DuoKey
Compliance

NCA ECC-2:2024

Saudi national baseline cybersecurity controls. Cryptography, IAM, logging and cloud hosting that a KMS can evidence.

Requirements

What the regulation expects

The Essential Cybersecurity Controls (ECC-2:2024) are the NCA national baseline for government entities and private-sector operators of Critical National Infrastructure. Control text quoted in bids should come from the official Public / TLP White document. DuoKey contributes where a key management platform can enforce policy, lifecycle, audit and cloud key custody, not where the entity still needs organisational process alone.
What the regulation expects

National baseline for government and CNI

Four domains and 29 subdomains. Cryptography (2-8), IAM (2-2), event logs (2-12) and cloud hosting (4-2) decide most KMS scopes.

Cryptography as enforced configuration

2-8 requires approved crypto requirements to be identified, documented, approved and implemented. A catalogue that rejects unapproved key types is the practical answer.

Key lifecycle under 2-8-3-2

Secure management across the lifecycle. Pre-Active, Active, Deactivated and Compromised states with enforced transitions, Compromised terminal.

Cloud hosting without provider-held keys

4-2 expects classification-aligned protection and usable return of data on exit. Entity-held keys make returned ciphertext useless to the provider alone.

Evidence the assessor can take

Key inventory, tamper-evident audit trail, posture reports and access review output produced by the platform, not written for the occasion.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

Approved key types per vault and tenant, NIST-style key states, exportable inventory for ECC evidence packs.

Learn more

Microsoft 365 Customer Key & DKE

Keep master keys outside Microsoft administrative custody for regulated mail and files.

Learn more

AWS XKS / cloud BYOK

Bind cloud encryption to keys held outside the provider trust boundary.

Learn more

SQL & database encryption

Oracle TDE, SQL Server EKM and KMIP consumers under the same vault policy.

Learn more

Key themes

Where independent key control fits

Only subdomains a key management platform materially contributes to are listed. Quote control text from the official ECC-2:2024 document when scoping a bid.

2-8-1 / 2-8-2 Cryptography requirements

Identify, document, approve and implement crypto requirements. DuoKey turns approved key types, sizes and usages into enforced vault configuration; creation outside that set is rejected.

Relevant products

2-8-3-1 Approved cryptographic systems

One catalogue of approved key types across software vault, MPC, PKCS#11 HSMs and major cloud KMS backends, with FIPS flags carried per type.

Relevant products

2-8-3-2 Key lifecycle management

NIST SP 800-57 style states with enforced transitions. Compromised is terminal. Activity log covers create, activate, rotate, deactivate, revoke and destroy.

Relevant products

2-8-3-3 Encryption in transit and at rest

AES-256-GCM for material at rest, TLS on service paths, integrations (M365 DKE, TDE, EKM, KMIP, PKCS#11, BYOK) extend the same keys to data systems.

2-8-4 Periodic crypto review

Scheduled posture scans, Quantum Risk Score reporting, certificate expiry checks and privilege-creep audits replace a once-a-year project.

Relevant products

2-2 Identity and access management

MFA (TOTP, WebAuthn, client certs), leaf-level permissions, JIT elevation and scheduled access reviews map to 2-2-3-2 through 2-2-3-5.

Relevant products

2-12 Event logs and monitoring

HMAC-signed audit log plus hash-chained activity log, SIEM forwarders (Splunk HEC, syslog), retention policy owned by the operator.

Relevant products

4-2 Cloud computing and hosting

Entity-held keys mean provider-returned data is usable only with the entity's material. Exit exports keys and config in standard formats.

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.