CloudCompliance

Cloud key management decider

Most companies should stay on provider-managed keys. This asks the five questions that justify moving up, and says what each level costs you in work.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Five questions. The recommendation and the reasons appear on this page.

Has a customer, regulator or contract asked for control of encryption keys?

Do you need a log of every time data is decrypted?

Do you promise customers their data can be destroyed on request?

Do buyers ask whether a foreign government could compel your provider to hand over data?

Who would run the keys?

The four levels

Provider-managed keys, customer-managed keys in the provider KMS, bring your own key material, and dedicated or external key stores. The trade-offs are on key management compared, and decision records covers how to write the choice down.

Will customer-managed keys help us pass SOC 2?

Not directly. SOC 2 accepts provider-managed encryption at rest. Customer keys help with specific contract requirements and with proving who decrypted data.

Need the key design done?

Firms in the network design key hierarchies and write the cryptography policy.

Get matched