AWS Backups Unencrypted

Hello everyone… Newbie question,

I am creating vaults, plans, rules and selections in AWS with Terraform, but I’m running in to what must me a very simple issue… My backup vault is encrypted, but for some reason the backups that are going in to it are reported as “unencrypted”. I am using the default aws/backup key to encrypt the vault and as such I thought the backups would be encrypted too. Where am I going wrong?

resource “aws_backup_vault” “vault” {
name = “vault”
kms_key_arn = var.vault_kms_key_arn
}

kms_key_arn is the arn of the aws/backup key…

Do I need to specify the backups are encrypted too? If so, where? In the aws_backup_plan?

TIA, Steve