Requirements
What the regulation expects

Dubai layer on top of the federal baseline
Applies to Dubai Government entities, Dubai-based critical sector operators, and IT/cloud suppliers under contract to a Dubai Government entity.
Classification and residency
Dubai expectations on where data and keys sit. In-country or on-premise key custody is a deployment choice to commit in writing.
Supplier obligations
IT and cloud suppliers contracted to Dubai Government entities inherit security expectations. External keys limit how much trust the contract alone must carry.
Evidence from the platform
Framework gap reports for the Dubai rule pack, key inventory with location attestation, and tamper-evident audit trail.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
On-premise or in-UAE vault with exportable inventory and posture reports for the Dubai rule pack.
Learn moreMicrosoft 365 Customer Key & DKE
Customer-held keys so the SaaS host is not the sole custodian.
Learn moreKey themes
Where independent key control fits
Confirm current DESC control numbering per engagement. The mappings below are the KMS contribution relative to federal IA plus Dubai residency/classification practice.
Cryptographic controls and key custody
Approved key policy as enforced configuration, lifecycle states and inventory with custody backend per key.
Data classification and residency
Key location attestation and deployment topology (primary, backup, DR) as inputs to Dubai residency expectations.
Cloud and supplier separation
Keys outside the cloud application so contractual security clauses have a technical control behind them.
Automated Dubai rule-pack reporting
Gap report, CBOM and Quantum Risk Score with UAE jurisdiction profile selected.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
