Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Customer-Provided Key Encryption
Cyber Security

Customer-Provided Key Encryption

← Back to Glossary
By NHI Mgmt Group Updated August 24, 2026 Domain: Cyber Security

Customer-provided key encryption means the customer supplies the key that protects storage data, rather than relying entirely on platform-managed keys. It can strengthen control over sensitive data, but it also creates a sharp dependency on key availability and access controls. If the key is missing, data may become unreadable.

Expanded Definition

Customer-Provided Key Encryption is a storage protection model in which the customer, not the platform operator, provides the key material used to encrypt or decrypt data at rest. It is often discussed alongside customer-managed keys and bring-your-own-key patterns, but the distinctions matter: in some deployments the customer controls the key lifecycle directly, while in others the provider still hosts the key management service. Usage in the industry is still evolving, so documentation should state exactly who generates, stores, rotates, revokes, and restores the key.

This model is most relevant where organisations need stronger separation from default provider-controlled encryption, especially for regulated records, high-value intellectual property, or tenant-specific retention requirements. It can support stronger governance, but it also makes data availability dependent on correct key custody, backup, and recovery procedures. For operational context, the NIST Cybersecurity Framework 2.0 is useful for mapping the governance and recovery expectations that surround key-controlled protection.

The most common misapplication is treating customer-provided key encryption as a simple configuration toggle, which occurs when teams ignore key escrow, rotation ownership, and recovery testing.

Examples and Use Cases

Implementing customer-provided key encryption rigorously often introduces operational dependency on the customer’s own key management process, requiring organisations to weigh stronger control against the risk of self-inflicted data loss.

  • A financial services team encrypts analytics storage with a customer-supplied key so that access can be revoked independently of the cloud platform account.
  • A healthcare provider uses separate keys for different data classes to support internal policy segmentation and more explicit auditability.
  • An M&A workstream stores deal documents under customer-provided keys so a transfer event can include key custody decisions as part of the handover plan.
  • A SaaS security team documents how key rotation, break-glass access, and recovery are handled before enabling the feature for a regulated tenant.
  • A compliance programme aligns key ownership with data residency expectations and records those decisions in the asset register, following guidance such as NIST Cybersecurity Framework 2.0.

Why It Matters for Security Teams

Customer-provided key encryption changes the threat model from provider trust to customer responsibility. Security teams must understand that compromise is not limited to theft of ciphertext; loss of the key, loss of key access, or incorrect rotation can create permanent data unavailability. That makes identity and privileged access controls central to the design, because whoever can administer the key service effectively controls access to the protected data. For that reason, this pattern often intersects with PAM, separation of duties, and NHI governance where automation or service identities manage rotation and retrieval.

It also creates a compliance and incident-response burden: teams need tested procedures for revocation, restoration, and forensic review, not just encryption enabled at rest. Guidance in the NIST Cybersecurity Framework 2.0 helps organisations connect protection, recovery, and governance, while key-handling details should be documented with the same discipline as any other critical secret. Organisations typically encounter the true impact only after a key is lost, rotated incorrectly, or access is denied, at which point customer-provided key encryption becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 provides the primary governance reference for this term.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.DS-1Data-at-rest protection covers encryption using customer-controlled key material.

Treat customer-provided keys as part of data protection, with documented ownership and recovery.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org