ServiceNow CSA: Skills Measured on the Exam

ServiceNow’s current Certified System Administrator mainline blueprint was updated in January 2026. The CSA exam contains 60 questions in 90 minutes and uses both multiple-choice and multiple-select items. ServiceNow reports a conditional pass or fail immediately after submission and provides section-level percentages, while keeping detailed scoring methodology private.

The current six domains are Platform Overview and Navigation 7%, Instance Configuration 10%, Configuring Applications for Collaboration 20%, Self Service & Automation 20%, Database Management and Platform Security 30%, and Data Migration and Integration 13%. Those percentages make data/platform security the largest area by a clear margin.

Platform Overview and Navigation is 7%

The first domain covers ServiceNow platform purpose, capabilities and services, the instance concept, and Next Experience Unified Navigation. Candidates should understand how the platform is organized before studying configuration details.

This is a small domain, but weak navigation slows every practical task and makes later objectives harder to visualize.

Instance Configuration is 10%

This area covers installing applications and plugins, personalizing or customizing the instance, and common user interfaces in the platform. The administrator should understand what configuration belongs at user level versus application or instance level.

Configuration choices should be made with maintainability in mind because excessive customization can complicate upgrades and support.

Collaboration configuration is 20%

Lists, filters, tags, list/form anatomy, form configuration, templates, advanced form behavior, task management, Visual Task Boards, visualizations, dashboards, Platform Analytics, and notifications all appear here.

The administrator should be comfortable moving between data presentation, task workflow, and user communication rather than treating a form as a static screen.

Lists, forms, and filters are everyday administrator tools

Lists expose many records at once; filters narrow the dataset; forms show individual records; views and configuration determine what users see. Administrators need to understand reference fields, related lists, field attributes, and common form/list customization patterns.

Good configuration improves usability without hiding information users need to perform their role.

Self Service & Automation is 20%

The current blueprint includes Knowledge Management, Service Catalog, Workflow Studio, and Virtual Agent. These capabilities let organizations shift routine work from manual fulfillment toward reusable knowledge, request models, automation, and conversational self-service.

A ServiceNow CSA preparation plan should connect catalog requests with flows, approvals, tasks, and knowledge rather than study each capability independently.

Database Management and Platform Security is 30%

The largest domain covers data schema, application/access control, importing data, CMDB and Common Service Data Model concepts, Security Center, and ServiceNow’s shared-responsibility model.

This weighting signals that CSA candidates need to understand how records, tables, relationships, access, configuration data, and platform security work together.

Data schema and access control belong together

Tables can extend other tables, fields have data types and attributes, references create relationships, and records are protected by roles or access controls. An administrator should know that hiding a field in a form is not the same as enforcing access control.

Security must be implemented at the platform/data layer where all interfaces respect it.

CMDB and CSDM introduce service-aware data modeling

The CMDB stores configuration-item records and relationships used by IT service-management processes, while CSDM provides guidance for organizing service-related data. CSA does not require deep enterprise-architecture expertise, but candidates should recognize why consistent classes, relationships, and ownership matter.

Poor CMDB data reduces the value of incident, change, service, and reporting processes that depend on it.

Data Migration and Integration is 13%

The blueprint lists UI Policies, Business Rules, system update sets, and scripting in ServiceNow. These topics connect local configuration, server-side behavior, migration between instances, and custom logic.

CSA candidates should understand what each mechanism is for and when configuration can solve a requirement without unnecessary custom scripting.

The current CSA is an administration-and-platform exam

ServiceNow recommends official training such as Welcome to ServiceNow and ServiceNow Administration Fundamentals, plus several months of hands-on instance experience. The blueprint assumes practical familiarity with an instance rather than pure memorization.

ServiceNow’s blueprint also recommends three to six months of experience using or maintaining an instance. That recommendation explains why purely memorized preparation can feel insufficient: many questions assume familiarity with the way lists, forms, records, roles, and configuration behave in a real instance.

Platform capabilities and services should be learned at an architectural level. ServiceNow is a platform on which multiple applications share data, automation, security, reporting, and user-interface services. Understanding that common platform model makes it easier to reason about configuration that affects several applications.

Applications and plugins should be treated differently from simple navigation modules. Installing a plugin can add tables, roles, business logic, and features to the instance. Administrators should review dependencies and the impact on the instance before enabling optional functionality casually.

Personalization is typically user-specific, while customization/configuration can affect broader audiences. A candidate should be able to recognize whether a list-layout change is only for one user or whether a form/configuration change alters the shared application experience.

Filters and tags are important because ServiceNow administrators constantly work with large record sets. A well-built filter expresses business criteria precisely, while tags can help organize work without altering the data model. Complex filters should be validated to avoid excluding important records accidentally.

Form configuration includes field order, sections, related lists, views, mandatory/read-only behavior, and templates. Administrators should know which changes affect all users and which are scoped to a view or role. Usability depends on presenting the right information without overwhelming the fulfiller.

Task management matters because many ServiceNow applications inherit from the Task table. Incidents, changes, and other work records share common behaviors while adding specialized fields or processes. Understanding table extension helps candidates see why certain fields and workflows appear across applications.

Visual Task Boards provide a visual way to organize work by state or assignment. The underlying records still remain in their source tables, so board movement should be understood as another interface to record data rather than a separate workflow database.

Platform Analytics and dashboards turn operational data into trends and performance views. A visualization is only as trustworthy as the source records and filters feeding it. Administrators should understand how to validate a report before using it for management decisions.

Notifications combine events or conditions, recipients, and message content. A poorly scoped notification can spam users or expose information to the wrong audience. Testing recipient logic and understanding when a message is triggered are ordinary administrator responsibilities.

Knowledge Management should be understood as content lifecycle, not just article creation. Authors, approvers, knowledge bases, categories, publishing, feedback, and retirement all affect whether self-service information remains accurate and trusted.

Service Catalog items define repeatable requests. Variables collect user input, flows or workflows create fulfillment logic, and approvals or tasks route work to the correct teams. Catalog design is stronger when it reduces ambiguity for both requester and fulfiller.

Workflow Studio represents ServiceNow’s modern automation environment. Administrators should recognize triggers, actions, conditions, approvals, subflows, and data pills at the conceptual level and know when automation is preferable to manual task routing.

Virtual Agent extends self-service with conversational interactions. A topic can answer a question or guide a user into a supported process. The key administrative concern is whether the topic connects to accurate knowledge and controlled fulfillment rather than simply creating a conversational front end.

The data-schema portion of the 30% domain includes table extensions, fields, reference relationships, dictionary configuration, and record behavior. A schema change can affect forms, reports, business rules, imports, and integrations, so administrators should treat data-model edits as platform changes with broad impact.

Access Control should be learned as enforceable platform security. Roles, ACLs, and application scope can determine whether a user can read, create, write, or delete records or fields. A client-side visibility rule alone does not provide equivalent protection because other interfaces may still reach the data.

Importing data requires more than uploading a spreadsheet. Administrators should understand import sets, transform maps, coalesce behavior, field mapping, and data validation at an appropriate CSA level. A bad import can create duplicate or malformed records quickly.

Security Center and the shared responsibility model bring security posture into the CSA foundation. ServiceNow protects the underlying cloud/platform according to its responsibilities, while customers remain responsible for identity, access, data, configuration, and many application-level decisions.

UI Policies and Business Rules are intentionally grouped in the migration/integration domain because both are common extension mechanisms. UI Policies influence form behavior on the client; Business Rules execute server-side around record operations. Choosing the wrong layer can create inconsistent behavior across interfaces.

Scripting in ServiceNow should be treated as a tool used when declarative configuration is insufficient. CSA candidates need to recognize scripts and basic use cases, but developer-level mastery belongs in later credentials. Excessive scripting can make upgrades and maintenance harder.

The blueprint’s current weighting also changes how to allocate preparation time. Nearly one-third of questions map to database/security, while collaboration and self-service/automation each represent one-fifth. Navigation is essential but should not consume the same study time as schema, ACLs, CMDB, imports, and platform security.

Because multiple-select items provide no partial credit, careful reading matters. If a question says select three, choose exactly three and evaluate every option against platform behavior. Hands-on familiarity helps because distractors often sound plausible when you know only definitions.

Update sets deserve careful scope awareness because they are primarily a mechanism for transporting configuration, not arbitrary operational data. Administrators should preview and validate them in the target instance and understand that some records, attachments, or data migrations require separate methods.

Within the ServiceNow certification path, CSA validates the platform-administration foundation on which implementation, development, and specialist credentials build.