DuoKey
Resources

Insights that help security teams make better decisions.

Guides, research and practical reads on data control, quantum readiness and AI governance.

Resources

45 resources

Switzerland Post-Quantum Cryptography Regulation: NCSC Guidance and FINMA 05/2026

Sep 04, 2026

Article

Switzerland has no single PQC statute. NCSC's technology briefs say start now; FINMA Guidance 05/2026 expects a board-backed roadmap by mid-2027, with inventory, crypto-agility and harvest-now-decrypt-later prioritisation.

Read article

NIS2 Crypto-Agility: What the Implementing Regulation Actually Requires

Sep 03, 2026

Article

What Commission Implementing Regulation (EU) 2024/2690 actually requires for cryptography and crypto-agility under NIS2, who it applies to, and what it leaves to member states.

Read article

Germany Post-Quantum Cryptography Regulation: What BSI TR-02102 Actually Requires

Sep 02, 2026

Article

BSI TR-02102-1 version 2026-01 names migration dates: classical-only key agreement ends 2031, high-protection systems by 2030, signatures by 2035. Here is who is in scope under BSIG and what to do first.

Read article

DORA Encryption Requirements: Technical Checklist (Articles 9-13)

Sep 01, 2026

Article

What DORA Articles 9-13 and the RTS on ICT risk management actually require for encryption, key management and crypto-agility, with a concrete technical checklist.

Read article

DORA encryption requirements: what financial firms must control

Aug 25, 2026

Article

What DORA expects for encryption and key control: ICT risk, third-party concentration and evidence boards can defend, without surrendering keys to the cloud.

Read article

How to Build a PQC Migration Roadmap and Where to Start

Jul 02, 2026

Article

Build a funded post-quantum migration roadmap: inventory crypto, rank business impact and sequence algorithm change without freezing delivery.

Read article

HashiCorp Vault and BSL 1.1: What It Means and What to Do About It

Apr 14, 2026

Article

Plan a Vault-to-OpenBao migration after HashiCorp BSL: keep the API, cut licensing cost and protect unseal keys with customer-held MPC.

Read article

Why Your Microsoft 365 Encryption Isn't Enough

Apr 01, 2026

Article

Why Microsoft 365 default encryption still leaves Microsoft able to unlock content and when Double Key Encryption or Customer Key becomes a board-level control.

Read article

Data Sovereignty for Enterprise SaaS: Microsoft 365, AWS & Customer-Managed Keys

Mar 24, 2026

Article

Data sovereignty in enterprise SaaS: how customer-managed keys for Microsoft 365 and AWS change who can be compelled to unlock your data.

Read article

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.

Resources | duokey