Quick Research now supports customer managed keys
Bring your own KMS keys to Quick Research for full encryption control, rapid key revocation, and audit-ready compliance in regulated environments.
View original announcement →Visual Summary
What's New
Amazon Quick Research now supports customer-managed keys (CMK) via AWS Key Management Service (KMS), giving organizations direct control over the encryption keys protecting their business intelligence and research data. This feature enables enterprises with strict security and compliance requirements to bring their own symmetric KMS keys rather than relying solely on AWS-managed encryption. The capability is generally available across all AWS Regions where Amazon Quick Research is offered.
How It Works
- CMK Integration via AWS KMS: Customers create symmetric KMS keys in the same AWS account and region as their Quick Research resources, then designate one as the default key per account per region.
- Multiple CMK Support: The feature allows multiple CMKs to be associated with a single account, enabling granular encryption control across different datasets or organizational units.
- Symmetric Keys Only: Only symmetric AWS KMS keys are supported; asymmetric keys are not compatible with this feature.
- CloudTrail Audit Integration: All key usage and data access events are logged through AWS CloudTrail, providing a comprehensive, tamper-evident audit trail for security and compliance reviews.
- Key Revocation: In the event of a security incident, access to a compromised key can be revoked within 15 minutes, limiting the blast radius of potential data exposure.
- Same-Region Requirement: CMKs must reside in the same AWS account and region as the Quick Research resources they protect, ensuring data sovereignty and low-latency key operations.
Why It's Important
- Regulatory Compliance: Organizations subject to frameworks such as HIPAA, FedRAMP, GDPR, or PCI-DSS often mandate customer-controlled encryption keys; this feature removes a previous blocker to adopting Quick Research in regulated environments.
- Enhanced Security Posture: Owning the key lifecycle—creation, rotation, and deletion—means organizations are not dependent on AWS's key management schedule, reducing shared-responsibility ambiguity.
- Rapid Incident Response: The ability to revoke key access within 15 minutes provides a meaningful operational control during active security incidents, limiting potential data exposure windows.
- Auditability: Deep CloudTrail integration satisfies auditor demands for evidence of who accessed what data and when, which is critical for internal governance and external audits.
- Enterprise Readiness: CMK support signals that Quick Research is maturing toward enterprise-grade security requirements, making it viable for use cases involving sensitive IP, financial data, or proprietary research.
How It's Different
- Customer vs. AWS-Managed Keys: Previously, Quick Research relied on AWS-managed encryption keys, where AWS controlled the key material. CMK support shifts that control entirely to the customer.
- Granular Multi-Key Management: Unlike a single default encryption model, this feature supports multiple CMKs per account, allowing different encryption policies for different datasets or business units—a level of granularity not available with AWS-managed keys.
- Active Revocation Capability: AWS-managed keys cannot be revoked by the customer on demand; CMKs allow near-immediate revocation (within 15 minutes), a critical differentiator for incident response.
- Full Audit Trail Ownership: With CMKs, CloudTrail logs for key usage are owned and accessible by the customer, whereas AWS-managed key usage logs are less directly surfaced to end users.
- Compliance Posture: CMK support enables Quick Research to meet compliance requirements that explicitly prohibit the use of provider-managed keys, expanding its eligible deployment scenarios.
When to Prefer It
- Regulated Industries: Use CMKs when operating in healthcare, financial services, government, or other sectors where regulations require demonstrable control over encryption key material.
- Zero-Trust Security Architectures: Prefer CMKs when your security model mandates that no third party—including AWS—can access data without explicit customer-controlled key authorization.
- Multi-Tenant or Multi-Business-Unit Environments: Use multiple CMKs to enforce encryption boundaries between different teams, projects, or data sensitivity levels within the same AWS account.
- Active Incident Response Programs: Organizations with mature security operations centers (SOCs) that need the ability to rapidly revoke data access during a breach should leverage CMK revocation capabilities.
- Audit-Intensive Workloads: When external auditors or internal compliance teams require detailed, customer-owned logs of every data access event, CMK + CloudTrail integration is the appropriate choice.
- Data Sovereignty Requirements: Use CMKs when contractual or legal obligations require that encryption keys never leave a specific AWS account or region boundary.
Availability
- GA Status: Generally available as of May 21, 2026; this is not a preview or beta feature.
- Regional Availability: Available in all AWS Regions where Amazon Quick Research is supported, including US East (N. Virginia), US West (Oregon), and multiple Asia Pacific, Europe, and other regions.
- Key Constraints: Only symmetric AWS KMS keys are supported; asymmetric keys are not compatible.
- Account/Region Boundary: CMKs must be created in the same AWS account and region as the Quick Research resources they encrypt; cross-account or cross-region keys are not supported.
- Default Key Limit: One default CMK per AWS account per region is enforced, though multiple CMKs can be configured for use across different datasets.
- Pricing: AWS KMS charges apply for CMK creation, storage, and API calls; Quick Research feature enablement itself does not carry an additional announced surcharge, but customers should review KMS pricing for key usage costs.