DuoKey

Data Encryption for DORA Compliance

Meet DORA's expectations for encryption and key management with keys your organisation controls—not only encryption toggles in the cloud.

Who it is for

Financial entities that must prove ICT key custody

Built for banks, insurers and other DORA-scoped organisations whose critical data sits in hyperscale cloud and SaaS.

01

ICT risk and outsourcing owners

Need to show that cloud or SaaS access does not equal plaintext access to critical data.

02

CISO and crypto architecture

Need one custody model across Microsoft 365, AWS, secrets platforms and databases.

03

Compliance and audit

Need evidence of who can unlock data, under which policy, for supervisors and internal audit.

Articles 9–13

DORA ICT security focus areas where encryption and key management support confidentiality and integrity

Customer-controlled keys

Custody outside the cloud operator so encryption measures are yours to govern and evidence

One programme

Same custody idea across M365, AWS XKS, OpenBAO/Vault, SQL and ServiceNow

What DORA changes for encryption

What DORA changes for encryption

The Digital Operational Resilience Act (DORA - EU Regulation 2022/2554) and its delegated act raise expectations for ICT security. Encryption matters; who controls the keys determines whether that control is real or delegated to the cloud operator.

Financial entities must protect confidentiality and integrity of data and systems, manage third-party ICT risk, and produce evidence for testing and incidents. Customer-controlled keys close the gap when data sits in vendor environments.

How it works

Apply customer-controlled keys where critical data already lives

DuoKey connects to each platform’s supported external-key or customer-key path. You keep the applications; you move decryption authority.

Microsoft 365

Microsoft 365

Double Key Encryption and Customer Key so Microsoft cannot unlock regulated collaboration content alone.

AWS External Key Store

AWS External Key Store

Keep KMS APIs in applications while cryptographic operations run in an external key store outside Amazon.

OpenBAO + SD-HSM

OpenBAO + SD-HSM

Vault-compatible secrets management with MPC auto-unseal instead of a single physical unseal HSM dependency.

SQL and ServiceNow

SQL and ServiceNow

External key management for SQL Server EKM and ServiceNow CLE / Edge Encryption for operational and structured data.

What changes for your DORA programme

Outcomes tied to ICT risk, outsourcing and evidence—not generic security slogans.

  • Provable separation from the operator

    Show that a provider compromise or lawful access channel at the operator does not automatically mean plaintext access to your data.

  • Mapped product path

    Concrete integrations for M365, AWS, OpenBAO, SQL and ServiceNow instead of a single abstract KMS slide.

  • Evidence for auditors

    Key use, approval and custody that you govern and can produce in ICT risk and outsourcing reviews.

Next step

Still weighing the control model?

Bring the constraint. We’ll map the shortest practical path.

Map your DORA product path

Review the DORA compliance page and product integrations for your estate, or schedule a scoped architecture discussion.