Google-managed encryption keys (KMS) and Customer-managed encryption keys (CMEK)
Google-managed encryption keys (KMS):
Google-managed encryption keys (KMS) and Customer-managed encryption keys (CMEK)
Photo by Mika Baumeister on Unsplash
Google-managed encryption keys (KMS):
- Definition: Encryption keys that are created, managed, and stored entirely by Google within its infrastructure.
- Control: Google has full control over key management operations, including creation, rotation, access, and deletion.
- User involvement: No setup or configuration required by users. Enabled by default for most GCP services that support encryption.
- Visibility: Users cannot directly view or manage these keys.
- Compliance: May not meet the strictest compliance requirements where full key control is mandated.
Customer-managed encryption keys (CMEK):
- Definition: Encryption keys that are created and managed by customers using Google Cloud Key Management Service (Cloud KMS).
- Control: Customers have full control over key management, including creation, rotation, access, storage location, and deletion.
- User involvement: Requires setup and configuration within Cloud KMS.
- Visibility: Customers have full visibility and control over their keys.
- Compliance: Can meet stricter compliance requirements due to customer control over keys.
Here’s a comprehensive comparison of Google-managed encryption keys (KMS) and customer-managed encryption keys (CMEK) within Google Cloud Platform (GCP):
Key Management:

Control and Compliance:

Ease of Use and Cost:

Best Practices for Choosing:
Use Google-managed keys (KMS):
- When you need a simple and cost-effective encryption solution.
- When you trust Google to manage your keys securely.
- When you don’t have strict compliance requirements that mandate full control over keys.
Use customer-managed keys (CMEK):
- When you need more control over key management and access.
- When you have strict compliance requirements that necessitate full key control.
- When you need to meet data residency or locality requirements.
- When you want to restrict Google’s access to your data.
Additional Considerations:
- CMEK is not available for all GCP services. Check the list of supported services.
- Using CMEK can add complexity to your key management processes.
- It’s essential to have a robust key management strategy in place, regardless of the key type you choose.
메타데이터
- post_id
- 5d38f482fbd5
- slug
- google-managed-encryption-keys-kms-and-customer-managed-encryption-keys-cmek-5d38f482fbd5
- url
- https://medium.com/@h369kr/google-managed-encryption-keys-kms-and-customer-managed-encryption-keys-cmek-5d38f482fbd5
- canonical_url
- https://medium.com/@h369kr/google-managed-encryption-keys-kms-and-customer-managed-encryption-keys-cmek-5d38f482fbd5
- author_url
- https://medium.com/@h369kr
- status
- ok
- fetched_at
- 2026-06-28 10:39:35