Loading

MuleSoft Object Store V2 Data-at-Rest Encryption Standard and FIPS 140-3 Compliance

Publiseringsdato: Jul 22, 2026
Beskrivelse

MuleSoft's transition plan for Object Store V2 data-at-rest encryption after the deprecation of FIPS 140-2 in September 2026. The customer specifically wanted to know the replacement encryption standard, the timeline for availability, and whether any SLA applied.

CAUSE

The concern arises from the upcoming NIST deprecation of FIPS 140-2 as a validated cryptographic module standard. Organizations need to ensure that their data processing and storage solutions, including MuleSoft Object Store V2, will remain compliant with current and future security standards, specifically FIPS 140-3.

 

Løsning

MuleSoft Object Store V2 already utilizes FIPS 140-3 validated cryptographic modules for data-at-rest encryption. This ensures compliance well in advance of the NIST 2026-09-21 historical cutoff date for FIPS 140-2.

 

Key details regarding Object Store V2 encryption:

1. Encryption Standard: FIPS 140-3. Object Store V2's data-at-rest encryption is delivered via FIPS 140-3 validated cryptographic modules with active CMVP certificates.
2. Encryption Algorithm: AES-256 (unchanged from previous posture).
3. TLS Support: TLS 1.2 and TLS 1.3 remain supported. TLS 1.0 and TLS 1.1 remain unsupported.
4. Timeline: There is no customer-visible migration event for Object Store V2 related to this transition. The underlying encryption is already backed by FIPS 140-3 validated modules today, well ahead of the NIST 2026-09-21 date.
5. Customer Impact: No customer-side action is required. There are no API changes, no re-keying, and no reconfiguration necessary.
Flere ressurser

FAQ page that is being updated: https://docs.mulesoft.com/object-store/osv2-faq#how-is-object-store-v2-data-secured

Knowledge-artikkelnummer

005389639

 
Laster
Salesforce Help | Article