Use default encryption at rest for new Amazon Aurora clusters
Database Blog
This article announces that Amazon Aurora now enables encryption at rest by default for all new database clusters using AWS owned keys, improving security and compliance without additional cost or configuration.
- All new Aurora clusters automatically encrypted with AWS owned keys (SSE-RDS)
- New StorageEncryptionType field shows encryption status: sse-rds, sse-kms, or none
- Existing clusters remain unchanged; no automatic encryption applied
- Three encryption options available: AWS owned, AWS managed, or customer managed keys
- Restoring unencrypted snapshots creates encrypted clusters by default
- Existing unencrypted databases can migrate via snapshot restore process
- No performance impact or additional charges for default encryption
- Meets regulatory requirements: GDPR, HIPAA, PCI DSS, SOC 2
Aurora's default encryption simplifies compliance and enhances data security for new deployments while allowing existing databases to maintain their current state.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2026
2026
2026
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.