Vulnerabilities or scan findings: build for Vulnerability Response
For infrastructure, application-security, container and configuration scanners, and vulnerability-intelligence vendors, whose customers run ServiceNow Vulnerability Response.
If your product finds vulnerabilities, build a scoped Store app on ServiceNow’s Vulnerability Response integration framework. Your findings then land in the records security teams already work. The framework serves Vulnerability Response, Application Vulnerability Response, Container Vulnerability Response and Configuration Compliance.
Plan for one date now. ServiceNow says “USEM will become the required version of VR starting with the Brazil platform release”. USEM is Unified Security Exposure Management, and VR is Vulnerability Response. Brazil reached early-availability customers on 24 September 2026, and ServiceNow targets general availability for early November.
When this plan fits
- Your product finds infrastructure vulnerabilities, or produces application-security findings (DAST, SAST, SCA and more), container findings or configuration test results that customers triage in ServiceNow.
- Or you sell vulnerability intelligence, such as exploit context for CVEs, that enriches the vulnerability data customers already hold.
- Your customers run Vulnerability Response, or the application your findings belong in.
- You want findings tied to configuration items in the customer’s CMDB.
- Check first whether ServiceNow already ships an integration for your product; it builds its own for several large scanners, so yours has to add something theirs doesn’t.
What your customers will need licensed
- Customers need the application your findings go into: Vulnerability Response (Application Vulnerability Response is part of it), Container Vulnerability Response or Configuration Compliance. In the customer’s instance, Application Manager can show your app as “Not Licensed”; ServiceNow lists “A required dependency is not licensed” among the possible causes.
- Linking findings to CIs relies on the customer’s own CMDB data.
- If your app is free, list it as type Integration: the Store says free apps of type Integration “are exempted from the custom table count and do not require custom table entitlement.” A free app of any other type uses each customer’s custom-table entitlement.
What you need before you start
- Build Program membership, and vendor instances that can run the Security Operations plugins you need. Confirm plugin access before you plan the build.
- Test data that exercises your real finding types and volumes, not demo records.
- A plan for USEM: build against the version customers will run after the Brazil release.
- ServiceNow’s Security Operations integration development guidelines, which say: “Any requirements for application certification or guidelines given in the Technology Partner Program literature supersede any information in this guide.”
The documents certification needs
Certification reviews your documents as well as your app, and in our experience it’s the part most teams miss. ServiceNow’s certification guide says “Certification has two tracks”: an app review and a listing review.
- For the app review, ServiceNow asks for a “Design Document (for certification team only)”, a “Test Plan with results (for certification team only)” and an “Installation Guide (customer facing)”. Write the design document and test plan on ServiceNow’s templates; it provides a recommended template for the installation guide too.
- For the listing review, your Store listing “consists of marketing documentation, demo videos, and other resources”, and the team inspects it for “Accuracy” and “Adherence to branding guidelines”.
ServiceNow lists “How well you documented your architecture in your Design Documentation” among the things that decide how long certification takes. The calendar gives the documents a week of their own.
Calendar to a Store listing
Plan on roughly 11–17 weeks (8–13 with a team that already knows the framework) from the start of design to a Store listing. The framework takes time to learn, and design is where that time goes.
| Phase | Weeks | Notes |
|---|---|---|
| Design | 4–6 | 1–2 weeks with a team that already knows the framework |
| Build and test | 3–5 | |
| Certification documents | 1 | Design document, test plan, installation guide and listing |
| ServiceNow certification review | 3–5 | ServiceNow’s typical range; no SLA is published |
Not in ServiceNow’s Build Program yet? Add admission first: in our experience it takes 2–6 weeks, because ServiceNow reviews each application.
Weeks for design, build, documents and any programme steps come from our own projects. The review range is ServiceNow’s: certification “typically requires 3-5 weeks”, and no service level is published.
Certification risks on this path
- Writing to Vulnerability Response tables directly instead of through the integration framework. For the move to USEM, ServiceNow says: “There should be no changes to custom integrations leveraging the integration framework.”
- API credentials stored in properties or scripts instead of credential records.
- Large scheduled imports without batching; performance is one of the review areas.
- Missing ACLs on custom tables, and client-callable script includes without ACLs, both in ServiceNow’s ten most-failed checks.
After launch
- Maintenance is a release certification for each family release: retest on the new release and submit a revised test plan. ServiceNow’s Upgrade Policy says it “generally releases two new release families per year”. Any change to the app is a recertification, planned as new work. Retest when ServiceNow updates its Security Operations applications.
- Track the USEM change: customers on Brazil or later will be on USEM.
What your prospect’s security reviewer will ask
- What data leaves their instance, and in which direction.
- Which service account the integration runs as. Expect them to reject admin; use a dedicated integration role.
- Whether it’s certified, and what that covers. Certification is strict on most security and performance issues, but it isn’t a full security audit, and the Store’s terms still leave use at the customer’s own risk. Have your own security answers ready.
Sources
- Vulnerability Response Integration Framework (Store listing)
- Vulnerability Response (ServiceNow docs)
- Exploring Application Vulnerability Response (ServiceNow docs)
- Container Vulnerability Response (ServiceNow docs)
- Configuration Compliance (ServiceNow docs)
- Vulnerability Response CI lookup rules (ServiceNow docs)
- Security Operations integration development guidelines (ServiceNow docs)
- USEM office hours: FAQs, migration and adoption
- ServiceNow Store app installation, updates, and terms and conditions acceptance (KB2632787)
- Guide to getting your app certified (KB1270874)
- Top ten failed certification checks
- Custom Table Guide
- ServiceNow Store licensing requirements (shown on every listing)
- ServiceNow Upgrade Policy
- Brazil release notes: available patches and hotfixes
- Brazil release dates (Community thread, ServiceNow reply, June 2026)
- ServiceNow Store Terms of Use (reseller edition, 2020; public copy hosted by Carahsoft)
Review this plan with our team
We’ll check your plan with no commitment: the build path, what your customers will need, and a fixed-scope estimate. Personal reply within 24 business hours.
Review my plancheck_circleFounded by a former ServiceNow certification team member check_circle25+ apps taken through certification check_circleFree project scoping