificate to the 2013 edition has been void since 31 October 2025.","Rewrite the scope to name the product, the delivery model, the supporting functions, the locations including the cloud regions and the Statement of Applicability version, and put it to the certification body before the next surveillance audit.","\nA vendor sends its ISO 27001 certificate and the customer's security team reads one line of it: the scope. If that line says \"the information security management system of Example Ltd at its registered office\", the certificate has just told a buyer that the SaaS product running in a cloud region, operated by a team that works from home, may or may not be inside it. Since 15 July 2024 that reading has a regulatory basis for every financial customer: point (b) of Article 8(3) of Delegated Regulation (EU) 2024\u002F1773 lets a bank rely on a certification instead of auditing its vendor only where the scope of the certification covers the systems and key controls the bank has identified, and points (c) and (d) require the certificate to be current and to keep covering those systems in future versions. This article explains what the scope statement is, what the certificate must show, how a buyer reads both, and what a software company's scope should say. It is not legal advice and it is not the standard; the standard is the text to buy and read.\n\n## What clause 4.3 requires\n\nISO\u002FIEC 27001:2022 clause 4.3 requires the organisation to determine the boundaries and applicability of its information security management system to establish its scope, considering the external and internal issues of clause 4.1, the requirements of interested parties of clause 4.2, and the interfaces and dependencies between activities the organisation performs and activities performed by other organisations, and to keep the scope as documented information. Three things follow. The scope is the organisation's decision, not the auditor's: a certification body audits what the organisation has declared, and a narrow scope is a valid scope. The scope has to be written down and available, which is why a buyer may ask for the scope document and not just the certificate. And the third consideration, interfaces and dependencies, is the sentence that decides how a cloud-hosted product is described: the cloud provider is another organisation, its activities are outside the scope, and the interface to it is inside.\n\n## What the certificate shows\n\nISO\u002FIEC 17021-1, the standard accreditation bodies hold certification bodies to, requires the certification document to identify the client and the sites covered, the standard and its edition, the scope of the certification, the certification body, the dates of granting and of expiry, and a unique identification. Most certificates also name the accreditation body whose mark they carry and the version of the Statement of Applicability the audit was performed against. Two of those fields are the ones a buyer checks first. The edition: certificates to ISO\u002FIEC 27001:2013 are no longer valid, because the accredited transition to the 2022 edition ended on 31 October 2025, and a certificate that still cites 2013 is a certificate that lapsed. And the sites: a certificate lists the locations covered, and a product operated from a cloud region is not operated from any of them unless the scope says how.\n\n## How a buyer decides whether it is current\n\nAccredited certification runs on a three-year cycle. The certification body performs a surveillance audit at least once a calendar year, the first within 12 months of the certification decision, and a recertification audit before the certificate expires. A buyer who applies Article 8(3)(c) of the Delegated Regulation, or who simply does the job, asks for the date of the last surveillance audit and whether nonconformities are open, because a certificate is only as current as its last audit. The [certification bodies](\u002Fiso-27001\u002Fcertification-bodies) page lists the national accreditation register for each member state, where the buyer confirms that the certifier is accredited for ISO 27001 specifically; accreditation for ISO 9001 is not accreditation for ISO 27001, and a certifier in no national register is not accredited, whatever its website says.\n\n## One scope statement that fails, and three that pass\n\nThe one that fails: \"The information security management system of Example Ltd at 1 Example Street.\" It names no product, no service, no system and no location other than an office. A financial customer's policy cannot map it to the systems it depends on, so Article 8(3)(b) is not met, and the audit clause is used instead.\n\nThe three that pass are written for a software company and are illustrations, not templates; the certification body decides whether a scope is auditable.\n\nFirst, a single product operated from a cloud provider: \"The development, operation and support of the Example payroll platform, delivered as a multi-tenant SaaS from Example Cloud regions in the Union, including the customer support and incident response functions, performed by staff working from the Example Ltd office and remotely, in accordance with Statement of Applicability version 4.\" It names the product, the delivery model, the regions, the supporting functions, the people and the SoA version.\n\nSecond, a company with several products where only one is sold to regulated customers: \"The design, development, hosting and operation of the Example Ledger service for financial-sector customers, including the infrastructure it runs on at Example Cloud and the processes for change, incident, backup and supplier management that support it.\" The other products are outside the scope on purpose, and the statement says so by naming one.\n\nThird, a company whose product is installed by customers: \"The development, release and maintenance of the Example software product, including the build and release pipeline, the vulnerability handling process and the technical support service, at the Example Ltd offices in Dublin and Lisbon and remotely.\" Here the customer's own systems are outside the scope, so the scope names the pipeline and the support service the customer depends on.\n\n## Where the cloud provider goes\n\nA vendor cannot bring its cloud provider inside its own scope, and does not need to. Clause 4.3's third consideration puts the interface inside: the supplier relationship controls of Annex A, A.5.19 to A.5.21 (information security in supplier relationships, supplier agreements, the ICT supply chain), and the monitoring of supplier services, A.5.22, are the controls the scope statement points at when it says \"delivered from Example Cloud regions\". The provider's own certificate, its shared-responsibility documentation and the contract terms are the evidence those controls produce. That is also why the [register of information](\u002Fdora\u002Fregister-of-information) a financial customer files asks for the countries of storage and processing and for the subcontractor chain by rank: the customer maps the register's rows onto the scope statement's interfaces, and a scope that names the regions makes the mapping possible.\n\n## What to do before the next surveillance audit\n\nRewrite the scope so that it names the product, the delivery model, the supporting functions, the locations including the cloud regions, and the Statement of Applicability version, and put the rewritten scope to the certification body before the next surveillance audit, because a scope change is a change it evaluates. Publish the scope statement alongside the certificate rather than the certificate alone. Keep the last surveillance audit report ready to share under a non-disclosure agreement, because the [DORA due-diligence article](\u002Farticles\u002Fdora-vendor-due-diligence-rts-2024-1773-the-six-questions-the-five-sources-of-assurance-the-eight-conditions-for-relying-on-your-certificate-and-the-five-reports) shows that the certificate alone never satisfies the eight conditions. And treat the scope statement as the first document of the management system rather than the last line of the certificate: StandardOS keeps it next to the Statement of Applicability and the controls they name, versioned, so that the sentence on the certificate and the system behind it say the same thing. The [free page](\u002Fiso-27001\u002Fscope) writes the scope statement from twelve answers, the certificate sentence first. The [ISO 27001 hub](\u002Fiso-27001) holds the rest.\n",1789383984267]