Combined Configuration Compliance release notes for upgrades from Yokohama to Zurich

  • Release version: Zurich
  • Updated August 11, 2026
  • 10 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Configuration Compliance Release Notes for Upgrades from Yokohama to Zurich

    This consolidated guide covers the release notes for Configuration Compliance upgrades from Yokohama to Zurich, focusing on new features, important upgrade considerations, and integration enhancements. It is designed to help ServiceNow customers understand changes, plan upgrades, and utilize new functionalities effectively.

    Show full answer Show less

    Important Upgrade Information

    • Before upgrading to Zurich, complete pre- and post-upgrade tasks as recommended.
    • If not upgrading to Unified Security Exposure Management (USEM), install Configuration Compliance versions below v30.x for compatibility with third-party integrations.
    • The Missing Assets [snvulwizmissingasset] table used in Vulnerability Response Integration with Wiz is deprecated; post-upgrade to version 1.1, backdate existing Wiz integrations by three days and rerun them.
    • Backfill integrations related to Wiz are activated by default to handle missing assets previously unprocessed.
    • Refer to the Vulnerability Response Compatibility Matrix for supported third-party and ServiceNow applications with Zurich.

    New Features

    • Wiz Resource Type Identification: Select Wiz asset types to import via the Wiz Integration Resource Type configuration page in the ServiceNow AI Platform instance; applies to most Wiz integrations except the Container Vulnerability Integration.
    • Wiz Backfill Integrations: Specialized integrations to process missing assets data, activated by default.
    • Host Test Result Vulnerability Integration: Imports test results for VIRTUAL MACHINE resource types and is activated by default.
    • Manual Remediation Task Creation: Users with snvulc.admin role can create remediation tasks in the Vulnerability Manager Workspace; those with snvulc.remediationowner role can do so in the IT Remediation Workspace. Tasks are grouped based on selected criteria.
    • Risk Score Details in Work Notes: System property snseccmn.riskscorechangesaddworknotes (inactive by default) controls visibility of risk score changes in test result work notes.
    • Quick Start Tests: Recommended after upgrades or new integrations to verify Configuration Compliance functionality; customizable for tailored implementations.
    • Qualys Integration Parameter: Added ignorepassedresult parameter (default false) to control import of passed test results, improving data relevance.
    • Granularity Configuration for Test Results: Ability to split Tenable and Qualys Configuration Test Results into unique findings per instance, enhancing visibility into patching efforts.
    • Related List Row Limit: System property allows limiting rows shown in related lists to improve form readability and performance.
    • Enhanced State Management: Improved logic for state roll-up and roll-down between remediation tasks and findings for better accuracy and streamlined workflows.
    • Dark Theme Support: Zurich introduces a Coral theme with dark mode option for web and mobile to improve readability and reduce eye strain.

    Changes and Deprecations

    • Deprecated Features: The Missing Assets [snvulwizmissingasset] table and the isignored column in Host Test Results and Test Results integrations are deprecated and replaced by updated fields such as isresultignored.
    • Source Severity Mapping: Source severity is now mapped to the Priority column on the Test Results table.
    • Resource Type Filters: Enhanced filtering options on Wiz configuration tabs allow more precise resource type import management; integration instance settings take precedence over global configurations.
    • Additional Attributes: Attributes from Wiz not stored in Discovered Items are now stamped as Asset Attributes.
    • CMDB Field Mapping: The internet-facing field on discovered items is mapped to Limited Internet Exposure on findings.
    • Description Field Length Increased: Host Vulnerability import table descriptions support longer text.

    Activation and Installation

    • Configuration Compliance and related third-party integrations are available through the ServiceNow Store; customers should request installation from there.
    • For cumulative release notes and app updates, refer to the ServiceNow Store version history.

    Additional Information

    • No new browser or localization requirements were introduced in Zurich.
    • Accessibility improvements include the addition of a dark theme to enhance user experience.
    • Manual remediation task creation continues to be supported in both Vulnerability Manager and IT Remediation Workspaces with appropriate roles.
    • For customers planning to upgrade to USEM, separate release notes provide migration guidance.

    Consolidated page of all release notes for Configuration Compliance from Yokohama to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Configuration Compliance release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Configuration Compliance to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    If you are currently using Configuration Compliance, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Configuration Compliance and for upgrades to supported third-party integration applications.

    The Missing Assets [sn_vul_wiz_missing_asset] table used for storing assets imported by the backfill integrations for the Vulnerability Response Integration with Wiz is deprecated. If you are currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, you must backdate any of your existing Wiz primary integrations by three days and run them. Please review more information about the Wiz integration at SecOps articles on the Security Operations Community.

    For more information about the released versions of the Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Zurich release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base.

    New features

    Between your current release family and Zurich, new features were introduced for Configuration Compliance.

    Release Release notes

    Yokohama

    Identify Wiz Resource Types for import

    Identify the Resource Types (assets) reported by Wiz in your environment on the Wiz Integration Resource Type configuration page in your ServiceNow AI Platform instance that you want to import.

    The Resource Types that you select apply to all the primary Wiz vulnerability and compliance integrations except the Wiz Container Vulnerability Integration.

    Wiz Backfill Integrations
    Retrieve and process data stored on the Wiz Missing Assets [sn_vul_wiz_missing_asset] table for missing assets that were not processed by the primary compliance integrations with specialized Wiz Backfill Integrations.
    • Test Results Backfill Integration
    • Host Test Results Backfill Integration
    • Issues Backfill Integration

    The Wiz Backfill Integrations are activated by default.

    Wiz Host Test Result Vulnerability Integration
    Import test results associated with the resource type, VIRTUAL MACHINE with the Wiz Host Test Result Vulnerability Integration. This integration is activated by default.
    Create remediation tasks manually in the Vulnerability Manager Workspace
    With the sn_vulc.admin role, you can create remediation tasks manually by selecting some or all the records in the Configuration Test Results lists in the Vulnerability Manager Workspace. These records are grouped into one or more remediation tasks according to the grouping criteria selected while creating remediation tasks.
    Create remediation tasks manually in the IT Remediation Workspace
    With the sn_vulc.remediation_owner role, you can create remediation tasks manually by selecting desired records in the Configuration Test Results lists in the IT Remediation Workspace. These records are grouped into one or more remediation tasks according to the grouping criteria selected while creating remediation tasks.
    View risk score details of a test result in the Work notes section
    Starting with v15.2.1 of Configuration Compliance, the system property sn_sec_cmn.risk_score_changes_add_worknotes is inactive by default. If you enable it, only then you can see all the changes related to the risk score of a test result in the Work notes section. Additionally, the work notes are updated only if there’s a change in the risk score.
    Quick Start Tests for Configuration Compliance

    After upgrades and deployments of new applications or integrations, run quick start tests to verify that Configuration Compliance works as expected. If you customized Configuration Compliance, copy the quick start tests and configure them for your customizations.

    Zurich

    Enhancements to the Vulnerability Response Integration with Wiz

    The Missing Assets [sn_vul_wiz_missing_asset] is deprecated. After updating to version 1.1, you must backdate your existing primary Wiz integrations by three days and run them.

    The backfill integrations are activated by default.

    After you backdate and run your integrations, the following backfill integrations are no longer required:
    • Host Vulnerability Backfill Integration
    • Test Results Backfill Integration
    • Host Test Results Backfill Integration
    • Issues Backfill Integration

    The [is_ignored] column is deprecated for the Host Test Results and Test Results Integrations. This column was replaced by the [is_result_ignored] column.

    Source severity is mapped to the Priority column on the Test Results [sn_vulc_result] table.

    Resource type filters are on the Test Results, Issues, and Host Test Results configuration tabs on the Wiz Configuration page. You can add any of the resource types listed.
    Note:

    If you configure resource types on the Resource Type Configuration tab, and you choose to configure parameters on the integration instance records, your configurations on integration instance take precedence over your settings on the Resource Type Configuration tab. See Identify Wiz Resource types for more information.

    Additional attributes imported from Wiz that are not stored in the Discovered items [sn_sec_cmn_src_ci] table are stamped with Asset Attributes in this table.

    Test results from the Host misconfiguration integration are classified as result type 'host_misconfiguration'.

    Data for resources that have the validated_at_runtime flag set to 'yes' is imported and populated on detections.

    The is_ignored column is deprecated on the Host Test Results and Test Results Integrations. This column was replaced by the is_result_ignored column.

    The CMDB internet-facing field on the discovered item is mapped to Limited Internet Exposure on findings.

    Column length for the descriptions in the Host Vulnerability import table has been increased.

    Qualys parameter to ignore passed test results
    Starting with v15.2.5 of Configuration Compliance, the ignore_passed_result integration instance parameter for the Qualys Integration for Security Operations has been added.

    This parameter is set to false by default so that passed test results imported by Qualys are not ignored.

    Set the parameter to true to ignore passed test results on import.
    Note:
    If activated, this parameter does not impact closure of the test results. For example, if you activate the parameter, and a failed test result from a previous import has since passed, it will be closed correctly.
    Identify Wiz Resource Types for import

    Identify the Resource Types (assets) reported by Wiz in your environment on the Wiz Integration Resource Type configuration page in your ServiceNow AI Platform instance that you want to import.

    The Resource Types that you select apply to all the primary Wiz vulnerability and compliance integrations except the Wiz Container Vulnerability Integration.

    Wiz Backfill Integrations
    Retrieve and process data stored on the Wiz Missing Assets [sn_vul_wiz_missing_asset] table for missing assets that were not processed by the primary compliance integrations with specialized Wiz Backfill Integrations.
    • Test Results Backfill Integration
    • Host Test Results Backfill Integration
    • Issues Backfill Integration

    The Wiz Backfill Integrations are activated by default.

    Wiz Host Test Result Vulnerability Integration
    Import test results associated with the resource type, VIRTUAL MACHINE with the Wiz Host Test Result Vulnerability Integration. This integration is activated by default.
    The Wiz Configuration Compliance (Test Results) and Issues Integrations
    • Import configuration test results with the Wiz Configuration Compliance Integration (Wiz Test Results) to detect non-compliant cloud configurations. Findings are mapped to cloud test results (CTRs) in the Configuration Compliance application to help you enforce security policies and standards across your cloud environment.
    • Import data with the Wiz Issues Integration that can help you identify assets that are involved in toxic combinations of vulnerabilities and misconfigurations. These findings are also mapped to CTRs with Wiz Issues labeled as the source to help you track and remediate assets that may pose complex multi-vector risks.

    Changes

    Between your current release family and Zurich, some changes were made to existing Configuration Compliance features.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    Configure Test Result Granularity
    Starting with v15.6.1, you can configure the granularity of Tenable Configuration Test Results (CTRs) to split results into unique findings. For example, if a database has five instances, the system generates five distinct test results, one per instance, providing improved visibility into individual patching efforts.
    Configure Test Result Granularity
    Starting with v15.4.3, you can configure the granularity of Qualys Configuration Test Results (CTR) in configuration compliance and split CTRs into unique findings. For example, if a database has five instances, the system generates five distinct test results, one per instance, providing improved visibility into individual patching efforts.
    Configure maximum rows in related lists
    To improve readability and performance, you can now limit the number of rows shown in related lists on forms by setting the system property sn_vul_cmn.related_list.set_max_row.
    Improved state management for remediation tasks and vulnerable items
    State management logic for roll down of state from remediation tasks (RTs) to findings and roll up of state from findings to RTs has been refined across all modules. Updates improve accuracy by handling mixed item states (a combination of Deferred and Closed), supporting closure of tasks in sub-states like In-Review, and reopening tasks based on the Assigned To field. The update also improves handling of False Positive state transitions based on scanner results as source of truth. These enhancements reduce manual effort, clarify task ownership, and streamline remediation workflows.

    Removed

    Between your current release family and Zurich, some Configuration Compliance features or functionality were removed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some Configuration Compliance features or functionality were deprecated.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Activation information

    Review information on how to activate Configuration Compliance.

    Release Release notes

    Yokohama

    Install Configuration Compliance by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Zurich

    Install Configuration Compliance and third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Additional requirements

    If any additional requirements were introduced or changed for Configuration Compliance we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Configuration Compliance we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Accessibility information

    Review details on accessibility information for Configuration Compliance, such as specific requirements or compliance levels.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    Dark theme
    The new Coral theme includes a dark theme option for web and mobile experiences. This option is commonly used to alleviate eye strain and improve readability.

    Localization information

    If there are specific localization considerations for Configuration Compliance we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Configuration Compliance we have noted them here.

    Release Release notes

    Yokohama

    • With the sn_vulc.admin role, create remediation tasks manually in the Vulnerability Manager Workspace.
    • With the sn_vulc.remediation_owner role, create remediation tasks manually in the IT Remediation Workspace.

    See Configuration Compliance for more information.

    Zurich

    • If you are currently using Configuration Compliance and you want to upgrade to Unified Security Exposure Management (USEM), see Unified Security Exposure Management release notes for more information about USEM and the Unified Security Exposure Management migration.
    • Import Wiz issues and configuration test results from the Wiz scanners into test results in the Configuration Compliance application with the Vulnerability Response Integration with Wiz.
    • With the sn_vulc.remediation_owner role, create remediation tasks manually in the IT Remediation Workspace.
    • With the sn_vulc.admin role, create remediation tasks manually in the Vulnerability Manager Workspace.

    See Configuration Compliance for more information.