ServiceNow Licensing
ServiceNow offers a portfolio of robust cloud-based applications that automate and manage enterprise services. Our applications have the advantage of being built on a single service automation platform with one user interface, one code base, and one data model, delivering easy, automated upgrades.
Features
- Digital workflows for IT, employees and customers
- Ability to build your own applications on the platform
- Native platform intelligence - predict, prioritise and proactively manage work
- Access from anywhere - mobile applications
- Collaboration - agent workspace/chat/visual taskboards
- Easy to use GUI with drag-and-drop graphical workflow
- Granular access control and certified multi-layered security
- Integration hub - multiple out-of-the-box integrations
- Real-time reporting, dashboards and analytics
- Automation of business process across the enterprise
Benefits
- One API
- One web service interface
- One data-store, one data-model
- One job scheduler
- One development approach
- One architecture
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 4 1 3 7 8 8 2 8 5 8 7 6 6 6
Contact
UP3 SERVICES LTD
Matthew Shears
Telephone: 0203 432 1432
Email: hello@up3.co.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Location and geospatial data management and analytics
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No
- System requirements
-
- ServiceNow is a Saas-based solution
- ServiceNow implement and maintains the required infrastructure
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
-
Standard response varies by ticket type and priority, and may vary based on customer's requirements at
weekends. Typical target response for a P3 Incident would be two hours. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- EN 301 549
- Web chat accessibility testing
- ServiceNow has a User Experience (UX) team that has based much of their analysis on customer feedback and best practices. To help ensure usability, ServiceNow has asked customers to perform external audits, and ServiceNow staff have personally gone onsite to view some customers' operations. The ServiceNow UX team conducted eight separate site visits in the past year to watch how customers use the ServiceNow system and incorporated this information into work requests and SCRUM stories. One recent trip included a visit to an accessibility lab at a public educational institution. Our development team worked specifically with a blind user to help accessibility design.
- Onsite support
- Yes
- Support levels
-
Varying degrees based on impact package. See pricing and packging presentation on the link below.
Product details - https://partnersuccess.servicenow.com/products/impact.html - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
UP3 is able to provide access to ServiceNow accredited training courses.
Our implementation services also include training to ensure that customers receive training on how to use their specific instance of ServiceNow. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- The process for the return of data follows: 1) ServiceNow exports the entire database in a MySQL format. 2) ServiceNow provides the customer a set of instructions on how to import the data on the customer's side. 3) The customer can FTP the files from ServiceNow to their site. Customers are permitted to store data hosted within ServiceNow for the duration of their service subscription with ServiceNow. Under this model, the customer can purge or retain data according to their own retention policy. ServiceNow retains customer data for up to 45 days from the end of a contract. Within the 45 days, the customer can request their data to be sent to them in a standard database export format. After 45 days, all data from the customer instances is removed from ServiceNow servers
- End-of-contract process
- On termination of an Order Form or expiration of a Subscription Term, Customer will stop accessing and using the Subscription Service and all related rights granted to Customer in this Agreement terminate. At any time during the applicable Subscription Term, Customer may export Customer Data using the functionality of the Subscription Service. After termination of an Order Form or expiration of a Subscription Term, ServiceNow may delete all Customer Data unless legally prohibited. ServiceNow will, within 30 days after the effective date of Customer’s termination for ServiceNow’s uncured breach, refund to Customer any prepaid fees received by ServiceNow covering the remainder of the Subscription Term for the affected Subscription Service. Within 30 days after the effective date of ServiceNow’s termination for Customer’s breach, Customer will pay all remaining amounts, if any, payable under this Agreement for the Subscription Term applicable to the terminated Order Form, regardless of the due dates in the Order Form.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The ServiceNow mobile experiance is similar to the desktop experiances allowing users to perform the same functions as they would from the desktop. The mobile experiance does not however provide a mechanism to perform administration of the ServiceNow platform.
- Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- Customers' access is provided via the web portal, this includes the management interface for the instance. The ServiceNow platform is based on service-oriented architecture (SOA), in which all data objects can use web services to access bi-directional data-level integration. The interface is also direct and dynamic because all modifications to existing objects and all new objects are automatically published as a Direct Web Service. A more indirect web service creation and usage can be achieved through Mapped Web Service where a transform map is used to gather incoming web service data into the final targeted tables.
- Accessibility standards
- EN 301 549
- Accessibility testing
- ServiceNow has a User Experience (UX) team that has based much of their analysis on customer feedback and best practices. To help ensure usability, ServiceNow has asked customers to perform external audits, and ServiceNow staff have personally gone onsite to view some customers' operations. The ServiceNow UX team conducted eight separate site visits in the past year to watch how customers use the ServiceNow system and incorporated this information into work requests and SCRUM stories. One recent trip included a visit to an accessibility lab at a public educational institution. Our development team worked specifically with a blind user to help accessibility design.
- API
- Yes
- What users can and can't do using the API
- Inbound web services, such as the REST API, allow you to interact with ServiceNow instance data using web service requests. ServiceNow outbound REST functionality allows you to retrieve, create, update, or delete data on a web services server that supports the REST architecture. ServiceNow integrates with many third-party applications and data sources. A variety of techniques can be used, most notably Web Services, JDBC, LDAP, Excel, CSV, and Email, as well as any industry-standard technologies that use REST, SOAP or WSDL. With the correct permissions users can use these API's to bring data in and out of ServiceNow. Users who create these tend to be power users or Admin users.
- API documentation
- Yes
- API documentation formats
-
- HTML
- ODF
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users with the appropriate roles can configure various aspects of lists or forms. Configuration changes apply to all users.
With list configuration, you can add, remove, and reorder list columns. You can configure calculations to appear under columns. You can also hide controls and define access conditions by role for existing list controls. Users can also personalise lists which will not effect what other see.
Users can create their own reports and dashboards also with the correct permissions.
Forms can be configured as well, this includes the ability to configure a form to show or hide fields from a view. You can even create new fields on the table that is associated with the form, and put business rules, UI policies around them as well as define the data dictionary for the fields. With a runtime license you also have the ability to create new business applications in ServiceNow
Scaling
- Independence of resources
- ServiceNow’s data centers and cloud-based infrastructure have been designed to be highly available. All servers and network devices have redundant components and multiple network paths to avoid single points
Analytics
- Service usage metrics
- Yes
- Metrics types
- Users can configure SLA reports to consolidate data by any field or combination of fields. ServiceNow offers predefined reports that pertain to applications and features like incident management and service catalog requests. Reports can be scheduled for email delivery at specific times of the day, week, or month, internally and externally. These powerful features, combined with nearly 200 customizable, commonly used reports that are delivered with ServiceNow, provide the most robust native reporting tool available in any service management application on the market today. If out-of-box reports do not meet your needs, new reports can be created at any time.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- ServiceNow
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- Never
- Protecting data at rest
- Other
- Other data at rest protection approach
-
ServiceNow can provide two types of encryption for data at rest upon customer request.
-Column encryption of customer added fields and attachments: Provides data encryption using AES128/256 or 3DES symmetric key encryption. Customer provides the keys for this encryption. Data stored in these fields cannot be searched or reported on.
-Full disk encryption: Provided via self-encrypting hard drives with AES256 bit encryption. This encryption capability is only available by purchasing dedicated ServiceNow hardware at additional cost. This delivers “at-rest” protection only and is focused solely on preventing data exposure through the loss or theft of hard disks holding customer data. - Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Export individual records via PDF or XML directly from a form.
-Export multiple records via CSV, Excel, PDF or XML directly from a list.
-Automatically Export multiple records from a table on a set schedule. -Create a scheduled job to regularly Export data as a report.
-Export multiple records from a table using CSV, Excel, PDF or XML. specifying the table form or list you want to Export in the URL.
-Web services/SOAP: Export multiple records from a table when an external client makes a Web services request - Data export formats
-
- CSV
- Other
- Other data export formats
-
- .xlxs
- JSON
- XML
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- ServiceNow provides 99.8% availability (calculated monthly) for production instances. This design includes redundancy and fault tolerance of the entire ServiceNow application and platform stack, including electrical, cooling, network, security, and server infrastructure. Over the last 3 years (2014-2016), we have averaged 99.995% availability and have not fallen below 99.8% (contract SLA) in any quarter. In 2016 we averaged 99.996% and did not fall below 99.8% in any quarter.
- Approach to resilience
-
ServiceNow’s data centers are arranged in pairs. All customer production data is stored in both data centers and kept in sync using asynchronous database replication. Both data centers are active at all times, each with the ability to support the combined production load of the pair. A production instance from one customer may be operating out of one data center in the pair and a production instance of another customer from the other.
More details available on request
ServiceNow maintains continuous, asynchronous replication from the database in the current primary data center (read-write) to the secondary data center (read-only). To transfer a customer instance from a primary data center to a secondary, ServiceNow designates the secondary to be the primary and the primary to be the secondary if it still exists.
ServiceNow’s data centers and cloud-based infrastructure have been designed to be highly available. All servers and network devices have redundant components and multiple diverse network paths to avoid single points of failure. - Outage reporting
- ServiceNow have a customer portal where all requests, changes and incidents can be logged. Customers also now have complete transparency into the real availability of their production and non-production instances. Users can view the impact severity of issues and even drill into incident records to view details for problems. It is this level of transparency that further sets ServiceNow apart.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
By User Access control lists and Groups and user roles
All ServiceNow staff are placed into Groups and have a user role, these groups and roles have access rights attached to them. Any personal that try to access an interface will have their group membership and user role checked and if they do not belong to the user role and group that is required to access that particular interface then access will be denied - Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
ISO27001
• SSAE 18 SOC 1 Type 1
• SSAE 18 SOC 1 Type 2
• SSAE 18 SOC 2 Type 1
• SSAE 18 SOC 2 Type 2
• BSI Cloud Computing Compliance Controls Catalogue (C5) Standard
• APEC Privacy Recognition for Processors (PRP)
• FedRAMP JAB High P-ATO (for US government entities)
• DoD Impact Level 4 Authorisation (for US DoD/IC entities)
• Multi-Tier Cloud Security Standard for Singapore (MTCS) Level 3
• ASD IRAP assessed for OFFICIAL and PROTECTED cloud services
• Government of Canada GC Cloud Provider
• SOC 2 + HITRUST Report
• Cyber Essentials Plus Certification
• More details available on request - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- ServiceNow has a formally documented change management process that uses an internal ServiceNow instance to track change requests and approvals. All changes to production environments must go through the change management process. Change requests must include the change procedure, risk, and back out plans. Change requests are reviewed and approved by the Change Advisory Board (CAB). All assets are tagged and tracked though the ServiceNow CMDB.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- ServiceNow's Infrastructure stack is customized at each layer to specifically support the only application residing in the ServiceNow cloud. With the small footprint and limited ports/services enabled, many system and patches published do not apply to the private cloud's systems. ServiceNow follows an approach to determine if the patch is to be deployed. When confirmed that a patch needs be deployed, this then follows the Change process the testing process as well as the timeline for deployment. ServiceNow leverages the Advanced-High-Availability architecture to transfer customers' production instances to the other datacenter. Remediation timeframes are subject to ServiceNow's Vulnerability Management SOP.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- ServiceNow has an implementation of Sourefire for IDS and Splunk for SIEM. The IDS system monitors inbound traffic in the DMZ. Splunk does log collection on network devices, IDS and servers used to support customer information. These systems are monitored with both proactive alerting and regular log files reviews. Events are responded to within 24 hours.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- ServiceNow's documented Security Incident Response policy, process and workflow aligns with NIST 800-61. ServiceNow Incident Response process includes event discovery, triage, escalation, notification (including customer notification) remediation, and post-mortem review.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Saturday 1 August 2026
- What the ISO/IEC 27001 doesn’t cover
- Nothing
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Saturday 1 August 2026
- What the ISO 9001 doesn’t cover
- Nothing
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 9002854e-438c-4925-8b47-3cc5df99852b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 7a4c588f-8626-4e4b-b7c3-69bbfbb3f179
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Volunteering opportunities for staff
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
-