How to answer
Do you support customer-managed encryption keys (BYOK/CMEK)?
The question is about custody, not encryption. Answering "yes, AES-256" answers a different question and a reviewer will notice.
No. Customer data is encrypted at rest using AES-256 with keys held in our cloud provider's managed key service and rotated annually. We do not currently offer customer-managed or customer-supplied keys.
FillTrust grades an answer like this answered “no” from your documents when your documents support it.
- Answered from
- Your encryption policy, and whichever architecture document says who holds the keys.
- Evidence to attach
- Occasionally a diagram showing where keys live. Never the keys, obviously, and never the key management console.
- Where it is asked
- CAIQ v4.0 · CEK-08SIG Lite
Nearly everyone answers this one wrong on the first pass, because it looks like the encryption question two rows above it and is not.
"Do you encrypt data at rest" asks whether the data is protected. "Do you support customer-managed keys" asks who can turn the protection off. A buyer raising it wants to know whether they can hold the key themselves, rotate it on their own schedule, and revoke it without asking you. Usually that is because their own policy requires it, or because they are thinking about what happens if the relationship ends badly.
No is a normal answer. Customer-managed keys are an enterprise feature with real operational weight: key rotation becomes a shared responsibility, a revoked key means an outage you cannot fix, and a lost key means data you cannot recover. Most companies below a certain size do not offer it, and saying so directly costs less than a paragraph that hedges.
What to put beside the no. Name where the keys actually live and who can reach them: the provider's managed key service, the rotation cadence, and the fact that no individual holds key material directly. That answers the worry behind the question, which is that a key sits in a config file somewhere, even when the feature itself is absent.
If this is a deal blocker, it is a roadmap conversation, not a questionnaire answer. Do not write "planned" unless it is on a plan with a date. "Not currently offered" is a fact; "on our roadmap" is a promise, and a questionnaire is a poor place to make one.
How this one goes wrong
Specific to this question, not general advice.
- Reading it as "is the data encrypted" and answering yes. The question is about custody, not about encryption, and a yes here means something specific: the customer can hold, rotate and revoke the key.
- Saying yes because your cloud provider offers CMEK. Your provider supporting it is not the same as your product exposing it, and the gap between those two is a delivery project.
- Treating a no as a failure. Most companies under a hundred people answer no, and the honest no with the compensating control beside it reads better than a hedged maybe.
- Forgetting that revocation is the point. A buyer asking this usually wants to know they can cut off access unilaterally. If you cannot offer that, say so plainly rather than describing your rotation schedule at them.