Home icon

Implementing encryption in transit across connectivity patterns with VPC Encryption Controls

Networking & Content Delivery Blog



This article explains how VPC Encryption Controls provides centralized visibility and enforcement of encryption in transit across VPCs and hybrid connectivity patterns to meet regulatory compliance requirements.

  • AWS provides multiple encryption layers: physical network encryption, IPsec with Site-to-Site VPN, MACsec with Direct Connect, TLS for APIs, and Nitro hardware encryption between EC2 instances
  • VPC Encryption Controls operates in monitor mode (audit encryption status via Flow Logs) and enforce mode (block non-compliant resources and unencrypted traffic)
  • Monitor mode automatically migrates managed resources to encryption-capable hardware; enforce mode restricts ENIs to encryption-capable instance types
  • Reference architectures cover single VPCs, VPC peering, Transit Gateway hub-and-spoke, PrivateLink endpoints, S3/DynamoDB gateway endpoints, and hybrid connectivity
  • Transit Gateway encryption support requires explicit enablement and can take up to 14 days to migrate with no downtime
  • Declarative policies enable organization-wide enforcement across multiple regions without per-VPC configuration
  • Inspection VPCs with Network Firewall or Gateway Load Balancer cannot be placed in enforce mode; consider Nitro-based appliances for full enforcement

VPC Encryption Controls helps organizations demonstrate continuous encryption enforcement across their environment while preventing non-compliant resources from being introduced.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Nov 21
2025
Introducing VPC encryption controls: Enforce encryption in transit within and across VPCs in a Region
Aug 19
2026
Encrypt Amazon ECS traffic: VPC encryption controls and Service Connect TLS
Jul 7
2026
AWS introduces declarative controls for VPC Encryption Controls
Aug 11
2026
Deployment models for AWS Network Firewall: Transit Gateway attachment and multiple VPC endpoints

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.