AWS Storage Blog
Advanced notice: Amazon S3 to disable the use of SSE-C encryption by default for all new buckets and select existing buckets in April 2026
Starting on April 6, 2026, we will be changing how server-side encryption with customer-provided keys (SSE-C) is enabled for Amazon S3 buckets. With this change, SSE-C will be disabled by default on all new S3 general purpose buckets. Furthermore, SSE-C will also be disabled for all existing buckets in Amazon Web Services (AWS) Accounts that […]
Enhance savings for read-heavy workloads with Amazon S3 Bucket Keys
Organizations continue to grow their data lakes in the cloud as they build out new and innovative analytics, machine-learning, and generative AI workloads. At the same time, these workloads often access data that requires compliance with stringent data security and privacy standards. These compliance frameworks typically specify additional requirements for encryption at-rest, which leads customers […]
Reducing AWS Key Management Service costs by up to 99% with Amazon S3 Bucket Keys
Note: On 1/29/2026, Amazon S3 added support for the UpdateObjectEncryption API letting you change the server-side encryption type of encrypted objects in S3 without any data movement regardless of the object size or storage class. Using S3 Batch Operations, you can use UpdateObjectEncryption at scale to enable S3 Bucket Keys on entire buckets of objects […]

