Understand customer-managed encryption in Acrobat Sign

Last updated on Aug 31, 2026
Alert

This article contains prerelease information. Release dates, features, and other information are subject to change without notice.

Learn how Acrobat Sign uses your organization's encryption key to protect supported content at rest and what happens throughout the encryption lifecycle.

Customer-managed encryption lets your organization control the key used to protect supported Adobe Acrobat Sign content at rest.

Your organization provisions and controls the encryption key in AWS Key Management Service (KMS). Acrobat Sign uses that key as part of its encryption process while continuing to manage the storage, processing, and delivery of supported content.

This model gives your organization control over a critical part of the encryption chain without changing how senders and recipients normally work with agreements.

How customer-managed encryption works

Acrobat Sign uses a customer-specific encryption model for supported content.

At a high level:

  1. Your organization creates and controls a key in AWS KMS.
  2. An account administrator configures Acrobat Sign to use that key.
  3. Acrobat Sign validates that it can access the key.
  4. Supported content is encrypted using the customer-managed encryption configuration.
  5. When protected content must be accessed, Acrobat Sign must be able to use the configured key.

The AWS KMS key remains under your organization's control. Acrobat Sign does not take ownership of the key.

Customer-managed encryption protects data at rest

Customer-managed encryption applies to supported content while it is stored by Acrobat Sign.

It does not replace the encryption Acrobat Sign already uses to protect information while it is transmitted. Existing protections for data in transit continue to apply.

Not every type of data stored by Acrobat Sign is currently protected by the customer-managed key.

For the current protection scope, see Customer-managed encryption considerations and limitations.

What happens when customer-managed encryption is enabled

After customer-managed encryption is configured and enabled, supported newly created content is protected using the configured customer-managed key.

This includes supported content created as part of normal agreement and template workflows.

Senders do not choose an encryption key when creating an agreement. Encryption is applied automatically according to the account-level configuration.

Recipients likewise do not need to take any additional action because customer-managed encryption does not change the normal signing experience.

Existing content can be migrated

Enabling customer-managed encryption does not require existing content to remain permanently under Adobe-managed encryption.

Account administrators can start a background migration that re-encrypts eligible existing content using the configured customer-managed key.

While migration is underway, the account can contain both:

  • content already protected using the customer-managed key; and
  • content that remains protected using Adobe-managed encryption.

Both states are supported during the transition, and agreements remain available while the migration proceeds.

For instructions on migrating existing content and monitoring the operation, see Manage customer-managed encryption keys.

Acrobat Sign must retain access to the key

Because your organization controls the AWS KMS key, continued access to that key becomes part of the availability model for protected content.

Acrobat Sign maintains cached key-encryption information for a configurable period. The Time to Live (TTL) setting determines how long that cached information remains usable before Acrobat Sign must access AWS KMS again.

The supported TTL is 5 to 60 minutes.

If Acrobat Sign loses access to the AWS KMS key, previously cached information can allow access to continue temporarily. After the TTL expires, content that depends on the unavailable key can no longer be accessed until key access is restored.

This means changes such as disabling the key, revoking credentials, or removing the required IAM permissions can affect access to protected Acrobat Sign content.

For key-access failures and recovery steps, see Troubleshoot customer-managed encryption.

AWS key rotation does not necessarily change the Acrobat Sign configuration

AWS KMS can rotate the underlying cryptographic material for a customer-managed key while retaining the same key ARN.

When AWS rotates the key material and the key ARN remains unchanged, Acrobat Sign continues to reference the same configured key.

This differs from replacing the configured AWS KMS key with another key. See Manage customer-managed encryption keys for supported key-management operations.

You can verify how an agreement is currently protected

During a migration, individual agreements can be at different stages of the encryption transition.

The Protection Information action on the agreement's Manage page lets users with access to the agreement check whether its documents are currently protected using:

  • the organization's customer-managed encryption key; or
  • Adobe-managed encryption.

This provides a direct way to verify the protection state of a specific agreement without relying on the status of an account-wide migration.

What happens when customer-managed encryption is disabled

Customer-managed encryption can be disabled without permanently making previously protected content dependent on the customer key.

When an administrator disables customer-managed encryption, Acrobat Sign starts a background operation that returns eligible customer-key-protected content to Adobe-managed encryption.

The customer-managed AWS KMS key must remain accessible while this operation is running because Acrobat Sign still needs it to read content that has not yet been migrated.

During the transition, some content can remain protected by the customer-managed key while other content has already returned to Adobe-managed encryption.

Once the migration is complete, the migrated content no longer depends on the customer-managed key.

Customer-managed encryption does not change agreement workflows

Customer-managed encryption operates as an account-level security capability.

It does not require senders to:

  • select encryption when creating agreements;
  • choose an AWS KMS key;
  • change recipient configuration; or
  • modify normal sending workflows.

Recipients do not see a different signing workflow because an agreement uses customer-managed encryption.

The primary operational responsibility belongs to the administrators responsible for the Acrobat Sign account and the organization's AWS KMS resources.