Plan your ServiceNow Store app
Ten questions give you a plan: what to build, what customers need licensed, the documents certification needs and a dated calendar. No email asked.
Know your route already? Browse all eleven plans, or see an example plan.
In our experience, most software companies building for ServiceNow need one of a handful of builds. Security vendors build for Vulnerability Response, Security Incident Response or Threat Intelligence Security Center, and compliance vendors for GRC. CMDB data needs a Service Graph Connector or a standard CMDB integration, and AI agents need an Action Fabric app.
Anything that lives inside ServiceNow is a scoped Store app, and a product that only keeps records in sync needs the minimum certifiable app. An integration for your own instance or a close partner’s may need no Store app at all. The planner above picks yours, using the rules on this page.
Which ServiceNow integration should a software company build?
Pick the build from what your product has to do inside ServiceNow. Each path changes what your customers must license and how long the route to a listing takes.
| Your situation | Build | What your customers need |
|---|---|---|
| You feed vulnerabilities, application or container findings, or configuration test results | A Vulnerability Response integration app | The application you feed: Vulnerability Response (Application Vulnerability Response is part of it), Container Vulnerability Response or Configuration Compliance; USEM from the Brazil release |
| Your alerts should become security incidents, or you offer response actions | A Security Incident Response integration app | Security Incident Response (for a DLP tool, Data Loss Prevention Incident Response) |
| You supply threat intelligence | A threat intelligence integration app | Threat Intelligence Security Center |
| You supply compliance content, control checks or regulatory change | A GRC (IRM) integration app | The IRM application you feed |
| Your data belongs in the CMDB: devices, cloud resources, software | A Service Graph Connector, or a standard CMDB integration | For a Service Graph Connector, subscription-unit-based ITOM Visibility or Discovery; for some identified connectors, an ITAM subscription-unit product |
| ServiceNow’s AI agents should call your product, or your agent should act in ServiceNow | An Action Fabric app (MCP or A2A) | The AI their ServiceNow package includes, and an assists estimate from you |
| You need your own screens, data or workflow inside ServiceNow | A scoped Store app | Any product whose tables you use; App Engine for a free app’s custom tables, unless it’s of type Integration |
| You create or update records, such as keeping tickets in sync, for customers | The minimum certifiable Store app | The products whose records you write |
| The integration is for your own instance or a close partner’s | No Store app: integrate through the API | An integration user; IntegrationHub transactions if their flows call you |
| You built a prototype on a personal developer instance | Get it converted when you join, then certify | As for your target build |
| You already have a Store listing | A release certification, or a recertification | Unchanged, unless you add features |
Where you are comes first.
- An app that’s already listed (a new release, a changed version, or findings on a new version) goes to the existing-listing plan.
- A prototype on a personal developer instance goes to the developer-instance plan, which names your target build.
- The exception is a prototype only for your own instance or a close partner’s, whose target build is a direct API integration. That goes to the direct API plan.
Otherwise the planner picks the most specialised build, in the order of this table, and lists the others as “also consider”. A product that only creates or updates records goes to the scoped Store app plan if it’s already built on ServiceNow. It goes to the direct API plan if it’s only for your own instance or a close partner’s. Findings on a first submission follow your build’s plan.
What will your customers need to license?
Your design decides your customers’ bill as much as your own price does. The rules below are our reading of ServiceNow’s public documents and Store listings, not licensing advice. Each customer’s own agreement decides, so have them confirm with their ServiceNow account team.
- Custom tables. ServiceNow’s Custom Table Guide (October 2025) says paid partner-built apps “transacted on the ServiceNow Store with a contract value greater than zero dollars ($0), do not consume Custom Tables”, and that free apps of type Integration “are exempted from the Custom Table count”. Other free apps need App Engine entitlement, and either exemption ends once the app “is expanded with the creation of additional Custom Tables”.
- Products you depend on. If your app reads or writes a licensed product’s tables, such as ITSM, CSM, HR, a Security Operations application or an IRM application, the customer needs that product. In the customer’s instance, Application Manager can show your app as “Not Licensed”; ServiceNow lists “A required dependency is not licensed” among the possible causes (KB2632787).
- IntegrationHub transactions, when customers’ own flows call your product. ServiceNow defines an IntegrationHub transaction as “any outbound call originating from Integration Hub, Flow Designer, Remote Tables, or Orchestration”, and says transactions “are not included in ServiceNow product Subscriptions” (Integration Hub and Workflow Data Fabric overview).
- ITOM or ITAM for a Service Graph Connector. ServiceNow’s connector listings say: “Usage of this Service Graph Connector requires a subscription to a Subscription Unit based IT Operations Management (ITOM) Visibility or ITOM Discovery application.” ServiceNow’s Service Graph Connector Licensing listing also lets “identified third-party Service Graph Connectors” be “entitled with specific ITOM SU or ITAM SU based SKUs”. A standard CMDB integration doesn’t carry that requirement.
- AI and assists. ServiceNow says “every ServiceNow customer now starts with a complete AI package” (April 2026), in tiers customers choose from. Its Action Fabric guide lists a “Now Assist SKU for the relevant domain (ITSM, ITOM, etc.)” for the MCP server console. AI use is metered in assists, and the Store’s licensing requirements say: “Partners are required to provide Customers with an estimate of how many assists may be consumed through use of their Apps.”
What documents does ServiceNow certification need?
More than most teams expect, and in our experience it’s the part they miss. ServiceNow’s certification guide says “Certification has two tracks”: an app review and a listing review.
- For the app review, ServiceNow asks for a “Design Document (for certification team only)”, a “Test Plan with results (for certification team only)” and an “Installation Guide (customer facing)”. Write the design document and test plan on ServiceNow’s templates; it provides a recommended template for the installation guide too.
- For the listing review, your Store listing “consists of marketing documentation, demo videos, and other resources”, and the team inspects it for “Accuracy” and “Adherence to branding guidelines”.
ServiceNow lists “How well you documented your architecture in your Design Documentation” among the things that decide how long certification takes. Every new Store build here gives the documents a week of their own. The Service Graph Connector and AI plans say what their paths add, and the existing-listing plan says what each kind of recertification needs.
Can a product hosted outside ServiceNow be listed on the Store?
Yes, as an installable, certified app: in our experience a link or a brochure won’t do. ServiceNow’s certification guidance says the app “should have minimum files such as application menu, contact support module and a working use case”. It adds that “any app that doesn’t have any code or any business logic is not recommended”. The minimum certifiable Store app plan covers it.
Outside the Store, your pieces go into a customer’s instance as an update set or a similar import. None of it is certified, so that route suits only your own instance or a close partner.
Can you build a Store app on a personal developer instance?
You can prototype on one, but you can’t submit from one. ServiceNow’s KB0794197 says “Partners can publish to the ServiceNow Store only from a vendor instance”. The KB also says “every partner receives two vendor instances”. They are initially provisioned on the release family “two releases prior to the current release (N-2)”, and they come with membership of ServiceNow’s Build Program.
When you apply to the Build Program, say which developer instance you want converted into a vendor instance. In our experience ServiceNow converts it as part of joining, so the work carries over. Copying the app into a new vendor instance instead leaves it under a prefix you don’t own.
Not ready to enrol fully? ServiceNow’s January 2026 announcement says “A new Access Tier also invites aspiring and entry-stage partners to start building immediately”. Check with ServiceNow what it includes. The developer-instance plan covers the rest.
How long does it take to get a ServiceNow Store app listed?
In our projects it takes between about 6 and 23 weeks from the start of design, depending on the build. Of that, ServiceNow says certification “typically requires 3-5 weeks”, and no service level is published. The rest is design, build, the certification documents and, for a Service Graph Connector, the programme’s design review and customer validation. In our experience that programme step is the longest.
Add Build Program admission, which we allow 2–6 weeks for, if you haven’t joined. On the security and GRC frameworks, experience is the biggest variable. Design runs 4–6 weeks for a team new to them and 1–2 for one that knows them.
| Plan | Weeks | ServiceNow review |
|---|---|---|
| As a Service Graph Connector | 17–23 | Yes, 3–5 weeks |
| As a standard CMDB integration | 7–11 | Yes, 3–5 weeks |
| Vulnerability Response integration | 11–17 (8–13 experienced) | Yes, 3–5 weeks |
| Security Incident Response integration | 11–17 (8–13 experienced) | Yes, 3–5 weeks |
| Threat intelligence integration | 11–17 (8–13 experienced) | Yes, 3–5 weeks |
| GRC (IRM) integration | 11–17 (8–13 experienced) | Yes, 3–5 weeks |
| AI agent integration (Action Fabric) | Sized with you | Yes, 3–5 weeks |
| Scoped Store app | 7–11 | Yes, 3–5 weeks |
| Minimum certifiable Store app | 6–9 | Yes, 3–5 weeks |
| Direct API integration | 2–4 | No certification |
| Built on a personal developer instance | 5–12 | Yes, 3–5 weeks |
| Release certification (no code or listing changes) | 2–3 | Yes, 1–2 weeks (our experience) |
| Recertification (any change to the app) | 4–8 | Yes, 3–5 weeks |
Weeks come from our own projects, except ServiceNow’s 3–5 week review. For new builds they run from the start of design to a Store listing, including a week for the certification documents. For the direct API plan, they run to a working integration.
For an existing listing, the weeks run from upgrading your vendor instance (release certification) or starting the changes (recertification) to the new version being certified. For the developer-instance plan they run from joining the Build Program. Add Build Program admission, which we allow 2–6 weeks for, if you haven’t joined. “Experienced” means a team that already knows the framework.
What does it take to keep a Store app listed?
In our experience a listing stays live while it’s certified on one of the last three family releases, and one outside that window is unpublished. ServiceNow’s Upgrade Policy says it “generally releases two new release families per year”. We plan maintenance as a release certification for each one, so a listing stays well inside that window (see our n-3 guide).
ServiceNow’s App Publisher blog (February 2023) separates the two kinds of certification that follow the first, and calls both of them recertifying. An app you don’t change gets what we call a release certification. The blog’s post on new releases asks for “a revised version of your Scoped Application Test Plan along with the results”. In our experience that review takes 1–2 weeks.
Any change to the code or the listing means you “must re-submit the app for app and listing re-certification” (the blog’s post on code changes). The resubmission is reviewed like a new app, so plan every change as new work. The existing-listing plan dates both.
What does it cost to list an app on the ServiceNow Store?
ServiceNow charges an annual Build Program membership fee, which it quotes when you apply. In January 2026 it announced that “all global partners will move to a streamlined single annual membership fee”. The larger, more variable cost is engineering: the build, the certification documents, each round of certification findings, and a release certification for each family release.
All eleven plans
Every plan the planner can give, each complete on its own page.
- Service Graph Connector or CMDB integration For vendors whose product knows about devices, cloud resources or software that ServiceNow customers track as configuration items.
- Vulnerability Response integration For infrastructure, application-security, container and configuration scanners, and vulnerability-intelligence vendors, whose customers run ServiceNow Vulnerability Response.
- Security Incident Response integration For SIEM, EDR and XDR, email-security and network-security vendors whose customers run ServiceNow Security Incident Response.
- Threat intelligence integration For threat-intelligence feed and enrichment vendors whose customers run ServiceNow Threat Intelligence Security Center (TISC).
- GRC (IRM) integration For compliance-content, control-testing and regulatory-intelligence vendors whose customers run ServiceNow Integrated Risk Management (GRC).
- AI agent integration (Action Fabric) For vendors with an MCP server, an AI agent or tools that customers want ServiceNow’s agents to call, or that need to act in ServiceNow.
- Scoped Store app For vendors whose product has to live inside ServiceNow, with its own data model, forms, workspaces or workflow, not just exchange data with it.
- Minimum certifiable Store app For SaaS and on-premises vendors whose customers want records kept in sync by a certified ServiceNow app, often after a security or platform review.
- Direct API integration For integrations with your own ServiceNow instance, or a close partner’s, where nobody needs a certified app.
- Built on a personal developer instance For teams that prototyped their Store app on a free personal developer instance before joining ServiceNow’s Build Program.
- Existing listing: release certification or recertification For publishers with a live Store app that needs certifying for a new release, a new version certified, or an answer to certification findings.
How the planner works
The planner applies the rules on this page to your answers and sends you to the matching plan, with your own dates added. Your answers stay in your browser. They travel after the # in your plan’s link, which browsers never send to any server, so you can share the link.
Our web server logs which plan page opened. Its address carries ?via=planner when you came from the questions, and ?via=share when you reopen a saved or shared plan. Our cookieless page events count how far a page was read, which questions were reached and which plan buttons were used, never your answers. We see your answers only if you send your plan through the contact form. To stop the page events on this device, use “Opt out of measurement” at the foot of this page or in our cookie policy.
Sources
- Guide to getting your app certified (KB1270874)
- Technology Partner Program: vendor instances (KB0794197)
- Recertifying your app for new ServiceNow releases
- Recertifying your app with code changes
- ServiceNow Upgrade Policy
- Top ten failed certification checks
- Custom Table Guide
- Integration Hub and Workflow Data Fabric overview
- ServiceNow moves beyond the sidecar AI era (9 April 2026)
- ServiceNow enhances global Partner Program (20 January 2026)
- ServiceNow Store app installation, updates, and terms and conditions acceptance (KB2632787)
- Service Graph Connector Licensing (Store listing)
- Service Graph Connector for Microsoft Intune (Store listing)
- ServiceNow Store licensing requirements (shown on every listing)
- Action Fabric: MCP server, MCP client and A2A explained
- ServiceNow app certification guide (XpertApps)
Rather talk it through first?
Tell us what you’re building and we’ll map the path and give you a fixed-scope estimate. You get a personal reply within 24 business hours.
Book a Free Consultationcheck_circleFounded by a former ServiceNow certification team member check_circle25+ apps taken through certification check_circleFree project scoping