Requirements
What the regulation expects

Requirements 3 and 4 still decide KMS deals
Stored account data and data in transit. Key management under 3.7 is where auditors dig in.
Split knowledge and dual control
MPC key shares and dual-control workflows support the spirit of split knowledge without spreadsheet ceremonies.
Evidence for QSAs
Key inventory, custodian records, rotation history and audit logs QSAs actually ask for.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Custodian-visible ownership, lifecycle states, dual-control style approvals and exportable inventory.
Learn moreDatabase and payment data encryption
External keys for stores that hold PAN or sensitive authentication data under the customer's CDE design.
Learn moreKey themes
Where independent key control fits
Map to the customer's PCI DSS version and ROC scope. Product evidence below covers cryptography and key management, not the full standard.
Encryption of stored account data
Strong encryption with keys outside the application trust boundary where the CDE design requires it.
Encryption in transit
TLS on service-to-service paths that carry or unwrap account data keys.
Key management (Req. 3.7)
Documented custodians, generation, distribution, storage, rotation, retirement and destruction with audit history.
Split knowledge / dual control
MPC shares and approval workflows so key-encrypting material is not under one person's sole control.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
