Amazon S3 starts rolling out new security best practice to new and existing buckets by default
News
This article announces Amazon S3's rollout of a new default security setting that disables server-side encryption with customer-provided keys (SSE-C) by default.
- SSE-C disabled by default for all new general purpose S3 buckets
- Existing buckets without SSE-C encrypted objects will also have SSE-C disabled
- Accounts actively using SSE-C will retain existing bucket configurations unchanged
- Rollout spans 37 AWS Regions including China and GovCloud over coming weeks
- Change announced November 19, 2025; deployment began April 6, 2026
In summary, Amazon S3 is implementing a new default security best practice by disabling SSE-C encryption by default, while preserving existing configurations for accounts actively using this feature.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Nov 20
2025
2025
Amazon S3 adds new bucket-level setting to standardize encryption types used in your buckets
Dec 1
2024
2024
Amazon S3 adds new default data integrity protections
Dec 1
2024
2024
Introducing default data integrity protections for new objects in Amazon S3
Nov 19
2025
2025
Advanced notice: Amazon S3 to disable the use of SSE-C encryption by default for all new buckets and select existing buckets in April 2026
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.