Your 2026 Guide to Qualys and ServiceNow Integrations: What’s New, What Matters, and What to Use

Bob Beliveau

Key Takeaways

  • The Qualys–ServiceNow integrations connect prioritized risk detection and remediation workflows, eliminating manual handoffs between security and IT teams 
  • Without integration, vulnerability management relies on manual exports, spreadsheet tracking, and disconnected ticketing, leading to delays and data inconsistencies – woefully inadequate today 
  • Integrated workflows improve cyber risk management through automatic ticket creation, assignment, tracking, and closure based on real-time, prioritized security findings, achieving faster remediation cycles, improved data integrity, and consistent accountability across teams 
  • AI with Hyper Prioritization in Qualys ETM is your best defense against adversaries using AI 
  • CMDB synchronization is foundational – accurate asset context determines ownership, prioritization, and workflow routing 
  • Automated integrations ensure that vulnerabilities are mapped to the correct CMDB configuration items (CIs), reducing duplication, misassignment, and missed remediation 
  • Pre-built, certified integrations reduce operational risk by replacing custom scripts and fragmented processes with tested and supported workflows 

Why the Qualys–ServiceNow Stack Matters in 2026

Artificial intelligence (AI) has fundamentally changed cybersecurity in 2026. Attackers are using AI models to discover and weaponize vulnerabilities at a speed that far outpaces manual human remediation, usually exceeding the capability of most automated remediation workflows as well. 

Bad actors are using AI tools to launch hyper-targeted, autonomous, enterprise reconnaissance and attacks at machine speed. Agentic AI is being leveraged to autonomously identify new vulnerabilities, create new POCs, identify exploit targets, and launch exploits against your valuable cyber assets.

Not only are attackers better and faster, but recent AI frontier modes have kicked open the door to even more potential attackers with less sophisticated software skills to threaten organizations. This 2026 reality has forced defenders into a continuous, real-time “AI vs. AI” arms race against adversaries who are both much better and more numerous than before.    

Now is the time to step up your defenses to help level the playing field.  Organizations need to work to aggressively phase out legacy, manual security models and implement streamlined remediation workflows and AI predictive defense capabilities that can identify, isolate, patch and remediate vulnerabilities faster than adversarial agents can exploit them. 

Qualys ETM: Driving Hyper Prioritization Today 

Qualys Enterprise TruRisk Management (ETM) fully enables hyper-prioritization by reducing massive volumes of exposures down to the 1-2% that are actually exploitable, validated in your environment, and pose real business risk 

Without Qualys ETM, organizations that use ServiceNow’s Vulnerability Response and who upgraded to Unified Security Exposure Management (USEM) prioritization rely primarily on native scoring inputs such as NVD severity, CISA KEV, EPSS probability, threat intelligence, MITRE ATT&CK mappings, and CMDB business context. While useful, these signals can still produce broad severity-based queues that increase MTTR and contribute to alert fatigue. 

With Qualys ETM enrichment, organizations gain additional validated intelligence, including TruRisk Score, TruConfirm validation, RTIs for active attacks and wormable vulnerabilities, exploit code maturity, patch reliability, and asset criticality scoring. These enriched findings allow ServiceNow USEM to create validated, risk-based remediation queues with stronger prioritization accuracy, shorter MTTR, audit-ready evidence, and more defensible remediation decisions.

Qualys Policy Audit: Continuous Audit-Readiness at Machine Speed, Integrated with ServiceNow

Qualys Policy Audit delivers AI-driven, continuous audit-readiness across 100+ regulatory frameworks. Instead of treating compliance as a periodic scramble before each audit, Policy Audit operates as an always-on program that continuously identifies control gaps and misconfigurations, prioritizes them by real risk, automates remediation through ServiceNow workflows at machine speed, and produces audit-ready reports on demand. The result: security, IT, and compliance teams work in collaboration from a single platform, audits stop being fire drills, and exposure gets reduced where it matters, and at the pace AI-driven attackers are now moving.

Policy Audit continuously validates controls against CIS, NIST, PCI, ISO, and other benchmarks using real-time telemetry and AI-powered analysis, surfacing control and compliance gaps the moment they emerge.

Through native integration with ServiceNow ITSM and GRC, every step of the Policy Audit cycle flows directly into the workflows your teams already use:

  • Discover — End-to-end compliance visibility. Continuously discover every asset across endpoints, servers, cloud, and containers, mapped to the controls that matter for each framework.
  • Prioritize — AI-driven, risk-based gap analysis. TruRisk and QDS apply machine learning to cut through the noise of low-impact failures, surfacing the misconfigurations tied to real exposure, MITRE ATT&CK techniques, and ransomware behaviors.
  • Remediate — Integrated compliance automation at machine speed. Audit Fix deploys pre-built scripts mapped to CIS, STIG, and PCI controls through ServiceNow ITSM workflows to help close gaps in minutes, not weeks.
  • Report — Audit-ready reports with TruRisk. Generate reports across 100+ frameworks from a single data collection, fed directly into ServiceNow GRC that’s always audit-ready, on demand.
  • Monitor — Detect compliance gaps in real time. Continuously catch control gaps, unauthorized configuration changes, and manage fixes before they become audit findings.

The combination of Qualys Policy Audit and ServiceNow transforms compliance from a quarterly scramble into continuous, AI-driven audit-readiness that operates at machine speed. Control gaps are found before auditors or attackers do, remediation happens through workflows that IT and security teams already trust, and audit-ready evidence is always one click away. This allows teams to focus on reducing real risk instead of chasing reports, matching the speed of an AI-driven threat landscape.

Improve Your Cyber Risk Management with Qualys’ Multiple ServiceNow Integration Options

Qualys continues to enhance its ServiceNow integrations, offering a flexible set of options that support remediation workflows for all ServiceNow customers, whether they have licensed only ServiceNow’s base ITSM package or have invested in ServiceNow’s Vulnerability Response VR/USEM offering.

All integrations are packaged as ServiceNow Store applications, certified by ServiceNow and continuously validated to ensure compatibility with each new ServiceNow release.

Most of these integrations are developed and supported by Qualys, while some are developed and supported by ServiceNow, as noted below.

CMDB Integrations

Integration AppsDescription
Qualys CMDB Sync

Or

Qualys CMDB Bi-directional Sync

NOTE: Qualys CMDB Sync application is no longer available to new Qualys customers. New customers must use the Qualys CMDB Bi-Directional sync integration instead.    
License Dependencies: Qualys CSAM, ServiceNow ITSM  

Supported by: Qualys

Key Functionalities:

Sync data between systems in either or both directions

Sync Qualys Asset data to ServiceNow CMDB CIs

Sync CSAM risk findings, such as software and port authorizations, missing required SW, Tech Debt (EOL/EOS), EASM, and certificate data to Qualys app tables in ServiceNow, that can be referenced from CIs using Related Lists

Sync CIs and or Business Metadata back to Qualys, including Operational Status, Owner, Support group, Department, Environment, related applications, and their Business criticality, as well as custom attributes

Highly configurable for asset scope, schedule frequency, field, and class mappings

Uses the ServiceNow Identification and Reconciliation Engine (IRE) for matching Qualys Assets to CIs, with control over class upgrade/downgrade/switch

Stages data into Qualys-scoped staging tables in ServiceNow, allowing you to review the data before submitting to IRE for CMDB updates

Populate either ITSM SW tables or SAM Pro Software tables

Brings Cloud Metadata from Qualys into ServiceNow (VM Instances, datacenter, networks/VPCs, images, etc.) into the CMDB if you have licensed ServiceNow Discovery. If Discovery is not licensed, this data is still stored in Qualys app tables in ServiceNow
Service Graph Connector for QualysLicense Dependencies: Qualys CSAM or GAV, ServiceNow ITOM  

Supported by: ServiceNow

Key Functionalities:

One Way Sync only – Qualys Assets to ServiceNow CIs

Integrates with Service Graph Dashboards

Does not sync: EOL/EOS Info (Tech Debt), External Attack Surface information, SSL Certificates, Asset groups

Lacks many of the options available in the Qualys-supported CMDB apps to select assets and control how the data is transformed and matched.

This is your only pre-built option if you do not have Qualys CSAM or if you require data visibility into Service Graph dashboards

ITSM Ticketing Integrations

Integration AppsDescription
Qualys VMDR Plus Qualys Core

License Dependencies: Qualys VMDR, ServiceNow ITSM  

Supported by: Qualys

Two Qualys apps (Core and VMDR) work together to:

Bring VMDR Host detections and vulnerability findings into ServiceNow Incidents

Creates ServiceNow Tasks to address those Incidents

Automatic or manual Task assignments to Assignment Groups

Re-Scan and automatically close out the Tasks once the vulnerabilities are remediated

Sync the VMDR-related KnowledgeBase entries from Qualys with ServiceNow
Qualys Policy Audit Plus Qualys CoreLicense Dependencies: Qualys Policy Audit (PA), ServiceNow ITSM  

Supported by: Qualys

Two Qualys apps (Core and Policy Audit) work together to:

Import Qualys Policy Audit findings into ServiceNow on-demand or on schedule

Automatically assign Qualys Policy Audit incidents for posture failures  to the appropriate owners

Automatically close out incidents once postures are corrected in Qualys

Define SLA based on Asset, Posture, Threat Exposure

Automatically measure the remediation timelines

Launch targeted Posture scans
Qualys FIM Plus Qualys CoreLicense Dependencies: Qualys File Integrity Monitoring (FIM), ServiceNow ITSM  

Supported by: Qualys

Two Qualys apps (Core and FIM) work together to:

Creates File Integrity incidents and Events from Qualys findings

View Incidents Assigned to My Group or Me

Automatically convert unauthorized or suspicious changes, such as configuration tampering, privilege escalation, or unexpected file modifications, into incidents tracked through existing ServiceNow workflows
Qualys ETM ITSM Plus Qualys CoreLicense Dependencies: Qualys Enterprise TruRisk Management (ETM), ServiceNow ITSM  

Supported by: Qualys

Two Qualys apps (Core and ETM ITSM) work together, allowing you to:

Automated ticketing process that creates ITSM Incidents directly from Qualys ETM findings

View Grouped Qualys ETM Incidents

View Report Queue of ETM Reports

ServiceNow SecOps/VR/USEM Ticketing Integrations

Qualys Integration for Security OperationsLicense Dependencies: Qualys VMDR, ServiceNow SecOps/VR    

Supported by: ServiceNow

Key Functionalities:

Import Qualys VMDR vulnerabilities into ServiceNow VR to create  and manage Vulnerable Items (VITs)

Re-Scan and automatically close out the tasks once the vulnerabilities are remediated
Qualys Patch Orchestration with VRLicense Dependencies: Qualys Patch Management (PM), ServiceNow SecOps/VR    

Supported by: Qualys

Key Functionalities:

Integration with Qualys Patch Management for patches available and missing on the assets onboarded to Qualys

Auto-syncing assets and their associated patches

Creates Change Requests for Patching

Reads VITs and closes VITs once patched or mitigated

Automatically creates remediation tasks and assigns the appropriate workflows.

Out-of-the-box dashboard with statistics of patches available on assets, patches awaiting application on assets, and many more
Qualys Container Vulnerability Response IntegrationLicense Dependencies: Qualys Container Security, ServiceNow SecOps/VR

Supported by: Qualys

Key Functionalities:

Import Containers and their Vulnerabilities from Qualys Container Security into ServiceNow CVR

Creates CVITs tied to container Images

Helps create Container Vulnerable Items (CVITs) to manage container vulnerabilities
Vulnerability Response Integration with Qualys TotalAppSecLicense Dependencies:  Qualys TotalAppSec (TAS), ServiceNow SecOps/AVR

Supported by: Qualys

Key Functionalities:

View Qualys TAS-related vulnerabilities for web application DAST scans within ServiceNow

View all web applications and scans by Qualys in ServiceNow 

Run web application scans with Qualys TAS and view their results in ServiceNow

Syncs the TAS-related KnowledgeBase entries from Qualys with ServiceNow
Qualys ETM VR IntegrationLicense Dependencies: Qualys Enterprise TruRisk Management (ETM), ServiceNow SecOps/VR

Supported by: Qualys

Key Functionalities:

Automated ticketing process that creates Vulnerable Items (VITs) entries directly from Qualys ETM findings

VIT Enrichment with critical information such as EPSS (Exploit Prediction Scoring System), CISA Known Exploits, Exploit Maturity, Threat Actor, and RTI (Real-Time Intelligence), Impact, Recommendation, and Detection Result

Patch intelligence with patch IDs, advisory links, release dates, and supersedence details

Supports updating the CI in CMDB

Scheduled integrations for report requests and downloads, using QQL-based filtering

Application logging and monitoring within ServiceNow to enhance visibility
Qualys CSPM IntegrationLicense Dependencies: Qualys TotalCloud™ (TC), ServiceNow SecOps/CC  

Supported by: Qualys

Key Functionalities:

Integration with Qualys TotalCloud CSPM for compliance issues

Supports all major public cloud providers such as AWS, Azure, GCP, and OCI

Auto-syncing policies and controls

Granular filtering by cloud account, region, tags, and more

Automatically creates test results, remediation tasks, and assigns the appropriate workflows.

Extensive evidence, metadata, and remediation recommendations

Out-of-the-box dashboard for cloud misconfiguration visibility

Key Benefits of Certified Integrations

  • Faster Remediation: Automated ticket creation and closure significantly reduce mean time to remediate (MTTR).
  • Better Prioritization: Qualys ETM hyper-prioritization ensures teams focus on the exposures that matter most.
  • Improved Data Integrity: Accurate CMDB mapping reduces misassignment and duplicate efforts.
  • Reduced Operational Risk: Pre-built certified apps replace fragile custom scripts.
  • Audit-Ready Evidence: Consistent workflows and logging support compliance and audit requirements.

Turning Qualys Risk Insight into ServiceNow Execution

Qualys and ServiceNow integrations move remediation from coordination to execution. They ensure that risk signals are not only visible, but consistently acted upon within the systems teams already use.

With accurate asset context and automated workflows in place, organizations reduce delays, eliminate ambiguity, and maintain accountability across remediation efforts.

The result is a more reliable operating model where security and IT do not need to reconcile data or intent. Execution follows directly from insight.


Explore Qualys integrations on the ServiceNow Store


Frequently Asked Questions (FAQs)

What does the Qualys–ServiceNow integration do?

It connects Qualys risk findings with ServiceNow workflows, enabling automatic creation, assignment, tracking, and closure of remediation tasks based on prioritized vulnerability and configuration data.

Why is manual vulnerability management ineffective?

Manual processes that rely on exported reports and manual ticket creation lead to delays, incorrect asset mapping, duplicate work, and untracked remediation gaps — especially dangerous in the current AI-driven threat landscape.

How does Qualys ETM improve prioritization in ServiceNow?

Qualys ETM enriches findings with TruRisk Score, TruConfirm validation, Real-Time Intelligence, and asset criticality. This allows ServiceNow to create much more accurate, risk-based remediation queues instead of broad severity-based lists.

Which CMDB integration should new customers use?

New customers should use Qualys CMDB Bi-Directional Sync. The older one-way Qualys CMDB Sync application is no longer available to new customers.

Do these integrations support real-time workflows?

Yes. Most integrations support scheduled or near real-time synchronization, enabling faster detection-to-response cycles.

Can I integrate Qualys Container Security (CSPM) with ServiceNow?

Yes. Qualys offers dedicated integrations for Container Vulnerability Response and CSPM (via TotalCloud) that create relevant items and remediation tasks in ServiceNow.

Show Comments (3)

Comments

Your email address will not be published. Required fields are marked *

  1. As recommended by ServiceNow only ‘Qualys Web Application List Integration’ is
    kept active and other integrations are inactive,

    Why?

  2. As recommended by ServiceNow only ‘Qualys Web Application List Integration’ is
    kept active and other integrations are inactive,

    Why?
    Why we need to do manually?