DuoKey
Compliance

NCA CCC-1:2020

Cloud Cybersecurity Controls for KSA. Provider vs tenant split, and 2-15 Key Management that decides most KMS deals.

Requirements

What the regulation expects

CCC-1:2020 extends the ECC for cloud. Agree the P/T split in writing at contract stage: when DuoKey is delivered as a managed service, DuoKey carries P controls and the customer carries T controls; on-premise, the customer carries both. Subdomain 2-15 Key Management is unique to CCC and is the clause that rules out provider-held keys for serious Kingdom deals.
What the regulation expects

ECC extended for cloud

Controls ending in P apply to the Cloud Service Provider; controls ending in T apply to the Cloud Service Tenant.

Trusted key store outside the cloud

2-15-T-3-2 demands secure retrieval if keys are lost, with trusted storage strictly external to the cloud application.

Ownership you can audit

2-15 requires well-defined ownership for cryptographic keys. Owner and tenant must be fields an auditor can read, not a spreadsheet convention.

NCS ADVANCED crypto strength

2-7 points at NCS-1:2020 ADVANCED. AES-256-GCM meets the symmetric bar; do not claim blanket ADVANCED for asymmetric and hash without checking the boundary.

Exit and disposal

2-6 exit strategy. Destroying the key renders provider-side ciphertext unusable when physical disposal is impossible.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

Per-key owner and tenant, custody in software, MPC or HSM, activity trail forwarded to the customer SIEM.

Learn more

Microsoft 365 DKE

Double Key Encryption so Microsoft never holds the only usable key.

Learn more

AWS XKS / BYOK / HYOK

External key store patterns that keep trusted storage where the entity decides, including inside the Kingdom.

Learn more

Certificate management

Internal CA with OCSP/CRL, or connectors to a designated national or commercial CA.

Learn more

Key themes

Where independent key control fits

P controls are CSP; T controls are tenant. Agree the split at contract stage. Do not claim blanket NCS ADVANCED conformance in a bid without checking asymmetric and hash parameters.

2-15-P/T-3-1 Key ownership

Every key carries an owner and a tenant. Ownership is an auditable field, not a convention.

Relevant products

2-15-T-3-2 Trusted store external to cloud

Key material held outside the cloud application (DKE, BYOK/HYOK, external DB key stores), including in-Kingdom custody.

2-15-P-3-3 Key audit trails

Key operations on the same tamper-evident, hash-chained trail as the rest of the platform, forwarded to the customer SIEM.

Relevant products

2-7 Strong encryption (NCS ADVANCED)

AES-256-GCM meets ADVANCED symmetric. Map key inventory line by line to the NCS level claimed; do not over-claim.

Relevant products

2-7-P-1-2 Certification authority

Internal CA with OCSP and CRL, enrolment over ACME, EST, SCEP and CMP, or connectors to an external designated CA.

Relevant products

2-6 Exit and secure disposal

Key destruction is an audited operation. Destroying the key is the cleanest proof of disposal for data the entity cannot physically reach.

Relevant products

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.