If you have an on premise instance and you’re migrating to AES-256 GCM encryption (docs) please remember to save your CMK (customer managed key) - be sure to store it in a safe and permanent location before continuing!
Losing the CMK after encrypting the internal database can result in the loss of your instance.