Glossary

    KMS Key

    Data Protection

    A KMS Key (formerly called a Customer Master Key or CMK) is a cryptographic key created and managed in AWS Key Management Service. KMS keys are used to encrypt data across 70+ AWS services - S3, EBS, RDS, DynamoDB, Secrets Manager, and more.

    Key Types

    • AWS managed keys: created and rotated by AWS for specific services (free, less control)
    • Customer managed keys: you create, control policies, and decide rotation ($1/month + API costs)
    • AWS owned keys: used by AWS services internally (no cost, no visibility)

    Key Features

    • Keys never leave AWS KMS in plaintext (FIPS 140-3 Level 3 validated HSMs)
    • Automatic key rotation (every year for customer managed keys)
    • Key policies + IAM policies control who can use the key
    • All key usage is logged in CloudTrail
    • Post-quantum digital signatures (ML-DSA) available since June 2025; post-quantum TLS (ML-KEM) rolled out across services throughout 2025

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.