Implementing encryption in transit across connectivity patterns with VPC Encryption Controls
Networking & Content Delivery Blog
This article explains how VPC Encryption Controls provides centralized visibility and enforcement of encryption in transit across VPCs and hybrid connectivity patterns to meet regulatory compliance requirements.
- AWS provides multiple encryption layers: physical network encryption, IPsec with Site-to-Site VPN, MACsec with Direct Connect, TLS for APIs, and Nitro hardware encryption between EC2 instances
- VPC Encryption Controls operates in monitor mode (audit encryption status via Flow Logs) and enforce mode (block non-compliant resources and unencrypted traffic)
- Monitor mode automatically migrates managed resources to encryption-capable hardware; enforce mode restricts ENIs to encryption-capable instance types
- Reference architectures cover single VPCs, VPC peering, Transit Gateway hub-and-spoke, PrivateLink endpoints, S3/DynamoDB gateway endpoints, and hybrid connectivity
- Transit Gateway encryption support requires explicit enablement and can take up to 14 days to migrate with no downtime
- Declarative policies enable organization-wide enforcement across multiple regions without per-VPC configuration
- Inspection VPCs with Network Firewall or Gateway Load Balancer cannot be placed in enforce mode; consider Nitro-based appliances for full enforcement
VPC Encryption Controls helps organizations demonstrate continuous encryption enforcement across their environment while preventing non-compliant resources from being introduced.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2025
2026
2026
2026
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.