All Products
Search
Document Center

Cloud Config:kms-key-rotation-enabled

Last Updated:Jun 16, 2026

Evaluates whether automatic rotation is enabled for Key Management Service (KMS) customer master keys (CMKs). The configuration is compliant if automatic rotation is enabled.

Scenarios

Enabling automatic rotation for KMS CMKs reduces the risk of key leaks and improves system security. Ensure that your applications support key rotation before you enable this feature.

Risk level

Default risk level: medium.

You can change the risk level when you configure this rule.

Compliance evaluation logic

  • The configuration is compliant if automatic rotation is enabled for KMS CMKs.
  • The configuration is non-compliant if automatic rotation is disabled for KMS CMKs. For more information about how to remediate the non-compliant configuration, see Non-compliance remediation.

Rule details

Item Description
Rule name kms-key-rotation-enabled
Rule ID kms-key-rotation-enabled
Tag KMS and CMK
Automatic remediation Supported
Trigger type Configuration change
Supported resource type KMS CMKs
Input parameter None

Non-compliance remediation

Enable the automatic rotation feature for KMS CMKs. For more information, see Automatic key rotation.