Home icon

Use default encryption at rest for new Amazon Aurora clusters

Database Blog



This article announces that Amazon Aurora now enables encryption at rest by default for all new database clusters using AWS owned keys, improving security and compliance without additional cost or configuration.

  • All new Aurora clusters automatically encrypted with AWS owned keys (SSE-RDS)
  • New StorageEncryptionType field shows encryption status: sse-rds, sse-kms, or none
  • Existing clusters remain unchanged; no automatic encryption applied
  • Three encryption options available: AWS owned, AWS managed, or customer managed keys
  • Restoring unencrypted snapshots creates encrypted clusters by default
  • Existing unencrypted databases can migrate via snapshot restore process
  • No performance impact or additional charges for default encryption
  • Meets regulatory requirements: GDPR, HIPAA, PCI DSS, SOC 2

Aurora's default encryption simplifies compliance and enhances data security for new deployments while allowing existing databases to maintain their current state.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Feb 17
2026
Amazon Aurora now supports Server-Side Encryption at Rest
Feb 11
2026
Migrate relational-style data from NoSQL to Amazon Aurora DSQL
Jan 30
2026
Change the server-side encryption type of Amazon S3 objects
Jan 8
2026
Unlock Amazon Aurora’s Advanced Features with Standard JDBC Driver using AWS Advanced JDBC Wrapper

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.