Combined Configuration Compliance release notes for upgrades from Xanadu to Zurich

  • Release version: Zurich
  • Updated July 20, 2026
  • 16 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Configuration Compliance Release Notes for Upgrades from Xanadu to Zurich

    This consolidated release notes document provides ServiceNow customers with a comprehensive overview of the Configuration Compliance application updates, features, and important upgrade considerations spanning from the Xanadu release through to Zurich. It assists customers in preparing for upgrades by summarizing new functionality, changes, and deprecated features across these releases.

    Show full answer Show less

    Important Upgrade Considerations

    • Before upgrading to Zurich, review and complete pre- and post-upgrade tasks to ensure compatibility and smooth transition.
    • The Missing Assets [snvulwizmissingasset] table used in the Vulnerability Response Integration with Wiz is deprecated in Zurich. After upgrading to version 1.1, existing Wiz primary integrations must be backdated by three days and rerun.
    • For customers not upgrading to Unified Security Exposure Management (USEM), install Configuration Compliance versions below v30.x and supported third-party integration applications.

    Key Features and Enhancements

    • Wiz Integration Enhancements: Identify and select Wiz Resource Types to import across primary Wiz vulnerability and compliance integrations (excluding Wiz Container Vulnerability Integration). Wiz Backfill Integrations are activated by default to process missing assets data, improving asset visibility.
    • Properties Module: Introduced in v15.1, enables direct, user-friendly management of system property values within Configuration Compliance.
    • Customizable Test Result Calculations: Starting v15.1, users can configure how Age and Age Closed durations are calculated from various date fields (Created, Opened, First Found).
    • Qualys Integration Improvements: Ability to associate Qualys Tests with Test Groups and configure import granularity, allowing detailed visibility into individual findings per instance.
    • Vulnerability Manager and IT Remediation Workspaces: Enhancements from v24.0.6 allow search results and list navigation to open in these workspaces by default, conditional bulk editing of test results, re-evaluation of remediation properties, and customizable UI features such as hiding record counts and automatic dashboard refresh.
    • Remediation Task Enhancements: Improved state management and logic for remediation tasks and vulnerable items reduce manual efforts and clarify task ownership.
    • New Integration Parameters: Added parameter to ignore passed Qualys test results on import while still enabling correct closure of test results.
    • Dark Theme: Zurich introduces a dark theme option to improve readability and reduce eye strain for web and mobile users.

    Changes and Deprecated Features

    • Deprecated the Missing Assets [snvulwizmissingasset] table and the isignored column replaced by isresultignored in Host Test Results and Test Results integrations.
    • Removed the Reason field in the Resolve modal and Close button for remediation tasks across classic UI and workspaces in Xanadu.
    • Restricted deletion of test results to users with the snvulc.delete granular role instead of the admin role to enhance data integrity.
    • Source severity is now mapped to the Priority field on the Test Results table.
    • Wiz integration resource type configuration on the Resource Type Configuration tab takes precedence over integration instance parameter settings.

    Activation and Installation

    • Install Configuration Compliance and third-party integrations by requesting them from the ServiceNow Store starting from Yokohama and continuing through Zurich.
    • For cumulative release notes and app version histories, ServiceNow Store provides centralized information.

    Practical Guidance for ServiceNow Customers

    • Run Quick Start Tests after upgrades or new deployments to verify Configuration Compliance functionality, especially if customizations exist.
    • Manage Wiz integration carefully during upgrades, particularly addressing the deprecation of missing assets storage and backfill integration usage.
    • Utilize new workspace features for streamlined remediation workflows, bulk editing capabilities, and enhanced reporting visibility.
    • Configure properties and calculation settings to tailor compliance data and remediation timelines to organizational needs.
    • Leverage the new dark theme for improved user experience and accessibility.
    • Adopt the updated role-based privileges and property settings to maintain security and operational control.

    Consolidated page of all release notes for Configuration Compliance from Xanadu to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Configuration Compliance release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Configuration Compliance to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    If you are currently using Configuration Compliance, and you do not intend to upgrade to Unified Security Exposure Management (USEM), install a version below v30.x of Configuration Compliance and for upgrades to supported third-party integration applications.

    The Missing Assets [sn_vul_wiz_missing_asset] table used for storing assets imported by the backfill integrations for the Vulnerability Response Integration with Wiz is deprecated. If you are currently using the Vulnerability Response with Wiz integrations, after updating to version 1.1, you must backdate any of your existing Wiz primary integrations by three days and run them. Please review more information about the Wiz integration at SecOps articles on the Security Operations Community.

    For more information about the released versions of the Vulnerability Response application as well as the third-party and ServiceNow applications that are compatible with the Zurich release, see the Vulnerability Response Compatibility Matrix and Release Schema Changes [KB0856498] article in the Now Support Knowledge Base.

    New features

    Between your current release family and Zurich, new features were introduced for Configuration Compliance.

    Release Release notes

    Xanadu

    Identify Wiz Resource Types for import

    Identify the Resource Types (assets) reported by Wiz in your environment on the Wiz Integration Resource Type configuration page in your ServiceNow AI Platform instance that you want to import.

    The Resource Types that you select apply to all the primary Wiz vulnerability and compliance integrations except the Wiz Container Vulnerability Integration.

    Wiz Backfill Integrations
    Retrieve and process data stored on the Wiz Missing Assets [sn_vul_wiz_missing_asset] table for missing assets that were not processed by the primary compliance integrations with specialized Wiz Backfill Integrations.
    • Test Results Backfill Integration
    • Host Test Results Backfill Integration
    • Issues Backfill Integration

    The Wiz Backfill Integrations are activated by default.

    Wiz Host Test Result Vulnerability Integration
    Import test results associated with the resource type, VIRTUAL MACHINE with the Wiz Host Test Result Vulnerability Integration. This integration is activated by default.
    New Properties module
    Starting with v15.1 of Configuration Compliance, a new Properties module has been added to the navigation menu under the Administration section. This module enables direct modification of the values, offering a user-friendly method to manage and update system properties directly from the interface.
    Customize the calculation of Age and Age closed durations of a test result
    Starting with v15.1 of Configuration Compliance, the Age and Age Closed durations of a test result can be configured to be calculated from the date in the Created, Opened, or First Found fields.
    Associating a Qualys Test with its Test Group
    You can associate a Qualys Test with its Test Group by enabling the sn_vulc.add_policy_as_key system property. This helps you to identify the Test Group to which a Test Result belongs to and differentiate Test records with the same Test id that are associated with different Test Groups.
    Calculate the remediation target date of a remediation task with respect to the Last Opened date
    Starting with v15.1 of Configuration Compliance, you can customize the calculation of the remediation target date of a remediation task to be calculated with respect to the Last Opened date.
    Open the search results in the Vulnerability Manager Workspace or IT Remediation Workspace rather than the Classic UI
    Starting with v24.0.6 of Vulnerability Response, automatically open your search results in the Vulnerability Manager Workspace or IT Remediation Workspace rather than the Classic UI, by adjusting the application scope in the unified navigation bar to Vulnerability Manager Workspace or IT Remediation Workspace respectively. These application scopes are available to you based on your assigned role.
    Vulnerability Manager Workspace access to the sn_vulc.read role
    Starting with v24.0.6 of Vulnerability Response, as a user with the sn_vulc.read role, you can view the test results in the Vulnerability Manager Workspace.
    Navigate to the List page in the Vulnerability Manager Workspace or IT Remediation Workspace by selecting the links from the All menu
    Starting with v24.0.6 of Vulnerability Response, when you enable the 'sn_vul_cmn_ws.navigate_to_workspace' system property, selecting predefined filter links in the Configuration Compliance module from the 'All' menu will automatically open these links in the List page in the Vulnerability Manager Workspace or IT Remediation Workspace based on your role.
    Hide the record count on the lists in the Vulnerability Manager Workspace and IT Remediation Workspace
    Starting with v24.0.6 of Vulnerability Response, you can hide the record count on the lists in the List page of the Vulnerability Manager Workspace and IT Remediation Workspace by adding the table names to the glide.ui.list.seismic.omit.count system property.
    Enable automatic refresh for the Home page dashboard in the Vulnerability Manager Workspace
    Starting with v24.0.6 of Vulnerability Response, when creating and editing filters on the Configuration Test Results tab on the Home page of the Vulnerability Manager Workspace, you can configure the widgets to refresh automatically. Otherwise, you can manually refresh the widgets by selecting the Refresh button on the Configuration Test Results tab.
    Re-evaluating remediation properties for all records in the Vulnerability Manager Workspace
    Starting with v24.0.6 of Vulnerability Response, you can evaluate the remediation properties for all the test results from the Configuration Test Results list by selecting the All items in the Record selection field of the Re-evaluate remediation properties modal in the Vulnerability Manager Workspace.
    Re-evaluate remediation properties for test results in the Vulnerability Manager Workspace
    Select the test results conditionally for reevaluating the following remediation properties in Vulnerability Manager Workspace:
    • Assignments
    • Remediation tasks
    • Remediation target date
    • Exceptions (Vulnerability Response v24.0.6)
    • Risk score
    Using bulk edit for test results in the Vulnerability Manager Workspace
    Perform the following tasks on multiple test results simultaneously or a remediation task in Vulnerability Manager Workspace:
    Populating additional information for the test results
    The Age, Age closed, Closed date, Active, and Last open date columns have been added in the test results table.

    The test results that aren’t in the Closed state are marked as true in the Active field. The Active field replaces the Result and State fields in the filter conditions of the default-saved filters across the All menu, Configuration Compliance Overview, Unified, Cybersecurity Executive, and Health dashboards.

    CI compliance and test results compliance on a Test Group in the Vulnerability Manager Workspace
    View the percentage of CI compliance and test results compliance on a Test Group in Vulnerability Manager Workspace.
    Enabling or disabling the test results import for a Qualys test group in the Vulnerability Manager Workspace
    Enable or disable the import of test results for a Qualys test group in Vulnerability Manager Workspace.
    Updating Rollup weights section in the roll up calculators
    Other than the script format, an alternative approach of adding the weights in the Rollup Weights section for the rollup calculators has been introduced.
    Percentage test result compliance in the Discovered Items table
    The percentage of test results compliance of a CI is populated in the % Test Results Compliance column of the Discovered Item. To populate this value in the % Test Results Compliance column, set calcTRComplianceForCI to true in the Update remediation metrics scheduled job.
    Quick Start Tests for Configuration Compliance

    After upgrades and deployments of new applications or integrations, run quick start tests to verify that Configuration Compliance works as expected. If you customized Configuration Compliance, copy the quick start tests and configure them for your customizations.

    Yokohama

    Identify Wiz Resource Types for import

    Identify the Resource Types (assets) reported by Wiz in your environment on the Wiz Integration Resource Type configuration page in your ServiceNow AI Platform instance that you want to import.

    The Resource Types that you select apply to all the primary Wiz vulnerability and compliance integrations except the Wiz Container Vulnerability Integration.

    Wiz Backfill Integrations
    Retrieve and process data stored on the Wiz Missing Assets [sn_vul_wiz_missing_asset] table for missing assets that were not processed by the primary compliance integrations with specialized Wiz Backfill Integrations.
    • Test Results Backfill Integration
    • Host Test Results Backfill Integration
    • Issues Backfill Integration

    The Wiz Backfill Integrations are activated by default.

    Wiz Host Test Result Vulnerability Integration
    Import test results associated with the resource type, VIRTUAL MACHINE with the Wiz Host Test Result Vulnerability Integration. This integration is activated by default.
    Create remediation tasks manually in the Vulnerability Manager Workspace
    With the sn_vulc.admin role, you can create remediation tasks manually by selecting some or all the records in the Configuration Test Results lists in the Vulnerability Manager Workspace. These records are grouped into one or more remediation tasks according to the grouping criteria selected while creating remediation tasks.
    Create remediation tasks manually in the IT Remediation Workspace
    With the sn_vulc.remediation_owner role, you can create remediation tasks manually by selecting desired records in the Configuration Test Results lists in the IT Remediation Workspace. These records are grouped into one or more remediation tasks according to the grouping criteria selected while creating remediation tasks.
    View risk score details of a test result in the Work notes section
    Starting with v15.2.1 of Configuration Compliance, the system property sn_sec_cmn.risk_score_changes_add_worknotes is inactive by default. If you enable it, only then you can see all the changes related to the risk score of a test result in the Work notes section. Additionally, the work notes are updated only if there’s a change in the risk score.
    Quick Start Tests for Configuration Compliance

    After upgrades and deployments of new applications or integrations, run quick start tests to verify that Configuration Compliance works as expected. If you customized Configuration Compliance, copy the quick start tests and configure them for your customizations.

    Zurich

    Enhancements to the Vulnerability Response Integration with Wiz

    The Missing Assets [sn_vul_wiz_missing_asset] is deprecated. After updating to version 1.1, you must backdate your existing primary Wiz integrations by three days and run them.

    The backfill integrations are activated by default.

    After you backdate and run your integrations, the following backfill integrations are no longer required:
    • Host Vulnerability Backfill Integration
    • Test Results Backfill Integration
    • Host Test Results Backfill Integration
    • Issues Backfill Integration

    The [is_ignored] column is deprecated for the Host Test Results and Test Results Integrations. This column was replaced by the [is_result_ignored] column.

    Source severity is mapped to the Priority column on the Test Results [sn_vulc_result] table.

    Resource type filters are on the Test Results, Issues, and Host Test Results configuration tabs on the Wiz Configuration page. You can add any of the resource types listed.
    Note:

    If you configure resource types on the Resource Type Configuration tab, and you choose to configure parameters on the integration instance records, your configurations on integration instance take precedence over your settings on the Resource Type Configuration tab. See Identify Wiz Resource types for more information.

    Additional attributes imported from Wiz that are not stored in the Discovered items [sn_sec_cmn_src_ci] table are stamped with Asset Attributes in this table.

    Test results from the Host misconfiguration integration are classified as result type 'host_misconfiguration'.

    Data for resources that have the validated_at_runtime flag set to 'yes' is imported and populated on detections.

    The is_ignored column is deprecated on the Host Test Results and Test Results Integrations. This column was replaced by the is_result_ignored column.

    The CMDB internet-facing field on the discovered item is mapped to Limited Internet Exposure on findings.

    Column length for the descriptions in the Host Vulnerability import table has been increased.

    Qualys parameter to ignore passed test results
    Starting with v15.2.5 of Configuration Compliance, the ignore_passed_result integration instance parameter for the Qualys Integration for Security Operations has been added.

    This parameter is set to false by default so that passed test results imported by Qualys are not ignored.

    Set the parameter to true to ignore passed test results on import.
    Note:
    If activated, this parameter does not impact closure of the test results. For example, if you activate the parameter, and a failed test result from a previous import has since passed, it will be closed correctly.
    Identify Wiz Resource Types for import

    Identify the Resource Types (assets) reported by Wiz in your environment on the Wiz Integration Resource Type configuration page in your ServiceNow AI Platform instance that you want to import.

    The Resource Types that you select apply to all the primary Wiz vulnerability and compliance integrations except the Wiz Container Vulnerability Integration.

    Wiz Backfill Integrations
    Retrieve and process data stored on the Wiz Missing Assets [sn_vul_wiz_missing_asset] table for missing assets that were not processed by the primary compliance integrations with specialized Wiz Backfill Integrations.
    • Test Results Backfill Integration
    • Host Test Results Backfill Integration
    • Issues Backfill Integration

    The Wiz Backfill Integrations are activated by default.

    Wiz Host Test Result Vulnerability Integration
    Import test results associated with the resource type, VIRTUAL MACHINE with the Wiz Host Test Result Vulnerability Integration. This integration is activated by default.
    The Wiz Configuration Compliance (Test Results) and Issues Integrations
    • Import configuration test results with the Wiz Configuration Compliance Integration (Wiz Test Results) to detect non-compliant cloud configurations. Findings are mapped to cloud test results (CTRs) in the Configuration Compliance application to help you enforce security policies and standards across your cloud environment.
    • Import data with the Wiz Issues Integration that can help you identify assets that are involved in toxic combinations of vulnerabilities and misconfigurations. These findings are also mapped to CTRs with Wiz Issues labeled as the source to help you track and remediate assets that may pose complex multi-vector risks.

    Changes

    Between your current release family and Zurich, some changes were made to existing Configuration Compliance features.

    Release Release notes

    Xanadu

    Test result and remediation task state transitions
    Enhancements to policy audits for Security Posture Control verify that retired assets are not evaluated by activated policies. If the state of an asset transitions from Retired back to Active, it is included in the next policy evaluation.
    Non-zero risk score for passed test results
    The risk score is calculated for passed test results to determine how much risk is mitigated.
    Deprecated the privilege to delete a test result for the Admin role
    As an admin with the sn_vulc.admin role, you can’t delete a test result. This privilege is now given to the sn_vulc.delete granular role.
    Updates to the Risk Score calculation for a Remediation Task
    The average risk score of all the test results in a Remediation Task is considered for the risk score calculation of a Remediation task.

    Yokohama

    No updates for this release.

    Zurich

    Configure Test Result Granularity
    Starting with v15.6.1, you can configure the granularity of Tenable Configuration Test Results (CTRs) to split results into unique findings. For example, if a database has five instances, the system generates five distinct test results, one per instance, providing improved visibility into individual patching efforts.
    Configure Test Result Granularity
    Starting with v15.4.3, you can configure the granularity of Qualys Configuration Test Results (CTR) in configuration compliance and split CTRs into unique findings. For example, if a database has five instances, the system generates five distinct test results, one per instance, providing improved visibility into individual patching efforts.
    Configure maximum rows in related lists
    To improve readability and performance, you can now limit the number of rows shown in related lists on forms by setting the system property sn_vul_cmn.related_list.set_max_row.
    Improved state management for remediation tasks and vulnerable items
    State management logic for roll down of state from remediation tasks (RTs) to findings and roll up of state from findings to RTs has been refined across all modules. Updates improve accuracy by handling mixed item states (a combination of Deferred and Closed), supporting closure of tasks in sub-states like In-Review, and reopening tasks based on the Assigned To field. The update also improves handling of False Positive state transitions based on scanner results as source of truth. These enhancements reduce manual effort, clarify task ownership, and streamline remediation workflows.

    Removed

    Between your current release family and Zurich, some Configuration Compliance features or functionality were removed.

    Release Release notes

    Xanadu

    • The Reason field in the Resolve modal has been removed for a remediation task in the classic UI, Vulnerability Manager Workspace, and IT Remediation Workspace.
    • The Close button has been removed for a remediation task, in the classic UI, Vulnerability Manager Workspace, and IT Remediation Workspace.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some Configuration Compliance features or functionality were deprecated.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Activation information

    Review information on how to activate Configuration Compliance.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    Install Configuration Compliance by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Zurich

    Install Configuration Compliance and third-party integrations by requesting them from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Additional requirements

    If any additional requirements were introduced or changed for Configuration Compliance we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Configuration Compliance we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Accessibility information

    Review details on accessibility information for Configuration Compliance, such as specific requirements or compliance levels.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    Dark theme
    The new Coral theme includes a dark theme option for web and mobile experiences. This option is commonly used to alleviate eye strain and improve readability.

    Localization information

    If there are specific localization considerations for Configuration Compliance we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Configuration Compliance we have noted them here.

    Release Release notes

    Xanadu

    • Reevaluate the risk score, assignments, remediation target date, exceptions, and remediation task for a set of test results in Vulnerability Manager Workspace.
    • View the percentage of CI compliance and test results compliance on a Test Group in Vulnerability Manager Workspace.

    See Configuration Compliance for more information.

    Yokohama

    • With the sn_vulc.admin role, create remediation tasks manually in the Vulnerability Manager Workspace.
    • With the sn_vulc.remediation_owner role, create remediation tasks manually in the IT Remediation Workspace.

    See Configuration Compliance for more information.

    Zurich

    • If you are currently using Configuration Compliance and you want to upgrade to Unified Security Exposure Management (USEM), see Unified Security Exposure Management release notes for more information about USEM and the Unified Security Exposure Management migration.
    • Import Wiz issues and configuration test results from the Wiz scanners into test results in the Configuration Compliance application with the Vulnerability Response Integration with Wiz.
    • With the sn_vulc.remediation_owner role, create remediation tasks manually in the IT Remediation Workspace.
    • With the sn_vulc.admin role, create remediation tasks manually in the Vulnerability Manager Workspace.

    See Configuration Compliance for more information.