CloudCompliance

AWS KMS, Key Vault and Cloud KMS compared

Most companies should use provider-managed keys and stop there. Customer-managed keys are worth their cost when a contract asks for key control, a regulator names it, or you need to prove who could decrypt data.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

There are four levels of key control in the cloud. Provider-managed keys are free and invisible. Customer-managed keys in the provider's KMS let you set the key policy and see every use. Bring your own key lets you generate the key material yourself. Dedicated or external HSMs keep keys in hardware you control or even outside the provider. Each step up adds cost and operational risk: lose access to a key you manage and the data is gone.

Key management options by provider
LevelAWSAzureGoogle Cloud
Provider-managedAWS owned or AWS managed keysMicrosoft-managed keysGoogle default encryption
Customer-managed in the provider KMSKMS customer managed keysKey Vault keys (CMK)Cloud KMS keys (CMEK)
Bring your own key materialKMS imported key materialKey Vault BYOKCloud KMS imported keys
Dedicated HSMCloudHSM, KMS custom key storeManaged HSM, Dedicated HSMCloud HSM
Keys held outside the providerExternal key store (XKS)Managed HSM with your key release policyCloud External Key Manager

When are customer-managed keys worth it?

  • A contract names them. Financial services and some public sector buyers ask for customer-managed keys by name.
  • You need a decrypt log. Every use of a customer-managed key is logged in CloudTrail, Azure Monitor or Cloud Audit Logs, which proves who read encrypted data.
  • Crypto-shredding. Deleting a per-tenant key makes that tenant's data unrecoverable, which some deletion commitments rely on.
  • Foreign access concerns. External key management means the provider cannot decrypt without your key service, which answers the hardest residency question a buyer asks.

If none of those apply, provider-managed keys meet SOC 2, ISO 27001 and PIPEDA's safeguarding principle. The key management decider walks through the choice.

What you take on with customer-managed keys

Key policy
Who can use and administer each key. A wrong key policy can lock out your own services.
Rotation
Automatic annual rotation on AWS and configurable rotation on Azure and Google Cloud. Turn it on and record it.
Deletion protection
AWS enforces a 7 to 30 day waiting period; Key Vault soft delete and purge protection; Cloud KMS scheduled destruction. Keep these on.
Separation of duties
Key administrators should not also be the people who read the data. Auditors look for this.
Cost
A monthly charge per key and per request. Small for a handful of keys, material for per-tenant keys at scale.

Key management evidence

Auditors ask for the key inventory, key policies, rotation settings, deletion protection status and a sample of key usage logs. For ISO 27001, control 8.24 (use of cryptography) expects a written cryptography policy covering algorithms, key lengths, key lifecycle and responsibilities. It can be two pages.

What is the difference between CMK and BYOK?

A customer-managed key is created and stored in the provider's key service, under your policy. Bring your own key means you generate the key material outside the provider and import it. BYOK gives you an offline copy of the key material and more work to manage it.

Does Azure Key Vault keep keys in Canada?

A Key Vault is created in a region, and keys in a Canada Central or Canada East vault are stored there. Managed HSM is regional too. Check Microsoft's documentation for geo-replication behaviour of the tier you use.

Can the cloud provider read data encrypted with my key?

With keys in the provider's KMS, the provider's systems perform encryption and decryption on your behalf under your key policy. Contractual commitments and logging govern that. Only external key management keeps the key entirely outside the provider's control.

Need a key management design?

Firms in the network design key hierarchies and write the cryptography policy.

Get matched