Configuration Compliance release notes
Summarize
Summary of Configuration Compliance release notes
The ServiceNow® Configuration Compliance application enables customers to quickly prioritize and remediate critical configuration-related vulnerabilities within their environments. The Australia release, updated July 31, 2026, delivers enhancements that improve integrations with third-party security tools and streamline vulnerability management workflows.
Show less
Key Features
- AWS Integration for Security Exposure Management: Supports imports from AWS Inspector and AWS Security Hub, enabling automated vulnerability and misconfiguration detection across AWS resources.
- Vulnerability Response Integration with Wiz: Imports Wiz scanner issues and test results into Configuration Compliance, with enhanced AI asset handling and flexible asset import configuration.
- Manual Remediation Task Creation: Users with appropriate roles (snvulc.remediationowner and snvulc.admin) can manually create remediation tasks through IT Remediation Workspace and Vulnerability Manager Workspace respectively.
- Tenable Compliance Test Matching: Allows configuration of identifiers (compliancecontrolid, checkid, or compliancefunctionalid) to uniquely match incoming Tenable conformance test records, preventing data overwrites.
- Qualys Integration Enhancements: Includes a parameter to ignore passed test results on import, and upgraded support for newer Qualys API versions with additional data fields for improved visibility.
- Unified Microsoft Defender Integration: Consolidates Microsoft Defender for Cloud and Threat and Vulnerability Management plugins into a single integration, adding container image vulnerability ingestion and providing a guided migration path.
- Remediation Task Rule Execution Modes: Offers a new "Match First" mode to assign findings to a single remediation task by evaluating rules sequentially, in addition to the existing "Match All" mode.
Important Upgrade Information
- Configuration Compliance is available via the ServiceNow Store; installation requires requesting the app and third-party integrations there.
- Customers not upgrading to Unified Security Exposure Management (USEM) should install versions prior to v30.x and compatible third-party integrations.
- Now Assist for Vulnerability Response is being deprecated starting Australia Patch 5 but remains supported on existing instances.
- The Vulnerability Response Integration with Wiz has deprecated the Missing Assets table; customers should backdate existing Wiz integrations by three days and rerun after updating.
- ServiceNow Otto® branding replaces Now Assist naming but does not affect product entitlements.
Activation and Next Steps
To enable Configuration Compliance and its integrations, customers must request installation from the ServiceNow Store. For detailed compatibility and upgrade planning, consult the Vulnerability Response Compatibility Matrix and Release Schema Changes documentation available through ServiceNow support resources.
These updates empower ServiceNow customers to enhance their vulnerability and configuration compliance workflows by leveraging improved integrations, flexible configuration options, and streamlined remediation processes, thereby increasing security posture visibility and response efficiency.
The ServiceNow® Configuration Compliance application enables you to prioritize and remediate the most critical configuration-related vulnerabilities in your environment quickly and efficiently. Configuration Compliance was enhanced and updated in the Australia release.
Configuration Compliance highlights for the Australia release
- The AWS Integration for Security Exposure Management supports integrations with AWS Inspector and AWS Security Hub.
- If you're currently using Configuration Compliance and you want to upgrade to Unified Security Exposure Management (USEM), see Unified Security Exposure Management (USEM) release notes for more information about USEM and the Unified Security Exposure Management migration.
- Import Wiz issues and configuration test results from the Wiz scanners into test results in the Configuration Compliance application with the Vulnerability Response Integration with Wiz.
- With the sn_vulc.remediation_owner role, create remediation tasks manually in the IT Remediation Workspace.
- With the sn_vulc.admin role, create remediation tasks manually in the Vulnerability Manager Workspace.
See Configuration Compliance for more information.
Important information for upgrading Configuration Compliance to Australia
If you're currently using Configuration Compliance, and you don't intend to upgrade to Unified Security Exposure Management (USEM), install a version previous v30.x of Configuration Compliance and for upgrades to supported third-party integration applications.
Starting with Australia Patch 5, Now Assist for Vulnerability Response is being prepared for future deprecation. It will be hidden and no longer installed on new instances but will continue to be supported. For details, see the Deprecation Process [KB0867184] article in the Now Support Knowledge Base.
ServiceNow Otto® is the new AI experience brand. This change is reflected in the name of ServiceNow products, including the Now Assist for Vulnerability Response product name, which will be replaced with ServiceNow Otto for Unified Security Exposure Management. Your product entitlements remain unchanged. Check your entitlements to determine your access to specific features.
The Missing Assets [sn_vul_wiz_missing_asset] table used for storing assets imported by the backfill integrations for the Vulnerability Response Integration with Wiz is deprecated. If you're currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, backdate any of your existing Wiz primary integrations by three days and run them. See more information about the Wiz integration at SecOps articles on the Security Operations Community.
For more information about the released versions of the Vulnerability Response application and the third party and ServiceNow applications that are compatible with the Australia release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base.
New in the Australia release
- Enhancements to the Vulnerability Response Integration with Wiz
-
Enhancements to the Wiz integration that imports cloud configuration findings as Test Results in Configuration Compliance. Configuration issues related to AI assets, such as AI models and agents are routed into AI security exposure management tables (AI posture findings).
This enhancement helps with better visibility within AI Control Tower and for any AI-specific remediation workflows to be added in the future. The 'Send AI security findings to AI security exposure management' configuration setting has been added to the Wiz Test Results integration configuration page so that AI security findings are routed into AI security exposure management.
- Activate the Wiz Asset Integration and identify resource types for import
- Enhancements to the Wiz integration include:
-
Starting with version 32.1 (USEM) and version 4.1 (non-USEM), the Asset integration is deactivated by default. It is not a mandatory prerequisite for the other Wiz integration imports.
If you choose to activate it, the Asset integration will retrieve assets for all resource types if you don't specify the ones you want on the Asset Integration Configuration tab. To avoid importing vulnerability data you don't need, identify only the resources (assets) that you want to import with this integration.
- Resource Type is no longer a mandatory field for configuring the Vulnerability Response Integration with Wiz. You can now save Wiz configurations for the integrations without specifying a Resource Type, simplifying setup for use cases where specifying a Resource Type isn't appropriate.
-
- Tenable compliance test uniqueness key
- You can now configure which identifier the system uses to uniquely match incoming Tenable conformance test records. Previously, conformance tests were identified by the check_id field, which caused records to be overwritten when multiple tests shared the same control identifier. You can now select the identifier that best matches how your Tenable data is structured (compliance_control_id, check_id, or compliance_functional_id), ensuring test records are accurately preserved during ingestion.
- Qualys parameter to ignore passed test results
- Starting with v15.2.5 of Configuration Compliance, the ignore_passed_result integration instance parameter for the Qualys Integration for Security Operations has been added.
This parameter is set to false by default so that passed test results imported by Qualys aren't ignored.
Set the parameter to true to ignore passed test results on import.Note:If activated, this parameter does not impact closure of the test results. For example, if you activate the parameter, and a failed test result from a previous import has since passed, it will be closed correctly. - AWS Integration for Security Exposure Management
- The AWS Integration for Security Exposure Management supports integrations with the following AWS services:
- AWS Inspector is an automated vulnerability management service that continuously scans EC2 instances, ECR container images, and Lambda functions for software vulnerabilities (CVEs) and unintended network exposure. The Vulnerability Response integration with AWS Inspector imports host and container vulnerability findings from AWS Inspector.
- AWS Security Hub is a security service that is used to centralize and update security checks across AWS accounts. It provides a unified view of security alerts and conformance status by integrating with various AWS services. The Vulnerability Response integration with AWS Security Hub imports host, container vulnerabilities, and misconfigurations from AWS Security Hub.
- Optimized Tenable.io Compliance Results ingestion
- Starting with v 6.1.3, the Tenable.io conformance Results Integration is replaced by the Tenable.io Fixed conformance Results Integration and Tenable.io Open conformance Results Integration. conformance results are now imported based on their status, optimizing ingestion performance and scalability for environments with large volumes of conformance data while keeping remediation and conformance tracking aligned with the current state of findings.
- Qualys Integration – API enhancements
- The Qualys Vulnerability Integration has been upgraded to support newer Qualys API versions across Host Detection, Host List, Knowledgebase, PC Controls, PC Policies, and PCRS integrations. The integrations now ingest additional data fields, including vulnerability detection
source, authentication privilege status, active status for controls and policies, and cloud metadata, giving you better visibility into your vulnerability and conformance data. Use the new
posture_api_versionintegration instance parameter to choose between the default v2.0 APIs or the newer v5.0 streaming APIs for the PCRS Policy Host and PCRS Test Results integrations. - Unified Microsoft Defender Integration for Security Exposure Management
- The Microsoft Defender for Cloud and Microsoft Defender Threat and Vulnerability Management (MS TVM) plugins are now consolidated into a single plugin: Microsoft Defender Integration for Security Exposure Management. This consolidation deprecates the standalone Microsoft Defender for Cloud plugin. The unified plugin also introduces container image vulnerability ingestion from Microsoft Defender for Cloud, creating Container Vulnerable Items on your instance. A guided migration path is available to transfer existing data from the deprecated applications to the unified plugin.
- Remediation task rule execution mode
- You can now choose how remediation task rules are evaluated during ingestion. The new Match First execution mode evaluates rules sequentially and applies only the first matching rule, assigning each finding to exactly one remediation task. The default Match All mode continues to evaluate all applicable rules.
Activation information
Install Configuration Compliance and third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.