Cloud encryption at rest and in transit
Encryption at rest is mostly a default now on all three providers. Encryption in transit is where findings appear: old TLS versions, internal traffic in the clear, and certificates nobody owns.
To satisfy an auditor, every data store holding customer data must be encrypted at rest, every connection carrying it must use TLS 1.2 or higher, and you must be able to show both with a report rather than an assertion. On Google Cloud, at-rest encryption is automatic. On AWS and Azure it is the default for most services created today, but older resources and a few services still need checking.
Encryption at rest, by service
| Service type | AWS | Azure | Google Cloud |
|---|---|---|---|
| Object storage | S3 encrypted by default since January 2023 | Storage encryption always on | Always on |
| Block storage | EBS encryption by default is a per-region account setting; turn it on | Managed disks encrypted by default | Always on |
| Relational databases | RDS encryption chosen at creation; cannot be added in place | Azure SQL TDE on by default | Cloud SQL always encrypted |
| NoSQL | DynamoDB encrypted by default | Cosmos DB encrypted by default | Firestore always encrypted |
| Backups and snapshots | Inherit source encryption | Encrypted in vault | Encrypted |
The unencrypted RDS instance
An RDS database created without encryption stays unencrypted. The fix is a snapshot, an encrypted copy of the snapshot, and a restore to a new instance, which means a maintenance window. Find these before the audit, not during.
Encryption in transit
Three places to check:
- The edge. Load balancers, API gateways and CDNs should accept TLS 1.2 and 1.3 only. Set the security policy on each listener; defaults on older resources may still allow TLS 1.0 and 1.1.
- Internal traffic. Traffic between services inside a VPC is often plain HTTP. Auditors increasingly ask. Service mesh mutual TLS, TLS to databases and private endpoints close the gap.
- Database connections. Enforce TLS on the database side:
rds.force_sslon PostgreSQL RDS, require secure transport on Azure Database for MySQL, and SSL mode on Cloud SQL.
Who holds the keys?
Every provider encrypts with provider-managed keys by default. Customer-managed keys in AWS KMS, Azure Key Vault or Cloud KMS let you control key policy, rotation and deletion, and they produce a log of every decrypt. They add work and cost, and most SOC 2 audits do not require them. Use them when a contract, a regulator or a data residency commitment asks for control of the keys. Key management covers the options and the key management decider picks one.
How to prove encryption to an auditor
| Provider | At rest | In transit |
|---|---|---|
| AWS | AWS Config rules for S3, EBS, RDS and DynamoDB encryption, with compliance history | Load balancer listener policies, Config rule for TLS |
| Azure | Azure Policy compliance for storage, SQL TDE and disk encryption | Minimum TLS policy results |
| Google Cloud | Google's default encryption statement, plus CMEK configuration where used | SSL policy on load balancers, Security Health Analytics findings |
A continuous configuration rule beats a screenshot, because it proves the control held across the period rather than on the day you took the picture.
Is data encrypted at rest by default in AWS?
For S3 and DynamoDB, yes. EBS encryption by default is an account and region setting you should turn on. RDS encryption is chosen when the instance is created, so older unencrypted instances need a snapshot and restore to fix.
Does SOC 2 require customer-managed encryption keys?
No. SOC 2 requires that data is protected appropriately, and provider-managed encryption at rest meets that for most companies. Customer-managed keys are a choice driven by contracts or specific risk, not a SOC 2 requirement.
Is TLS 1.2 still acceptable in 2026?
Yes. TLS 1.2 with modern cipher suites remains acceptable to auditors and to PCI DSS v4.0.1. TLS 1.0 and 1.1 are not. Offer TLS 1.3 where your load balancer supports it.
Want an encryption gap check?
Firms in the network review storage, databases and TLS across your estate.
Get matched