DuoKey
Conformité

Répondre aux exigences réglementaires sans abandonner le contrôle des clés.

DuoKey aide les équipes régulées à conserver l’autorité de chiffrement indépendamment des fournisseurs cloud.

Cadres

Clés contrôlées par le client, par réglementation

Le chiffrement cloud n’est solide que si la garde des clés l’est aussi. DuoKey soutient les preuves attendues par les régulateurs.

Région

UAE

ADHICS v2

Abu Dhabi Healthcare Information and Cyber Security Standard. CS 1.2 says the cloud provider must not store or control the entity's keys.

Lire le guide
UAE

CBUAE

Central Bank of the UAE IT risk and information security standards for licensed financial institutions. Cryptography, key management and outsourcing.

Lire le guide
Certifications

Common Criteria

International IT security evaluation standard. DuoKey architecture follows Common Criteria security functional requirements.

Lire le guide
UAE

DESC Dubai

Dubai Electronic Security Center information security regulation for Dubai Government entities, critical sectors and contracted IT/cloud suppliers.

Lire le guide
Europe

DORA

ICT risk management and resilience for the EU financial sector, with encryption and keys you can prove you control.

Lire le guide
Switzerland

Swiss FADP (nFADP)

The revised Federal Act on Data Protection, security by design, data sovereignty and defensible technical measures.

Lire le guide
Certifications

FIPS 140-2/3

Federal Information Processing Standard for cryptographic modules. DuoKey uses FIPS-validated cryptographic components.

Lire le guide
Europe

GDPR

Article 32 security, breach risk and transfers, encryption that is meaningful because you hold the keys.

Lire le guide
United States

HIPAA

Technical safeguards for ePHI, encryption and key management you can stand behind in a BA audit.

Lire le guide
Certifications

ISO 27001

International standard for information security management systems. DuoKey is ISO/IEC 27001 certified.

Lire le guide
Saudi Arabia

NCA CCC-1:2020

Cloud Cybersecurity Controls for KSA. Provider vs tenant split, and 2-15 Key Management that decides most KMS deals.

Lire le guide
Saudi Arabia

NCA DCC-1:2022

Data Cybersecurity Controls. Lifecycle, third-party and cloud controls. Quote control text from the official PDF, not from summaries.

Lire le guide
Saudi Arabia

NCA ECC-2:2024

Saudi national baseline cybersecurity controls. Cryptography, IAM, logging and cloud hosting that a KMS can evidence.

Lire le guide
Saudi Arabia

NCA NCS-1:2020

National Cryptographic Standards. MODERATE and ADVANCED strength levels, plus the key lifecycle section ECC and CCC point to.

Lire le guide
Europe

NIS2

Network and information security for essential and important entities, encryption and keys you govern, not just a checkbox.

Lire le guide
United States

NIST SP 800-53

US federal security and privacy control catalogue. Map DuoKey key management and crypto controls into your baseline.

Lire le guide
United States

NIST PQC (CSWP 48)

Map DuoKey crypto posture and migration tooling to NIST CSF 2.0 and SP 800-53 using NIST CSWP 48 PQC migration guidance.

Lire le guide
Certifications

PCI DSS

Payment Card Industry Data Security Standard. Key custody, split knowledge and encryption for account data environments.

Lire le guide
Saudi Arabia

SAMA CSF

Saudi Central Bank Cyber Security Framework. Mandatory for member organisations. 3.3.9 Cryptography and 3.3.5 IAM are the KMS buy triggers.

Lire le guide
Saudi Arabia

SDAIA PDPL

Saudi Personal Data Protection Law and its regulations. Key location becomes a legal question, not only an architecture preference.

Lire le guide
Certifications

SOC 2 Type II

Trust service criteria for security, availability, processing integrity, confidentiality and privacy. DuoKey is SOC 2 Type II aligned.

Lire le guide
UAE

TDRA UAE IA Regulation

Federal Information Assurance Regulation. Cryptography in T7.4, key management in T7.4.2. Successor to NESA IAS.

Lire le guide
Certifications

TISAX

Trusted Information Security Assessment Exchange for automotive. Assessment Level 3 (AL3) certified.

Lire le guide
UAE

UAE PDPL

Federal Decree-Law No. 45 of 2021 on personal data protection. Security measures and cross-border transfer, with customer-held keys as architecture not legal conclusion.

Lire le guide

Parlons des décisions qui comptent pour votre programme de sécurité.

Dites-nous où le contrôle est difficile aujourd’hui. Nous vous aiderons à définir une prochaine étape concrète.