Requirements
What the regulation expects

Control catalogue for US federal and contractors
SP 800-53 is the reference many baselines and FedRAMP-style questionnaires still cite.
Cryptography and key management families
SC and related controls for encryption, key establishment, and protection of key material.
Audit and access
AU and AC/IA controls for logging key operations and restricting who can use privileged cryptographic functions.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Enforced key policy, lifecycle, access matrix and tamper-evident logs for control implementations.
Learn moreFIPS-validated backends
Route operations through FIPS-validated components where the baseline requires it.
Learn moreAWS XKS
External key store so cloud encryption keys stay outside the provider trust boundary.
Learn moreKey themes
Where independent key control fits
Representative control areas only. Bind each response to the customer's baseline and overlays.
Cryptographic protection (SC family)
Encryption at rest and in transit with approved algorithms; key material held under customer or programme custody.
Key management
Generation, distribution, storage, rotation, revocation and destruction with inventory and state history.
Identification and authentication
MFA for privileged access, federation options and per-key authorization checks.
Audit and accountability
HMAC-signed audit log and hash-chained activity log for cryptographic and administrative events.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
