DuoKey
Compliance

Common Criteria

International IT security evaluation standard. DuoKey architecture follows Common Criteria security functional requirements.

Requirements

What the regulation expects

Common Criteria is the international standard for IT security evaluation. DuoKey architecture follows Common Criteria security functional requirements. Status is aligned, not a product EAL4+ certificate for every SKU. Lead with security target documentation, threat modeling, formal architecture and completed penetration testing when the buyer needs evaluation-process evidence.
What the regulation expects

Formal evaluation language for government and defence

Important for European government and defence RFPs that expect a structured security target story.

Security target and threat model

Documented security target, threat modeling and mitigations, and a formal security architecture reviewers can walk.

Independent assessment

Penetration testing completed and independent security assessment as part of the assurance story.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

Key policy, lifecycle states and audit trails that map to security functional requirements.

Learn more

Certificate management

CA hierarchy, enrolment and revocation under the same governance model.

Learn more

Key themes

Where independent key control fits

Status: aligned. Do not claim a product EAL4+ certificate unless the specific TOE and certificate ID are part of the bid package.

Security target documentation

Architecture and control descriptions written so a security target can reference concrete product behaviour.

Relevant products

Threat modeling and mitigation

Custody models (software, MPC, HSM), network exposure and privilege boundaries documented as mitigations.

Relevant products

Formal security architecture

Separation of key material, authorization checks on every operation, and tamper-evident audit trails.

Relevant products

Independent testing

Penetration testing and independent security assessment as evidence for evaluation-minded buyers.

Relevant products

Resources

Continue reading

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.