Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no single correct key-rotation interval for every encryption key. Choose one based on the key’s purpose, workload risk, applicable requirements, and what its provider supports. Before scheduling rotation, confirm the key is eligible, test that applications can use new material and still read older ciphertext, and decide how long prior key versions must remain available.

What scheduled key rotation does—and does not do

Scheduled rotation creates or selects newer key material for future cryptographic operations. It does not necessarily re-encrypt data already protected with an older version. Google Cloud states that data encrypted with previous key versions is not automatically re-encrypted when a key rotates (Google Cloud: Key rotation).

That distinction matters operationally: rotation and data migration are separate tasks. A provider may retain historical material so ciphertext made earlier can still be decrypted, but you should verify the behavior for the specific key and application rather than assume rotation changes every stored copy of data.

How often should you rotate encryption keys?

Set the interval from the workload’s sensitivity and exposure, contractual or regulatory requirements that actually apply, provider guidance, and the time your team needs to test and respond to failures. Treat provider examples as guidance for the named service and key class—not universal cryptographic rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Provider guidance or setting What the figure means
Google Cloud CMEK: 90 days Google recommends this period for software-backed customer-managed encryption keys. It is provider guidance for this key category, not a universal requirement. Google Cloud CMEK practices
Google Cloud CMEK: 365 days Google recommends this period for Cloud HSM keys. Workload sensitivity and compliance still inform the choice. Google Cloud CMEK practices
AWS KMS: 365 days AWS documents this as the default automatic rotation period for eligible customer-managed KMS keys; it is approximately one year, not a default for every KMS key. AWS EnableKeyRotation API
AWS KMS: 90 to 2,560 days AWS announced this configurable rotation-period range for customer-managed KMS keys in April 2024. Confirm the current options and the particular key’s eligibility before configuring it. AWS announcement, April 2024

Google Cloud schedules can be based on key age or the count or volume of messages encrypted. AWS automatic rotation uses a configured period; an on-demand rotation can be initiated separately. In both services, a manual or on-demand rotation does not change the existing automatic schedule (Google Cloud; AWS KMS rotation guide).

Check whether the key can be rotated automatically

Eligibility depends on key type, material origin, and provider. Do not apply a schedule to a key merely because the console offers rotation settings for other keys.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Google Cloud KMS: Automatic rotation supports symmetric encryption keys. Asymmetric signing and encryption keys require manual or application-coordinated procedures. External key material must be rotated manually according to the chosen schedule. Google Cloud key rotation
  • AWS KMS: Automatic rotation is limited to eligible symmetric KMS keys. AWS documentation excludes asymmetric keys, HMAC keys, imported key material, and custom key stores from automatic rotation. AWS-managed keys rotate on the service’s schedule, which customers cannot configure. Check current eligibility and account-specific configuration in the AWS KMS rotation guide.

Asymmetric keys often need additional coordination: applications may need a new public key, certificates or integrations may need updating, and systems must continue to verify signatures made with older material. A calendar setting alone does not perform those steps.

Prepare a schedule that can be operated safely

  1. Inventory and classify. Record each key’s purpose, symmetric or asymmetric type, material origin, dependent applications and services, protected data, and region or location constraints. Verify provider eligibility for each key.
  2. Choose and document the interval. Tie it to workload risk, applicable controls, provider recommendations, data volume where relevant, and the time needed to validate a rotation. Record why the interval is appropriate; do not label a 90-day or annual period mandatory unless the applicable requirement says so.
  3. Assign ownership and set the first run. Name the operational owner, exception approver, and escalation path for a missed or failed rotation. Record when rotation will first occur and whether the provider creates a new key version or changes a key identifier.
  4. Test application behavior. In a safe test or controlled rollout, verify that new encryptions use the newer material and reads still work for data encrypted under prior versions. For asymmetric keys, test distribution and verification across every dependent system.
  5. Define observability and audit evidence. Track the configured period, next scheduled time, successful completion, failures, and exceptions. AWS identifies CloudWatch and CloudTrail as monitoring surfaces for key-material rotation; its guide also describes checking rotation status through AWS KMS controls and APIs. AWS EnableKeyRotation API
  6. Plan re-encryption separately if required. If policy or risk calls for old ciphertext to be protected with current material, create a migration plan with backups, validation, rollback criteria, and coverage of retained data. Rotation by itself does not perform this migration.
  7. Set an out-of-cycle response. Define how to act on suspected compromise or an algorithm migration without waiting for the next scheduled date. Confirm whether an emergency rotation affects the recurring schedule; Google Cloud and AWS document that their manual or on-demand rotations leave the existing automatic schedule unchanged.
  8. Retire old versions only after dependency review. Account for retained ciphertext, backups, recovery needs, and legal or retention obligations before disabling or destroying prior material. Google Cloud warns that key destruction is irreversible and can cause permanent data loss. Google Cloud key rotation

Provider-specific details to verify

Google Cloud KMS

Google’s setup guidance covers configuring a rotation period and next rotation time. Before enabling a schedule, confirm the key is a supported symmetric encryption key and that the planned timing aligns with the workload. Review the Google Cloud instructions for rotating a key alongside its guidance on rotation behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

AWS KMS

AWS documents a one-year default for eligible customer-managed keys and a configurable period for supported keys. Verify the key’s type and material origin, inspect the account’s actual setting, and monitor completion rather than assuming that enabling rotation covers excluded keys. See the AWS KMS rotation guide and EnableKeyRotation API reference.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do not treat key rotation as secret or password rotation

KMS encryption-key rotation changes key material under a provider’s key-management model. Passwords, API tokens, and application secrets can require deployment-specific overlap, replacement, and rollback steps; the KMS rotation behavior described here does not establish how those credentials should be rotated.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.