Change the server-side encryption type of Amazon S3 objects
News
This article announces the new UpdateObjectEncryption API for Amazon S3, enabling users to change server-side encryption types of objects without data movement.
- Change encryption type atomically without moving data
- Works with any object size or storage class
- Use S3 Batch Operations to update entire buckets at scale
- Migrate from SSE-S3 to SSE-KMS for compliance requirements
- Switch customer-managed KMS keys for rotation standards
- Enable S3 Bucket Keys to reduce KMS request costs
- Available in all AWS Regions via Console and SDKs
UpdateObjectEncryption simplifies compliance by allowing encryption standardization across S3 buckets without operational overhead.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
May 14
2025
2025
Understanding Amazon S3 client-side encryption options
Nov 20
2025
2025
Amazon S3 adds new bucket-level setting to standardize encryption types used in your buckets
Jan 16
2025
2025
Preventing unintended encryption of Amazon S3 objects
Apr 16
2025
2025
Amazon S3 Tables now support server-side encryption using AWS KMS with customer-managed keys
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.