Requirements
What the regulation expects

Federal baseline for government and CII
Management families M1 to M6 and technical families T1 to T9. Cryptography sits in T7.4; key management in T7.4.2.
Crypto policy as enforced configuration
T7.4.1 expects a crypto policy reviewed at planned intervals. Approved key types that reject unapproved creation are the practical form.
Key generation and storage standards
T7.4.2 requires generation process and storing standards. Custody is a per-vault configuration, not a per-team habit.
Tamper-evident logs
T3.6.4 protects log information against tampering. Hash-chained trails and optional on-premise WORM mirror answer that directly.
Cloud requirements in agreements
T6.3 expects security requirements for cloud retention, processing and storage, governed through service agreements. External keys turn a contractual promise into a technical control.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Enforced key types, NIST-style states, vault inventory and SIEM-forwarded audit trail.
Learn moreAWS XKS / cloud BYOK
Key custody outside the cloud provider attached to the cloud risk assessment.
Learn moreKey themes
Where independent key control fits
Control text and numbering from UAE IA Regulation v1.1 on the TDRA website. Only controls a KMS materially contributes to are listed.
T7.4.1 Cryptographic controls policy
Approved key types, sizes and usages per vault and tenant; creation outside the set is refused. Dated posture reports for each review cycle.
T7.4.2 Key management
Generation in software vault, MPC or PKCS#11 HSM. Revoke/block via enforced states. Protect keys against modification, loss, unauthorized use and disclosure.
T3.6 Audit logging
HMAC-signed audit log and hash-chained activity log. Chain verification for T3.6.4. Administrator actions on the same trail (T3.6.5).
T5.2 Privileged access
Leaf-level permissions, MFA for admin access, logged administrative actions, and scheduled privilege-creep audits for T5.2.4.
T3.5.1 Backups
Tenant snapshot/restore for control plane; key backup follows the custody model so hardware-pinned keys stay non-exportable.
T6.3 Cloud security requirements
Holding the key outside the cloud application so the provider processes ciphertext it cannot unilaterally read.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
