Encryption in Transit
Encryption in transit is the practice of scrambling data while it moves across a network, such as between a user and a cloud service or between two systems, so that anyone who intercepts the communication cannot read its contents. It protects information during the moment it is being transferred, rather than while it is stored. The data may exist in an unencrypted form at its origin or destination; the protection specifically applies to the journey between them.
Encryption in transit refers to the application of cryptographic algorithms to data as it is transmitted between two nodes of a network, rendering the payload unintelligible to an eavesdropper who intercepts communications in flight. Only parties holding the appropriate decryption keys can recover the plaintext. It is distinct from encryption at rest, which protects stored data, and from end-to-end encryption, which ensures that only the communicating endpoints (and no intermediary, including service providers) can decrypt the content; encryption in transit as commonly implemented may terminate at intermediate services that can access the plaintext. This entry describes a technical security control rather than a legal requirement; while various regulations and frameworks may reference or expect such protections, the specific obligations, algorithms, and configurations depend on jurisdiction, data category, and applicable contractual or certification requirements, which readers should verify against current authoritative sources.
Why it matters
Data is often at its most exposed while moving across a network. As information travels between an end user and a cloud service, or between two internal systems, it can pass through routers, intermediate networks, and infrastructure outside the sender's direct control. Encryption in transit addresses the risk that a party positioned along this path intercepts communications in flight; without it, an eavesdropper who captures the traffic can read its contents directly. Major cloud providers such as Google Cloud and Microsoft describe encryption in transit as a core protection they apply to customer data as it moves between users and their services, and between internal services.
For compliance professionals, the significance lies in how this control relates to broader expectations around protecting personal, financial, health, and other sensitive data categories. Various regulations and frameworks may reference or expect appropriate safeguards for data during transmission, but the specific obligations, acceptable algorithms, and configuration requirements depend on jurisdiction, data category, and applicable contractual or certification commitments. Encryption in transit should therefore be understood as one technical security control among several, rather than a standalone measure that satisfies any particular legal requirement on its own.
It is important to recognize what this control does and does not do. Encryption in transit protects data only during the journey between two points; it does not protect data while stored (which is the role of encryption at rest), and as commonly implemented it may terminate at intermediate services that can then access the plaintext. This distinguishes it from end-to-end encryption, where only the communicating endpoints can decrypt content. Treating encryption in transit as equivalent to end-to-end protection is a common misunderstanding that can lead to overstated assurances about who can access data.
Who it's relevant to
Inside Encryption in Transit
Common questions
Answers to the questions practitioners most commonly ask about Encryption in Transit.
