NIS2 Encryption Requirements: What Enterprises Must Implement
Mar 12, 2025
ArticleNIS2 encryption and key-management expectations for essential and important entities, what supervisors look for beyond “data is encrypted.”
Read article
What DORA expects for encryption and key control: ICT risk, third-party concentration and evidence boards can defend, without surrendering keys to the cloud.
The EU Digital Operational Resilience Act (DORA) does not ask financial entities to “encrypt more.” It asks them to prove they can keep critical ICT services running and that third-party cloud and SaaS providers cannot silently become the single point of failure for the business.
For CISOs, CTOs and compliance leads, the practical question is narrower: who can unlock the data that keeps the franchise running and can you show that answer under stress?
DORA (Regulation (EU) 2022/2554) ties operational resilience to ICT risk management, incident reporting, resilience testing and oversight of critical ICT third-party providers. Encryption sits inside that story as a control on confidentiality, integrity, and, when keys are customer-held, concentration risk.
Boards and supervisors will not score you on algorithm fashion. They will ask:
DORA’s ICT risk framework expects proportionate cryptographic protection for data at rest and in transit, aligned with the sensitivity of the service. In regulated cloud deployments that usually means:
Where DORA’s third-party risk chapter bites hardest is concentration: if the same provider stores the data and holds the last encryption key, resilience language on the contract does not change the technical fact that one party can unlock production.
Customer-managed and dual-control key architectures (BYOK, HYOK, external key stores, double-key encryption) are how many firms shrink that concentration. The business outcome is simple:
DuoKey’s approach keeps key authority outside the operator using multi-party computation so no single vault, cloud account, or administrator holds a complete key, which maps cleanly to DORA’s insistence on reducing single points of failure in ICT supply chains.
When resilience testing or an ICT incident review asks for proof, thin policy PDFs fail. Useful artefacts include:
If those artefacts only exist inside the cloud provider’s console, you have outsourced the evidence as well as the infrastructure.
DORA will not be satisfied by a logo on a compliance slide. It will be satisfied by controls that keep the business able to operate and able to prove who held the last word on the keys.
Written by
DuoKey
Related Resources
Tell us where control is difficult today. We will help you identify a practical next step.