---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Defer a Remediation task

# Defer a Remediation task {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If you determine that the issue associated with a remediation task (VUL) is a low
priority and can be immediately deferred without further analysis, you can use the
Request Exception feature.

## Before you begin

Role required: sn_vul.vulnerability_admin or sn_vul.admin (deprecated)

## About this task

You can defer a remediation task from a remediation task
record in the Vulnerability Response Workspaces. After you submit the request, it
is sent for approval. See [Request an exception in the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/u8048LRMppDaxV9c9jKGkg "Request an exception for the host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT) and remediation task (VUL, AVUL, CVUL, or CRG) from the IT Remediation Workspace.").

A scheduled job runs every day checking for deferred remediation tasks that have
reached their reopen date. On the day the task's deferral is set to expire, the task
is reopened.  
Note:  
You can manually move change requests and remediation tasks through the states of their life cycles on their respective records with state synchronization enabled, but when the system registers that a CHG has changed its state, or you add a CHG or remove it from a remediation task, state synchronization potentially can override your manual intervention. However, change request states do not automatically move remediation tasks from the Closed or Deferred states.

## Procedure

1. Navigate to AllVulnerability ResponseRemediation Tasks.
2. Open a record.
3. Click Request Exception.
4. Fill in the fields on the form, as appropriate.  
   {#defer-vuln-group__table_s52_yvn_r6__entry__2}

   | Field | Description |
   |-|-|
   | Until | Select the date when the Defer state expires and the remediation task is reactivated. After the record is submitted, if [email notifications](https://servicenow-prod.fluidtopics.net/JPkqSBydpqxEsGxwINbCCg "Set up email notifications to share useful information about important updates and activities such as approval and rejection of false-positive requests. Creating an email notification involves specifying when to send it, who receives it, and what it contains.") are defined, members of the Vulnerability Response group receive an email when the expiration date is within one week. When the defer date expires, the remediation task is set back to Open and a second email notification is sent out. |
   | Reason | Enter the reason for deferring the issue. Choices include: * Awaiting maintenance window * False positive * Fix unavailable * Risk accepted * Mitigating control in place * Other {#defer-vuln-group__ul_r55_vb1_xdb} |
   | Additional information | Enter any other relevant information. |
   [ ]

   {#defer-vuln-group__table_s52_yvn_r6}
5. Click Submit.  
   The group is marked In Review. A Reopen related link appears. The reopen date and reason appear in work notes under the State Change Approvals tab.
* **[Request an extension for a deferred remediation task](https://servicenow-prod.fluidtopics.net/TubbJCagVBBFhHzAWdHV1A)**   
  Request an extension for a deferred remediation task (VUL) before it reaches its deferred until due date. As a remediation owner, you're no longer required to wait until the deferred due date to make this request.

*[\>]: and then


