Can we certify one product, team or location to ISO 27001?
Yes, an ISO/IEC 27001 certification scope can cover a defined part of an organisation. The boundary must reflect how that part works, the information it handles and the people, systems and services it depends on.
ISO 27001 certifies an information security management system (ISMS). A scope focused on a product or service is not the same as certification of the product itself, and it does not automatically cover the rest of the business.
What makes a narrower scope workable?
Start with the activity you want covered. Identify the organisation responsible for it, the information involved, where work happens and who supports delivery.
For example, a software service may depend on shared identity management, cloud hosting, support staff and suppliers. Those dependencies need to be understood and managed even when the proposed scope does not include every business activity. Drawing a boundary around one team does not remove its connections to the rest of the organisation.
What should we prepare for a quote?
Send a short description of:
- The product, service or activity you want covered.
- The teams, locations and remote workers involved.
- The systems, information and shared services it depends on.
- Relevant suppliers and outsourced activities.
- Any scope wording or certification requirements your customers expect.
This gives ACS a clearer starting point for discussing the proposed scope and audit work. Check that the eventual scope matches what your customers need, rather than assuming a narrower certificate will meet every requirement.
Discuss your proposed scope with ACS or request a quote.
