Combined Encryption release notes for upgrades from Yokohama to Zurich

  • Release version: Zurich
  • Updated August 11, 2026
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Encryption release notes for upgrades from Yokohama to Zurich

    This consolidated release note page provides essential information for ServiceNow customers upgrading Encryption features from the Yokohama release to the Zurich release. It highlights new features, changes, deprecations, and important upgrade considerations relevant to Encryption capabilities within the platform.

    Show full answer Show less

    Important Upgrade Information

    • 3DES Deprecation: The Zurich release officially removes the use of the Triple Data Encryption Standard (3DES) in the GlideEncrypter API due to NIST 800-131A Rev 2 recommendations. 3DES is no longer supported for encrypted string keys, with the Key Management Framework (KMF) and Advanced Encryption Standard (AES) algorithms now mandated for encryption and decryption operations.
    • GlideEncrypter API Changes: The API defaults to KMF-based AES encryption for upgraded instances. For instances created on Zurich or later, GlideEncrypter API is not supported.
    • Column Level Encryption Upgrade: Column Level Encryption has been upgraded to use KMF-CLE due to 3DES deprecation across the platform.
    • Activation: Encryption features require activation of the com.glide.now.platform.encryption plugin as part of the Platform Encryption subscription bundle, which includes Field Encryption Enterprise and Cloud Encryption.

    New Features

    • Row Condition Encryption: Field Encryption now supports defining encryption rules based on row conditions within specific columns, enabling dynamic and granular encryption policies.
    • Attachment Encryption: The Field Encryption Enterprise API supports encryption on attachments using any of the three available Encryption APIs without requiring a specific one.

    Changes

    • The Field Encryption Enterprise API now allows flexible encryption on attachments using all three Encryption APIs.

    Deprecated Features

    • Use of 3DES encryption format for encrypted string keys is deprecated and no longer supported. Customers must transition to KMF-based encryption formats.

    Other Considerations

    • No updates were noted for Yokohama release.
    • There are no additional changes to browser requirements, accessibility, or localization related to Encryption in Zurich.

    Practical Impact for Customers

    When upgrading from Yokohama to Zurich, customers should prepare by completing pre- and post-upgrade tasks related to encryption key formats and API usage. Transitioning away from 3DES to KMF and AES ensures compliance with modern security standards. The new row condition encryption feature allows for more precise control over encrypted data. Activation of the appropriate plugins and subscription bundles is required to leverage these Encryption features effectively.

    Consolidated page of all release notes for Encryption from Yokohama to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Encryption release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Encryption to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    For the GlideEncrypter API, NIST 800-131A Rev 2 has recommended against using the Triple Data Encryption Standard (3DES) encryption. The following changes are taking place in the Zurich release with the official removal of 3DES encryption for GlideEncrypter.
    • The GlideEncrypter API defaults to using the Key Management Framework (KMF) based algorithm, Advanced Encryption Standard (AES), for encryption and decryption operations for upgraded instances only.
    • For instances created with the Zurich release or later, this API isn’t supported.
    • Learn more about 3DES deprecation in KB1704481.

    In the Zurich release, Column Level Encryption has received a required upgrade to Key Management Framework Column Level Encryption (KMF-CLE) due to the platform-wide deprecation of 3DES. For more information about this upgrade, see KB1700704.

    New features

    Between your current release family and Zurich, new features were introduced for Encryption.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    Encrypt data using Row Conditions
    Use row conditions for Field Encryption to define encryption rules for rows within a specific column, based on dynamic conditions.

    Changes

    Between your current release family and Zurich, some changes were made to existing Encryption features.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    Field Encryption Enterprise API

    Use all three Encryption APIs to encrypt on attachments, without needing to use any one specific API.

    Removed

    Between your current release family and Zurich, some Encryption features or functionality were removed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some Encryption features or functionality were deprecated.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    Prepare your instance for GlideEncrypter deprecation
    Encrypted string keys 3DES format is no longer supported. Key Management Framework (KMF) is the supported format.

    Activation information

    Review information on how to activate Encryption.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    The Platform Encryption subscription bundle is a group commercial entitlement that includes Field Encryption Enterprise and Cloud Encryption.

    Field Encryption Enterprise is the unlimited license of Field Encryption. The Enterprise plugin is available with the activation of the com.glide.now.platform.encryption plugin. For details, see the Encryption and Key Management subscription bundle.

    Additional requirements

    If any additional requirements were introduced or changed for Encryption we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Encryption we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Accessibility information

    Review details on accessibility information for Encryption, such as specific requirements or compliance levels.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Localization information

    If there are specific localization considerations for Encryption we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Encryption we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    • Use row conditions for Field Encryption to define encryption rules for rows within a specific column, based on dynamic conditions.
    • Use any of the three Field Encryption APIs to encrypt attachments.

    See Encryption for more information.