Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
AI Services
AI Services
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

Changing Your Scope AFTER ISO Certification

ISO Certifications

So you're ISO certified, but you want to make some changes to the scope of your certification, can you do it? Do you have to wait until the certification review three years down the road? In this video, we're going to talk about some of the considerations when clients or organizations want to make changes to the scope of their certification.

Hi, I'm Danny Manimbo, I'm a principal with Schellman and one of the co-directors of our ISO certification practices. So you want to make changes to the scope of your certification, but you're not sure how. We often get asked this question by our clients. Now that I'm certified, I want to add some products or some applications or services, or maybe even some different locations or sector-specific standards, such as 27017, 27018, or 27701 to the scope of my management system. But I'm just not sure how, are we able to do that now? Or do we have to wait three years during our recertification review and do it then?

The good news is you have multiple options when it comes to modifying or expanding the scope of your management system. You can do it during your scheduled annual surveillance or recertification review, whichever audit is coming next, and your certification term. Or you can do a one-off scope expansion review if you say don't want to wait another 12 or 6 months before your next scheduled audit. But what are the things you need to consider when modifying the scope of your ISMS? It depends on the actual change you're making to your management system, but generally, the things you want to look at are:

  • Your scope statement
  • Revisiting your risk assessment to consider those changes to your scope
  • Ensuring that your internal audit is also ensuring any of those changes to scope are being incorporated into the scope of your internal audit and that all of those things are being reported through your management review process.

This will give us confidence that your management system has been appropriately updated to reflect those changes in scope, and that will allow us following the completion of either that scope, expansion, your surveillance, or your recertification when that new scope was assessed to issue an updated certificate reflecting those changes.

So now that you understand how to incorporate changes to the scope of your management system, reach out through our website and we'd be happy to help. 

About DANNY MANIMBO

Danny Manimbo is a Principal with Schellman based in Denver, Colorado. As a member of Schellman’s West Coast / Mountain region management team, Danny is primarily responsible for leading Schellman's AI and ISO practices as well as the development and oversight of Schellman's attestation services. Danny has been with Schellman for 10 years and has over 13 years of experience in providing data security audit and compliance services.