The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →ServiceNow’s acquisition of Armis is complete. ServiceNow announced the approximately $7.75 billion all-cash deal on December 23, 2025, and closed it on April 20, 2026. The transaction gives ServiceNow Armis’ visibility into unmanaged IT, operational technology, internet-of-things, medical and other connected assets, which ServiceNow plans to combine with its workflow, risk and automation platform.
What happened to the ServiceNow-Armis deal?
The original headline that ServiceNow would “acquire” Armis described the announcement, not the current status. The transaction timeline is:
| Date | Event |
|---|---|
| December 23, 2025 | ServiceNow announced an agreement to buy Armis for approximately $7.75 billion in cash, subject to customary adjustments and closing conditions. ServiceNow’s announcement said the deal was then expected to close in the second half of 2026. |
| April 20, 2026 | ServiceNow announced that the acquisition had closed. It paid with cash on hand and debt. |
| May 5, 2026 | ServiceNow launched its Autonomous Security & Risk offering, incorporating Armis and Veza capabilities. |
| August 4, 2026 | ServiceNow announced additional autonomous-security products and availability milestones. |
Armis was founded in 2015 and remained privately held when acquired, but calling it merely a startup understates its scale. At announcement, ServiceNow said Armis had more than $340 million in annual recurring revenue (ARR), ARR growth above 50% year over year and approximately 950 employees.
The closing announcement is available from ServiceNow.
#1 Best Overall
What Armis contributes
Armis focuses on cyber-exposure management and cyber-physical security: finding connected assets, assessing their risk and helping organizations monitor and remediate exposures. Its Armis Centrix platform is cloud-native and covers:
- Traditional IT endpoints and network devices
- Operational technology in factories, utilities and transportation
- IoT devices
- Internet-connected medical equipment
- Cloud environments and connected physical infrastructure
- Code and other technology assets
The core problem is the visibility gap. Many devices cannot run a conventional endpoint agent, are managed by a different department or appear only intermittently on a network. An organization cannot reliably prioritize an asset it does not know exists.
Discovery is not the same as protection. A finding may still require segmentation, a patch, a configuration change, an access restriction or approval from an operational owner. Coverage also depends on network architecture, integrations, sensors, protocols and cloud permissions; agentless discovery is not a guarantee that every asset will be identified.
Why ServiceNow paid for Armis
From records to real-world asset intelligence
ServiceNow is best known for service management, workflows, configuration-management records, risk and response. Armis adds current intelligence about what devices are actually present and exposed. The intended chain is:
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →- Armis discovers and contextualizes a connected asset.
- ServiceNow links it to a business service, owner, criticality and existing risk records.
- Identity and permission information from Veza adds access context.
- Security teams prioritize the exposure.
- ServiceNow coordinates remediation, approvals, change requests and audit evidence.
That is strategically different from simply adding another alert feed. It aims to connect an asset’s technical condition to the business service it supports and the action an organization is authorized to take.
OT, IoT and medical-device reach
Hospitals, manufacturers, utilities and critical-infrastructure operators often cannot install agents on sensitive equipment or take systems offline for scanning. Armis’ emphasis on passive and non-invasive visibility gives ServiceNow an entry into environments where conventional IT security products can be incomplete or disruptive.
AI governance and automation
ServiceNow says Armis supplies asset context, Veza supplies identity and permission context, and the ServiceNow AI Platform supplies orchestration and governance. The company markets this as a way to let AI agents act with traceability and control. “Autonomous” and “agentic” are product positioning, however—not proof that security operations can run safely without human review.
Was $7.75 billion a high price?
Using the figures ServiceNow reported at announcement, the approximately $7.75 billion cash price divided by more than $340 million of ARR implies a rough transaction value of about 22.8 times ARR. This is an approximate comparison using company-reported recurring revenue, not a GAAP revenue, earnings or audited valuation multiple. It also does not adjust for cash, debt, retention arrangements or other definitive deal terms.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
The premium could be rational if Armis’ growth, enterprise customer base and scarce cyber-physical asset data accelerate ServiceNow’s existing business. ServiceNow also gets a potential cross-selling route into its installed base and data that may improve automated security workflows. Those are strategic possibilities, not guaranteed financial outcomes.
Execution risks include:
- Integrating Armis data with ServiceNow’s existing security products and CMDB
- Overlapping products or confusing packaging
- Retention of Armis engineering and sales talent
- Customer concern about higher prices or forced bundling
- Difficulty converting technical capability into durable incremental revenue
- Product development slowing during integration
How the purchase was financed
ServiceNow said it would use cash and debt. A subsequent SEC filing identified a $4 billion unsecured term loan maturing October 16, 2026, used to finance part of the cash consideration. That does not mean the entire $7.75 billion was borrowed; the disclosed structure was a combination of cash on hand and debt.
Near-term effect on ServiceNow’s finances
In its first-quarter 2026 materials, ServiceNow projected acquisition-related FY2026 pressure of approximately:
| Measure | Expected FY2026 effect |
|---|---|
| Subscription gross margin | 25-basis-point headwind |
| Operating margin | 75-basis-point headwind |
| Free-cash-flow margin | 200-basis-point headwind |
| Second-quarter operating margin | 125-basis-point headwind |
These are management projections for integration-related effects, not realized long-term results. ServiceNow said it expected margin expansion to normalize in 2027. Its security-and-risk annual contract value had already exceeded $1 billion in the third quarter of 2025, according to the company.
Rank #4
See the company’s first-quarter 2026 results for the guidance and assumptions.
What ServiceNow launched after closing
On May 5, ServiceNow introduced Autonomous Security & Risk, describing an offering that integrates Armis and Veza capabilities. By August 4, ServiceNow said these capabilities were available:
- Agentic Exposure Management
- Autonomous Remediation Agents
- Application Security
- Dynamic Application Security Testing
- External Attack Surface Management
- Agentic AI for Cyber-Physical Security
- AI Agent Access Security
- Non-Human Identity Remediation
ServiceNow said a Tier 2 SOC AI Specialist and Vulnerability Resolution AI Specialist were expected in December 2026. “Available,” “announced,” and “planned” are different categories; an acquired technology is not automatically a generally available product. The August claims come from ServiceNow’s announcement, which also uses “most complete” as marketing language.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What enterprise customers should evaluate
Potential fit
- You already use ServiceNow for ITSM, CMDB, SecOps, risk or compliance.
- You have substantial unmanaged, OT, IoT or medical-device exposure.
- Security and operations teams need shared asset and business-service context.
- You want remediation workflows, approvals and audit evidence rather than alerts alone.
- Governance and human oversight matter for automated or AI-assisted actions.
Potentially poor fit
- Your requirement is limited to endpoint detection and response.
- Your environment is small, mostly cloud-native and has little unmanaged-device or OT exposure.
- You do not operate ServiceNow and do not want to adopt its workflow platform.
- Your primary need is SIEM, network detection, identity protection or cloud posture management.
- You require transparent public pricing and simple self-service deployment.
Implementation failure points
ServiceNow’s Unified Security Exposure Management documentation shows that findings from tools such as CrowdStrike, Microsoft Defender, Qualys, Tenable, Palo Alto Networks, AWS and Tanium must be matched to CMDB assets. Duplicate records, incorrect ownership or stale criticality can therefore produce bad prioritization. Sensitive OT remediation also needs operational-owner approval; an automated change that fixes a vulnerability but interrupts production is not a successful outcome.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
Buyers should ask how Armis data is mapped to the CMDB, which existing integrations remain supported, how licensing is packaged, what happens to current Armis customers and how the vendor measures reduced exposure and faster remediation.
How the deal changes the competitive choice
This is not necessarily a choice between ServiceNow and every specialist security product. ServiceNow can act as the workflow and governance layer above tools already used by an enterprise. Microsoft Defender may be more natural for organizations centered on Microsoft 365, Azure and Entra. CrowdStrike remains strongly oriented toward endpoint and cloud security. Palo Alto Networks may fit network, SASE and cloud-platform consolidation. Tenable or Qualys may be better for conventional vulnerability management, Tanium for endpoint administration, and Claroty for highly specialized industrial or healthcare environments.
Armis is most differentiated when broad cyber-physical visibility is the problem and ServiceNow workflow integration is valuable. Public list pricing for the combined offering was not stated in the reviewed official materials; enterprise quotes will vary with asset count, modules, geography, integrations, support and existing commitments. The ServiceNow security page, Armis Centrix page and Armis-ServiceNow integration page direct buyers to enterprise conversations rather than self-serve checkout.
What investors and customers should watch next
- Whether Armis’ engineering and sales teams remain intact.
- Evidence that customers receive simpler workflows instead of another expensive platform layer.
- Retention of Armis’ integrations and perceived vendor neutrality.
- Changes in packaging, contract terms and renewal pricing.
- Actual improvements in exposure reduction, remediation time and service reliability.
- Whether margin pressure eases as ServiceNow indicated in its 2027 outlook.
The Bottom Line
ServiceNow’s $7.75 billion Armis purchase is no longer pending: it closed on April 20, 2026. The strategic logic is clear—combine Armis’ broad asset visibility with ServiceNow’s workflow and governance—but the deal’s success depends on clean data, careful automation, retained talent and measurable customer outcomes.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




