Requirements
What the regulation expects

The algorithm list ECC and CCC reference
Two strength levels, MODERATE (128-bit) and ADVANCED (256-bit), plus a full key lifecycle management section.
Generation without weak keys
Keys must not be vulnerable to prediction or bias. Generation inside the selected backend with an approved type catalogue.
Sole control where required
Non-repudiation keys must remain under the sole control of the user. Custody model is a deliberate per-vault choice.
Archive vs destroy
Deactivated keys stay available for decrypt and verify while refused for new encryption. Destruction is an explicit audited state change.
Accounting for asymmetric keys
Inventory is the account; activity trail is the usage record. Both exportable for the audit period.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Generation in HSM, MPC or software vault; enforced states; exportable inventory mapped to NCS levels.
Learn moreCertificate management
Key and binding certificate managed together; CRL and OCSP responders in the same platform.
Learn moreHSM-backed custody
Pin keys to Securosys or other PKCS#11 HSMs where export must never be allowed.
Learn moreKey themes
Where independent key control fits
Section 6 sets out the key lifecycle processes an entity must demonstrate. Only the product-shaped processes are listed below.
Key generation
Generation inside the selected backend with the approved key type catalogue constraining what can be created.
Registration and certification
Key management and certificate lifecycle on one platform so a key and its owner-binding certificate are one object.
Distribution and installation
Consuming systems reach keys over PKCS#11, KMIP or mutually authenticated REST, not by copying key files between hosts.
Key use and authorization
Every operation passes an authorization check bound to caller identity and the key's access policy, audited on success and failure.
Storage, archive and destruction
Custody per vault (software, MPC or HSM). Deactivated for archive-but-usable. Destruction audited; the record survives the key.
Revocation, validation and accounting
CRL and OCSP in-platform. Inventory and activity trail exportable as the accounting record for asymmetric keys and use.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
