Requirements
What the regulation expects

ECC extended for cloud
Controls ending in P apply to the Cloud Service Provider; controls ending in T apply to the Cloud Service Tenant.
Trusted key store outside the cloud
2-15-T-3-2 demands secure retrieval if keys are lost, with trusted storage strictly external to the cloud application.
Ownership you can audit
2-15 requires well-defined ownership for cryptographic keys. Owner and tenant must be fields an auditor can read, not a spreadsheet convention.
NCS ADVANCED crypto strength
2-7 points at NCS-1:2020 ADVANCED. AES-256-GCM meets the symmetric bar; do not claim blanket ADVANCED for asymmetric and hash without checking the boundary.
Exit and disposal
2-6 exit strategy. Destroying the key renders provider-side ciphertext unusable when physical disposal is impossible.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Per-key owner and tenant, custody in software, MPC or HSM, activity trail forwarded to the customer SIEM.
Learn moreAWS XKS / BYOK / HYOK
External key store patterns that keep trusted storage where the entity decides, including inside the Kingdom.
Learn moreCertificate management
Internal CA with OCSP/CRL, or connectors to a designated national or commercial CA.
Learn moreKey themes
Where independent key control fits
P controls are CSP; T controls are tenant. Agree the split at contract stage. Do not claim blanket NCS ADVANCED conformance in a bid without checking asymmetric and hash parameters.
2-15-P/T-3-1 Key ownership
Every key carries an owner and a tenant. Ownership is an auditable field, not a convention.
2-15-T-3-2 Trusted store external to cloud
Key material held outside the cloud application (DKE, BYOK/HYOK, external DB key stores), including in-Kingdom custody.
2-15-P-3-3 Key audit trails
Key operations on the same tamper-evident, hash-chained trail as the rest of the platform, forwarded to the customer SIEM.
2-7 Strong encryption (NCS ADVANCED)
AES-256-GCM meets ADVANCED symmetric. Map key inventory line by line to the NCS level claimed; do not over-claim.
2-7-P-1-2 Certification authority
Internal CA with OCSP and CRL, enrolment over ACME, EST, SCEP and CMP, or connectors to an external designated CA.
2-6 Exit and secure disposal
Key destruction is an audited operation. Destroying the key is the cleanest proof of disposal for data the entity cannot physically reach.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
