DuoKey
Compliance

NIST PQC (CSWP 48)

Map DuoKey crypto posture and migration tooling to NIST CSF 2.0 and SP 800-53 using NIST CSWP 48 PQC migration guidance.

Requirements

What the regulation expects

NIST CSWP 48 provides official guidance for mapping Migration to PQC Project capabilities to NIST Cybersecurity Framework 2.0 and SP 800-53. DuoKey CPM (crypto posture / formerly PQC Scanner) supports inventory, vulnerability identification and risk prioritisation that line up with those mappings. Use the mapping to justify PQC readiness spend. Do not invent coverage percentages that are not tied to a current assessment.
What the regulation expects

Official mapping for PQC migration capabilities

NIST CSWP 48 (initial public draft, September 2025) maps PQC migration work to CSF 2.0 and SP 800-53.

Identify before you migrate

Hardware, software/services and data/metadata inventory of cryptography actually in use.

Protect while you transition

Data-at-rest and data-in-transit protection, plus identity and authentication controls that must stay crypto-agile.

Solutions

How DuoKey supports the framework

Quantum readiness / CPM

CBOM-style inventory, Quantum Risk Score and dated remediation plans against a jurisdiction profile.

Learn more

OpenBAO + DuoKey SD-HSM

Approved key type catalogue and lifecycle so migration is enforced configuration, not a one-off project.

Learn more

Certificate management

Inventory, expiry and enrolment protocols in the same console as key management.

Learn more

Key themes

Where independent key control fits

Based on NIST CSWP 48 mappings of PQC migration capabilities to CSF 2.0 and SP 800-53. Coverage depends on the customer's assessment scope.

ID.AM-01 / ID.AM-02 Inventory

Hardware and software/services cryptographic inventory from posture scans and platform CBOM output.

Relevant products

ID.AM-07 Data and metadata inventory

Inventory of keys, certificates and algorithms protecting data stores and services.

ID.RA-01 / ID.RA-05 Risk

Vulnerability identification and risk prioritisation via Quantum Risk Score and dated remediation plans.

Relevant products

PR.DS-01 / PR.DS-02 Data protection

Data-at-rest and data-in-transit protection with customer-held keys; transit protection fully supported today, at-rest migration depends on workload cutover.

GV.PO-01 / PR.AA policy and identity

Cryptographic policy as enforced catalogue; identity and authentication factors on the KMS plane. Partial where enterprise IAM remains outside DuoKey.

Relevant products

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.