First challenge the premise. Ordinary rotation of a managed symmetric AWS KMS key does not make older ciphertext unreadable. KMS retains the old key material and uses the appropriate material when decrypting it. AWS's rotation documentation says so. If decryption broke immediately after “rotation,” find the exact operation. Did someone replace a key rather than rotate its material, delete an old key, expire imported key material, change access policy, lose the encrypted data key, or copy ciphertext into a region that lacks the corresponding key? Those are different incidents.

An envelope-encrypted snapshot usually has data encrypted under a data key, with that data key wrapped under a KMS key. Keeping the object bytes without the wrapped data key or the ability to unwrap it is not a backup. Read the object's encryption metadata and the KMS key identifier recorded at creation, then attempt one controlled decrypt with the correct principal and region. An access-denied error is not proof the material vanished. Conversely, AWS's key-deletion guidance warns that deleting the key can permanently prevent decrypting the protected data key. Do not “fix” that by inventing a new key under the same alias. An alias name is a pointer, not the old cryptographic secret.

The design needs two clocks: how long the snapshot must remain available, and how long its key material must remain usable. Before retiring a key, inventory the ciphertext it protects, re-encrypt or rewrap under a retained key where policy allows, and perform a restore drill on the oldest promised snapshot. Keep authorization and audit controls for who may decrypt. There may be a legal reason to make certain data unrecoverable. If so, the retention promise and deletion policy must agree, rather than silently discovering during an incident that one defeated the other.

If the key was actually destroyed and there is no independent backup of the needed material, the intact ciphertext may be unrecoverable. Say that plainly. The failure is in a dependency of the snapshot that the storage inventory did not count.