@nprofile1q... apart from controlling their lifecycle they don't fundamentally change anything about the security of your data. The assumption is still that your cloud provider is unable to extract them from the HSM. Additionally, there is a difference between having a CMK that is merely used for wrapping data keys and actually controlling the key used for encrypting, decrypting, signing, or verifying the data.