ServiceNow publishes its certifications and audit reports through its Trust Portal, and for NIS2, DORA, ISO 27001 and GDPR due diligence that portal is your primary evidence source for the vendor half of the assessment. What it gives you is ServiceNow's posture as a provider — not your instance's configuration, which remains entirely yours under the shared responsibility model. Auditors ask for both, and the portal answers only one of the two questions.
What This Is
ServiceNow operates the Trust Portal at trust.servicenow.com as the centralized source for its security posture, compliance certifications, and operational transparency. For organizations using ServiceNow as a critical ICT platform, this portal is the primary evidence source for third-party vendor due diligence required by NIS2, DORA, ISO 27001, and GDPR.
This article consolidates ServiceNow's vendor security posture — certifications held, security architecture, data protection controls, availability commitments, and vulnerability disclosure practices — into an auditor-ready reference that maps directly to regulatory requirements.
Why This Matters
ServiceNow is classified as a critical ICT third-party service provider under DORA and a key element of supply chain security under NIS2 Art.21§2(d). Regulators expect organizations to:
- Document the vendor's security posture and certifications
- Verify that vendor controls align with regulatory requirements
- Monitor the vendor's security practices on an ongoing basis
- Maintain evidence that due diligence was performed
Failing to assess ServiceNow as a third-party provider is a direct compliance gap under DORA Art.28 and NIS2 Art.21§2(d).
1. Certifications and Attestations
ServiceNow is reviewed annually by independent third-party auditors. The following certifications and attestations are maintained:
Information Security Management
| Certification | Scope | Held Since | Standard | Regulatory Mapping |
|---|---|---|---|---|
| ISO/IEC 27001:2022 | Information Security Management System (ISMS) | 2012 | Security management best practices and controls based on ISO/IEC 27002 | NIS2 §2(a), DORA Art.5, ISO A.5.1 |
| ISO/IEC 27017:2015 | Cloud-Specific Information Security Controls | 2018 | Cloud security implementation guidance extending 27001 | DORA Art.28, ISO A.5.23 |
| ISO/IEC 27018:2019 | PII Protection in Public Cloud | 2016 | Protection of personally identifiable information in cloud | GDPR Art.28, GDPR Art.32 |
| ISO/IEC 27701 | Privacy Information Management System (PIMS) | 2020 | Extension of 27001/27002 for privacy, PII processor requirements | GDPR Art.25, NIS2 §2(h) |
Quality, Continuity, and AI Governance
| Certification | Scope | Standard | Regulatory Mapping |
|---|---|---|---|
| ISO 9001 | Quality Management System | Organizational quality processes | General governance |
| ISO 22301:2019 | Business Continuity Management | Resilience and continuity of operations | NIS2 §2(c), DORA Art.11 |
| ISO/IEC 42001 | AI Management System | Responsible AI governance, transparency, and risk management | EU AI Act, DORA Art.5 |
Audit Reports and Attestations
| Report | Type | Audit Cycle | Regulatory Mapping |
|---|---|---|---|
| SOC 1 Type II | Financial controls over IT | Annual (SSAE 18) | DORA Art.28 (financial entities) |
| SOC 2 Type II | Security, availability, confidentiality, processing integrity, privacy | Annual (AICPA Trust Services Criteria) | DORA Art.28, NIS2 §2(d), ISO A.5.19-A.5.23 |
| C5 Attestation | BSI Cloud Computing Compliance Criteria Catalogue | Annual | NIS2 (German/EU customers), BSI requirements |
| CSA STAR Level 2 | Cloud Controls Matrix assessment against ISO 27001 | Annual | DORA Art.28 cloud vendor evidence |
Government and Sector-Specific
| Authorization | Scope | Regulatory Mapping |
|---|---|---|
| FedRAMP | US Federal Risk and Authorization Management Program | US federal cloud security requirements |
| DoD IL4 | US Department of Defense Impact Level 4 | Controlled Unclassified Information (CUI) |
| DoD IL5 | US Department of Defense Impact Level 5 | Higher sensitivity CUI and National Security Systems |
| IRAP | Australian Information Security Registered Assessors Program | Australian government cloud requirements |
| ISMAP | Information System Security Management and Assessment Program | Japanese government cloud procurement |
How to Access Audit Reports
SOC 1, SOC 2 Type II, ISO certificates, C5 attestation reports, and bridge letters are available through the CORE Compliance Portal on support.servicenow.com. Access must be requested through the ServiceNow account team.
| Document | Where to Request | Bridge Letter Coverage |
|---|---|---|
| SOC 2 Type II Report | CORE portal | Oct 1 - Dec 31 bridge letter available by end of Q1 following year |
| SOC 1 Type II Report | CORE portal | Same cycle as SOC 2 |
| ISO Certificates | CORE portal or Trust Portal | N/A — certificate validity period |
| C5 Attestation | CORE portal | Aligned with SOC 2 cycle |
2. Security Architecture
Multi-Instance Architecture
ServiceNow operates as a private enterprise cloud with a multi-instance architecture delivering logical single tenancy. Each customer's data is isolated from all other customers — this is not shared multi-tenant with logical separation but dedicated compute with isolated databases.
Encryption
Important: Encryption at rest is not included by default. ServiceNow enforces encryption in transit for all instances, but encryption at rest requires purchasing one of the Platform Encryption options. Without it, customer data is stored unencrypted on ServiceNow-managed infrastructure.
| Control | Implementation | Included by Default | Standard |
|---|---|---|---|
| Encryption in transit | TLS 1.2 minimum enforced for all inbound sessions; HTTP automatically redirected to HTTPS | Yes — all instances | NIST SP 800-52 |
| Platform Encryption | AES-256-XTS with 512-bit key stored on instance, customer-controlled key management | No — purchased separately | FIPS 140-2 Level 3 |
| Cloud Encryption (BYOK) | Volume-based encryption at rest with FIPS 140-2 Level 3 validated HSMs; Bring Your Own Key capability | No — purchased separately | NIST SP 800-57 |
| Field-level encryption | AES-128 or AES-256 symmetric encryption for individual fields via Edge Encryption or Encryption Starter plugin | No — purchased separately (Edge Encryption) or limited free tier (Encryption Starter) | Application-level |
Compliance risk: If your organization has not purchased Platform Encryption or Cloud Encryption, data at rest in your ServiceNow instance is not encrypted. This is a common gap for GDPR Art.32§1(a) ("encryption of personal data"), NIS2 Art.21§2(h) ("policies on cryptography and encryption"), and DORA Art.9§4(c). Verify your licensing includes encryption before claiming compliance.
Access Controls
| Control | Description |
|---|---|
| Zero-trust access | Policy-based approach — no implicit trust, continuous verification of every access request aligned with NIST 800-207 |
| Network security | Firewalls, secure logical access controls, intrusion detection systems |
| Vulnerability monitoring | Continuous monitoring for vulnerabilities and malicious activity |
Data Center Infrastructure
| Feature | Description |
|---|---|
| Paired data centers | Data center pairs for redundancy with near-instant failover |
| Regional storage | Customer data stored in designated geographic regions |
| On-site backups | Backups maintained to ensure data availability |
| Physical security | Data center access controls, surveillance, environmental protections |
3. Data Protection and Privacy
Data Processing
| Aspect | Detail | Evidence Document |
|---|---|---|
| Role | ServiceNow acts as data processor on behalf of the customer (data controller) | Data Processing Addendum (DPA) |
| Processing scope | Defined in customer's DPA — covers data categories, processing purposes, subprocessor list | DPA (request from account team) |
| Data residency | Customer selects hosting region at provisioning; data remains in selected region | Trust FAQ |
| Subprocessors | Maintained list of subprocessors with notification of changes | DPA, Trust Portal |
| Data Security Addendum (DSA) | Technical, physical, and organizational security measures for customer data protection | DSA (request from account team) |
Privacy Compliance
| Regulation | ServiceNow Posture | Evidence |
|---|---|---|
| GDPR | DPA covers Art.28 processor obligations, Art.32 security measures, Art.33 breach notification | DPA, ISO 27701 certificate |
| GDPR Art.25 | Privacy by design supported through platform configuration, data classification, access controls | ISO 27701, platform security features |
| GDPR Art.32 | Technical and organizational measures documented in DSA | DSA, SOC 2 Type II |
4. Availability and Business Continuity
Advanced High Availability (AHA)
ServiceNow's architecture provides:
- Paired data center failover — near-instant failover between data center pairs
- Regional redundancy — customer instances backed by geographically distributed infrastructure
- On-site and off-site backups — ensuring data recovery in disaster scenarios
- Disaster recovery procedures — documented and tested as part of ISO 22301 certification
Monitoring and Incident Communication
| Channel | URL | Purpose |
|---|---|---|
| Trust Portal Status | https://trust.servicenow.com/home | Real-time platform status and availability |
| Notifications | https://trust.servicenow.com/notifications | CVE publications, maintenance windows, incidents |
| Responsible Disclosure | disclosure@servicenow.com | Report security vulnerabilities in ServiceNow properties |
5. Vulnerability Disclosure and CVE Process
Responsible Disclosure Program
ServiceNow maintains a responsible disclosure program. Security researchers should:
- Report vulnerabilities to disclosure@servicenow.com
- Provide sufficient detail to reproduce the issue, including proof of concept
- Allow reasonable time for remediation before public disclosure
CVE Notification Process
| Step | Action | Timeline |
|---|---|---|
| 1 | Vulnerability reported or discovered internally | — |
| 2 | ServiceNow develops and tests security patch | Varies by severity |
| 3 | Patch deployed to hosted instances automatically | Priority deployment for Critical/High |
| 4 | Patches shared with partners and self-hosted customers | Concurrent with hosted deployment |
| 5 | Security advisory published on Now Support | After patch deployment |
| 6 | CVE notification on Trust Portal | https://trust.servicenow.com/notifications/?type=cve_publication |
CVE Advisory Resources
| Resource | URL |
|---|---|
| CVE Advisory Landing Page | https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1226057 |
| Trust Portal CVE Notifications | https://trust.servicenow.com/notifications/?type=cve_publication |
| Responsible Disclosure Policy | https://www.servicenow.com/company/trust/privacy/responsible-disclosure.html |
For details on specific ServiceNow CVEs and their impact, see KB articles: Jelly Template Injection RCE Chain (CVE-2024-4879, CVE-2024-5178, CVE-2024-5217) (CVE-2024-4879), BodySnatcher: Virtual Agent Impersonation (CVE-2025-12420) (CVE-2025-12420 BodySnatcher), Count(er) Strike: Data Inference via ACL Count Leakage (CVE-2025-3648) (CVE-2025-3648), Reflected XSS in ServiceNow AI Platform (CVE-2025-11449, CVE-2025-11450) (Reflected XSS), Remote Code Execution in ServiceNow AI Platform Sandbox (CVE-2026-0542) (CVE-2026-0542 AI Platform Sandbox RCE).
6. Regulatory Evidence Mapping
How to Use This for Compliance Audits
| Regulation | Requirement | ServiceNow Evidence | Where to Find |
|---|---|---|---|
| NIS2 Art.21§2(d) | Supply chain security — assess third-party ICT providers | SOC 2 Type II, ISO 27001, vendor risk assessment using Trust Portal | CORE portal, Trust Portal |
| DORA Art.28 | ICT third-party risk — due diligence on critical providers | SOC 2 Type II, SOC 1 Type II, ISO certificates, C5 attestation, CSA STAR | CORE portal |
| DORA Art.29 | Contractual arrangements with ICT third-party providers | DPA, DSA, SLA documentation | Account team |
| ISO A.5.19 | Information security in supplier relationships | ISO 27001 certificate, SOC 2 report | CORE portal |
| ISO A.5.20 | Addressing security within supplier agreements | DPA, DSA | Account team |
| ISO A.5.21 | Managing security in the ICT supply chain | CSA STAR, C5 attestation, subprocessor list | CORE portal, DPA |
| ISO A.5.22 | Monitoring, review, and change management of supplier services | Trust Portal status, CVE notifications, annual audit reports | Trust Portal |
| ISO A.5.23 | Information security for use of cloud services | ISO 27017, ISO 27018, SOC 2 Type II | CORE portal |
| GDPR Art.28 | Processor obligations | DPA, ISO 27701, SOC 2 Type II | Account team, CORE portal |
| GDPR Art.32 | Security of processing | DSA, ISO 27001, SOC 2 Type II | Account team, CORE portal |
Detection Script — Vendor Evidence Documentation Check
/*
* COMP-004: ServiceNow Trust Portal Evidence Audit
* Checks whether vendor due diligence documentation is tracked in the instance
*
* Run in: ServiceNow instance → System Definition → Scripts - Background
* Role required: admin
* Impact: Read-only, safe for production
*/
gs.info('=== COMP-004: VENDOR SECURITY EVIDENCE AUDIT ===');
gs.info('');
var gaps = [];
var findings = [];
// Check if GRC/Vendor Risk module is active
var grcPlugin = new GlideRecord('v_plugin');
grcPlugin.addQuery('id', 'com.snc.governance_risk_compliance');
grcPlugin.query();
var grcActive = grcPlugin.next() && (grcPlugin.getValue('active') === 'active' || grcPlugin.getValue('active') === '1');
if (grcActive) {
findings.push('GRC module is active — vendor risk management available');
// Check for ServiceNow vendor profile
var vendor = new GlideRecord('core_company');
vendor.addEncodedQuery('nameLIKEServiceNow^ORnameLIKEservicenow');
vendor.query();
if (vendor.next()) {
findings.push('ServiceNow vendor profile exists: ' + vendor.getValue('name'));
// Check for associated risk assessments
var assess = new GlideRecord('sn_risk_assessment');
if (assess.isValid()) {
assess.addQuery('entity', vendor.getUniqueValue());
assess.query();
if (assess.getRowCount() > 0) {
findings.push('Risk assessment records found for ServiceNow: ' + assess.getRowCount());
} else {
gaps.push('DORA Art.28: No risk assessment records for ServiceNow vendor profile');
}
}
} else {
gaps.push('DORA Art.28: No ServiceNow vendor profile in core_company — create one for third-party tracking');
}
} else {
findings.push('GRC module not active — vendor risk tracked externally');
gaps.push('Consider: GRC module enables structured vendor risk management for DORA Art.28 compliance');
}
// Check for ServiceNow connection (indicates active vendor relationship tracking)
var snConn = new GlideRecord('sn_connection');
if (snConn.isValid()) {
snConn.query();
findings.push('ServiceNow connection records: ' + snConn.getRowCount());
}
// Check knowledge base for vendor security documentation
var kb = new GlideRecord('kb_knowledge');
kb.addEncodedQuery('short_descriptionLIKEServiceNow trust^ORshort_descriptionLIKEvendor security^ORshort_descriptionLIKESOC 2^ORshort_descriptionLIKEISO 27001 ServiceNow');
kb.addQuery('workflow_state', 'published');
kb.query();
if (kb.getRowCount() > 0) {
findings.push('Vendor security KB articles found: ' + kb.getRowCount());
} else {
gaps.push('NIS2 §2(d): No published KB articles documenting ServiceNow vendor security posture');
}
// Output
gs.info('FINDINGS:');
for (var f = 0; f < findings.length; f++) {
gs.info(' [INFO] ' + findings[f]);
}
gs.info('');
gs.info('GAPS (' + gaps.length + '):');
for (var g = 0; g < gaps.length; g++) {
gs.info(' [GAP] ' + gaps[g]);
}
gs.info('');
gs.info('--- Manual Verification Required ---');
gs.info('1. Confirm SOC 2 Type II report obtained from CORE portal (support.servicenow.com)');
gs.info('2. Confirm ISO 27001 certificate on file from trust.servicenow.com/certifications');
gs.info('3. Confirm DPA/DSA executed with ServiceNow account team');
gs.info('4. Verify Trust Portal notifications are monitored: trust.servicenow.com/notifications');
gs.info('5. Confirm CVE advisory process is documented: support.servicenow.com/kb (KB1226057)');
Remediation — Closing Vendor Due Diligence Gaps
| Priority | Gap | Action | Evidence Produced |
|---|---|---|---|
| 1 | No SOC 2 Type II on file | Request from CORE Compliance Portal via account team | Audit report for DORA Art.28 |
| 2 | No DPA/DSA executed | Engage ServiceNow account team for current DPA and DSA | Contractual evidence for GDPR Art.28, DORA Art.29 |
| 3 | No vendor risk assessment | Create vendor profile in GRC module or document assessment externally | Risk assessment for NIS2 §2(d) |
| 4 | Trust Portal not monitored | Subscribe to CVE notifications at trust.servicenow.com/notifications | Ongoing monitoring for ISO A.5.22 |
| 5 | No internal KB documentation | Create internal article documenting ServiceNow's certifications and security posture | Awareness evidence for auditors |
Expert Notes
Auditor tip: The most common DORA Art.28 gap is not lacking the SOC 2 report, but lacking evidence that someone reviewed it and documented findings. Create an internal review memo for each annual SOC 2 report cycle.
Bridge letter gap: SOC 2 Type II reports typically cover Jan 1 - Sep 30. The Oct 1 - Dec 31 bridge letter is available by end of Q1 the following year. Plan audit schedules around this gap.
Self-hosted customers: If running ServiceNow on your own infrastructure (rare but possible), the shared responsibility model shifts significantly. ServiceNow's certifications cover the platform software, but infrastructure security (physical, network, backup) becomes your responsibility. This changes the evidence requirements for DORA Art.28 and NIS2 §2(d).