Requirements
What the regulation expects

Data-lifecycle controls from November 2022
Four domains including third-party and cloud computing cybersecurity.
Third-party and cloud data paths
When data sits with a processor or cloud host, key custody decides whether the contract is the only control.
Classification-aligned protection
Encryption and key policy should track data classification, not a single default for every store.
Exit and unusable return
Destroying or retaining entity keys determines whether returned cloud data remains usable after contract end.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
One approved key catalogue and lifecycle model for systems that hold classified data.
Learn moreKey themes
Where independent key control fits
Use the official NCA DCC PDF for control wording. The mappings below describe how a KMS contributes; they are not a substitute for the control text.
Cryptographic protection of data
Entity-held keys and an approved type catalogue so encryption tracks classification and policy, not provider defaults.
Third-party and cloud computing
External key custody (DKE, BYOK, HYOK, XKS) so the processor or host works on ciphertext it cannot unilaterally read.
Lifecycle and exit
Documented key states, backup/recovery per custody model, and audited destruction tied to terminated services.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
