Your organisation is starting SOC 2. Someone proposes scoping it to the whole estate "to be safe". What is your advice?
Show the full answer Hide the answer
Scoping wide is not the safe option
Everything inside scope must meet the full control set and be evidenced continuously. Everything outside must be demonstrably unable to affect what is inside.
Scoping the whole estate means every legacy system, every departmental tool and every half-abandoned environment is now in the assessment — each needing access reviews, change control evidence, logging, vulnerability management and encryption. The programme becomes an estate-wide remediation exercise, and its likely outcome is either a delayed certification or a report with exceptions.
Scope to what customers are actually asking about
The systems that store, process or transmit customer data for the service being sold. That is usually a small fraction of the estate.
Then make the boundary demonstrable, which is where architecture is directly implicated: separate accounts or subscriptions, network isolation, distinct identity boundaries, separate pipelines. An assessor accepts a boundary they can see enforced; they do not accept an assertion.
The cost of getting this wrong in the other direction
A scope so narrow that it excludes something the service depends on produces a certificate that does not answer the customer's question. Customers increasingly read the scope statement, and a certification covering one component of the service is worse than none because it invites the follow-up question.
What to do now
Draw the boundary, then look honestly at what crosses it — shared identity, shared logging, shared CI, an administrator with access to both sides. Each crossing either brings the other system into scope or needs a control at the boundary.
Retrofitting that separation is the common and avoidable cost of a first certification, which is the argument for doing this analysis before the readiness work rather than during the audit.
The reusable outcome
The same separation serves security and blast radius, and the evidence pipeline built for the audit serves incident investigation and customer questionnaires. Framing it that way is what stops it being seen as pure compliance cost.