Skip to main content

AWS Cloud Security

AWS Post-Quantum Confidentiality Readiness

Explore service-wise status and resources for protecting data in transit against harvest now, decrypt later

Shared responsibility for post-quantum confidentiality

Data in transit over an untrusted network can be recorded today and decrypted in the future when a large quantum computer is practical. Post-quantum key exchange in protocols like TLS helps secure data against this risk of harvest now and decrypt later. AWS relies on ML-KEM for post-quantum key exchange. We generally use hybrid PQ key exchange, which combines ML-KEM with a traditional key exchange method. This is the industry norm today, and will evolve toward pure PQ key exchange in the future. 

As with all aspects of PQC upgrades, AWS’s support for PQ key exchange will follow the shared responsibility model. For public AWS service endpoints, which are owned by AWS, we transparently deploy server-side support. The endpoints transparently enforce use of PQ key exchange for any client that advertises support for ML-KEM. Customers are responsible for updating clients that invoke AWS APIs to a version and configuration that supports ML-KEM (learn how to update your clients today). For services that manage customer-owned resources like load balancers on your behalf, customers will generally need to opt-in by updating their resource configuration with a newer quantum-resistant data-in-transit encryption policy. Links to service-wise documentation are provided in the table below.

PQ Key Exchange Support in AWS Service

Service endpoint support is transparent for updated clients. For managed resources, you can opt-in via service console or API call.
    Service Name Status of ML-KEM support for quantum-resistant confidentiality Shared Responsibility: Transparent or Opt-In Observability and Governance Additional Notes and Resources
Amazon API Gateway REST API endpoints can be configured with policies that prefer hybrid PQ key exchange Opt-in: Customers must select an appropriate TLS policy via API or console. Coming soon Read the launch blog to learn about configuring TLS policies with API Gateway 
AWS Application Auto Scaling On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
AWS AppSync On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS Certificate Manager (ACM) Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. Transparent. Customers must update clients. CloudTrail events, through tlsDetails, provide TLS version, cipher suite, and key exchange. This row covers TLS security for data exchanged with public service endpoints. For details on public and private certificate types supported by ACM, refer to ACM documentation
AWS Clean Rooms

AWS Clean Rooms ML
On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon Cloud Directory On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon CloudFront Connections between TLS client and CloudFront POP prefer hybrid PQ key exchange. Transparent. No action needed by customers. End users should use updated web browsers or client applications as appropriate.  Coming soon

Read the What's New post announcing automatically enabled support for hybrid PQ key exchange. Explore service documentation.

Note: For client-to-edge connections, PQC support is available on all existing security policies by default, requiring no re-configuration by customers. For connections to origin servers, support is coming soon. 

AWS CloudFormation On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS CloudHSM On the control plane, hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. Transparent. Customers must update clients used to make control plane calls. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. 

This row covers TLS security for data exchanged with public service endpoints.

On the data plane, HSM instances are accessed by your clients within your VPC, over a channel that is encrypted end-to-end between your client and your HSM instance (learn more).

For details on algorithms and key types supported within CloudHSM for direct use by your workloads, refer to CloudHSM documentation.

Amazon CloudSearch On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients used to make control plane calls. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS CodeArtifact On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS CodeBuild

Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS CodeCommitt
AWS CodeDeploy
On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS CodeGuru Profiler On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS CodePipeline Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon Cognito TLS policies that prefer hybrid PQ key exchange are available for custom user pool domains  Transparent. Customers may opt-in to stricter policies to disallow fallback to older TLS versions.  In the console or via API, an administrator can validate the TLS configuration applied to the custom domain. Learn more about custom domains in Cognito documentation
Amazon Comprehend On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
AWS Config On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS Database Migration Service (DMS) On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS Deadline Cloud On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS Device Farm On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
AWS Direct Connect Hybrid PQ key exchange launched in API endpoints Transparent. Customers must ensure they configure MAC security using updated clients CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon DocumentDB On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon EC2 Auto Scaling On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon EC2 Instance Connect On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
Amazon Elasticache On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
Amazon Elastic Block Store (Amazon EBS) On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon Elastic Container Registry (ECR) On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
Elastic Load Balancing: Application Load Balancer (ALB) TLS policies that prefer hybrid PQ key exchange are available for customers to apply to listeners. Opt-in: Customers must update listener configuration via API or console.

Connection logs include keyExchange (documentation)

IAM condition keys support allowlist of PQ-ready SSL policies and denylist of legacy SSL policies (learn more).

Read the What's New post announcing support for hybrid PQ-key exchange.

Explore Application Load Balancer (ALB) Documentation.

Elastic Load Balancing: Network Load Balancer (NLB) TLS policies that prefer hybrid PQ key exchange are available for customers to apply to listeners. Opt-in: Customers must update listener configuration via API or console. Access logs include keyExchange (documentation).

Read the What's New post announcing support for hybrid PQ key exchange.

Explore Network Load Balancer (NLB) Documentation.

AWS Elemental MediaConnect On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon EventBridge On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
AWS Firewall Manager Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes

Amazon GameLift Server

Amazon GameLift Streams

On the control plane, hybrid PQ key exchange launched in endpoints in all available regions. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon Glacier On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additonal notes
AWS HealthOmics On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS Identity and Access Management (IAM) Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. Transparent. Customers must update clients CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
AWS IAM Identity Center Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. Transparent. Customers must update clients CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
Amazon Interactive Video Service (IVS) On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
AWS Key Management Service (KMS) Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions Transparent. Customers must update clients. CloudTrail events, through tlsDetails, provide TLS version, cipher suite, and key exchange

Read the Launch blog, including in-depth performance analysis of hybrid PQ key exchange.

Refer to service documentation.

Explore the hands-on Builder Workshop

Note: This row covers TLS security for data exchanged with public service endpoints. For details on algorithms and key types supported within KMS for direct use by your workloads, refer to KMS documentation

Amazon Keyspaces On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon Kinesis Data Streams On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon Lightsail On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
Amazon Lookout For Equipment On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon Machine Learning (ML) On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
Amazon Managed Service for Apache Flink On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
AWS Network Firewall (NFW) Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. NFW can handle PQ-TLS handshakes, but you may need to adjust rules that aggressively drop connections. To learn more, see default drop actions, and re:Post forum guidance.  
AWS Payment Cryptography (APC) Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. Transparent. Customers must update clients. CloudTrail events, through tlsDetails, provide TLS version, cipher suite, and key exchange. Read the launch announcement.
AWS Secrets Manager (ASM) Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions Transparent. Customers must update clients. CloudTrail includes TLS version, cipher suite, and key exchange.

Read the Launch blog, including in-depth performance analysis of hybrid PQ key exchange.

Note: As of April 2026, current versions of all caching clients including the Secrets Manager Agent enable and prefer hybrid PQ key exchange by default (learn more). 

Amazon Simple Notification Service (SNS) On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
Amazon Simple Storage Service (S3) Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions, for all bucket types. Transparent. Customers must update clients.

Data plane logs include TLS version and ciphersuite, with key exchange coming soon.

IAM condition keys support enforcing use of TLS to access buckets. 

Read the launch announcement.

Explore service documentation.

Amazon Simple Queue Service (SQS) On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
AWS Secure Token Service (STS) Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon Simple Workflow Service (SWF) On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
AWS Transfer Family (SFTP domains) SFTP configurations that prefer ML-KEM are available for customers to apply. Opt-in: Customers must update SFTP endpoint configuration. SFTP logs include cipher suite and key exchange.

Read the blog post to understand how AWS Transfer Family supports post-quantum hybrid SFTP file transfers.

Refer to service documentation for in-depth guidance on upgrading your SFTP endpoint and clients that connect to the endpoint. 

Amazon Translate On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon. No additional notes
Amazon Workdocs On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes
Amazon Workspaces

Amazon Workspaces Applications
On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. Transparent. Customers must update clients. CloudTrail includes TLS version and cipher suite. Key exchange coming soon.  No additional notes

Learn More about Migrating to PQC

To explore resources on your migration to PQC, visit PQC Migration Strategies or Contact Us.