Combined Operational Resilience release notes for upgrades from Yokohama to Zurich

  • Release version: Zurich
  • Updated August 11, 2026
  • 9 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Operational Resilience release notes for upgrades from Yokohama to Zurich

    This consolidated release notes page provides ServiceNow customers with essential information for upgrading Operational Resilience from the Yokohama release to Zurich. It summarizes new features, changes, deprecations, and important upgrade tasks to help you effectively prepare and maximize the value of the Zurich release.

    Show full answer Show less

    The page combines cross-family updates and highlights key functionalities introduced or improved between these releases, with a focus on enhancing resilience metrics, incident reporting, regulatory compliance, and visualization capabilities.

    Important Upgrade Information

    • After upgrading to Operational Resilience version 21.0.x (Zurich), rerun the Update CSDM and other dependencies scheduled job to populate additional metadata introduced in Zurich.
    • No updates or changes were noted for Yokohama regarding upgrade tasks.

    New Features

    • Yokohama Introductions:
      • Measurement of resilience metrics using the Common Service Data Model (CSDM) by defining entity types, pillars, and establishing relationships among CSDM objects such as business services, service offerings, and application services.
      • Specification of primary origin for operational vulnerabilities to automatically include upstream impacted dependencies, facilitating comprehensive impact views.
      • Digital resilience incident reporting integrated with Incident Management and Security Incident Response, enabling classification, notification, and regulator-compliant reporting (initial, intermediate, final reports) triggered automatically upon major incident classification.
    • Zurich Enhancements:
      • Interactive Node Map (Nexus map) visualization for navigating operational dependencies with configurable nodes, edges, colors, and icons, accessible within the Operational Resilience Workspace.
      • Generation of Microsoft Word reports for action tasks using customizable Document designer templates, enabling audit-ready, regulator-compliant documentation saved within ServiceNow or Microsoft SharePoint.
      • Support for reporting incidents associated with multiple regulations and legal entities, automating regulatory reporting workflows and generating required Word reports.
      • Generation and validation of Register of Information (RoI) regulatory packages compliant with EU DORA, including structured ZIP files and automated validation reports to ensure file format and data accuracy.
      • Improved resilience metrics leveraging enhanced CSDM fix scripts that store nodes separately and process dependencies in parallel, supporting flexible top-level node configurations and efficient data retrieval.
      • Use of Smart Assessment templates for analyzing service importance and impact tolerance, with role-based access, auto-assigned tasks, email notifications, and the ability to generate flexible self-attestation PDF reports.
      • Enhanced Digital Operational Resilience Act (DORA) capabilities to configure contracts based on supply chains and assessments, upload contract records, and generate detailed Excel reports.
      • Tracking of third-party risk assessments as red flags within Operational Resilience reports and workspace, with updated role assignments for assessment reviewers included by default.

    Changes, Removed Features, and Deprecations

    • No changes or removed features were reported for either Yokohama or Zurich.
    • Zurich deprecates storing the entire dependency chain in the [snoperresprofile] table to reduce redundant data and improve performance. The optimized scheduled job now supports any node as top level and more efficient data retrieval.

    Activation and Installation

    • Operational Resilience is available for installation via the ServiceNow Store for both Yokohama and Zurich releases.
    • Refer to the ServiceNow Store for app requests, version history, and general installation guidance.

    Browser Requirements

    • Supported browsers for Operational Resilience include Google Chrome, Firefox (including Extended Support Release), Microsoft Edge Chromium, and Safari version 12.0 or later.

    Highlights for ServiceNow Customers

    • Zurich introduces advanced visualization with Nexus maps, allowing you to clearly define and explore dependencies to strengthen resilience planning and impact analysis.
    • Improved regulatory reporting workflows support multi-regulation scenarios with automated report generation and action task tracking to streamline compliance processes.
    • Enhanced CSDM integration and Smart Assessment capabilities provide more efficient data management, flexible evaluations, and customizable reporting to support operational resilience strategies.
    • Automated validation of regulatory packages reduces manual effort and helps ensure data accuracy and compliance with EU DORA requirements.
    • Integration with Microsoft Word and SharePoint enables creation and storage of audit-ready reports, enhancing documentation and collaboration.

    Consolidated page of all release notes for Operational Resilience from Yokohama to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Operational Resilience release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Operational Resilience to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    After upgrading to Operational Resilience version 21.0.x, rerun the Update CSDM and other dependencies scheduled job to populate the additional metadata that was introduced in this release.

    New features

    Between your current release family and Zurich, new features were introduced for Operational Resilience.

    Release Release notes

    Yokohama

    Measure resilience metrics using the CSDM model

    Define the entity types and pillars in Operational Resilience and generate the entities. Establish relationships between CSDM objects, including business services, service offerings, business processes, and application services. Specify the type of main node configuration that you want to use by setting the sn_oper_res.opres_csdm_main_node_config property.

    After generating the entities and setting up the main node configurations, you can import CMDB data into Operational Resilience for reporting. CSDM and their dependencies are updated weekly while the red flags data is calculated daily. The outcome is displayed on the Homepage or in the related list of the CSDM objects.

    Specify the primary origin of an operational vulnerability
    Identify the primary origin of an operational vulnerability in its record. Once the primary origin is specified, its upstream dependencies are automatically included in the impacted areas, enabling you to view the operational vulnerability from all affected perspectives.
    Using Digital resilience incident reporting

    Assess whether any critical services are affected and classify the reported incident as a major incident if necessary. Notify regulators of major incidents, categorized by their severity and security ratings.

    The Digital resilience incident reporting module, accessible from the Operational Resilience Workspace, is integrated with Incident Management and Security Incident Response to generate and share reports in the format that is specified by the regulators.

    You can generate an initial report within 24 hours, an intermediate report within 72 hours, and a final report within 1 month. All of these reports are automatically triggered by the application from the time that the incident is classified as a major incident.

    Zurich

    Use the interactive Node Map visualization

    Navigate operational dependencies using the interactive Node map visualization. Configure node and edge settings in the Nexus map, then display Main node configurations directly within the Operational Resilience Workspace. The Resilience map action provides access to relationships for Business Services (BS), Application Services (AS), Supporting Offerings (SO), Business Processes (BP), and Dependencies modules in the map view.

    You can configure node dependency directions and enhance visual elements with improved colors and icons for clarity. Additionally, you can gain comprehensive insights from the summary panel and address missing 'red flags' for a complete picture.

    Generate Word reports of action tasks
    Use the Document designer to set up Microsoft Word templates and download action task reports in Digital resilience incident reporting. This functionality enables you to customize predefined templates or create templates, incorporating specific data like tables and columns from records, to generate intuitive, audit-ready reports. You can then save these reports within the ServiceNow® instance or as cloud documents in Microsoft SharePoint.
    Report incidents associated with multiple regulations for various legal entities
    Report incidents or security incidents associated with multiple regulations for various legal entities in Digital resilience incident reporting. Its automated workflow generates regulatory reporting assessment of IT incidents, DRI Initial report, DRI Intermediate report, and DRI Final report within regulatory timelines, each with dedicated action tasks. You can complete these tasks and generate reports in Microsoft Word format required by regulatory authorities for analysis.
    Generate Register of Information (RoI) regulatory packages

    Generate regulator-ready Register of Information (RoI) regulatory packages using the Plain-CSV Report Package option on the download page in Digital resilience third-party registers. The resulting ZIP file, structured to regulator specifications, includes metadata and report folders with file names containing LEI, entity ID, and release version.

    This format helps you to verify EU DORA compliance and supports automated validation workflows. For suggested steps and permissions, refer to the user guide on the Download and Upload request page.

    Validate downloaded Register of Information regulatory packages

    Validate downloaded Register of Information (RoI) regulatory packages against requirements using the Plain-CSV Report Package option on the Digital resilience third-party registers download page. This process verifies file format, structure, encoding, naming conventions, and field-level data across multiple tables.

    If validation warnings are detected, an automated report is attached, mapping issues to regulator fields like Template Code, Row Code, and Column Code. These reports include real-world field labels, rule expressions, and record identifiers. You can easily cross-reference validation errors using a downloadable Excel template that mirrors the CSV structure, simplifying issue location and resolution. Further enhancements include support for 'Not applicable' values, enforced file size limits, and clearer error messages for malformed data.

    Improve resilience metrics with the enhanced CSDM model

    Leverage the enhanced fix scripts in the Common Service Data Model (CSDM) to enhance your Operational Resilience metrics. Each node in the hierarchy is now stored separately, with its class and parent nodes, to help you manage your data more efficiently.

    The Update CSDM and other dependencies scheduled job script has been optimized to process the main node configurations in parallel, triggering a separate event for each node. Any node can be at the top level. Additionally, you can store impacted objects, including all parents, in a single table, so that you can efficiently retrieve children nodes and improve your data retrieval.

    Configure the sn_oper_res.top_class_name property to designate any class as the top class. You can view the downstream data and various dashboards based on the selected top class, such as the number of application services that are under a business service.

    Analyze importance and impact tolerance of a service using Smart Assessment
    Analyze a service's importance and impact tolerance through flexible assessments by using one or multiple Smart Assessment templates. Role-based access controls and auto-assigned tasks help you to streamline the process. You can reopen and complete assessments as needed and send email notifications to relevant users.
    Generate customized and flexible self-attestation reports using Smart Assessment
    Generate customized and flexible self-attestation reports by using Smart Assessment. Start with the default template, add relevant scopes and users, and generate a PDF report on completion of the self-attestation process. By creating custom templates with various data types, you make the self-attestation process more efficient.
    Leverage enhanced DORA capabilities for contracts, supply chains, and assessments
    Use the enhanced Digital Operational Resilience Act (DORA) data model in Operational Resilience. You can configure contracts based on their supply chains and assessments, upload the contract records, and generate a detailed report in Microsoft Excel that provides information on the entities, third parties, and specific contract details.
    Track third-party risk assessments
    Track third-party risk assessments as red flags in Operational Resilience reports and overview pages for business services, service offerings, and business processes. Operational Resilience users, managers, and administrators can review these assessments in Operational Resilience Workspace. The sn_vdr_risk_asmt.vendor_assessment_reviewer role is now included in the sn_oper_res.user role, so that you can grant the necessary access to the assessments.

    Changes

    Between your current release family and Zurich, some changes were made to existing Operational Resilience features.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Removed

    Between your current release family and Zurich, some Operational Resilience features or functionality were removed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some Operational Resilience features or functionality were deprecated.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    The Operational Resilience application previously stored the entire dependency chain in the [sn_oper_res_profile] table, which resulted in redundant data and potential performance issues. The Update CSDM and other dependencies scheduled job script has been optimized to address this issue. Any node can now be at the top level. Data retrieval is more efficient because you can store the impacted objects in a single table.

    Activation information

    Review information on how to activate Operational Resilience.

    Release Release notes

    Yokohama

    Install Operational Resilience by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Zurich

    Install Operational Resilience by requesting it from the ServiceNow Store.

    Additional requirements

    If any additional requirements were introduced or changed for Operational Resilience we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Operational Resilience we have noted them here.

    Release Release notes

    Yokohama

    Business Continuity Management requires the following browsers:
    • Google Chrome
    • Firefox and Firefox Extended Support Release (ESR)
    • Microsoft Edge Chromium
    • Safari 12.0 and later versions

    Zurich

    Operational Resilience requires the following browsers:
    • Google Chrome
    • Firefox and Firefox Extended Support Release (ESR)
    • Microsoft Edge Chromium
    • Safari 12.0 and later versions

    Accessibility information

    Review details on accessibility information for Operational Resilience, such as specific requirements or compliance levels.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    Localization information

    If there are specific localization considerations for Operational Resilience we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Operational Resilience we have noted them here.

    Release Release notes

    Yokohama

    • Align with the CSDM model to set up configurable main node configurations, which are used to retrieve CSDM and their dependency data.
    • Add the primary origin to an operational vulnerability, and the impacted areas are automatically included. The vulnerability can then be viewed from any impacted area.
    • All CSDM objects, dependencies, and their red flags can be rolled up based on the entity hierarchy.
    • Use Smart Assessment for evaluating an Operational vulnerability.

    See Operational Resilience for more information.

    Zurich

    • Set up the nexus map configurations and use the interactive node map view to define dependencies and relationships between records.
    • Generate a Microsoft Word document for the action tasks in Digital resilience incident reporting.
    • Create DIR cases for multiple regulations from either an incident or a security incident report. You can map entities to regulations and configure the Smart Assessment Engine (SAE) template for each regulation within the regulatory agency profile.
    • Generate and validate regulator-ready Register of Information (RoI) packages for EU DORA compliance.
    • Use the enhanced fix scripts in the Common Service Data Model for improved Operational Resilience metrics.
    • Evaluate the importance and impact tolerance of services and self-attest their status by using Smart Assessment.

    See Operational Resilience for more information.