---
sourceDocument: Zurich Release Notes
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/zurich/release-notes

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Release Notes

ft:clusterId :

    - rn

bundleId :

    - rn


---

# Encryption Release Notes

# Encryption Release Notes {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
The ServiceNow®
Encryption Key Management application protects your data by using encryption, tightly controlled key access, National Institute of Standards and Technology (NIST) 800-57-based key life-cycle management, and FIPS 140-2-L3
validated key protection. Encryption Key Management was enhanced and updated in the Zurich release.

## About Encryption {#encryption-rn__encryption-rn-highlights}

* Use row conditions for Field Encryption to define encryption rules for rows within a specific column, based on dynamic conditions.
* Use any of the three Field Encryption APIs to encrypt attachments.
{#encryption-rn__ul_irz_b5w_lfc}

See [Encryption](https://www.servicenow.com/docs/access?context=encryption-landing&version=zurich&pubname=zurich-platform-security&ft:locale=en-US) for more information.{#encryption-rn__encryption-rn-highlights-2}

## Activation and other requirements

Activation information

:   The Platform Encryption subscription bundle is a group commercial entitlement that includes Field Encryption Enterprise and Cloud Encryption.{#encryption-rn__encryption-rn-activation-1}

    Field Encryption Enterprise is the unlimited license of Field Encryption. The Enterprise plugin is available with the activation of the com.glide.now.platform.encryption plugin. For details, see the [Encryption and Key Management subscription bundle](https://www.servicenow.com/docs/access?context=encryption-sku&version=zurich&pubname=zurich-platform-security&ft:locale=en-US).{#encryption-rn__encryption-rn-activation-2}

Upgrade information
:   For the GlideEncrypter API, NIST 800-131A Rev 2 has recommended against using the Triple Data Encryption Standard (3DES) encryption. The following changes are taking place in the Zurich release with the official removal of 3DES encryption for GlideEncrypter.

    * The GlideEncrypter API defaults to using the Key Management Framework (KMF) based algorithm, Advanced Encryption Standard (AES), for encryption and decryption operations for upgraded instances only.
    * For instances created with the Zurich release or later, this API isn't supported.
    * Learn more about 3DES deprecation in [KB1704481](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1704481).
    {#encryption-rn__ul_t33_dww_lfc}

    In the Zurich release, Column Level Encryption has received a required upgrade to Key Management Framework Column Level Encryption (KMF-CLE) due to the platform-wide deprecation of 3DES. For more information about
    this upgrade, see KB1700704.{#encryption-rn__encryption-rn-upgrade-info-2}

## Zurich {#ariaid-title2}

The ServiceNow®
Encryption Key Management application protects your data by using encryption, tightly controlled key access, National Institute of Standards and Technology (NIST) 800-57-based key life-cycle management, and FIPS 140-2-L3
validated key protection. Encryption Key Management was enhanced and updated in the Zurich release.

### What's new {#encryption-rn-release__encryption-rn-new-features}

[Encrypt data using Row Conditions](https://www.servicenow.com/docs/access?context=encrypt-data-using-row-conditions&version=zurich&pubname=zurich-platform-security&ft:locale=en-US)
:   Use row conditions for Field Encryption to define encryption rules for rows within a specific column, based on dynamic conditions.
{#encryption-rn-release__encryption-rn-new-features-1}

### What's changed {#encryption-rn-release__encryption-rn-changed-features}

[Field Encryption Enterprise](https://www.servicenow.com/docs/access?context=now-platform-encryption&version=zurich&pubname=zurich-platform-security&ft:locale=en-US) API{#encryption-rn-release__encryption-release-notes-rn-workspace}

:   Use all three Encryption APIs to encrypt on attachments, without needing to use any one specific API.

{#encryption-rn-release__encryption-rn-changed-features-1}

### What's deprecated or removed {#encryption-rn-release__encryption-rn-deprecations}

[Prepare your instance for GlideEncrypter deprecation](https://www.servicenow.com/docs/access?context=check-3des&version=zurich&pubname=zurich-platform-security&ft:locale=en-US)
:   Encrypted string keys 3DES format is no longer supported. Key Management Framework (KMF) is the supported format.
{#encryption-rn-release__encryption-rn-deprecations-1}

