← All security articles
HIGHAll

ServiceNow Trust Portal — Vendor Security Posture and Certification Evidence

Domain 6: Regulatory Compliance·

ServiceNow publishes its certifications and audit reports through its Trust Portal, and for NIS2, DORA, ISO 27001 and GDPR due diligence that portal is your primary evidence source for the vendor half of the assessment. What it gives you is ServiceNow's posture as a provider — not your instance's configuration, which remains entirely yours under the shared responsibility model. Auditors ask for both, and the portal answers only one of the two questions.

What This Is

ServiceNow operates the Trust Portal at trust.servicenow.com as the centralized source for its security posture, compliance certifications, and operational transparency. For organizations using ServiceNow as a critical ICT platform, this portal is the primary evidence source for third-party vendor due diligence required by NIS2, DORA, ISO 27001, and GDPR.

This article consolidates ServiceNow's vendor security posture — certifications held, security architecture, data protection controls, availability commitments, and vulnerability disclosure practices — into an auditor-ready reference that maps directly to regulatory requirements.

Why This Matters

ServiceNow is classified as a critical ICT third-party service provider under DORA and a key element of supply chain security under NIS2 Art.21§2(d). Regulators expect organizations to:

  1. Document the vendor's security posture and certifications
  2. Verify that vendor controls align with regulatory requirements
  3. Monitor the vendor's security practices on an ongoing basis
  4. Maintain evidence that due diligence was performed

Failing to assess ServiceNow as a third-party provider is a direct compliance gap under DORA Art.28 and NIS2 Art.21§2(d).


1. Certifications and Attestations

ServiceNow is reviewed annually by independent third-party auditors. The following certifications and attestations are maintained:

Information Security Management

Certification Scope Held Since Standard Regulatory Mapping
ISO/IEC 27001:2022 Information Security Management System (ISMS) 2012 Security management best practices and controls based on ISO/IEC 27002 NIS2 §2(a), DORA Art.5, ISO A.5.1
ISO/IEC 27017:2015 Cloud-Specific Information Security Controls 2018 Cloud security implementation guidance extending 27001 DORA Art.28, ISO A.5.23
ISO/IEC 27018:2019 PII Protection in Public Cloud 2016 Protection of personally identifiable information in cloud GDPR Art.28, GDPR Art.32
ISO/IEC 27701 Privacy Information Management System (PIMS) 2020 Extension of 27001/27002 for privacy, PII processor requirements GDPR Art.25, NIS2 §2(h)

Quality, Continuity, and AI Governance

Certification Scope Standard Regulatory Mapping
ISO 9001 Quality Management System Organizational quality processes General governance
ISO 22301:2019 Business Continuity Management Resilience and continuity of operations NIS2 §2(c), DORA Art.11
ISO/IEC 42001 AI Management System Responsible AI governance, transparency, and risk management EU AI Act, DORA Art.5

Audit Reports and Attestations

Report Type Audit Cycle Regulatory Mapping
SOC 1 Type II Financial controls over IT Annual (SSAE 18) DORA Art.28 (financial entities)
SOC 2 Type II Security, availability, confidentiality, processing integrity, privacy Annual (AICPA Trust Services Criteria) DORA Art.28, NIS2 §2(d), ISO A.5.19-A.5.23
C5 Attestation BSI Cloud Computing Compliance Criteria Catalogue Annual NIS2 (German/EU customers), BSI requirements
CSA STAR Level 2 Cloud Controls Matrix assessment against ISO 27001 Annual DORA Art.28 cloud vendor evidence

Government and Sector-Specific

Authorization Scope Regulatory Mapping
FedRAMP US Federal Risk and Authorization Management Program US federal cloud security requirements
DoD IL4 US Department of Defense Impact Level 4 Controlled Unclassified Information (CUI)
DoD IL5 US Department of Defense Impact Level 5 Higher sensitivity CUI and National Security Systems
IRAP Australian Information Security Registered Assessors Program Australian government cloud requirements
ISMAP Information System Security Management and Assessment Program Japanese government cloud procurement

How to Access Audit Reports

SOC 1, SOC 2 Type II, ISO certificates, C5 attestation reports, and bridge letters are available through the CORE Compliance Portal on support.servicenow.com. Access must be requested through the ServiceNow account team.

Document Where to Request Bridge Letter Coverage
SOC 2 Type II Report CORE portal Oct 1 - Dec 31 bridge letter available by end of Q1 following year
SOC 1 Type II Report CORE portal Same cycle as SOC 2
ISO Certificates CORE portal or Trust Portal N/A — certificate validity period
C5 Attestation CORE portal Aligned with SOC 2 cycle

2. Security Architecture

Multi-Instance Architecture

ServiceNow operates as a private enterprise cloud with a multi-instance architecture delivering logical single tenancy. Each customer's data is isolated from all other customers — this is not shared multi-tenant with logical separation but dedicated compute with isolated databases.

Encryption

Important: Encryption at rest is not included by default. ServiceNow enforces encryption in transit for all instances, but encryption at rest requires purchasing one of the Platform Encryption options. Without it, customer data is stored unencrypted on ServiceNow-managed infrastructure.

Control Implementation Included by Default Standard
Encryption in transit TLS 1.2 minimum enforced for all inbound sessions; HTTP automatically redirected to HTTPS Yes — all instances NIST SP 800-52
Platform Encryption AES-256-XTS with 512-bit key stored on instance, customer-controlled key management No — purchased separately FIPS 140-2 Level 3
Cloud Encryption (BYOK) Volume-based encryption at rest with FIPS 140-2 Level 3 validated HSMs; Bring Your Own Key capability No — purchased separately NIST SP 800-57
Field-level encryption AES-128 or AES-256 symmetric encryption for individual fields via Edge Encryption or Encryption Starter plugin No — purchased separately (Edge Encryption) or limited free tier (Encryption Starter) Application-level

Compliance risk: If your organization has not purchased Platform Encryption or Cloud Encryption, data at rest in your ServiceNow instance is not encrypted. This is a common gap for GDPR Art.32§1(a) ("encryption of personal data"), NIS2 Art.21§2(h) ("policies on cryptography and encryption"), and DORA Art.9§4(c). Verify your licensing includes encryption before claiming compliance.

Access Controls

Control Description
Zero-trust access Policy-based approach — no implicit trust, continuous verification of every access request aligned with NIST 800-207
Network security Firewalls, secure logical access controls, intrusion detection systems
Vulnerability monitoring Continuous monitoring for vulnerabilities and malicious activity

Data Center Infrastructure

Feature Description
Paired data centers Data center pairs for redundancy with near-instant failover
Regional storage Customer data stored in designated geographic regions
On-site backups Backups maintained to ensure data availability
Physical security Data center access controls, surveillance, environmental protections

3. Data Protection and Privacy

Data Processing

Aspect Detail Evidence Document
Role ServiceNow acts as data processor on behalf of the customer (data controller) Data Processing Addendum (DPA)
Processing scope Defined in customer's DPA — covers data categories, processing purposes, subprocessor list DPA (request from account team)
Data residency Customer selects hosting region at provisioning; data remains in selected region Trust FAQ
Subprocessors Maintained list of subprocessors with notification of changes DPA, Trust Portal
Data Security Addendum (DSA) Technical, physical, and organizational security measures for customer data protection DSA (request from account team)

Privacy Compliance

Regulation ServiceNow Posture Evidence
GDPR DPA covers Art.28 processor obligations, Art.32 security measures, Art.33 breach notification DPA, ISO 27701 certificate
GDPR Art.25 Privacy by design supported through platform configuration, data classification, access controls ISO 27701, platform security features
GDPR Art.32 Technical and organizational measures documented in DSA DSA, SOC 2 Type II

4. Availability and Business Continuity

Advanced High Availability (AHA)

ServiceNow's architecture provides:

Monitoring and Incident Communication

Channel URL Purpose
Trust Portal Status https://trust.servicenow.com/home Real-time platform status and availability
Notifications https://trust.servicenow.com/notifications CVE publications, maintenance windows, incidents
Responsible Disclosure disclosure@servicenow.com Report security vulnerabilities in ServiceNow properties

5. Vulnerability Disclosure and CVE Process

Responsible Disclosure Program

ServiceNow maintains a responsible disclosure program. Security researchers should:

  1. Report vulnerabilities to disclosure@servicenow.com
  2. Provide sufficient detail to reproduce the issue, including proof of concept
  3. Allow reasonable time for remediation before public disclosure

CVE Notification Process

Step Action Timeline
1 Vulnerability reported or discovered internally
2 ServiceNow develops and tests security patch Varies by severity
3 Patch deployed to hosted instances automatically Priority deployment for Critical/High
4 Patches shared with partners and self-hosted customers Concurrent with hosted deployment
5 Security advisory published on Now Support After patch deployment
6 CVE notification on Trust Portal https://trust.servicenow.com/notifications/?type=cve_publication

CVE Advisory Resources

Resource URL
CVE Advisory Landing Page https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1226057
Trust Portal CVE Notifications https://trust.servicenow.com/notifications/?type=cve_publication
Responsible Disclosure Policy https://www.servicenow.com/company/trust/privacy/responsible-disclosure.html

For details on specific ServiceNow CVEs and their impact, see KB articles: Jelly Template Injection RCE Chain (CVE-2024-4879, CVE-2024-5178, CVE-2024-5217) (CVE-2024-4879), BodySnatcher: Virtual Agent Impersonation (CVE-2025-12420) (CVE-2025-12420 BodySnatcher), Count(er) Strike: Data Inference via ACL Count Leakage (CVE-2025-3648) (CVE-2025-3648), Reflected XSS in ServiceNow AI Platform (CVE-2025-11449, CVE-2025-11450) (Reflected XSS), Remote Code Execution in ServiceNow AI Platform Sandbox (CVE-2026-0542) (CVE-2026-0542 AI Platform Sandbox RCE).


6. Regulatory Evidence Mapping

How to Use This for Compliance Audits

Regulation Requirement ServiceNow Evidence Where to Find
NIS2 Art.21§2(d) Supply chain security — assess third-party ICT providers SOC 2 Type II, ISO 27001, vendor risk assessment using Trust Portal CORE portal, Trust Portal
DORA Art.28 ICT third-party risk — due diligence on critical providers SOC 2 Type II, SOC 1 Type II, ISO certificates, C5 attestation, CSA STAR CORE portal
DORA Art.29 Contractual arrangements with ICT third-party providers DPA, DSA, SLA documentation Account team
ISO A.5.19 Information security in supplier relationships ISO 27001 certificate, SOC 2 report CORE portal
ISO A.5.20 Addressing security within supplier agreements DPA, DSA Account team
ISO A.5.21 Managing security in the ICT supply chain CSA STAR, C5 attestation, subprocessor list CORE portal, DPA
ISO A.5.22 Monitoring, review, and change management of supplier services Trust Portal status, CVE notifications, annual audit reports Trust Portal
ISO A.5.23 Information security for use of cloud services ISO 27017, ISO 27018, SOC 2 Type II CORE portal
GDPR Art.28 Processor obligations DPA, ISO 27701, SOC 2 Type II Account team, CORE portal
GDPR Art.32 Security of processing DSA, ISO 27001, SOC 2 Type II Account team, CORE portal

Detection Script — Vendor Evidence Documentation Check

/*
 * COMP-004: ServiceNow Trust Portal Evidence Audit
 * Checks whether vendor due diligence documentation is tracked in the instance
 *
 * Run in: ServiceNow instance → System Definition → Scripts - Background
 * Role required: admin
 * Impact: Read-only, safe for production
 */

gs.info('=== COMP-004: VENDOR SECURITY EVIDENCE AUDIT ===');
gs.info('');

var gaps = [];
var findings = [];

// Check if GRC/Vendor Risk module is active
var grcPlugin = new GlideRecord('v_plugin');
grcPlugin.addQuery('id', 'com.snc.governance_risk_compliance');
grcPlugin.query();
var grcActive = grcPlugin.next() && (grcPlugin.getValue('active') === 'active' || grcPlugin.getValue('active') === '1');

if (grcActive) {
    findings.push('GRC module is active — vendor risk management available');

    // Check for ServiceNow vendor profile
    var vendor = new GlideRecord('core_company');
    vendor.addEncodedQuery('nameLIKEServiceNow^ORnameLIKEservicenow');
    vendor.query();
    if (vendor.next()) {
        findings.push('ServiceNow vendor profile exists: ' + vendor.getValue('name'));

        // Check for associated risk assessments
        var assess = new GlideRecord('sn_risk_assessment');
        if (assess.isValid()) {
            assess.addQuery('entity', vendor.getUniqueValue());
            assess.query();
            if (assess.getRowCount() > 0) {
                findings.push('Risk assessment records found for ServiceNow: ' + assess.getRowCount());
            } else {
                gaps.push('DORA Art.28: No risk assessment records for ServiceNow vendor profile');
            }
        }
    } else {
        gaps.push('DORA Art.28: No ServiceNow vendor profile in core_company — create one for third-party tracking');
    }
} else {
    findings.push('GRC module not active — vendor risk tracked externally');
    gaps.push('Consider: GRC module enables structured vendor risk management for DORA Art.28 compliance');
}

// Check for ServiceNow connection (indicates active vendor relationship tracking)
var snConn = new GlideRecord('sn_connection');
if (snConn.isValid()) {
    snConn.query();
    findings.push('ServiceNow connection records: ' + snConn.getRowCount());
}

// Check knowledge base for vendor security documentation
var kb = new GlideRecord('kb_knowledge');
kb.addEncodedQuery('short_descriptionLIKEServiceNow trust^ORshort_descriptionLIKEvendor security^ORshort_descriptionLIKESOC 2^ORshort_descriptionLIKEISO 27001 ServiceNow');
kb.addQuery('workflow_state', 'published');
kb.query();
if (kb.getRowCount() > 0) {
    findings.push('Vendor security KB articles found: ' + kb.getRowCount());
} else {
    gaps.push('NIS2 §2(d): No published KB articles documenting ServiceNow vendor security posture');
}

// Output
gs.info('FINDINGS:');
for (var f = 0; f < findings.length; f++) {
    gs.info('  [INFO] ' + findings[f]);
}
gs.info('');
gs.info('GAPS (' + gaps.length + '):');
for (var g = 0; g < gaps.length; g++) {
    gs.info('  [GAP] ' + gaps[g]);
}

gs.info('');
gs.info('--- Manual Verification Required ---');
gs.info('1. Confirm SOC 2 Type II report obtained from CORE portal (support.servicenow.com)');
gs.info('2. Confirm ISO 27001 certificate on file from trust.servicenow.com/certifications');
gs.info('3. Confirm DPA/DSA executed with ServiceNow account team');
gs.info('4. Verify Trust Portal notifications are monitored: trust.servicenow.com/notifications');
gs.info('5. Confirm CVE advisory process is documented: support.servicenow.com/kb (KB1226057)');

Remediation — Closing Vendor Due Diligence Gaps

Priority Gap Action Evidence Produced
1 No SOC 2 Type II on file Request from CORE Compliance Portal via account team Audit report for DORA Art.28
2 No DPA/DSA executed Engage ServiceNow account team for current DPA and DSA Contractual evidence for GDPR Art.28, DORA Art.29
3 No vendor risk assessment Create vendor profile in GRC module or document assessment externally Risk assessment for NIS2 §2(d)
4 Trust Portal not monitored Subscribe to CVE notifications at trust.servicenow.com/notifications Ongoing monitoring for ISO A.5.22
5 No internal KB documentation Create internal article documenting ServiceNow's certifications and security posture Awareness evidence for auditors

Expert Notes

Auditor tip: The most common DORA Art.28 gap is not lacking the SOC 2 report, but lacking evidence that someone reviewed it and documented findings. Create an internal review memo for each annual SOC 2 report cycle.

Bridge letter gap: SOC 2 Type II reports typically cover Jan 1 - Sep 30. The Oct 1 - Dec 31 bridge letter is available by end of Q1 the following year. Plan audit schedules around this gap.

Self-hosted customers: If running ServiceNow on your own infrastructure (rare but possible), the shared responsibility model shifts significantly. ServiceNow's certifications cover the platform software, but infrastructure security (physical, network, backup) becomes your responsibility. This changes the evidence requirements for DORA Art.28 and NIS2 §2(d).