Skip to content

ServiceNowCompliance, certifications and attestations

Certifications held, by family24 held
Status
Public
Founded
2004
Trust center Company profile
24
Certifications held
4
Backed by a registry
25
Pieces of evidence
Sep 24, 2026
Last captured
Across fru.devAcquisitionsEarningsPaydaysConferences

SOC reports

ISO standards

AI governance

US government

Health

Payments

Privacy

Cloud security

Regional

From public trust centers and registries on the date shown. Confirm scope with the vendor. Logos via logo.dev; trademarks belong to their owners.

History

Added or renewedUpgradedIn process or ReadyLapsed or removed
  1. AddedFedRAMP HighGovernment Community Cloud
  2. AddedCSA STARFirst listed in the CSA STAR Registry
  3. In processFedRAMP HighGovernment Community Cloud
  4. AddedData Privacy FrameworkServiceNow, Inc.

Evidence

Every source, what it says and when it was read.

SOC 11 source

Held · Type IIVendor compliance page
...Personally Identifiable Information (PII). ServiceNow received this certification in 2020. SSAE 18 SOC 1 and SOC 2 Reports The Service Organizational Control (SOC) framework is an attestation that ServiceNow meets...
Captured Sep 24, 2026Open source

SOC 21 source

Held · Type IIVendor compliance page
...Identifiable Information (PII). ServiceNow received this certification in 2020. SSAE 18 SOC 1 and SOC 2 Reports The Service Organizational Control (SOC) framework is an attestation that ServiceNow meets the required...
Captured Sep 24, 2026Open source

ISO/IEC 270011 source

HeldVendor compliance page
...independent audit and ServiceNow has been an ISO/IEC 27017:2015 certified organization since 2018. ISO/IEC 27001:2022 The ISO/IEC 27001:2022 certification specifies security management best practices and controls based on the...
Captured Sep 24, 2026Open source

ISO/IEC 270171 source

HeldVendor compliance page
...customers adopt AI with confidence while meeting global regulatory and ethical expectations. ISO/IEC 27017:2015 The ISO/IEC 27017:2015 standard is concerned with the implementation of the cloud-specific information security...
Captured Sep 24, 2026Open source

ISO/IEC 270181 source

HeldVendor compliance page
...an ISO/IEC 27001 certified organization since 2012 and the certificate is available here . ISO/IEC 27018:2019 The ISO/IEC 27018:2019 is a code of practice based on ISO/IEC 27002 and is concerned with the protection...
Captured Sep 24, 2026Open source

ISO/IEC 277011 source

HeldVendor compliance page
...independent audit and ServiceNow has been an ISO/IEC 27018:2019 certified organization since 2016. ISO/IEC 27701:2019 This extension to ISO/IEC 27001 focuses on the establishment, and maintenance of a Privacy Information Management...
Captured Sep 24, 2026Open source

ISO/IEC 420011 source

HeldVendor compliance page
...our security protocols to rapidly changing regulatory landscapes. Expand All Collapse All ISO/IEC 42001 – Artificial Intelligence Management System (AIMS) ISO/IEC 42001 is the first international standard for managing...
Captured Sep 24, 2026Open source

FedRAMP1 source

Held · HighFedRAMP Marketplace

Government Community Cloud

FedRAMP Authorized, High impact; authorized 2019-08-12 (JAB); assessor Kratos; 90 agency authorizations
Captured Sep 23, 2026Since Aug 12, 2019Open source

DoD Impact Level1 source

Held · IL5Vendor compliance page
...Provisional Authority to Operate (P-ATO) in August 2019. GCC also meets Department of Defense (DoD) Impact Level 4 (IL4) and CNSSI 1253F Privacy Overlay High PII + PHI control requirements. Click here to see ServiceNow on the...
Captured Sep 24, 2026Open source

HITRUST1 source

HeldVendor compliance page
...government defined data classification level that is approved to be stored within the cloud. HITRUST Certification HITRUST was developed by the healthcare industry to standardize compliance objectives through their...
Captured Sep 24, 2026Open source

PCI DSS1 source

HeldVendor compliance page
...auditor. Due to the regional focus of the scheme, the certification is scoped to the UK region. PCI DSS Compliance The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards formed in...
Captured Sep 24, 2026Open source

Data Privacy Framework1 source

HeldData Privacy Framework List

EU-US, UK extension, Swiss-US; non-HR data and HR data. ServiceNow, Inc.

EU-US status: Active; certified since 2016-10-07; recertification due 2027-01-06; verification: Self-Assessment
Captured Sep 23, 2026Since Oct 7, 2016Renewal due Jan 6, 2027Open source

EU Cloud Code of Conduct2 sources

HeldCSA STAR Registry

Partner entry in the STAR Registry

Listed as ServiceNow since 2019-02-27; EU Cloud Code of Conduct entry
Captured Sep 23, 2026Since Feb 27, 2019Open source
HeldVendor compliance page
...provider against the CSA Cloud Controls Matrix together with ISO/IEC 27001 requirements. EU Cloud CoC The EU Cloud Code of Conduct (EU Cloud CoC) is a set of control requirements designed to develop trust and transparency...
Captured Sep 24, 2026Open source

CSA STAR1 source

Held · Level 2CSA STAR Registry

CAIQ, certification

Listed as ServiceNow since 2019-02-27; Level 2 (third-party audit)
Captured Sep 23, 2026Since Feb 27, 2019Open source

IRAP1 source

HeldVendor compliance page
...is proud to have achieved MTCS Level 3, the highest level of certification available. ASD IRAP assessed for OFFICIAL and PROTECTED Cloud Services ServiceNow's Australian Platforms has been independently assessed...
Captured Sep 24, 2026Open source

BSI C51 source

HeldVendor compliance page
...the end of each calendar Q1 of next year. BSI Cloud Computing Compliance Controls Catalog (C5) Standard C5 is a cloud-specific compliance controls catalog developed by the German Federal Office for Information...
Captured Sep 24, 2026Open source

ISMAP1 source

HeldVendor compliance page
...that would have a significant impact on the Processor’s Privacy processes and/or procedures. ISMAP Cloud Service The Information system Security Management and Assessment Program (ISMAP) is a program that aims...
Captured Sep 24, 2026Open source

Compare with

Weekly: vendors that gained or lost a certification, Wednesdays.