What is the difference between a key managed by SQS vs a KMS key managed by SQS?
17:51 02 Dec 2025

I'm looking into encrypting an SQS Queue that I've got using the CDK, and as options, there are

Encryption type Description
UNENCRYPTED Messages in the queue are not encrypted.
KMS_MANAGED Server-side KMS encryption with a KMS key managed by SQS
SQS_MANAGED Server-side encryption key managed by SQS (SSE-SQS)
KMS Server-side encryption with a KMS key managed by the user.

but I don't understand the significance in the difference between #2 and #3. Both KMS_MANAGED and SQS_MANAGED have a Service Side encrypted key that's managed by SQS, but in the former case that is a KMS key, and in the latter case there is no KMS key.

Now... why does that matter to me as an end user / person who's looking to encrypt? In both cases, AWS is managing the key, what difference does it make to me whether they use key A or key B to do it, when in both cases I don't have control, and both cases are assumably secure?

Essentially, I don't understand the significance of it being a KMS managed key or not, when in both cases, it is encrypted safely?

amazon-web-services encryption amazon-sqs amazon-kms