Tom OwlesTom Owles· Risk & Security Solutions Lead

Earlier this year, ServiceNow sent close to $9bn acquiring Veza and Armis, with Armis alone standing as the largest acquisition ServiceNow has ever made. For most customers that's just news. For anyone working toward NIS CAF v4.0, with the UK's Cyber Security and Resilience Bill now moving through the House of Lords, it's worth a closer look.
At Pulsar, we’ve spent the last few months mapping ServiceNow against all 234 'Achieved' criteria in the framework, and our read is simple: ServiceNow just bought its way past the two hardest gaps in it.


The gap ServiceNow had

Scored on its own, ServiceNow met 67% of CAF v4.0's criteria, a strong base for a platform that was never built as a compliance product first. But two areas held it back consistently: identity (proving who can actually access what, not just who's assigned a role) and asset visibility (seeing everything connected to your network, not just what's formally enrolled). Both are exactly the kind of evidence gaps that trip up an audit.
Neither reflects poorly on ServiceNow. A workflow platform was never built to answer those two questions alone. It's telling that ServiceNow reached the same conclusion we did and went and bought the answer rather than bolting one on.


Veza: closing the identity gap

Veza proves who can genuinely access what, right now, across every system, human and machine, and evidences it well enough to survive an audit. Layered onto ServiceNow, it takes several identity-related outcomes in CAF v4.0 from barely addressed to strongly covered. For a compliance lead, that's the difference between a criterion you can't currently evidence and one you can.


Armis: closing the asset visibility gap

Armis sees everything genuinely connected to your network, agentlessly, including the OT, IoT and contractor devices a standard inventory never catches. CAF v4.0 assumes you know your estate well enough to protect it, and that assumption breaks down fast for any Operator of Essential Services or Designated Critical Supplier with real-world infrastructure. Armis closes that gap, and sharpens detection outcomes along the way.


The result

Add both to ServiceNow's existing platform and overall coverage climbs from 67% to 76%, with the sharpest single improvement landing in Objective B, protecting against attack, where identity and asset visibility both sit.
There's more to it than two numbers, though. A meaningful share of the CAF's requirements can't be met by any platform, ours or anyone else's, because they aren't really about tooling. They come down to things like board-level accountability, a genuine security culture, skilled people in the right roles, and secure-by-design architecture, alongside a handful of specialist controls that sit outside any workflow, identity or asset platform. No vendor can sell you those.


That's why knowing exactly which criteria stay unmet, and why, matters just as much as knowing what's covered. It's the difference between a realistic compliance roadmap and a sales pitch. That full picture, criterion by criterion, is what our whitepaper sets out.


Want the full picture?

If you're already running ServiceNow, the real question is whether Veza and Armis are switched on for your environment yet, and what that means for your compliance timeline. Our 90-minute introductory workshop, at no cost, walks that assessment through against your own platform.

Or, download the full whitepaper for the complete breakdown.

Facing something similar?

Talk to the practitioners behind this work — we'll tell you honestly what we'd do.