aws AWS What's New ·

Amazon QuickSight now supports customer-managed keys

securityawsgaengineer
feature

Amazon QuickSight now allows customers to encrypt data using their own AWS Key Management Service (KMS) customer-managed keys (CMK). This feature enhances security and compliance for organizations by providing greater control over encryption and auditability via CloudTrail. It is now generally available in all AWS Regions where QuickSight is offered, requiring CMKs to be created in the same account and region, and supporting only symmetric KMS keys.

  • Encrypt QuickSight data with customer-managed KMS keys
  • Granular control and auditability with CMKs
  • Prerequisites and availability
Features (1)
  • Encrypt QuickSight data with customer-managed KMS keys

    Amazon QuickSight now supports encryption of customer data using customer-managed keys (CMK) via AWS Key Management Service (KMS). This provides enhanced security controls and audit capabilities, allowing organizations to manage their own encryption keys for sensitive business intelligence data.

Enhancements (1)
  • Granular control and auditability with CMKs

    With customer-managed keys, users gain enhanced security control, comprehensive audit capabilities through AWS CloudTrail, and the ability to revoke access to compromised keys within 15 minutes. The feature supports multiple CMKs with one default key per AWS account per region.

Notes (1)
  • Prerequisites and availability

    Customer-managed keys must be created in the same AWS account and region as QuickSight resources, and only symmetric AWS KMS keys are supported. This feature is generally available in all AWS Regions where Amazon QuickSight is available.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-quick-research-cmk

Related releases