- - Introduces declarative policies to centrally enable VPC Encryption Controls in monitor or enforce mode across all VPCs, including future ones
- - Allows applying policies at account, organization, or OU level with unified visibility of encryption status
- - No additional cost for using these policies within AWS Organizations