Technical evaluation

vCISO Lite versus ServiceNow IRM

ServiceNow IRM is the risk and GRC product family inside the Now Platform. vCISO Lite runs cyber risk quantification and TPRM from $299/mo— with productized M&A cyber diligence and risk operations your own AI agents can call.

Prepared
Method
Capability walk against ServiceNow’s published IRM product surface (servicenow.com/products/integrated-risk-management, ServiceNow docs, Zurich release notes, trust.servicenow.com) and vCISO Lite’s live platform.
Sources
servicenow.com/products/integrated-risk-management, ServiceNow product docs, Zurich release notes (Q3 2025), Action Fabric GA press (mid-2026), SAFE Security partnership press (SAFE One Connector for ServiceNow), trust.servicenow.com/certifications, vcisolite.com/pricing, vcisolite.com/diligence, vcisolite.com/evidence-graph, vcisolite.com/briefs-and-specs. See §10.
Corrections
Both vendors invited to review. Send corrections to /contact; the “Prepared” date above is bumped on any material update.
On this page · 10 sections

TL;DR

Findings§1

Where ServiceNow IRM leads

  • Enterprise scale + Now Platform bundle. IRM is one product family inside a $200B+ enterprise-workflow platform. Deloitte case study consolidated 60 tools + 38 cyber services onto IRM + Security Operations for 20-60% productivity gain. Buyers already running ServiceNow ITSM / ITOM / SecOps get IRM as a natural adjacency with platform-consistent identity, workflow, and data model reuse.[3]
  • CMDB-driven risk events. A flagged vulnerability in the CMDB or a service outage automatically triggers a risk event in IRM. Real integration story vCISO Lite doesn’t match on the workflow-integration axis.[3]
  • Broader regulatory content packs. CSRD (Operational Sustainability), DORA 5-pillar (JSON export + auto currency conversion Q1 2026), NIS 2, NIST RMF via CAM, OSCAL import/export (Q1 2026), DoD IL4, IRAP. Regulatory breadth vCISO Lite doesn’t match on this specific set.
  • FedRAMP High + DoD IL4 federal gate. Continuous Authorization & Monitoring runs on ServiceNow GCC at FedRAMP High + DoD IL4 + IRAP. If the buyer is US federal, DoD, or Australian federal, this is decisive.[7]
  • Native MCP + Action Fabric + AI Gateway. Zurich release (Q3 2025) added native MCP support (consumer + provider); Action Fabric GA mid-2026; AI Gateway connects to Anthropic-managed community MCP registry Q1 2026. MCP surface at Now-Platform scope, not just security domain.[4]
  • Most credentialed own security posture in this tranche. ISO 27001 (since 2012), ISO 27017 / 27018 / 27701 / 27035, ISO 42001 (AI Management System), SOC 2, FedRAMP High via GCC, DoD IL4, IRAP. Trust portal at trust.servicenow.com/certifications.[8]
  • 21 Now Assist for IRM features. Issue record summarization, issue-resolution agentic workflow, Common Control Objective Creation, Regulatory Change → Control Mapping, Risk Event Summarization, Risk Identification Agent, Issue Submission Agent, Compliance Case AI Summarization. Deep GenAI feature list.

Where vCISO Lite leads

  • Real CRQ engine vs dashboard-quant. ServiceNow IRM ships ALE = SLE × ARO in a 5×5 matrix and can model FAIR configurably, but no native Monte Carlo, no LEC, no probability distributions. The SAFE Security partnership (SAFE One Connector for ServiceNow) exists precisely because ServiceNow doesn’t run FAIR CRQ natively — SAFE runs it externally and posts results back. vCISO Lite ships a 10,000-iteration seed-deterministic Monte Carlo engine with ALE percentile bands, full LEC, and per-control what-if in production.[1][2]
  • No CMDB / Now Platform prerequisite. vCISO Lite works greenfield — buyers don’t need to have already committed $1M+ to ServiceNow ITSM / ITOM / SecOps for IRM to deliver value. If the enterprise isn’t already deep in ServiceNow, greenfield IRM without ITSM is strategically incoherent (analyst-common wisdom).
  • Productized M&A cyber diligence. QCD 5-pillar CCOD (Attack Surface, Third-Party Concentration, Data Sensitivity, Program Maturity, Integration) as a 72-hour deliverable defensible at the Investment Committee. Codified from Someone Else’s Debt (Yolonda Smith, 2026). ServiceNow has no M&A diligence surface.[6]
  • APRI over MCP scoped to security domain. APRI at mcp.vcisolite.com exposes per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval — every invocation Ed25519-signed to the Evidence Graph with a published foundation-model choice. ServiceNow’s Action Fabric is Now-Platform-wide but the IRM-specific tool graph is not publicly enumerated.[4]
  • Externally-anchored evidence chain. Every risk artifact Ed25519-signed and anchored to an external RFC-3161 timestamp authority + transparency log. A SOC 2 auditor, cyber-insurance carrier, or M&A diligence reviewer can prove the chain wasn’t tampered with, without trusting vCISO Lite. ServiceNow’s IRM audit trail is Now-Platform-internal. SDK-licensable since 2026-08-15.[5]
  • Auto-narrated board-report generation. QCD deliverables auto-generate the board-facing narrative alongside the dollar figure; APRI can compose executive summaries from scenario runs on demand. ServiceNow IRM ships Performance Analytics widgets that a team assembles into board packets.[9]
  • Published pricing from $299/mo at /pricing. ServiceNow IRM pricing is enterprise-sales-led with an all-employee-headcount base fee that scales off total active headcount even when only a small team uses IRM; large enterprise lands $500K-$2M+ ARR for IRM alone before ITSM / ITOM adjacency.[10]
  • Simpler procurement. Direct-buy without a scoping call. ServiceNow’s per-employee-headcount base fee for every employee even if only 5 use it is procurement friction; typical license-bloat observation is 25-40% of licensed IRM module access sits with people who never open it.
  • Founder-direct. [email protected] reaches the founder, not a sales-development queue.

Scope & evaluation criteria

Boundaries§2

In scope

Buyer profile
CISOs, CROs, and CFOs comparing enterprise IRM inside the Now Platform (ServiceNow IRM) against cyber + GRC + services on a narrower SKU (vCISO Lite). Especially useful for buyers who need a shipped Monte Carlo CRQ engine (not just FAIR-configurable dashboard-quant), risk operations callable from their own agent stack (not just through Now Platform Action Fabric), a productized M&A cyber diligence deliverable, or buyers who don’t already run ServiceNow ITSM / ITOM.
Evaluation frame
Ten capability categories the enterprise risk buyer typically weighs — native CRQ engine, per-control what-if primitive, CMDB-driven risk events, native MCP surface, evidence integrity foundation, M&A cyber diligence, federal gate (FedRAMP / DoD IL4), own trust posture, auto-narrated board report, published pricing. Not: everything each vendor does.
Comparison basis
ServiceNow’s published IRM product surface (servicenow.com/products/integrated-risk-management), Zurich release notes (Q3 2025), Action Fabric GA press (mid-2026), SAFE Security partnership press (SAFE One Connector), trust.servicenow.com/certifications. vCISO Lite’s live platform. Not: NDA material, unreleased roadmap, or third-party analyst reports behind paywalls.

Out of scope

Now Platform ITSM / ITOM adjacency
ServiceNow IRM sits inside a $200B+ enterprise-workflow platform with ITSM, ITOM, SecOps, CSM, HR, and more. If the buyer is evaluating IRM as one module inside a Now Platform rollup, that’s a different evaluation frame than this page. vCISO Lite does not compete with ServiceNow on the Now Platform breadth axis.
Federal / DoD deployment
ServiceNow IRM on ServiceNow GCC clears FedRAMP High + DoD IL4 + IRAP. vCISO Lite is not FedRAMP-authorized today. If the buyer needs the platform inside a federal boundary, ServiceNow IRM on GCC is the right choice — the federal-gate comparison is not this page’s scope.
CSRD / ESG-first buyers
ServiceNow’s ESG Management + CSRD-aligned reporting is a distinct product surface. If the buyer’s primary need is EU CSRD sustainability reporting alongside cyber risk, that’s a different evaluation frame than the cyber-first shape this page compares.

Capability coverage

Ten capabilities§3

Amber = ServiceNow IRM ships / has it. Teal = vCISO Lite ships it. Split = both. Hover a hex for the mechanism detail.

Capability deep-dives

How each side implements it§4

Five capabilities, one spec-card per side. Framework decomposition lives in §5.

EXTERNAL INPUTSSAFE Security connectorFAIR CRQ runs outside · posts backRegulatory contentTR (TRRI) / LexisNexis · separatelyAnthropic MCP registryAI Gateway (Q1 2026)community MCP serversfeedNOW PLATFORMCMDB foundationshared with ITSM · ITOM · SecOps · CSM · HRpowersIRM (~12 modules)Policy · Risk · Advanced Risk Assess · TPRM · BCM · CAM · Privacy · ESG · AI Ctrl TowerOutput: ALE = SLE × ARO · 5×5 qual+quant matrixNow Assist for IRM (21 features)Action Fabric + AI Gateway (Zurich Q3 2025)Operational Risk Dashboardheat maps · Performance Analytics widgetsBoard readout assembled from widgets · trust.servicenow.com · FedRAMP High + DoD IL4 + IRAPall-employee-headcount licensing$500K–$2M+ ARR for IRM alone
IRM modules ride on the shared Now Platform CMDB — but native Monte Carlo CRQ isn’t on the surface, so the SAFE Security connector supplies FAIR CRQ from outside.
§4.1

Native CRQ engine (Monte Carlo)

ServiceNow ships dashboard-quant (ALE = SLE × ARO). vCISO Lite ships the Monte Carlo engine in production.

ServiceNow IRM

Advanced Risk Assessment ships ALE calculated as SLE × ARO in a 5×5 qualitative-plus-quantitative matrix. FAIR is configurable capability, not a shipped FAIR engine.

Inputs
Risk scenarios, control assessments, and framework mappings inside the Advanced Risk Assessment / IT Risk / TPRM modules.
Outputs
5×5 matrix placement, ALE = SLE × ARO figure, heat-map rollup, Performance Analytics widgets. No Monte Carlo trial output, no LEC, no probability distributions.
Evidence
The SAFE Security partnership (SAFE One Connector for ServiceNow) exists precisely because ServiceNow doesn't run FAIR CRQ natively. SAFE runs FAIR CRQ externally and posts the results back to ServiceNow records.
Fails when
Buyer needs a defensible dollar-figure ALE with percentile bands, an LEC for cyber-insurance underwriting conversations, or Monte-Carlo-driven quantification. That's the SAFE partnership's job, not IRM's native surface.
vCISO Lite

10,000-iteration seed-deterministic Monte Carlo engine. Every simulation is reproducible for audit — identical inputs produce identical outputs.

Inputs
Scenario definition from the risk register; frequency low/high; magnitude low/high; control effectiveness; optional per-control what-if frequency and magnitude reductions.
Outputs
Baseline and projected ALE with percentile bands, full Loss Exceedance Curve, ALE reduction in dollars and percent, ROI (NPV, payback years, 10% discount, 3-year model).
Evidence
Trial count engineered for sub-30-second per-org runtime across the risk register. Every simulation Ed25519-signed to the Evidence Graph.
Fails when
Buyer's procurement requirement is a Forrester Wave CRQ Leader analyst cite specifically. Neither ServiceNow nor vCISO Lite currently holds that placement (Safe Security is the Q2 2025 Wave Leader).
§4.2

CMDB-driven risk events

ServiceNow's foundation advantage. Not a category vCISO Lite competes on — different assumption.

ServiceNow IRM

The Now Platform CMDB is the foundation. Pre-wired hooks to ITSM, ITOM, SecOps, and CSM mean a flagged vulnerability in the CMDB or a service outage automatically triggers a risk event in IRM.

Inputs
Vulnerability records, service outages, incident tickets, change events, and CMDB state changes from ITSM / ITOM / SecOps.
Outputs
Risk events created automatically, escalation workflows, control-effectiveness recalculation, dashboard rollup.
Evidence
Deloitte case study consolidated 60 tools + 38 cyber services onto IRM + Security Operations for 20-60% productivity gain. Real integration story.
Fails when
Buyer is not already deep in ServiceNow ITSM / ITOM / SecOps. Greenfield IRM without ITSM adjacency is analyst-common wisdom as strategically incoherent — the foundation advantage requires prerequisite adoption ($1M+ multi-year commitment).
vCISO Lite

vCISO Lite runs multi-tenant SaaS without a CMDB prerequisite. Risk events come from vCISO Lite's own scanner-service, from red-team engagements, from QCD diligence, and from vendor-incident (DC-TPIR) surfaces.

Inputs
Platform-native telemetry: scanner findings, vendor questionnaire responses, evidence uploads, control attestations, agent actions.
Outputs
Risk register updates, control-effectiveness recalculation, Ed25519-signed evidence-chain entries.
Evidence
vCISO Lite is greenfield-friendly — no prerequisite ITSM / ITOM / CMDB investment. If the enterprise isn't already deep in ServiceNow, this is where the total cost of ownership diverges.
Fails when
Buyer's primary need is CMDB-native risk-event automation across a 40+ tool ITSM/ITOM/SecOps stack. That's ServiceNow IRM's foundation strength.
§4.3

Native MCP surface for AI agents

Both ship MCP. ServiceNow's Action Fabric is Now-Platform-wide; APRI is scoped to the security / risk domain with a published foundation-model choice.

ServiceNow IRM

Zurich release (Q3 2025) brought native MCP support (consumer + provider). Action Fabric (ServiceNow's MCP + Google A2A implementation) GA mid-2026. AI Gateway connects to Anthropic-managed community MCP registry (Q1 2026). AI Agent Studio requires steward-approved MCP servers.

Inputs
Now Assist skills exposed as MCP tools. Claude / other MCP clients can interact with incidents, changes, CMDB, catalog, users, groups, and KB via natural language.
Outputs
MCP tool responses across the Now Platform. IRM-specific MCP tool graph not clearly enumerated in first-party docs — the surface is Now-Platform-wide.
Evidence
Zurich release notes describe native MCP; Action Fabric GA press describes MCP + A2A; AI Gateway documentation describes Anthropic community MCP registry connection.
Fails when
Buyer wants IRM-specific MCP tool signatures published so external agents know exactly which risk operations are callable. That's the gap — the surface exists, but IRM-scoped tool graph is not publicly enumerated.
vCISO Lite APRI

APRI at mcp.vcisolite.com exposes CRQ operations as callable MCP tools. Any Claude, Cursor, custom LLM, or autonomous loop can invoke per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval directly.

Inputs
Whatever context the invoking agent has — scenario ID, control candidate, risk threshold, workflow step from another MCP server.
Outputs
Same projection, delta, and ROI response the platform returns. Every invocation Ed25519-signed to the Evidence Graph regardless of which agent called it.
Evidence
Three architectural guarantees make composability safe: caller-entitlement scoped (invoking user's entitlements, not a service account), complete tool-call audit trail (Ed25519 on the Evidence Graph), observe-first (writes go through a confirmation gate). Published foundation-model choice (Anthropic Claude family).
Fails when
Buyer wants agent orchestration across the whole Now Platform (ITSM + ITOM + SecOps + IRM + HR) inside one platform. That's Action Fabric's Now-Platform-wide advantage.
§4.4

M&A cyber diligence as productized SKU

ServiceNow IRM has no M&A cyber diligence surface. vCISO Lite ships QCD 5-pillar CCOD as a 72-hour productized service.

ServiceNow IRM

Enterprise IRM inside the Now Platform is ServiceNow's shape. M&A cyber diligence as a productized 72-hour deliverable is not a ServiceNow surface. Deal-side buyers doing PE/M&A cyber diligence engage big-four services or specialist boutiques.

Inputs
N/A — no diligence product on public surface.
Outputs
N/A.
Evidence
Public product surface has no /diligence, /qcd, or M&A-diligence-branded page.
Fails when
Buyer is deal-team-side (PE, M&A) needing pre-close cyber diligence delivered in days, not weeks, defensible at Investment Committee.
vCISO Lite QCD

Quantitative Cyber Diligence — 5-pillar CCOD (Attack Surface, Third-Party Concentration, Data Sensitivity, Program Maturity, Integration) productized at /diligence. 72 hours from kickoff to a deliverable defensible at the Investment Committee.

Inputs
Target company scope + engagement letter · public attack-surface data · contracts and vendor list where accessible · framework attestations.
Outputs
Single-figure CCOD (Cyber Cost of Deal) with per-pillar decomposition · defensible narrative for the IC · portable format (ephemeral by design).
Evidence
Codified from Someone Else's Debt (Yolonda Smith, 2026). Published pillar-by-pillar on /diligence.
Fails when
N/A on the diligence axis — ServiceNow has no comparable productized diligence surface.
§4.5

Own security posture + federal gate

ServiceNow is the most credentialed vendor in this tranche. vCISO Lite publishes SOC 2 Type II + ISO 27001 but is not FedRAMP-authorized today.

ServiceNow IRM

Continuous Authorization & Monitoring (CAM) module runs on ServiceNow GCC at FedRAMP High. DoD Impact Level 4 gate cleared. IRAP (Australian Gov) accreditation held. OSCAL import/export shipped Q1 2026.

Inputs
Federal / DoD / AUS-federal buyers with authorization boundary requirements; CSRD-aligned CSRD / DORA / NIST RMF / DFARS regulatory content.
Outputs
Platform running inside FedRAMP High + DoD IL4 boundary; CSRD Operational Sustainability outputs; DORA 5-pillar JSON export (Q1 2026).
Evidence
Trust portal at trust.servicenow.com/certifications lists ISO 27001 (since 2012), ISO 27017, ISO 27018 (since 2016), ISO 27701 (since 2020), ISO 27035, ISO 42001, SOC 2, FedRAMP High via GCC, DoD IL4, IRAP.
Fails when
Buyer's primary requirement is externally-anchored auditor-grade evidence chain (Ed25519 + RFC-3161). ServiceNow's IRM audit trail is Now-Platform-internal.
vCISO Lite

SOC 2 Type II + ISO 27001 posture published on /about. Not FedRAMP-authorized today. Framework coverage includes FedRAMP + NIST 800-53 + CMMC L1-L3 + 800-171r3 for private-sector buyers who serve federal customers under DFARS 7012.

Inputs
Buyer's own regulatory footprint — cyber, financial services, healthcare, EU (GDPR / DORA / NIS 2), state (NYDFS 500), AI-governance (EU AI Act / ISO 42001 / NIST AI RMF).
Outputs
SCF-cross-mapped coverage rollups across 250+ frameworks (1,468 universal controls). Own posture visible on /about.
Evidence
vCISO Lite's own trust posture is a first-class marketing surface. Federal boundary itself is not vCISO Lite's shape today.
Fails when
Buyer needs the platform running inside FedRAMP High or DoD IL4 boundary. That's ServiceNow IRM on GCC's genuine strength.

Framework & control coverage

Framework depth§5

ServiceNow IRM names DORA (5-pillar Q1 2026 JSON export), NIS 2, NIST CSF / 800-53 Rev 5 / 800-171 / RMF, FedRAMP Low/Moderate/High, DoD IL4, ISO 27001, ISO 31000, ISO 42001, COSO ERM, PCI DSS, SOX, GDPR, CCPA, LGPD, DPDPA, HIPAA, FDA 21 CFR, CSRD — regulatory-content depth vCISO Lite doesn’t match on this specific set (regulatory content typically requires separately-purchased Content Packs). vCISO Lite ships 250+ SCF-cross-mapped frameworks (1,468 universal controls) — deeper on cyber/AI-governance/state-regulator frameworks, narrower on federal-boundary and CSRD.

ServiceNow IRM[8]

DORA
NIS 2
NIST CSF
NIST 800-53
NIST 800-171
NIST RMF
FedRAMP
DoD IL4
ISO 27001
ISO 31000
ISO 42001
COSO ERM
PCI DSS
SOX
GDPR
HIPAA
CSRD
CCPA / LGPD / DPDPA
FDA 21 CFR

vCISO Lite

SOC 2
ISO 27001
HIPAA
PCI DSS
NIST CSF 2.0
CMMC L1
CMMC L2
CMMC L3
800-171r3
NIST 800-53
FedRAMP
NIST RMF
NIST AI RMF
SEC cyber
CIS Controls
GDPR
DORA
NYDFS 500
HITRUST
CJIS
NIS 2
EU AI Act
ISO 42001
ISO 27002
ISO 27701
ISO 22301
SOC 1
SOC 3
CCPA / CPRA
GLBA
StateRAMP
TX-RAMP
CIS Benchmarks
MITRE ATT&CK
NIST 800-63
NIST 800-172
FFIEC CAT
SWIFT CSCF
LGPD
PIPEDA
COPPA
FERPA
CIPA
CSA CCM

Pricing & delivery model

All-employee headcount licensing vs published direct-buy§6

ServiceNow IRM is enterprise-sales-led with an all-employee-headcount licensing model — the base fee scales off total active headcount (including contractors and part-time) even when only a small team uses IRM. Mid-size enterprise with Advanced Risk + TPRM + BCM + Privacy + CAM lands low-to-mid six figures ARR minimum; large enterprise lands $500K-$2M+ ARR for IRM alone before ITSM / ITOM adjacency. vCISO Lite starts at $299/mo Starter, with every tier price on /pricing.

ServiceNow IRM

Enterprise SaaS

Contact-sales · all-employee-headcount base fee[10]

Sold to
Fortune 500 CIOs, CROs, CISOs — enterprise buyers already deep in Now Platform (ITSM / ITOM / SecOps)
Published tiers
None — contact-sales for pricing
Base fee model
All-employee-headcount licensing (scales off total active employees, incl. contractors + part-time)
Per-user tiers (est.)
ITSM fulfiller ~$70-$200/user/mo; standard packages ~$100/user/mo; Pro Plus with AI ~$160+/user/mo
Now Assist uplift
50-60% price uplift on base module pricing
Large enterprise (IRM alone)
$500K-$2M+ ARR before ITSM / ITOM adjacency
License bloat observation
25-40% of licensed IRM module access sits with people who never open it
vCISO Lite

From $299/mo

Direct-buy from Starter · every tier on /pricing

Starter
$299/mo — 5 vendors + 5 vendor questionnaires answered per month + CRQ scenario runs. Additional tiers on /pricing.
Base fee model
Flat monthly per tier — no per-employee-headcount base fee
Enterprise
$8,500/mo flat MSRP ($102,000/yr) — bundles Trustworthy Autonomy, Evidence Graph, APRI, and productized services on one SKU
Sales cycle
Direct-buy end-customer · Enterprise: one call, flat MSRP on file · no scoping-call gate to see a price

Integration surface

Native connectors§7

ServiceNow’s Now Platform gets everything Now does — the ServiceNow Store, Integration Hub, ITSM / ITOM / SecOps / HR modules, native MCP + Action Fabric. vCISO Lite runs its own connector catalog outside the Now Platform environment. Full catalog on /features/integrations.

IntegrationServiceNow IRMvCISO Lite
AWSNativeNative
AzureNativeNative
GCPNativeNative
SnowflakeNative
GitHubNative
GitLabNative
Google WorkspaceNative
Microsoft 365NativeNative
OktaNativeNative
JiraNativeNative
SlackNativeNative
MCP (Model Context Protocol)NativeNative
ServiceNow ITSM / ITOM / SecOpsNative
CMDB (native)Native
SAFE Security connector (FAIR CRQ)Native
Now Assist / Action Fabric / AI GatewayNative
Integration catalog published?ServiceNow Store + Integration HubFull catalog on /features/integrations

Deployment, data, extensibility

Platform architecture§8
AttributeServiceNow IRMvCISO Lite
Service modelSaaS multi-tenant · Now Platform foundation · CMDB-shared with ITSM / ITOM / SecOps / CSM / HR · ~12 IRM modulesSaaS multitenant · end-customer tenancy · Enterprise-tier isolated deployment on request
Native CRQ engineDashboard-quant: ALE = SLE × ARO in a 5×5 matrix; FAIR configurable; SAFE Security connector supplies real FAIR CRQ from outside10,000-iteration seed-deterministic Monte Carlo · reproducible for audit · every simulation Ed25519-signed to the Evidence Graph
Per-control what-if (FAIR-CAM primitive)Not surfaced as a distinct primitivePer-control frequency reduction × magnitude reduction re-run through the same engine · ALE reduction in dollars + NPV + LEC delta · callable from any MCP-speaking agent through APRI
CMDB-driven risk eventsSubstrate advantage · flagged vulnerability or service outage automatically triggers risk eventNo CMDB prerequisite · risk events from platform-native scanner / red-team / QCD / DC-TPIR
M&A cyber diligence surfaceNot on public product surfaceQCD 5-pillar CCOD productized at /diligence · 72-hour deliverable · defensible at the IC
Audit-trail modelNow Platform-internal · no external anchor / per-event signing / transparency log disclosedEvidence Graph · per-event Ed25519 signing · RFC 3161 external timestamp anchor · SDK-licensable
Where the AI actually runsNative MCP + Action Fabric + AI Gateway inside the Now Platform · Now-Platform-wide scope · IRM-specific tool graph not enumerated publiclyCallable from any MCP-speaking client via APRI at mcp.vcisolite.com · security/risk-domain scope · every invocation Ed25519-signed
Federal / DoD gateFedRAMP High via GCC · DoD IL4 · IRAPNot FedRAMP-authorized today · framework coverage supports federal-serving private-sector buyers under DFARS 7012
Own compliance postureMost credentialed in tranche: ISO 27001 since 2012, ISO 27017/27018/27701/27035/42001, SOC 2, FedRAMP High via GCC, DoD IL4, IRAP; trust portal at trust.servicenow.com/certificationsSOC 2 Type II · ISO 27001 · posture published on /about
Base-fee modelAll-employee-headcount licensing (scales off total active headcount)Flat monthly per tier · no per-employee-headcount base fee

Business-case briefing

For a budget request§9

Personalized briefing

Make the case for vCISO Lite alongside ServiceNow IRM

A PDF business case, personalized to your company, that lays out the three options — no integrated risk platform, ServiceNow IRM, or direct-buy vCISO Lite — with the cost math and honest tradeoffs. Written to be credible with a buyer who's already seen ServiceNow's Now Platform IRM depth and needs to see what the shipped Monte Carlo CRQ + productized M&A cyber diligence + externally-anchored evidence chain + published-pricing alternative actually delivers on a separate axis.

View pricing

Notes & sources

Provenance§10
  1. [1] ServiceNow IRM Advanced Risk Assessment CRQ posture (ALE = SLE × ARO in 5×5 qual+quant matrix, FAIR configurable but not a shipped engine) from servicenow.com/products/integrated-risk-management(accessed 2026-09-16). The SAFE Security partnership (SAFE One Connector for ServiceNow, marketed as “seamlessly integrates FAIR-based cyber risk scenarios from SAFE One to ServiceNow workflows”) is the observable evidence that ServiceNow doesn’t run FAIR CRQ natively. vCISO Lite ships a 10,000-iteration seed-deterministic Monte Carlo engine with ALE, percentile bands, and LEC output on every scenario.
  2. [2] Per-control what-if (FAIR-CAM primitive). Not surfaced as a distinct primitive on ServiceNow’s IRM product pages. vCISO Lite ships per-control frequency reduction × magnitude reduction re-run through the same Monte Carlo engine, returning ALE reduction in dollars, NPV, payback, and Loss Exceedance Curve delta. Callable from any MCP-speaking agent through APRI.
  3. [3]ServiceNow Now Platform CMDB foundation and CMDB-driven risk-event automation from ServiceNow product docs. Deloitte case study (60 tools + 38 cyber services consolidated onto IRM + Security Operations for 20-60% productivity gain) from ServiceNow customer case-study library. Analyst-common wisdom on greenfield IRM without ITSM being strategically incoherent (>$1M multi-year commitment before IRM delivers value) reflected in third-party evaluations.
  4. [4] ServiceNow Zurich release (Q3 2025) native MCP support (consumer + provider), Action Fabric GA mid-2026 (ServiceNow’s MCP + Google A2A implementation), AI Gateway connection to Anthropic-managed community MCP registry Q1 2026, AI Agent Studio steward-approved MCP-server governance from ServiceNow release notes and product docs. vCISO Lite APRI (MCP tool graph exposing per-control what-if, top-risk retrieval, scenario simulation, and Loss Exceedance Curve retrieval; live at mcp.vcisolite.com) verified against vcisolite.com/titanium.
  5. [5] vCISO Lite Evidence Graph (per-event Ed25519 signing shipped 2026-08-16 + RFC-3161 external timestamp anchor + transparency log live in production 2026-08-20; SDK-licensable since 2026-08-15) from vcisolite.com/evidence-graph. ServiceNow IRM audit-trail characteristics from servicenow.com product pages (Now Platform-internal; no external anchor / per-event signing / transparency log disclosed).
  6. [6] QCD 5-pillar CCOD (Cyber Cost of Deal) productized as M&A cyber diligence service from vcisolite.com/diligence. Methodology codified in Yolonda Smith’s 2026 book Someone Else’s Debt.
  7. [7] ServiceNow IRM federal / DoD gate (FedRAMP High via GCC, DoD IL4, IRAP) and Continuous Authorization & Monitoring (CAM) module from ServiceNow product docs and trust.servicenow.com/certifications. OSCAL import/export shipped Q1 2026 per ServiceNow release notes.
  8. [8] ServiceNow own security posture (ISO 27001 since 2012, ISO 27017, ISO 27018 since 2016, ISO 27701 since 2020, ISO 27035, ISO 42001 AI Management System, SOC 2, FedRAMP High via GCC, DoD IL4, IRAP) from trust.servicenow.com/certifications. vCISO Lite SOC 2 Type II + ISO 27001 posture published on vcisolite.com/about.
  9. [9] ServiceNow IRM board reporting (out-of-box Operational Risk Management Dashboard, Performance Analytics module for dashboards/KPIs, HTML dashboards + PDF export) from ServiceNow product docs. Team-assembly-from-widgets pattern reflected in first-party documentation; no auto-narrating board-report generator on the public product surface. vCISO Lite QCD deliverables auto-generate the board-facing narrative; APRI can compose executive summaries from scenario runs on demand with every generation Ed25519-signed.
  10. [10] ServiceNow IRM pricing (all-employee-headcount licensing; ITSM fulfiller ~$70-$200/user/mo; standard packages ~$100/user/mo; Pro Plus with AI ~$160+/user/mo; Now Assist AI add-on 50-60% price uplift; mid-size enterprise 1,000-5,000 employees with Advanced Risk + TPRM + BCM + P&C + CAM at low-to-mid six figures ARR minimum; large enterprise $500K-$2M+ ARR for IRM alone before ITSM / ITOM) from third-party aggregator data and ServiceNow public statements. License-bloat observation (25-40% of licensed IRM module access sits with people who never open it) from third-party procurement surveys. vCISO Lite platform tiers ($299/mo Starter through $8,500/mo Enterprise MSRP) from vcisolite.com/pricing.
  11. All product capability claims for both platforms are current as of the “Prepared” date at the top of this page. If ServiceNow publishes a native Monte Carlo CRQ engine, an IRM-specific MCP tool graph, or an externally-anchored evidence chain since publication, corrections at /contact.
  12. This page compares ServiceNow IRM (Now Platform enterprise IRM) against vCISO Lite (CRQ + GRC + services on a narrower SKU). It does not compare against other IRM platforms on their own merits — the buyer evaluating enterprise IRM should also see /vs/riskonnect. Dedicated CRQ specialists at /vs/safe-security, /vs/kovrr, and /vs/cybersaint.