Frameworks
Customer-controlled keys by regulation
Cloud encryption is only as strong as key custody. DuoKey supports the evidence regulators expect while keeping authority with your organisation.
Region
ADHICS v2
Abu Dhabi Healthcare Information and Cyber Security Standard. CS 1.2 says the cloud provider must not store or control the entity's keys.
CBUAE
Central Bank of the UAE IT risk and information security standards for licensed financial institutions. Cryptography, key management and outsourcing.
Common Criteria
International IT security evaluation standard. DuoKey architecture follows Common Criteria security functional requirements.
DESC Dubai
Dubai Electronic Security Center information security regulation for Dubai Government entities, critical sectors and contracted IT/cloud suppliers.
DORA
ICT risk management and resilience for the EU financial sector, with encryption and keys you can prove you control.
Swiss FADP (nFADP)
The revised Federal Act on Data Protection, security by design, data sovereignty and defensible technical measures.
FIPS 140-2/3
Federal Information Processing Standard for cryptographic modules. DuoKey uses FIPS-validated cryptographic components.
GDPR
Article 32 security, breach risk and transfers, encryption that is meaningful because you hold the keys.
HIPAA
Technical safeguards for ePHI, encryption and key management you can stand behind in a BA audit.
ISO 27001
International standard for information security management systems. DuoKey is ISO/IEC 27001 certified.
NCA CCC-1:2020
Cloud Cybersecurity Controls for KSA. Provider vs tenant split, and 2-15 Key Management that decides most KMS deals.
NCA DCC-1:2022
Data Cybersecurity Controls. Lifecycle, third-party and cloud controls. Quote control text from the official PDF, not from summaries.
NCA ECC-2:2024
Saudi national baseline cybersecurity controls. Cryptography, IAM, logging and cloud hosting that a KMS can evidence.
NCA NCS-1:2020
National Cryptographic Standards. MODERATE and ADVANCED strength levels, plus the key lifecycle section ECC and CCC point to.
NIS2
Network and information security for essential and important entities, encryption and keys you govern, not just a checkbox.
NIST SP 800-53
US federal security and privacy control catalogue. Map DuoKey key management and crypto controls into your baseline.
NIST PQC (CSWP 48)
Map DuoKey crypto posture and migration tooling to NIST CSF 2.0 and SP 800-53 using NIST CSWP 48 PQC migration guidance.
PCI DSS
Payment Card Industry Data Security Standard. Key custody, split knowledge and encryption for account data environments.
SAMA CSF
Saudi Central Bank Cyber Security Framework. Mandatory for member organisations. 3.3.9 Cryptography and 3.3.5 IAM are the KMS buy triggers.
SDAIA PDPL
Saudi Personal Data Protection Law and its regulations. Key location becomes a legal question, not only an architecture preference.
SOC 2 Type II
Trust service criteria for security, availability, processing integrity, confidentiality and privacy. DuoKey is SOC 2 Type II aligned.
TDRA UAE IA Regulation
Federal Information Assurance Regulation. Cryptography in T7.4, key management in T7.4.2. Successor to NESA IAS.
TISAX
Trusted Information Security Assessment Exchange for automotive. Assessment Level 3 (AL3) certified.
UAE PDPL
Federal Decree-Law No. 45 of 2021 on personal data protection. Security measures and cross-border transfer, with customer-held keys as architecture not legal conclusion.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.