AWS Security ChangesHomeSearch

AWS acm high security documentation change

Service: acm · 2026-06-04 · Security-related high

File: acm/latest/userguide/dochistory.md

Summary

Added deprecation notice for certificate transparency logging opt-out, requiring all public ACM certificates to be logged starting June 2026

Security assessment

This change documents mandatory certificate transparency logging to comply with upcoming browser security policies. It addresses potential security risks by eliminating opt-outs, ensuring all certificates are logged for enhanced monitoring and trust validation.

Diff

diff --git a/acm/latest/userguide/dochistory.md b/acm/latest/userguide/dochistory.md
index 127dbc144..7499eb14f 100644
--- a//acm/latest/userguide/dochistory.md
+++ b//acm/latest/userguide/dochistory.md
@@ -12,0 +13 @@ Change| Description| Date
+Certificate transparency logging opt-out deprecated| Certificate transparency logging opt-out is no longer available. All public ACM certificates are automatically recorded in certificate transparency logs. The `CertificateTransparencyLoggingPreference` option is deprecated. With this update, ACM issued public certificates will be compliant with upcoming browser policy changes which require that all TLS server authentication certificates issued after June 15, 2026 are logged to at least one Certificate Transparency log.| June 1, 2026