Apple's law enforcement guidelines[2] provide more detail about what Apple effectively has access to and can/will provide upon presentation of a warrant.
(As of iOS 9.3 and macOS 10.11.4, it appears that notes that you explicitly password-protect in the Notes app are also encrypted with a user-supplied key to which Apple has no access. They don't explicitly mention this functionality in [1] or [2], but they do imply that this is the case in [3].)
There have been rumblings [4] since the San Bernardino case that Apple is considering providing what you describe, so that users can provide their own encryption keys for their iCloud content and backups, such that Apple no longer has access to the plaintext. However, Apple has not implemented this functionality yet, and I haven't heard anything about it since the FBI dropped its case against Apple in this matter.
[1] http://www.apple.com/privacy/approach-to-privacy/
[2] https://www.apple.com/legal/privacy/law-enforcement-guidelin...
[3] https://support.apple.com/en-us/HT205794#forgot_password
[4] [paywall] http://www.wsj.com/articles/in-beefing-up-icloud-security-ap...