The Advanced Encryption Standard is a symmetric block cipher approved by NIST. The 256-bit key length is the strongest of the approved variants and is considered secure against foreseeable attack.

It is the default for data at rest in most enterprise systems.

Alternative Names:

AES, Advanced Encryption Standard

Why it Matters?

Because AES-256 is essentially universal, its presence in a vendor questionnaire response is uninformative and its absence is a genuine concern. The questions that distinguish vendors are about key management rather than algorithm: who holds the keys, how they are rotated, and whether the customer can control them. A vendor citing AES-256 as a differentiator is describing the baseline.

Frequently Confused with

Related terms

Frequently asked questions

Is AES-256 a meaningful differentiator?

Is AES-256 a meaningful differentiator?

No. It is essentially universal, so the informative questions concern key management rather than the encryption algorithm itself.

Does it satisfy breach safe harbors?

Does it satisfy breach safe harbors?

Generally yes, provided the encryption keys were not also compromised, which most state notification statutes require.