← Trust Directory

ServiceNow

servicenow.com · 1 assessment

ServiceNow
Approve with conditions
3 items to confirm in writing
Assessed Sep 3, 2026 · public evidence coverage 55% · evidence confidence medium · methodology 0.7.0

Assessed before company and product grades were shown separately; see the product assessments below.

Products assessed

A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.

Now Assist
Approve with conditions
3 items to confirm in writing
Assessed Sep 3, 2026 · public evidence coverage 55% · evidence confidence medium · methodology 0.7.0

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

ISO/IEC 42001
Claimed, scope unclear

Stated as held, with no certificate number, certification body, scope statement or issue date given. Whether Now Assist falls inside the AI management system scope is not stated.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 27001:2022
Vendor claimed only

Certified since 2012; three-yearly recertification with annual surveillance audit. The certificate is linked but the scope statement was not collected.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 27017:2015
Vendor claimed only

Certified since 2018, by annual independent audit.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 27018:2019
Vendor claimed only

Certified since 2016, by annual independent audit.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 27701:2019
Vendor claimed only

Privacy information management extension to ISO/IEC 27001, received 2020.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
SSAE 18 SOC 1 Type 2
Vendor claimed only

Maintained since 2011; report available to customers via ServiceNow CORE, not publicly.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
SOC 2 Type 2
Vendor claimed only

Annual since 2013, covering security, availability and confidentiality. Report available to customers via ServiceNow CORE, not publicly.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
BSI C5
Vendor claimed only

Attestation report received 2020.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
EU Cloud Code of Conduct
Claimed & corroborated

Level 2 compliance with partial third-party audit coverage. The adherence ID quoted on ServiceNow's own compliance page (2022LVL02SCOPE3113) matches the register entry exactly.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · EU Cloud Code of Conduct public register (eucoc.cloud) · checked Sep 3, 2026

Valid until Jul 27, 2027

FedRAMP High P-ATO
Claimed, scope unclear

Scoped to the ServiceNow Government Community Cloud (GCC) offering, not the commercial platform.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
IRAP assessment (OFFICIAL and PROTECTED)
Claimed, scope unclear

Scoped to the ServiceNow Australian platforms. IRAP is an assessment, not a certification.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISMAP Cloud Service registration
Claimed & corroborated

Registered as the ServiceNow AI Platform under registration number C22-0036-2, not the narrower 'Now Platform' the vendor's compliance page names. The register row also carries a dedicated generative-AI information document (生成AIに関する情報), so the scheme holds a generative-AI scope declaration for this service. Last updated on the register 2026-04-24.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · ISMAP Cloud Service List (Japanese government, ismap.go.jp) · checked Sep 3, 2026

MTCS Level 3
Vendor claimed only

Singapore multi-tier cloud security standard, highest level.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
PCI DSS
Vendor claimed only

Stated as compliant since 2023; no attestation of compliance or assessor named.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
EU-U.S. Data Privacy Framework
Claimed & corroborated

Self-certified participation, including the UK extension and Swiss-U.S. DPF. Checkable on the DPF public list.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Sep 3, 2026

CSA STAR Level 2
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · CSA STAR Registry · checked Sep 3, 2026

FedRAMP Authorization
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Sep 3, 2026

Supply chain

Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.

Models: Mistral-Nemo-12B
AI providers: Azure OpenAI

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Sep 3, 2026.