Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Look for a specific FIPS 140-2/3 level and true non-exportable HSM-bound key generation — 'HSM-backed' sometimes means only the master key is in hardware.
Strong answers explain the real revocation semantics per cloud (they differ meaningfully) rather than implying uniform instant revocation everywhere.
Look for policy-driven rotation and quorum controls on destruction — manual rotation practices are how keys quietly age past policy.
Interface breadth (KMIP + PKCS#11 + REST) determines integration reach; honest answers also address the hard part — migrating keys that can't leave an incumbent HSM.
The critical design question is whether applications keep decrypting when the KMS control plane is down — look for an explicit answer with cached/data-plane semantics.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Key managers are where PQC migration actually gets executed; look for shipped PQC key-type support and a re-keying story, not roadmap slides.
KEK rotation should be metadata-speed (re-wrap DEKs, not re-encrypt data) — strong answers demonstrate they understand and have executed this at customer scale.
The honest answer addresses the platform-operator threat model directly (HSM non-exportability, customer-held key shares) rather than deflecting to access policies alone.
Look for transparent, predictable scaling economics for high-transaction-volume use cases; per-operation pricing that becomes expensive at real production scale is a common budget surprise.
A fast, well-defined emergency revocation process with real blast-radius assessment is critical — ask for a concrete, tested procedure and timeline, not just a generic 'keys can be rotated' claim.
FIPS validation level (e.g., Level 2 vs Level 3) is a specific, checkable claim — a vague 'FIPS compliant' answer without a level and certificate number is insufficient evidence for a regulated buyer.
A KMS control-plane outage that fully blocks all encrypted-data access is a severe availability failure mode — ask for a specific data-plane resilience answer, not just a control-plane uptime SLA.
Integration with existing PKI tooling is materially less disruptive than requiring an entirely new parallel infrastructure — ask for a concrete integration example.
Some regulated or highly sensitive environments require a genuinely air-gapped option — a vendor should clarify this explicitly rather than assuming cloud deployment is universally acceptable.
Tamper-evident audit logging for key operations specifically is a meaningful security property — ask for the specific mechanism (e.g., append-only storage, hash-chained logs) rather than accepting a generic 'we log everything' claim.
Trend-over-time reporting on rotation compliance is a distinct capability from a real-time key inventory — confirm this exists as a maintained, exportable report.