DuoKey
Compliance

NCA NCS-1:2020

National Cryptographic Standards. MODERATE and ADVANCED strength levels, plus the key lifecycle section ECC and CCC point to.

Requirements

What the regulation expects

NCS-1:2020 is the algorithm and lifecycle standard that ECC and CCC point to. Section 6 (key lifecycle management) is the most product-shaped part of the Saudi framework. Map every key in inventory to the NCS level you claim. AES-256-GCM meets ADVANCED for symmetric use; asymmetric and hash parameters are a real constraint, address them under conformance boundaries rather than claiming blanket ADVANCED in a bid.
What the regulation expects

The algorithm list ECC and CCC reference

Two strength levels, MODERATE (128-bit) and ADVANCED (256-bit), plus a full key lifecycle management section.

Generation without weak keys

Keys must not be vulnerable to prediction or bias. Generation inside the selected backend with an approved type catalogue.

Sole control where required

Non-repudiation keys must remain under the sole control of the user. Custody model is a deliberate per-vault choice.

Archive vs destroy

Deactivated keys stay available for decrypt and verify while refused for new encryption. Destruction is an explicit audited state change.

Accounting for asymmetric keys

Inventory is the account; activity trail is the usage record. Both exportable for the audit period.

Solutions

How DuoKey supports the framework

OpenBAO + DuoKey SD-HSM

Generation in HSM, MPC or software vault; enforced states; exportable inventory mapped to NCS levels.

Learn more

Certificate management

Key and binding certificate managed together; CRL and OCSP responders in the same platform.

Learn more

HSM-backed custody

Pin keys to Securosys or other PKCS#11 HSMs where export must never be allowed.

Learn more

Key themes

Where independent key control fits

Section 6 sets out the key lifecycle processes an entity must demonstrate. Only the product-shaped processes are listed below.

Key generation

Generation inside the selected backend with the approved key type catalogue constraining what can be created.

Relevant products

Registration and certification

Key management and certificate lifecycle on one platform so a key and its owner-binding certificate are one object.

Distribution and installation

Consuming systems reach keys over PKCS#11, KMIP or mutually authenticated REST, not by copying key files between hosts.

Relevant products

Key use and authorization

Every operation passes an authorization check bound to caller identity and the key's access policy, audited on success and failure.

Relevant products

Storage, archive and destruction

Custody per vault (software, MPC or HSM). Deactivated for archive-but-usable. Destruction audited; the record survives the key.

Relevant products

Revocation, validation and accounting

CRL and OCSP in-platform. Inventory and activity trail exportable as the accounting record for asymmetric keys and use.

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.