Skip to the main content.

7 min read

DORA Audit Readiness: Cryptographic Controls, Key Management & Evidence

DORA Audit Readiness: Cryptographic Controls, Key Management & Evidence

Most financial institutions already encrypt sensitive data. Increasingly, that's not what regulators are questioning.

Under the Digital Operational Resilience Act (DORA), the challenge is proving that cryptographic controls are governed, documented and resilient throughout their lifecycle. Strong encryption is expected. Demonstrable control is what supervisors want to see.

Since DORA became fully applicable in January 2025, financial entities have moved beyond implementation projects and into ongoing supervisory oversight. Auditors are no longer asking whether cryptographic controls exist. They are asking organisations to demonstrate where cryptographic assets are, who owns them, how they are protected, how changes are managed and how evidence is maintained over time.

This shift moves cryptography beyond infrastructure and into governance. Organisations that can demonstrate visibility, lifecycle control and crypto-agility will be significantly better prepared for both regulatory inspections and future cryptographic change.

What You’ll Learn:

  • What DORA Articles 6 and 7 require from your cryptographic key lifecycle.
  • Why a Cryptographic Bill of Materials (CBOM) has become a key audit artefact.
  • How algorithm agility supports both operational resilience and post-quantum readiness.
  • What evidence auditors expect for cryptographic governance.
  • The documentation gaps that most commonly delay supervisory audits.

Why Do Cryptographic Controls Sit At The Centre Of A DORA Audit?

DORA audits do not simply verify that encryption is enabled. They assess whether cryptographic controls are governed, documented, monitored and supported by evidence. Supervisors want proof that organisations understand where cryptography is used, how it is managed and how it can be adapted as risks evolve.

Financial institutions depend on cryptography to secure payment systems, customer authentication, digital identities, software integrity and sensitive data. Weak governance over these controls can introduce operational resilience risks, even where encryption itself is technically sound.

Which Entities and Articles Apply?

The relevant DORA technical standards sit within Commission Delegated Regulation (EU) 2024/1774. Article 6 requires financial entities to develop, document and implement a policy on encryption and cryptographic controls, based on approved data classification and ICT risk assessment. Article 7 then sets out the operational requirements for cryptographic key management, including lifecycle controls, protection against loss or unauthorised access, contingency methods for compromised keys, and an up-to-date register of certificates and certificate-storing devices for ICT assets supporting critical or important functions.

What “Undocumented Controls Are Treated As Absent” Means

One of the most common causes of audit findings is not weak security, it is weak evidence.

During a supervisory review, organisations are expected to demonstrate how cryptographic controls operate in practice. Policies alone are not enough. Auditors want supporting evidence such as asset inventories, lifecycle records, access logs, certificate registers and change histories.

Pro Tip: Ask yourself: Could you hand a supervisor proof of this control today, not simply the policy describing it? If not, you've identified your audit gap.

Building A Complete Cyrptographic Asset Inventory

A Cryptographic Bill of Materials (CBOM) is a continuously maintained inventory of an organisation's cryptographic assets, including certificates, cryptographic keys, algorithms, protocols, cryptographic libraries and their relationships to business systems.

A CBOM gives organisations the visibility needed to understand where cryptography exists, assess exposure to vulnerabilities and demonstrate governance during regulatory reviews.

Rather than spending weeks manually gathering evidence before an audit, organisations with a mature CBOM can answer supervisory questions quickly and confidently.

Cryptomathic CrystalKey 360 helps regulated organisations centralise cryptographic governance and lifecycle automation across supported HSMs, cloud platforms, key stores, payment environments and cryptographic services. This supports clearer ownership, more consistent policy enforcement, better evidence collection and a more controlled operating model across hybrid estates.

Mapping Certificates, Keys & Algorithms

A comprehensive inventory should identify every production certificate, cryptographic key, algorithm, key length and cryptographic dependency across cloud, on-premises and hybrid environments.

This visibility enables organisations to answer critical audit questions such as:

  • Which certificates expire in the next 90 days?
  • Which systems still rely on legacy algorithms?
  • Which business services depend on a specific cryptographic key?
  • Which applications would be affected by a newly disclosed cryptographic vulnerability?

Connecting Cryptography To Business Services

Knowing where cryptographic assets exist is only part of the picture. Organisations should also link assets to business services, data classifications and system owners. This enables risk-based prioritisation and demonstrates that cryptographic governance supports operational resilience rather than existing as an isolated security function.

Reality Check: If your team cannot identify every production certificate, the business service it protects and its renewal date within minutes, your cryptographic governance is unlikely to satisfy a detailed supervisory review.

Key Management Lifecycle: What Does DORA Article 7 Demand?

Article 7 focuses on whether organisations can demonstrate effective control of cryptographic keys throughout their full lifecycle, not merely where those keys are stored.

Auditors typically expect documented processes covering key generation, renewal, storage, backup, archiving, retrieval, transmission, retirement, revocation and destruction, together with evidence that those controls protect keys against loss, unauthorised access, disclosure and modification.

Certificate management is also explicitly part of the Article 7 expectation. Financial entities must maintain an up-to-date register of certificates and certificate-storing devices for at least ICT assets supporting critical or important functions, and ensure certificates are renewed before expiry.

Documented, Board-Approved Procedures

Key management policies should clearly define ownership, responsibilities, approval processes and operational controls. These documents should be reviewed regularly and supported by evidence showing that procedures are followed in day-to-day operations.

Centralised Control With KMS & HSMs

A central control layer for cryptographic governance, lifecycle workflows and evidence collection can improve consistency across distributed environments. CrystalKey 360 is designed to operate across supported HSMs, cloud platforms, key stores, payment environments and cryptographic services, helping organisations reduce fragmented processes without forcing a rip-and-replace approach.

This matters because many regulated organisations now operate multiple HSMs, cloud key stores, payment-key workflows and application-specific cryptographic services. A more unified operating model helps standardise approvals, automate lifecycle tasks through API-based integrations and collect audit evidence across supported environments.

Least Privilege & Just-In-time Adminstration

Administrative access to cryptographic management platforms should follow least privilege principles, with privileged access granted only when required and fully recorded. Strong segregation of duties reduces operational risk while providing the audit evidence supervisors increasingly expect.

Pro Tip: If replacing your HSM vendor would require rewriting your entire key management process, you've created an operational resilience risk, not simply a technology dependency.

What Are The Data Confidentiality & Integrity Requirements Under Article 6?

Article 6 requires financial entities to develop, document and implement a policy on encryption and cryptographic controls as part of their broader ICT security framework. That policy should be based on approved data classification and ICT risk assessment, and should address encryption of data at rest and in transit, data in use where necessary, internal network connections, external communications and cryptographic key management.

Modern Encryption Standards

Although DORA does not prescribe specific algorithms, organisations should align with recognised standards and current best practice, including protocols such as TLS 1.3 and strong encryption algorithms such as AES-256 where appropriate. Cryptographic standards should be reviewed regularly as recommendations evolve.

Tamper-Proof Audit Trails

Audit logs are themselves critical evidence during a DORA inspection. Protecting them using cryptographic hashing, digital signatures and integrity verification mechanisms helps demonstrate that security events have not been altered, supporting both regulatory investigations and incident response.

Algorithm Agility & Post-Quantum Readiness

DORA does not currently require organisations to implement post-quantum cryptography. It does, however, require financial entities to manage evolving ICT risks and to update cryptographic technology as cryptanalysis and industry practice evolve.

That makes crypto-agility - the ability to replace cryptographic algorithms, certificates and keys without major operational disruption - a strategic capability rather than simply a future technology project.

Institutions that build visibility, ownership, lifecycle control, automation and evidence into their cryptographic operating model will be better positioned for future regulatory change, emerging threats and the staged transition to post-quantum cryptography.

Aligning With Recognised Standards

Cryptographic algorithms and key lengths should align with recognised guidance such as NIST, while governance processes should ensure that cryptographic policies evolve alongside industry recommendations.

Managing Legacy Systems

Not every critical system can immediately adopt newer cryptographic standards. Where legacy systems remain in operation, organisations should document compensating controls, migration plans and risk acceptance decisions. This demonstrates governance maturity and provides supervisors with evidence that known risks are actively managed.

Resilience Testing & Incident Traceability

Strong cryptographic governance requires continual validation.

Financial institutions should regularly test encryption, authentication and certificate management controls, validate key replacement procedures and demonstrate that certificate revocation and renewal processes function correctly.

Certificate failures affecting critical or important functions may contribute to reportable ICT incidents under DORA, depending on their operational impact. Maintaining complete audit trails enables organisations to investigate incidents quickly, demonstrate accountability and support regulatory reporting decisions.

The Most Common Evidence Gap Auditors Find

The biggest weakness auditors encounter is rarely poor cryptography.

It is poor documentation.

Many organisations have robust technical controls but struggle to demonstrate ownership, lifecycle governance, certificate management or operational processes when evidence is requested.

Before your next audit, ask yourself:

  • Can we produce a current inventory of all cryptographic assets?
  • Can we identify every production certificate and its owner?
  • Can we demonstrate the lifecycle of every production key?
  • Can we prove who accessed key management systems and why?
  • Can we identify systems affected by a newly discovered cryptographic vulnerability?

If any answer is "no", your audit readiness may need strengthening.

Conclusion

DORA has fundamentally changed how financial institutions are expected to manage cryptography.

Success is no longer measured solely by the strength of encryption algorithms or the security of Hardware Security Modules. Increasingly, it is measured by an organisation's ability to demonstrate visibility, governance and control across its entire cryptographic estate.

Institutions that invest in accurate cryptographic inventories, mature key lifecycle management and crypto-agile architectures will not only reduce audit preparation effort but also strengthen their resilience against future regulatory requirements, evolving cyber threats and the transition to post-quantum cryptography.

Cryptography is no longer judged solely by the strength of its algorithms. It is judged by the strength of the governance surrounding them.

Preparing for a DORA audit starts with understanding your cryptographic estate. Speak to a Cryptomathic security expert about assessing your cryptographic governance, key lifecycle controls and evidence model against DORA Articles 6 and 7, and discover how CrystalKey 360 can help improve visibility, lifecycle automation, auditability and crypto-agility across supported cryptographic environments.


FAQs

What does DORA Article 7 require for cryptographic key managegement?

Article 7 requires organisations to define and operate controls for the full cryptographic key lifecycle, including generation, renewal, storage, backup, archiving, retrieval, transmission, retirement, revocation and destruction. It also requires controls to protect keys from loss, unauthorised access, disclosure and modification, methods for replacing compromised or damaged keys, and an up-to-date register of certificates and certificate-storing devices for at least ICT assets supporting critical or important functions.

What is a Cyrptographic Bill of Materials (CBOM) and why does DORA audit readiness need one?

A Cryptographic Bill of Materials (CBOM) is a central inventory of cryptographic assets, including certificates, keys, algorithms and cryptographic libraries. It provides the visibility needed to identify risk, support operational resilience and quickly produce evidence during supervisory audits.

Does DORA require post-quantum cryptography today?

No. DORA does not currently mandate post-quantum cryptography. However, it requires organisations to manage evolving ICT risks, making crypto-agility and the ability to transition to future cryptographic standards increasingly important.

How long must audit trail data be retained under DORA?

DORA requires organisations to retain sufficient audit evidence to support operational resilience, supervisory reviews and incident investigations. Retention periods should align with applicable regulatory requirements, organisational policies and national legislation.