Requirements
What the regulation expects

National baseline for government and CNI
Four domains and 29 subdomains. Cryptography (2-8), IAM (2-2), event logs (2-12) and cloud hosting (4-2) decide most KMS scopes.
Cryptography as enforced configuration
2-8 requires approved crypto requirements to be identified, documented, approved and implemented. A catalogue that rejects unapproved key types is the practical answer.
Key lifecycle under 2-8-3-2
Secure management across the lifecycle. Pre-Active, Active, Deactivated and Compromised states with enforced transitions, Compromised terminal.
Cloud hosting without provider-held keys
4-2 expects classification-aligned protection and usable return of data on exit. Entity-held keys make returned ciphertext useless to the provider alone.
Evidence the assessor can take
Key inventory, tamper-evident audit trail, posture reports and access review output produced by the platform, not written for the occasion.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
Approved key types per vault and tenant, NIST-style key states, exportable inventory for ECC evidence packs.
Learn moreMicrosoft 365 Customer Key & DKE
Keep master keys outside Microsoft administrative custody for regulated mail and files.
Learn moreAWS XKS / cloud BYOK
Bind cloud encryption to keys held outside the provider trust boundary.
Learn moreSQL & database encryption
Oracle TDE, SQL Server EKM and KMIP consumers under the same vault policy.
Learn moreKey themes
Where independent key control fits
Only subdomains a key management platform materially contributes to are listed.
2-8-1 / 2-8-2 Cryptography requirements
Identify, document, approve and implement crypto requirements. DuoKey turns approved key types, sizes and usages into enforced vault configuration; creation outside that set is rejected.
2-8-3-1 Approved cryptographic systems
One catalogue of approved key types across software vault, MPC, PKCS#11 HSMs and major cloud KMS backends, with FIPS flags carried per type.
2-8-3-2 Key lifecycle management
NIST SP 800-57 style states with enforced transitions. Compromised is terminal. Activity log covers create, activate, rotate, deactivate, revoke and destroy.
2-8-3-3 Encryption in transit and at rest
AES-256-GCM for material at rest, TLS on service paths, integrations (M365 DKE, TDE, EKM, KMIP, PKCS#11, BYOK) extend the same keys to data systems.
2-8-4 Periodic crypto review
Scheduled posture scans, Quantum Risk Score reporting, certificate expiry checks and privilege-creep audits replace a once-a-year project.
2-2 Identity and access management
MFA (TOTP, WebAuthn, client certs), leaf-level permissions, JIT elevation and scheduled access reviews map to 2-2-3-2 through 2-2-3-5.
2-12 Event logs and monitoring
HMAC-signed audit log plus hash-chained activity log, SIEM forwarders (Splunk HEC, syslog), retention policy owned by the operator.
4-2 Cloud computing and hosting
Entity-held keys mean provider-returned data is usable only with the entity's material. Exit exports keys and config in standard formats.
Parlons des décisions qui comptent pour votre programme de sécurité.
Dites-nous où le contrôle est difficile aujourd’hui. Nous vous aiderons à définir une prochaine étape concrète.
