Just Published: PCI Key Management and Operations (KMO)™ Standard v1.0

By Alicia Malone

Just Published: PCI Key Management and Operations (KMO)™ Standard v1.0


The PCI Security Standards Council (PCI SSC) has published a new standard designed for entities involved in the use of cryptographic keys. The Payment Card Industry (PCI) Key Management and Operations (KMO)™ Standard v1.0 defines security requirements, test requirements, and guidance for entities involved in the operation and management of systems that use cryptographic keys for the security of account data.

PCI KMO requirements cover the entire lifecycle of a cryptographic key, from generation through to destruction, as well as the security of procedures, systems, and equipment used to manage and operate those keys during their lifecycle.

The PCI KMO Standard is intended to address the generic key management requirements for other PCI Standards and Programs. Therefore, the scope includes keys that are used to secure PINs, account data, and other sensitive assets (including other cryptographic keys used as storage, transport, or derivation keys).

The initial focus of PCI KMO is to address the key management requirements for the secure handling of PIN and P2PE keys and data types; consolidating, aligning, and updating those requirements. This allows for a single PCI KMO assessment to validate the security for both key types, with the resultant KMO Listing able to be referenced by a PCI P2PE implementation (where appropriate).

PCI KMO also directly addresses the use of cloud-based and remote HSMs and has been created in alignment with the recently published PCI HSM v5 requirements.

Future revisions of PCI KMO may address additional specific needs of other data types such as those covered by the PCI Card Production Standards. 

PCI KMO is intended as a single source for requirements covering key management operations, which support different key data types, and key management aspects. It includes data-specific requirements where appropriate. It is designed to be modular and support an “assess-once-use-many” approach.

The following documents are now available in the PCI SSC Document Library: 

The PCI Key Management and Operations (KMO)™ Assessor Qualification Requirements are expected to be available soon.

Download the Key Management and Operations Standard v1.0