AWS Encrypts All New S3 Objects by Default (Jan 2023)
Retrospective: this article looks back at events from January 2023, written in 2026 with the benefit of hindsight.
On January 5, 2023, AWS began automatically applying server-side encryption with Amazon S3 managed keys (SSE-S3) to all new objects uploaded to S3, at no additional cost and with no performance impact.
What changed
Previously, encryption at rest for S3 was optional — customers enabled default bucket encryption themselves. After the change:
- Every new object in every bucket was encrypted with SSE-S3 unless another encryption method was specified.
- Existing unencrypted objects remained unencrypted until rewritten.
- Customers could still choose SSE-KMS (AWS KMS keys) or later DSSE-KMS (dual-layer encryption).
Why it mattered
Encryption at rest was a common compliance requirement and audit finding. Making it default removed a configuration step and a whole class of findings.
What it didn't do
Default encryption with S3-managed keys protects against physical access to storage media. It does not protect against someone with valid AWS permissions reading data — S3 decrypts transparently for authorized requests. A misconfigured bucket policy that allows public access still exposes data, encrypted or not.
For stronger control, SSE-KMS with customer-managed keys adds a second permission layer: users need both S3 permissions and KMS key permissions, and key usage is logged in CloudTrail.
In hindsight
Default encryption is a good example of a security baseline becoming invisible. The remaining work — deciding which data needs KMS keys, key policies and separation of duties — is where real access control happens.
- How to Choose Between SSE-S3, SSE-KMS and DSSE-KMS for S3 How-To & Hardening
- S3 Encryption and KMS Key Policy Audit Checklist How-To & Hardening
- CIO Brief: Encryption by Default — What It Does and Doesn't Protect CIO Briefings