---
title: >-
  VM disks for critical VMs should be encrypted with customer-supplied
  encryption keys
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > VM disks for critical VMs should be
  encrypted with customer-supplied encryption keys
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# VM disks for critical VMs should be encrypted with customer-supplied encryption keys
 
## Description{% #description %}

This legacy rule evaluates Compute Engine disks created before July 20, 2026, when Google stopped supporting new customer-supplied encryption key (CSEK) encryption. Disks protected by customer-managed encryption keys (CMEK) and disks created on or after the cutoff are excluded. Google will completely remove CSEK on July 20, 2027.

## Remediation{% #remediation %}

Create a replacement disk protected with CMEK by following [Google's CSEK migration procedure](https://docs.cloud.google.com/compute/docs/deprecations/csek-deprecation-in-compute-engine).
