AWS Key Management Service - AWS Control Tower
This documentation is a draft for private preview for regions in the AWS European Sovereign Cloud. Documentation content will continue to evolve. Published: December 31, 2025.

AWS Key Management Service

AWS Key Management Service (AWS KMS) allows you to create and control keys that protect your data. AWS Control Tower optionally allows you to encrypt your data with AWS KMS encryption keys. For information about AWS KMS, see the AWS KMS Developer Guide.

For information about how to set up AWS KMS keys with AWS Control Tower, see Optionally configure AWS KMS keys.