---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Request an exception for a remediation task in Configuration Compliance

# Request an exception for a remediation task in Configuration Compliance {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Request an exception to defer the remediation of a remediation task for a specified period if it can't be remediated immediately.

## Before you begin

Role required: sn_vulc.remediation_owner

## About this task

Important:  
You can request an exception for:

* remediation tasks in the Vulnerability Manager Workspace and IT Remediation Workspace. For more information, see [Request an exception in the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/u8048LRMppDaxV9c9jKGkg "Request an exception for the host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT) and remediation task (VUL, AVUL, CVUL, or CRG) from the IT Remediation Workspace.").
* multiple test results simultaneously from the Vulnerability Manager Workspace. For more information, see [Request bulk exception in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/FrQxWrSlJMo6g0Fuc2z~EQ "Request an exception for multiple records (VITs, AVITs, CVITs or TRs) concurrently using the bulk edit feature instead of manually selecting each record.").
{#cc-ex-request-test-result-group__ul_zgq_3fr_dcc}  
Note:  
Starting with v14.9 of Configuration Compliance, the following terms have been renamed:{#cc-ex-request-test-result-group__context_fdm_4nz_byb__entry__2}

| Terminology prior to v14.9 | Terminology v14.9 onwards |
|-|-|
| Test Result Group | Remediation Task |
| Group Rules | Remediation Task Rules |
| Policy | Test group |
[Table 1. Changes in terminology]

## Procedure

1. Navigate to AllConfiguration ComplianceRemediation TasksAll Tasks.
2. Select the remediation task that you want to request an exception for.  
   The selected task must be in the Open, Under Investigation, or Awaiting Implementation state.
3. On the Remediation Task form, click Request Exception.  
   Note:  
   Depending on whether Vulnerability Response or GRC: Policy and Compliance Management is selected in the Configuration ComplianceException Management screen, the Request Exception form changes. See [Configure Exception Management for Configuration Compliance](https://servicenow-prod.fluidtopics.net/yYx_bPQ12WgvWMT7VpDiZg "Limit the duration of an exception requested and add a questionnaire to the exception using the Configuration Compliance module. By default, an exception is requested using the ServiceNow Vulnerability Response module. You can also request an exception using the GRC: Policy and Compliance Management integration.")
4. If Vulnerability Response is selected in the Exception Management screen, then do the following:
   1. On the form, fill in the fields.  
      {#cc-ex-request-test-result-group__table_kxh_gh2_4lb__entry__2}

      | Field | Description |
      |-|-|
      | Until | Date on which the exception request expires. This date must be within the duration selected in the AllConfiguration ComplianceAdministrationException Management screen. When the exception request expires, the remediation task reverts to its Open state. Note: Starting with version 14.7 of Configuration Compliance (CC), if a deferred remediation task is reopened by a scanner before the exception window expires, then the state of the remediation task changes from Open to Deferred. This functionality is disabled by default. To enable this functionality, set the value of the system property sn_vulc.auto_defer_test_result_in_active_exception_window to true. Also, the deferred until date persists even after the remediation task reopens after the expiration date. |
      | Reason | Reason for the exception. Choices are as follows: * Risk Accepted * Awaiting Maintenance Window * Fix Unavailable * Mitigating Control in Place * Other {#cc-ex-request-test-result-group__ul_ifx_15g_3nb} To see how to add new reason choices, see [Define policy reason mappings](https://servicenow-prod.fluidtopics.net/_iKIddW1uu~s7eMTJ4UbjQ "You can define the reason choices to be available to any user who requests an exception."). |
      | Additional information | Details that are related to the reason why this request is being made. This field is to be updated by the remediation owner. |
      [Table 2. Request Exception form]

      {#cc-ex-request-test-result-group__table_kxh_gh2_4lb}
   2. Submit the exception request by clicking Request Approval.
   {#cc-ex-request-test-result-group__substeps_mb3_q24_hvb}
{#cc-ex-request-test-result-group__steps_jxh_gh2_4lb}

## Result

The state of the remediation task changes to In Review. Use the State Change Approval tab to track the status of the exception request.

*[\>]: and then


