Always keep two sets of DNSSEC keys Resolvers at ISPs and other organizations already cache DNS records for performance reasons and this practice will not change with the introduction of DNSSEC. You need to ensure that cached, signed data about your zone remains validatable even during and immediately after a key rollover.