Requirements
What the regulation expects

Formal evaluation language for government and defence
Important for European government and defence RFPs that expect a structured security target story.
Security target and threat model
Documented security target, threat modeling and mitigations, and a formal security architecture reviewers can walk.
Independent assessment
Penetration testing completed and independent security assessment as part of the assurance story.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Key policy, lifecycle states and audit trails that map to security functional requirements.
Learn moreCertificate management
CA hierarchy, enrolment and revocation under the same governance model.
Learn moreKey themes
Where independent key control fits
Status: aligned. DuoKey architecture follows Common Criteria security functional requirements; this is not a product EAL4+ certificate for every SKU.
Security target documentation
Architecture and control descriptions written so a security target can reference concrete product behaviour.
Threat modeling and mitigation
Custody models (software, MPC, HSM), network exposure and privilege boundaries documented as mitigations.
Formal security architecture
Separation of key material, authorization checks on every operation, and tamper-evident audit trails.
Independent testing
Penetration testing and independent security assessment as evidence for evaluation-minded buyers.
Sprechen Sie über die Entscheidungen, die für Ihr Sicherheitsprogramm zählen.
Sagen Sie uns, wo Kontrolle heute schwierig ist. Wir helfen Ihnen, den nächsten praktischen Schritt zu finden.
