AWS Post-Quantum Confidentiality Readiness
Explore service-wise status and resources for protecting data in transit against harvest now, decrypt later
PQ Key Exchange Support in AWS Service
| Service Name | Status of ML-KEM support for quantum-resistant confidentiality | Shared Responsibility: Transparent or Opt-In | Observability and Governance | Additional Notes and Resources |
|---|---|---|---|---|
| Amazon API Gateway | REST API endpoints can be configured with policies that prefer hybrid PQ key exchange | Opt-in: Customers must select an appropriate TLS policy via API or console. | Coming soon | Read the launch blog to learn about configuring TLS policies with API Gateway |
| AWS Application Auto Scaling | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS AppSync | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Certificate Manager (ACM) | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. | Transparent. Customers must update clients. | CloudTrail events, through tlsDetails, provide TLS version, cipher suite, and key exchange. | This row covers TLS security for data exchanged with public service endpoints. For details on public and private certificate types supported by ACM, refer to ACM documentation. |
| AWS Clean Rooms
AWS Clean Rooms ML |
On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Cloud Directory | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon CloudFront | Connections between TLS client and CloudFront POP prefer hybrid PQ key exchange. | Transparent. No action needed by customers. End users should use updated web browsers or client applications as appropriate. | Coming soon |
Read the What's New post announcing automatically enabled support for hybrid PQ key exchange. Explore service documentation. Note: For client-to-edge connections, PQC support is available on all existing security policies by default, requiring no re-configuration by customers. For connections to origin servers, support is coming soon. |
| AWS CloudFormation | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS CloudHSM | On the control plane, hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. | Transparent. Customers must update clients used to make control plane calls. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. |
This row covers TLS security for data exchanged with public service endpoints. On the data plane, HSM instances are accessed by your clients within your VPC, over a channel that is encrypted end-to-end between your client and your HSM instance (learn more). For details on algorithms and key types supported within CloudHSM for direct use by your workloads, refer to CloudHSM documentation. |
| Amazon CloudSearch | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients used to make control plane calls. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS CodeArtifact | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS CodeBuild
|
Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS CodeCommitt
AWS CodeDeploy |
On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS CodeGuru Profiler | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS CodePipeline | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Cognito | TLS policies that prefer hybrid PQ key exchange are available for custom user pool domains | Transparent. Customers may opt-in to stricter policies to disallow fallback to older TLS versions. | In the console or via API, an administrator can validate the TLS configuration applied to the custom domain. | Learn more about custom domains in Cognito documentation |
| Amazon Comprehend | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Config | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Database Migration Service (DMS) | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Deadline Cloud | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Device Farm | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Direct Connect | Hybrid PQ key exchange launched in API endpoints | Transparent. Customers must ensure they configure MAC security using updated clients | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon DocumentDB | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon EC2 Auto Scaling | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon EC2 Instance Connect | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Elasticache | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Elastic Block Store (Amazon EBS) | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Elastic Container Registry (ECR) | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Elastic Load Balancing: Application Load Balancer (ALB) | TLS policies that prefer hybrid PQ key exchange are available for customers to apply to listeners. | Opt-in: Customers must update listener configuration via API or console. |
Connection logs include keyExchange (documentation) IAM condition keys support allowlist of PQ-ready SSL policies and denylist of legacy SSL policies (learn more). |
Read the What's New post announcing support for hybrid PQ-key exchange. |
| Elastic Load Balancing: Network Load Balancer (NLB) | TLS policies that prefer hybrid PQ key exchange are available for customers to apply to listeners. | Opt-in: Customers must update listener configuration via API or console. | Access logs include keyExchange (documentation). |
Read the What's New post announcing support for hybrid PQ key exchange. |
| AWS Elemental MediaConnect | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon EventBridge | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Firewall Manager | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
|
Amazon GameLift Server Amazon GameLift Streams |
On the control plane, hybrid PQ key exchange launched in endpoints in all available regions. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Glacier | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additonal notes |
| AWS HealthOmics | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Identity and Access Management (IAM) | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS IAM Identity Center | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. | Transparent. Customers must update clients | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Interactive Video Service (IVS) | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Key Management Service (KMS) | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions | Transparent. Customers must update clients. | CloudTrail events, through tlsDetails, provide TLS version, cipher suite, and key exchange |
Read the Launch blog, including in-depth performance analysis of hybrid PQ key exchange. Refer to service documentation. Explore the hands-on Builder Workshop Note: This row covers TLS security for data exchanged with public service endpoints. For details on algorithms and key types supported within KMS for direct use by your workloads, refer to KMS documentation. |
| Amazon Keyspaces | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Kinesis Data Streams | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Lightsail | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Lookout For Equipment | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Machine Learning (ML) | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Managed Service for Apache Flink | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Network Firewall (NFW) | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | NFW can handle PQ-TLS handshakes, but you may need to adjust rules that aggressively drop connections. To learn more, see default drop actions, and re:Post forum guidance. |
| AWS Payment Cryptography (APC) | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions. | Transparent. Customers must update clients. | CloudTrail events, through tlsDetails, provide TLS version, cipher suite, and key exchange. | Read the launch announcement. |
| AWS Secrets Manager (ASM) | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions | Transparent. Customers must update clients. | CloudTrail includes TLS version, cipher suite, and key exchange. |
Read the Launch blog, including in-depth performance analysis of hybrid PQ key exchange. Note: As of April 2026, current versions of all caching clients including the Secrets Manager Agent enable and prefer hybrid PQ key exchange by default (learn more). |
| Amazon Simple Notification Service (SNS) | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Simple Storage Service (S3) | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions, for all bucket types. | Transparent. Customers must update clients. |
Data plane logs include TLS version and ciphersuite, with key exchange coming soon. IAM condition keys support enforcing use of TLS to access buckets. |
Read the launch announcement. Explore service documentation. |
| Amazon Simple Queue Service (SQS) | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Secure Token Service (STS) | Hybrid PQ key exchange launched in FIPS & non-FIPS endpoints, in commercial and US GovCloud regions | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Simple Workflow Service (SWF) | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| AWS Transfer Family (SFTP domains) | SFTP configurations that prefer ML-KEM are available for customers to apply. | Opt-in: Customers must update SFTP endpoint configuration. | SFTP logs include cipher suite and key exchange. |
Read the blog post to understand how AWS Transfer Family supports post-quantum hybrid SFTP file transfers. Refer to service documentation for in-depth guidance on upgrading your SFTP endpoint and clients that connect to the endpoint. |
| Amazon Translate | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Workdocs | On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
| Amazon Workspaces
Amazon Workspaces Applications |
On the control plane, hybrid PQ key exchange launched in endpoints in commercial and US GovCloud regions with FIPS as applicable. | Transparent. Customers must update clients. | CloudTrail includes TLS version and cipher suite. Key exchange coming soon. | No additional notes |
Learn More about Migrating to PQC
To explore resources on your migration to PQC, visit PQC Migration Strategies or Contact Us.