Requirements
What the regulation expects

Official mapping for PQC migration capabilities
NIST CSWP 48 (initial public draft, September 2025) maps PQC migration work to CSF 2.0 and SP 800-53.
Identify before you migrate
Hardware, software/services and data/metadata inventory of cryptography actually in use.
Protect while you transition
Data-at-rest and data-in-transit protection, plus identity and authentication controls that must stay crypto-agile.
Solutions
How DuoKey supports the framework
Quantum readiness / CPM
CBOM-style inventory, Quantum Risk Score and dated remediation plans against a jurisdiction profile.
Learn moreOpenBAO + DuoKey SD-HSM
Approved key type catalogue and lifecycle so migration is enforced configuration, not a one-off project.
Learn moreCertificate management
Inventory, expiry and enrolment protocols in the same console as key management.
Learn moreKey themes
Where independent key control fits
Based on NIST CSWP 48 mappings of PQC migration capabilities to CSF 2.0 and SP 800-53. Coverage depends on the customer's assessment scope.
ID.AM-01 / ID.AM-02 Inventory
Hardware and software/services cryptographic inventory from posture scans and platform CBOM output.
ID.AM-07 Data and metadata inventory
Inventory of keys, certificates and algorithms protecting data stores and services.
ID.RA-01 / ID.RA-05 Risk
Vulnerability identification and risk prioritisation via Quantum Risk Score and dated remediation plans.
PR.DS-01 / PR.DS-02 Data protection
Data-at-rest and data-in-transit protection with customer-held keys; transit protection fully supported today, at-rest migration depends on workload cutover.
GV.PO-01 / PR.AA policy and identity
Cryptographic policy as enforced catalogue; identity and authentication factors on the KMS plane. Partial where enterprise IAM remains outside DuoKey.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
