Customer-managed encryption considerations and limitations

Last updated on Aug 31, 2026
Alert

This article contains prerelease information. Release dates, features, and other information are subject to change without notice.

Review the requirements, operational impacts, and current limitations of customer-managed encryption before enabling it for your Adobe Acrobat Sign account.

Customer-managed encryption gives your organization control of the AWS KMS key used to protect supported Acrobat Sign content at rest. That control also makes your organization responsible for keeping the key and its access credentials available.

Review these considerations before enabling customer-managed encryption or changing the key configuration.

Plan for continuous access to your encryption key

Acrobat Sign must be able to access your configured AWS KMS key to encrypt and decrypt protected content.

Content protected with your customer-managed key can become unavailable if:

  • The AWS KMS key is disabled or deleted.
  • The AWS credentials configured in Acrobat Sign are disabled or revoked.
  • IAM permissions no longer allow Acrobat Sign to use the key.

Acrobat Sign can continue using cached key-encryption information until the configured key cache TTL expires. The TTL can be set from 5 to 60 minutes.

Keep the key and required credentials available for as long as Acrobat Sign content remains protected by that key.

Note

Do not delete a customer-managed key while Acrobat Sign content is still protected by it. Deleting the key can make that content unrecoverable.

Understand what is protected

Customer-managed encryption applies to supported Acrobat Sign content stored at rest.

Content Customer-managed encryption
Agreement PDFs Supported
Templates Supported
Thumbnails Supported
Temporary files managed by the supported file service Supported
Active signature images Supported
Electronic seal logos Supported
Form field data Not supported
Government ID verification images Not supported
Sensitive account settings, including customer mTLS certificates Not supported

Customer-managed encryption does not change how Acrobat Sign protects data in transit. Existing transport encryption continues to apply.

AWS KMS is the supported key provider

The current implementation supports customer-managed keys in AWS Key Management Service (KMS).

The configured key must meet the requirements described in Configure Customer Managed Encryption, including use of a supported symmetric AWS KMS key and the required IAM permissions.

The following are not currently supported:

  • Azure Key Vault
  • Azure Government
  • Acrobat Sign for Government

Support for other key-management environments is outside the current release.

Customer-managed encryption is account-level

Customer-managed encryption applies at the Acrobat Sign account level.

It cannot be configured independently for individual groups. Once enabled, supported content created for the account uses the configured customer-managed encryption configuration.

This makes key availability and key-management practices an account-wide operational dependency.

Existing content requires background processing

Enabling customer-managed encryption does not immediately re-encrypt the account's entire history.

Existing eligible content is migrated through a background re-encryption process. Bulk encryption and decryption jobs run during the account's off-peak processing window, from 7:00 PM to 7:00 AM local time.

For accounts with large amounts of content, processing can span multiple windows and may take days or weeks.

Agreements remain accessible while processing is underway. During a migration, an account can temporarily contain both:

  • content protected with the customer-managed key; and
  • content that is still protected with Adobe-managed encryption.

For instructions on starting and monitoring these operations, see Manage customer keys.

Disabling customer-managed encryption takes time

Disabling customer-managed encryption does not immediately remove the dependency on the customer-managed key.

Acrobat Sign must first process content that is currently protected by the customer-managed key and return it to Adobe-managed encryption. The AWS KMS key and credentials must remain available throughout this process.

Do not disable or delete the AWS KMS key, revoke its credentials, or remove required permissions until the migration back to Adobe-managed encryption is complete.

Large migrations are asynchronous

Bulk encryption and decryption are background operations designed to avoid interrupting normal agreement activity.

Keep these behaviors in mind:

  • Processing occurs only during the off-peak processing window.
  • Large accounts can require multiple processing windows.
  • Individual items can fail even when the overall job completes.
  • Failed items can be retried without repeating successfully processed items.
  • A running migration can be stopped and resumed.
  • The status page does not refresh automatically; refresh it to see the latest processing state.

Detailed job management belongs to Manage customer keys.

Review automatically protected content

Automatically applying customer-managed encryption does not eliminate the need to understand which content types are within the supported encryption scope.

In particular, do not assume that enabling customer-managed encryption means every type of account data is protected by your AWS KMS key. Content listed as unsupported continues to use its existing Acrobat Sign protection model.

For a detailed explanation of the encryption model, see Understand customer-managed encryption in Acrobat Sign.

Plan AWS key maintenance carefully

AWS can rotate the underlying key material for a customer-managed KMS key without changing its key ARN.

Acrobat Sign does not provide a separate customer-key migration workflow for moving already protected content from the configured AWS KMS key to a different customer-managed key in the current implementation.

Plan changes to the configured key and its credentials carefully, and validate new access before removing access that Acrobat Sign currently depends on.

Consider compliance and operational ownership

Customer-managed encryption changes who controls a critical dependency for access to protected Acrobat Sign content.

Before enabling it, establish ownership for:

  • AWS KMS key administration.
  • IAM credential management.
  • Key-access monitoring.
  • Credential rotation.
  • Responding to key-access failures.
  • Keeping the key available during encryption and decryption migrations.

Acrobat Sign administrator notifications can alert active account administrators to key-access failures, but your organization remains responsible for restoring access to its AWS resources.