惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
L
LangChain Blog
aimingoo的专栏
aimingoo的专栏
IT之家
IT之家
B
Blog
博客园_首页
博客园 - 司徒正美
有赞技术团队
有赞技术团队
博客园 - 聂微东
I
InfoQ
美团技术团队
GbyAI
GbyAI
阮一峰的网络日志
阮一峰的网络日志
H
Help Net Security
大猫的无限游戏
大猫的无限游戏
MyScale Blog
MyScale Blog
WordPress大学
WordPress大学
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
人人都是产品经理
人人都是产品经理
Microsoft Azure Blog
Microsoft Azure Blog
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Cloudflare Blog

PCI Perspectives

The AI Exchange: Innovators in Payment Security Featuring Integrity360 Coffee with the Council Podcast: Celebrating 20 Years of Securing Payment Data The Quantum Leap: Preparing for Post Quantum Cryptography Featuring Futurex 2026 Asia-Pacific Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring GM Sectec Coffee with the Council Podcast: Meet This Year’s Europe Community Meeting Keynote Speaker, Ken Hughes Join Us at the Payment Industry Events of the Year Coffee with the Council Podcast: Meet This Year’s Asia-Pacific Community Meeting Keynote Speaker, CJ Meadows 2026 Europe Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring atsec Mapping PCI DSS v4.0.1 to the NIST Cybersecurity Framework 2.0 2026 North America Community Meeting Agenda Highlights Meet the Council’s New Head of Business Operations and Risk Management The AI Exchange: Innovators in Payment Security Featuring PCA Cyber Security Enhance Your Community Meeting Experience with Interactive Workshops The AI Exchange: Innovators in Payment Security Featuring PROSA Bring PCI SSC Training to Your Organization with the New Training Venue Host Program The AI Exchange: Innovators in Payment Security Featuring Utimaco Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Sharon Gai Welcome Our Newest Associate Participating Organizations The AI Exchange: Innovators in Payment Security Featuring SecurityMetrics PCI SSC Publishes New Guidance on Compensating Controls and the Customized Approach Spotlight On: Dreamplug Technologies Private Limited (CRED), a New Principal Participating Organization Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1 The AI Exchange: Innovators in Payment Security Featuring In-Solutions Global Ltd Coffee with the Council Podcast: Nominate Now for the Global Executive Assessor Roundtable (GEAR) PCI SSC Publishes PCI PTS HSM v5.0 Request for Comments: PCI Secure Software Lifecycle Standard v2.0 Spotlight On: Worldline, a New Principal Participating Organization Coffee with the Council Podcast: Stronger Together – The Value of Participating with PCI SSC
Just Published: PCI Key Management and Operations (KMO)™ ...
Alicia Malone · 2026-09-15 · via PCI Perspectives

The PCI Security Standards Council (PCI SSC) has published a new standard designed for entities involved in the use of cryptographic keys. The Payment Card Industry (PCI) Key Management and Operations (KMO)™ Standard v1.0 defines security requirements, test requirements, and guidance for entities involved in the operation and management of systems that use cryptographic keys for the security of account data.

PCI KMO requirements cover the entire lifecycle of a cryptographic key, from generation through to destruction, as well as the security of procedures, systems, and equipment used to manage and operate those keys during their lifecycle.

The PCI KMO Standard is intended to address the generic key management requirements for other PCI Standards and Programs. Therefore, the scope includes keys that are used to secure PINs, account data, and other sensitive assets (including other cryptographic keys used as storage, transport, or derivation keys).

The initial focus of PCI KMO is to address the key management requirements for the secure handling of PIN and P2PE keys and data types; consolidating, aligning, and updating those requirements. This allows for a single PCI KMO assessment to validate the security for both key types, with the resultant KMO Listing able to be referenced by a PCI P2PE implementation (where appropriate).

PCI KMO also directly addresses the use of cloud-based and remote HSMs and has been created in alignment with the recently published PCI HSM v5 requirements.

Future revisions of PCI KMO may address additional specific needs of other data types such as those covered by the PCI Card Production Standards. 

PCI KMO is intended as a single source for requirements covering key management operations, which support different key data types, and key management aspects. It includes data-specific requirements where appropriate. It is designed to be modular and support an “assess-once-use-many” approach.

The following documents are now available in the PCI SSC Document Library: 

The PCI Key Management and Operations (KMO)™ Assessor Qualification Requirements are expected to be available soon.

Download the Key Management and Operations Standard v1.0