DuoKey
Compliance

NCA DCC-1:2022

Data Cybersecurity Controls. Lifecycle, third-party and cloud controls. Quote control text from the official PDF, not from summaries.

Requirements

What the regulation expects

DCC-1:2022 is the NCA data cybersecurity control set. The official PDF distributes control text as page images, so quote from the source when scoping rather than from a secondary summary. DuoKey's contribution is the same as under ECC and CCC: customer-held keys, enforced lifecycle, and evidence the assessor can take. Cross-reference ECC 2-8 / CCC 2-15 for cryptography and key management detail.
What the regulation expects

Data-lifecycle controls from November 2022

Four domains including third-party and cloud computing cybersecurity.

Third-party and cloud data paths

When data sits with a processor or cloud host, key custody decides whether the contract is the only control.

Classification-aligned protection

Encryption and key policy should track data classification, not a single default for every store.

Exit and unusable return

Destroying or retaining entity keys determines whether returned cloud data remains usable after contract end.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

One approved key catalogue and lifecycle model for systems that hold classified data.

Learn more

Cloud BYOK / XKS / DKE

Keep trusted key storage outside the application provider.

Learn more

Microsoft 365 DKE

Double key encryption for high-classification content.

Learn more

Key themes

Where independent key control fits

Use the official NCA DCC PDF for control wording. The mappings below describe how a KMS contributes; they are not a substitute for the control text.

Cryptographic protection of data

Entity-held keys and an approved type catalogue so encryption tracks classification and policy, not provider defaults.

Relevant products

Third-party and cloud computing

External key custody (DKE, BYOK, HYOK, XKS) so the processor or host works on ciphertext it cannot unilaterally read.

Lifecycle and exit

Documented key states, backup/recovery per custody model, and audited destruction tied to terminated services.

Relevant products

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.