Requirements
What the regulation expects

Almost every enterprise RFP asks for it
Universal compliance requirement. Lead with certified status and the scope of the ISMS.
Cryptographic controls in Annex A
Policies, key lifecycle, access control and logging that support A.8 / cryptography-related controls in ISO 27001:2022.
Incident and continuity
Incident management and business continuity procedures under the certified ISMS.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Enforced key policy, lifecycle, access reviews and exportable audit evidence for customer SoA mapping.
Learn moreCloud BYOK / XKS / DKE
Customer-held keys so cloud processing stays within the customer's cryptographic boundary.
Learn moreKey themes
Where independent key control fits
Status: certified. Certificate available on request. Product pages below show how DuoKey helps customers map their own ISO control objectives for cryptography and access.
Information security policies
Customer key and access policy enforced as configuration, not only as a document.
Access control management
Leaf-level permissions, MFA for privileged access, JIT elevation and periodic access review output.
Cryptographic controls
Approved algorithms and key types, lifecycle states, custody backends and inventory for auditor evidence.
Incident management and continuity
Key disablement, rotation and recovery procedures that feed the customer's incident and continuity playbooks.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
