---
title: "Everything You Need to Know: Amazon S3 Automatic Encryption"
description: AWS rolled out new base-level encryption settings for Amazon S3. Learn what this means for existing objects and how to get a complete encryption report.
image: https://cloudstoragesecurity.com/hubfs/Website/Blog_Case_Study_Index_Page_Featured_Images/amazon%20s3%20automatic%20encryption%20image.webp
---

###### [BLOG](https://cloudstoragesecurity.com/news)

 Jan 23, 2023 

|

 5 min read

# What You Need To Know About Amazon S3 Automatic Encryption

[Cloud Storage Security](https://cloudstoragesecurity.com/news/author/cloud-storage-security)

##### Share:

![fb-icon](https://cloudstoragesecurity.com/hubfs/fb-icon.svg) 

[![insta-icon](https://cloudstoragesecurity.com/hubfs/insta-icon.svg) 

](https://www.instagram.com/)

![twit-icon](https://cloudstoragesecurity.com/hubfs/twit-icon.svg) 

[![YouTube Icon](https://cloudstoragesecurity.com/hubfs/youtube-icon.svg) 

](https://www.youtube.com/@cloudstoragesecurity7887)

![Amazon S3 Automatic Encryption](https://cloudstoragesecurity.com/hs-fs/hubfs/Website/Blog_Case_Study_Index_Page_Featured_Images/amazon%20s3%20automatic%20encryption%20image.webp?width=820&height=547&name=amazon%20s3%20automatic%20encryption%20image.webp)

On January 5, 2023, AWS automated server-side encryption for all new objects in Amazon Simple Storage Service (SSE-S3).  In this article, we review SSE-S3 (some features may surprise you), discuss how to assess encryption status (with and without help), and touch on how to encrypt existing objects in S3.

## A Look at SSE-S3

With server-side encryption, data at rest is protected; data is encrypted before it is saved and then decrypted when it is downloaded. With this update, Amazon S3 automatically applies SSE-S3 to all new buckets and existing buckets that lack a customer configured/default encryption setting. Every object put into Amazon S3 going forward is encrypted with SSE-S3 by default while objects created prior to January 5 do not have SSE-S3 applied by default. There is no additional cost for default encryption with SSE-S3, although requests to configure the default encryption feature incur standard Amazon S3 request charges.

| With SSE-S3, Amazon S3 automatically encrypts newly created objects.  This means objects that exist prior to the launch of SSE-S3 in January 2023 aren’t automatically encrypted. |
| --- |

SSE-S3 uses 256-bit Advanced Encryption Standard (AES-256). With SSE-S3, when an object is PUT into S3, AWS generates a unique key to encrypt the data and then encrypts that key with a root key that’s regularly rotated. When you GET an object, Amazon S3 automatically fetches and decrypts the key to decrypt the object before it’s sent back to you. You don’t have to take any additional steps to establish a base level of default encryption (unless you proactively choose to change the configuration by enabling one of the other two encryption options offered by AWS: [server-side encryption with AWS Key Management Service (SSE-KMS)](https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingKMSEncryption.html) or [server-side encryption with customer-provided keys (SSE-C)](https://docs.aws.amazon.com/AmazonS3/latest/userguide/ServerSideEncryptionCustomerKeys.html)). With the rollout of SSE-S3, encryption for new object uploads can no longer be disabled.

SSE-S3 is a fantastic step forward for enhancing data security, but it only applies to new objects. Security best practices dictate that you should verify encryption settings on all objects.  Moreover, encryption status should be revisited periodically to avoid configuration drift. These factors warrant an assessment that provides overall encryption status of both new and existing objects. 

 

## How to Tell if Encryption is Enabled on Your Buckets

Currently, AWS reports on SSE-S3 in [AWS CloudTrail](https://aws.amazon.com/cloudtrail/) data event logs; the AWS article [Amazon S3 Encrypts New Objects By Default](https://aws.amazon.com/blogs/aws/amazon-s3-encrypts-new-objects-by-default/) includes steps on how to verify encryption using CloudTrail. In the future, AWS will provide encryption status in other Amazon S3 tools such as Amazon S3 Inventory and Amazon S3 Storage Lens.

To help manage and simplify the verification process, [Cloud Storage Security (CSS)](https://cloudstoragesecurity.com/aws) also reports on encryption status AND we provide insight for both new and existing objects. Our solutions include malware scanning, sensitive data discovery and storage assessments for AWS-managed storage services. Every CSS report is designed to include all buckets across all regions in the account in which the CSS console is running as well as any active linked accounts. We report on encryption status no matter the type of encryption applied. You decide which accounts to report on. Additionally, for added security, CSS runs in your AWS environment so data never leaves your account. 

 

*Encryption Overview via CSS Storage Assessment*

CSS’ [Storage Assessment](http://help.cloudstoragesec.com/console-overview/storage-assessment/) (accessible under Monitoring in the main menu), shows the totality of encryption by summing how many objects you have and how many of those objects are encrypted (figure 1). 

![Figure 1 - Storage Assessment in CSS console showing object and encryption count](https://cloudstoragesecurity.com/hs-fs/hubfs/Figure%201%20-%20Storage%20Assessment%20in%20CSS%20console%20showing%20object%20and%20encryption%20count.jpg?width=1919&height=614&name=Figure%201%20-%20Storage%20Assessment%20in%20CSS%20console%20showing%20object%20and%20encryption%20count.jpg)

*Figure 1 - Storage Assessment in CSS console showing object and encryption count*

 

The Storage Assessment provides an overview of encryption by region – percent and bucket count (figure 2) – and also drills down into each bucket within each region to tell you the percentage of encrypted objects; it also provides a file age breakdown (figure 3). 

*![Figure 2 - Storage Assessment in CSS console showing % of buckets encrypted by region as well as the number of encryptedunencrypted by region](https://cloudstoragesecurity.com/hs-fs/hubfs/Figure%202%20-%20Storage%20Assessment%20in%20CSS%20console%20showing%20%25%20of%20buckets%20encrypted%20by%20region%20as%20well%20as%20the%20number%20of%20encryptedunencrypted%20by%20region.jpg?width=1878&height=858&name=Figure%202%20-%20Storage%20Assessment%20in%20CSS%20console%20showing%20%25%20of%20buckets%20encrypted%20by%20region%20as%20well%20as%20the%20number%20of%20encryptedunencrypted%20by%20region.jpg)*

*Figure 2 - Storage Assessment in CSS console showing % of buckets encrypted by region as well as the number of encrypted/unencrypted by region*

 

![Figure 3 - Storage Assessment in CSS console showing % encrypted by bucket and age](https://cloudstoragesecurity.com/hs-fs/hubfs/Figure%203%20-%20Storage%20Assessment%20in%20CSS%20console%20showing%20%25%20encrypted%20by%20bucket%20and%20age.jpg?width=1885&height=799&name=Figure%203%20-%20Storage%20Assessment%20in%20CSS%20console%20showing%20%25%20encrypted%20by%20bucket%20and%20age.jpg)

*Figure 3 - Storage Assessment in CSS console showing % encrypted by bucket and age*

 

Collectively, this information is useful because it provides you with the detail needed to investigate your encryption settings. For example, this information may lead you to investigate questions like “Should only 2% of my objects be encrypted? Is that reasonable based on the type of information we have?”, “Which buckets contain objects that aren’t encrypted that should be?” and “Which buckets contain unencrypted files older than Jan 2023 that should be investigated?”.  

 

*Encryption Overview via CSS Bucket Protection Reporting*

If you’re using SSE-KMS, CSS provides additional information on encryption status via the [Bucket Protection](https://help.cloudstoragesec.com/console-overview/protected-buckets/#bucket-protection) table in the CSS console (accessible via the main menu). This report provides a complete (filterable) list of your S3 buckets and their protection status that allows you to see which buckets are encrypted via a key icon next to the bucket name. Additional detail about the encryption setting is accessible by hovering your mouse pointer over the icon (figure 4).

*![Figure 4 - Bucket Protection table in CSS console showing green encryption key and detail ](https://cloudstoragesecurity.com/hs-fs/hubfs/Figure%204%20-%20Bucket%20Protection%20table%20in%20CSS%20console%20showing%20green%20encryption%20key%20and%20detail%20.jpg?width=1920&height=1060&name=Figure%204%20-%20Bucket%20Protection%20table%20in%20CSS%20console%20showing%20green%20encryption%20key%20and%20detail%20.jpg)*

*Figure 4 - Bucket Protection table in CSS console showing green encryption key and detail *

 

You will see a green key, a red key, or no key. 

![green key icon](https://lh6.googleusercontent.com/Jk6-lUS0gE4LLo9h5bo5wCU4WKGzoy9nne2zBwN_ZzNjmobak0hW5JxC0W6BT6QOrR2WNY2cqjjB0vn_GJ_04YF0_rAZAkYCmVcDfip5wjX-LHsSKP_tZHoWgz0o0EYIlamzeno7AxnpSbdjYt3x4AzHaDOTdqPhH4GZJSrVgqfMgFfVutfj6HREQ3Gzbg) A green key means KMS encryption is enabled on the bucket and CSS’ AgentRole has permission to the key in order to decrypt the bucket's contents for malware or sensitive data scanning. 

![red key icon](https://lh3.googleusercontent.com/SQ8O45rRC3RnrXxjj5jIjYyFbXgukoJ-eevjofBjwHdvyKdQmotbg0sZxj0EaHc2cdB4gyuhC7qjst-9WRXFDUz6wOZFlvu1AU4hsTmuQdcAGEIedtBJj1RlLS0QSyoMPAkVDmGoDMypi--DyUEuNYuAqawOU6IQdxIIflZgr5l14KEkb3KVVTJrWA5a8Q) A red key means KMS encryption is enabled on the bucket and CSS’ AgentRole does not have permission to the key. So,** **while the bucket is encrypted, you cannot scan its contents because CSS is unable to decrypt the objects.  (To scan an encrypted bucket, you can give the AgentRole [permissions to the key](https://help.cloudstoragesec.com/trouble-shooting/objects-show-unscannable-with-access-denied).)

No key means the bucket is unencrypted. 

## How to Encrypt Existing Objects in S3

Per [AWS documentation](https://docs.aws.amazon.com/AmazonS3/latest/userguide/default-encryption-faq.html), “to encrypt existing objects, you can use S3 Batch Operations to create encrypted copies of your objects. These encrypted copies will retain the existing object data and name and will be encrypted by using the encryption keys that you specify. For more details, see [Encrypting objects with Amazon S3 Batch Operations](http://aws.amazon.com/blogs/storage/encrypting-objects-with-amazon-s3-batch-operations/) in the *AWS Storage Blog*”  or check take a look at AWS' [Encryption Tutorial](https://catalog.us-east-1.prod.workshops.aws/workshops/aad9ff1e-b607-45bc-893f-121ea5224f24/en-US/s3/serverside/sses3).

However, we’ve done the work for you. 

The [Bucket Settings](https://help.cloudstoragesec.com/console-overview/bucket-settings/) report (accessible under Monitoring in the main menu of the CSS console), counts how many buckets are encrypted in total and with a simple “Yes” (green) or “No” (red) displays encryption status per bucket. Encrypting unencrypted buckets and existing objects is easy through the “Reconcile Encryption” option under the Actions dropdown menu above the table.  

*![Figure 5 - Bucket Settings Overview report showing count of encrypted buckets, encryption status by bucket and the Reconcile Encryption dropdown](https://cloudstoragesecurity.com/hs-fs/hubfs/Figure%205%20-%20Bucket%20Settings%20Overview%20report%20showing%20count%20of%20encrypted%20buckets%2c%20encryption%20status%20by%20bucket%20and%20the%20Reconcile%20Encryption%20dropdown.jpg?width=1919&height=910&name=Figure%205%20-%20Bucket%20Settings%20Overview%20report%20showing%20count%20of%20encrypted%20buckets%2c%20encryption%20status%20by%20bucket%20and%20the%20Reconcile%20Encryption%20dropdown.jpg)*

*Figure 5 - Bucket Settings Overview report showing count of encrypted buckets, encryption status by bucket and the Reconcile Encryption dropdown*

 

When “Reconcile Encryption” is selected, CSS will encrypt all objects in an unencrypted bucket with the key of your choice or default S3 encryption. For buckets that are already encrypted, any objects that are not encrypted with the same key will be updated to match the bucket encryption. To update encryption on an object, it needs to be copied over itself with new encryption configuration. A minimum of one GET call per object is required to enable encryption. If encryption needs to be updated, we will need to make an additional GET call and a COPY call. 

Rather than changing the encryption status of existing objects, you may choose to be notified about what unencrypted objects you have via CSS’ [Proactive Notifications](https://help.cloudstoragesec.com/console-overview/proactive-notifications/). This will kick off a task that will gather all of your unencrypted files and put them into an [SNS topic](http://help.cloudstoragesec.com/console-overview/proactive-notifications/) that is sent to the destination of your choice. From there you can selectively manage encryption.  

With SSE-S3, Amazon S3 only encrypts newly created objects automatically. CSS can help you report on and manage the encryption status of your existing objects that weren’t encrypted by default as well as any new objects. If you’re new to CSS, [start a free trial in AWS Marketplace](https://aws.amazon.com/marketplace/seller-profile?id=6ca3cdf7-b551-4872-b1cf-2f818b397df3) and assess the encryption status of 500 GB on us.  If you’re an existing customer with questions about the CSS capabilities outlined herein, [contact us.](http://help.cloudstoragesec.com/contact-us/)

 

 

##### Share:

![fb-icon](https://cloudstoragesecurity.com/hubfs/fb-icon.svg) 

[![insta-icon](https://cloudstoragesecurity.com/hubfs/insta-icon.svg) 

](https://www.instagram.com/)

![twit-icon](https://cloudstoragesecurity.com/hubfs/twit-icon.svg) 

[![YouTube Icon](https://cloudstoragesecurity.com/hubfs/youtube-icon.svg) 

](https://www.youtube.com/@cloudstoragesecurity7887)

## Continue Reading

[```
(String: Image of code discussing Security Alert as it relates to Codefinger)
```

![Image of code discussing Security Alert as it relates to Codefinger](https://cloudstoragesecurity.com/hs-fs/hubfs/Blog%20-%20Codefinger.png?width=387&height=258&name=Blog%20-%20Codefinger.png) 

](https://cloudstoragesecurity.com/news/codefinger-ransomware-attacks-target-amazon-s3-users)

 Jan 17, 2025

##### Security Alert: Codefinger Ransomware Attacks Target Amazon S3 Users

 A new ransomware campaign targeting Amazon Simple Storage Service (Amazon S3) users has been identified. Dubbed Codefinger, the attackers leverage compromised AWS credentials to access and encrypt the... 

[Cloud Storage Security](https://cloudstoragesecurity.com/news/author/cloud-storage-security)

##### [ Read now ](https://cloudstoragesecurity.com/news/codefinger-ransomware-attacks-target-amazon-s3-users)

[```
(String: new features and enhancements image)
```

![new features and enhancements image](https://cloudstoragesecurity.com/hs-fs/hubfs/Website/Website_On_Page_Graphics/blog%20post%20featured%20product%20update%20image%20820x547.webp?width=387&height=258&name=blog%20post%20featured%20product%20update%20image%20820x547.webp) 

](https://cloudstoragesecurity.com/news/antivirus-for-amazon-s3-product-updates-sept-2022)

 Sep 6, 2022

##### What's New: Antivirus for Amazon S3 Product Updates—September 2022

 Cloud Storage Security is always working to improve our users’ experience and we’re excited to share the following Antivirus for Amazon S3 updates: the addition of bucket configuration actions, deploy... 

[Cloud Storage Security](https://cloudstoragesecurity.com/news/author/cloud-storage-security)

##### [ Read now ](https://cloudstoragesecurity.com/news/antivirus-for-amazon-s3-product-updates-sept-2022)

[```
(String: Image of data along cloud infrastructure. Views of the cloud and all connected devices or storage locations, highlighting the importance of understanding the Shared Responsibility Model)
```

![Image of data along cloud infrastructure. Views of the cloud and all connected devices or storage locations, highlighting the importance of understanding the Shared Responsibility Model](https://cloudstoragesecurity.com/hs-fs/hubfs/Blog%20Featured%20Image%20(3).png?width=387&height=258&name=Blog%20Featured%20Image%20(3).png) 

](https://cloudstoragesecurity.com/news/your-responsibilitieyour-responsibilities-and-data-security-in-the-cloud)

 Jan 15, 2025

##### Your Responsibilities and Data Security in the Cloud

 If your organization leverages the Amazon Web Services (AWS) cloud, you have probably encountered the Shared Responsibility Model. This framework is distributed by AWS to delineate security and compli... 

[Cloud Storage Security](https://cloudstoragesecurity.com/news/author/cloud-storage-security)

##### [ Read now ](https://cloudstoragesecurity.com/news/your-responsibilitieyour-responsibilities-and-data-security-in-the-cloud)

![angled bg image](https://cloudstoragesecurity.com/hubfs/Website/Website_On_Page_Graphics/angled%20bg%20image.svg)

## Tired of Reading?

Want to watch something instead?

[ Check out our videos ](https://cloudstoragesecurity.com/webinars)

![watch video blog cta image 614x261](https://cloudstoragesecurity.com/hs-fs/hubfs/Website/Website_On_Page_Graphics/watch%20video%20blog%20cta%20image%20614x261.webp?width=614&height=261&name=watch%20video%20blog%20cta%20image%20614x261.webp)

![](https://px.ads.linkedin.com/collect/?pid=2428282&fmt=gif)