MuleSoft's transition plan for Object Store V2 data-at-rest encryption after the deprecation of FIPS 140-2 in September 2026. The customer specifically wanted to know the replacement encryption standard, the timeline for availability, and whether any SLA applied.
The concern arises from the upcoming NIST deprecation of FIPS 140-2 as a validated cryptographic module standard. Organizations need to ensure that their data processing and storage solutions, including MuleSoft Object Store V2, will remain compliant with current and future security standards, specifically FIPS 140-3.
MuleSoft Object Store V2 already utilizes FIPS 140-3 validated cryptographic modules for data-at-rest encryption. This ensures compliance well in advance of the NIST 2026-09-21 historical cutoff date for FIPS 140-2.
Key details regarding Object Store V2 encryption:
FAQ page that is being updated: https://docs.mulesoft.com/object-store/osv2-faq#how-is-object-store-v2-data-secured
005389639

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.