Requirements
What the regulation expects

National baseline for government and CNI
Four domains and 29 subdomains. Cryptography (2-8), IAM (2-2), event logs (2-12) and cloud hosting (4-2) decide most KMS scopes.
Cryptography as enforced configuration
2-8 requires approved crypto requirements to be identified, documented, approved and implemented. A catalogue that rejects unapproved key types is the practical answer.
Key lifecycle under 2-8-3-2
Secure management across the lifecycle. Pre-Active, Active, Deactivated and Compromised states with enforced transitions, Compromised terminal.
Cloud hosting without provider-held keys
4-2 expects classification-aligned protection and usable return of data on exit. Entity-held keys make returned ciphertext useless to the provider alone.
Evidence the assessor can take
Key inventory, tamper-evident audit trail, posture reports and access review output produced by the platform, not written for the occasion.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Approved key types per vault and tenant, NIST-style key states, exportable inventory for ECC evidence packs.
Learn moreMicrosoft 365 Customer Key & DKE
Keep master keys outside Microsoft administrative custody for regulated mail and files.
Learn moreAWS XKS / cloud BYOK
Bind cloud encryption to keys held outside the provider trust boundary.
Learn moreSQL & database encryption
Oracle TDE, SQL Server EKM and KMIP consumers under the same vault policy.
Learn moreKey themes
Where independent key control fits
Only subdomains a key management platform materially contributes to are listed. Quote control text from the official ECC-2:2024 document when scoping a bid.
2-8-1 / 2-8-2 Cryptography requirements
Identify, document, approve and implement crypto requirements. DuoKey turns approved key types, sizes and usages into enforced vault configuration; creation outside that set is rejected.
2-8-3-1 Approved cryptographic systems
One catalogue of approved key types across software vault, MPC, PKCS#11 HSMs and major cloud KMS backends, with FIPS flags carried per type.
2-8-3-2 Key lifecycle management
NIST SP 800-57 style states with enforced transitions. Compromised is terminal. Activity log covers create, activate, rotate, deactivate, revoke and destroy.
2-8-3-3 Encryption in transit and at rest
AES-256-GCM for material at rest, TLS on service paths, integrations (M365 DKE, TDE, EKM, KMIP, PKCS#11, BYOK) extend the same keys to data systems.
2-8-4 Periodic crypto review
Scheduled posture scans, Quantum Risk Score reporting, certificate expiry checks and privilege-creep audits replace a once-a-year project.
2-2 Identity and access management
MFA (TOTP, WebAuthn, client certs), leaf-level permissions, JIT elevation and scheduled access reviews map to 2-2-3-2 through 2-2-3-5.
2-12 Event logs and monitoring
HMAC-signed audit log plus hash-chained activity log, SIEM forwarders (Splunk HEC, syslog), retention policy owned by the operator.
4-2 Cloud computing and hosting
Entity-held keys mean provider-returned data is usable only with the entity's material. Exit exports keys and config in standard formats.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
