On this page

ServiceNow has an annual SOC 2 Type II report. ServiceNow says the report covers Security, Availability, and Confidentiality controls, runs from October 1 of the prior calendar year through September 30 of the current year, and becomes available through ServiceNow CORE by the end of December. If you need the document for a vendor review or your own audit, start in ServiceNow Support, open Trust Center, and select the CORE Compliance Portal. Access rights may be required.

That answers the download question, but not the ambiguity behind it. “ServiceNow SOC 2” can refer to three different jobs:

What you are trying to doWhat ServiceNow providesWhat to use
Assess ServiceNow as one of your vendorsServiceNow’s own SOC 2 Type II report and bridge letterCORE Compliance Portal; use TrustShare and the public compliance page to confirm the assurance family
Prove that your team followed an operational controlIncident, change, access, approval, and other workflow records generated in your ServiceNow instanceExport or retain the relevant records as evidence for your controls
Run your company’s SOC 2 programControl mapping, ownership, attestations, tests, evidence requests, issues, and audit engagements in ServiceNow IRMPolicy and Compliance Management plus the audit capabilities your implementation requires

The first report is about ServiceNow’s controls as a service provider. It does not make a ServiceNow customer SOC 2 compliant. The third use can help a customer run its own control program, but an independent licensed CPA firm still has to perform the examination and issue that customer’s report. For the second job, our guide to SOC 2 evidence collection shows how to tie workflow records to controls.

How to get the current ServiceNow SOC 2 report

Use the controlled distribution path rather than searching for an old PDF on the open web.

  1. Sign in to ServiceNow Support.
  2. Open Trust Center and select CORE Compliance Portal.
  3. Locate the current SOC 2 Type II report for the ServiceNow service and region you use.
  4. If the category or document is missing, ask your ServiceNow administrator, account team, or Support to confirm your access rights.
  5. Download the current bridge letter when your review date extends beyond the report’s period.

ServiceNow’s public compliance page is the best public source for confirming that the attestation exists and understanding its normal reporting cycle. ServiceNow’s public Trust and Compliance Center and TrustShare certification index are useful orientation pages, but the report itself is distributed through CORE.

An older accepted ServiceNow Community answer also directs customers to CORE. A later thread says users with the right support-portal permissions can reach the document through Trust Center → CORE Compliance Portal. Treat those threads as navigation clues; use the current compliance page and the dates inside the document as the source of truth.

Check the report before you send it to an auditor or customer

Do not label the first PDF you find “current” without opening it. Confirm these fields:

CheckWhat to verifyWhy it matters
Report typeSOC 2 Type IIA Type II report addresses operating effectiveness over a period; a different assurance document answers a different question
PeriodThe exact start and end dates in the independent auditor’s reportThe document may not cover the date your reviewer is assessing
Service scopeThe ServiceNow services, environments, and regions listed in scopeA report for one service boundary cannot be assumed to cover every product or deployment
Trust Services CriteriaWhich of Security, Availability, Confidentiality, Processing Integrity, or Privacy are actually coveredServiceNow publicly describes Security, Availability, and Confidentiality; use the report for the definitive scope
Auditor opinion and exceptionsThe opinion, tests, results, and any noted deviationsA SOC 2 report is evidence to evaluate, not a badge to collect
Complementary controlsControls ServiceNow expects customers to operateYour organization may need separate evidence for its side of the shared-control boundary

The SOC 2 audit report guide covers the opinion, tests, and exceptions in a report like this.

ServiceNow says its standard annual report period ends September 30 and the report is available by the end of December. It also says the SOC 2 bridge letter covers October 1 through December 31 and is available by the end of the following first quarter. If your assurance request falls outside those dates, do not assume the bridge letter closes every gap. Ask ServiceNow and your auditor what evidence is needed for the period under review.

What the ServiceNow report proves—and what it does not

ServiceNow’s report gives customers and their auditors independent assurance over the ServiceNow service organization and the controls included in the report. It can support your vendor-risk review and the inherited or shared controls in your own SOC 2 evidence package.

It does not prove that:

  • your ServiceNow instance is configured securely;
  • your administrators use appropriate roles and approvals;
  • your incident, change, access, or vendor-risk workflows operate as designed;
  • your company’s controls met the Trust Services Criteria; or
  • your company has passed a SOC 2 audit.

For your own audit, map the provider report only to controls that actually depend on ServiceNow’s service-organization controls. Pair it with tenant-specific evidence for configuration, access, approvals, exceptions, and the operation of your workflows. This is the same shared-control principle used for any important SaaS provider.

Can ServiceNow IRM run your own SOC 2 program?

Yes—for the right enterprise buyer. Current ServiceNow IRM documentation says the platform can continuously assess controls, automate control testing, and centralize audit evidence. Policy and Compliance Management centralizes policies, control objectives, controls, tests, frequencies, attestations, and mappings from authoritative sources. Audit Management adds engagement planning, audit tasks, control testing, evidence requests, and findings.

For SOC 2 specifically, an accepted ServiceNow Community answer describes selecting relevant controls through UCF integration, assigning control owners, performing attestations, gathering evidence of control effectiveness, and using Audit Management for the engagement. That is a real SOC 2 operating model, even though the reviewed public materials do not establish a dedicated, preconfigured SOC 2 point product comparable to a startup-focused compliance platform.

  • Choose ServiceNow IRM when your company already runs ServiceNow, has a dedicated compliance team, and needs SOC 2 inside a broader multi-framework risk program.
  • Compare implementation scope carefully. Policy and Compliance Management, Audit Management, UCF content, integrations, implementation services, and external-auditor access should be named in the proposal.
  • Do not expect the subscription to include the independent SOC 2 examination.
  • Prefer a purpose-built SOC 2 platform when a small team needs a faster, more preconfigured first-audit workflow and transparent implementation boundaries.

See our source-checked ServiceNow IRM SOC 2 software profile for the capability evidence, fit limits, pricing-disclosure status, and comparison notes.

Which ServiceNow SOC 2 path do you need?

If a customer or vendor-risk reviewer asked for ServiceNow’s report, use CORE and send the current Type II report plus the applicable bridge letter under the document’s distribution terms.

If your auditor asked for evidence from ServiceNow, identify the control first, then export the incident, change, access, approval, or other record that proves your team operated it. ServiceNow’s own report will not replace tenant-level evidence for your process. Our SOC 2 evidence request list covers what to pull from a ticketing system like ServiceNow and which auditor requests each export answers.

If you are choosing software to manage your SOC 2 program, evaluate ServiceNow IRM as an enterprise GRC platform. It belongs on the shortlist for complex organizations already invested in ServiceNow; it is usually a poor default for a small company buying its first compliance tool. To see the alternatives, compare SOC 2 compliance software.

And if you need the firm that will issue your company’s report, compare licensed SOC 2 auditors. Software can organize the work. Only the independent CPA firm can issue the attestation.