PCI KMO Standard
PCI Key Management and Operations (KMO) v1.0 — the key lifecycle it governs, the assess-once assessment process, and how it relates to PCI PIN, P2PE, and PTS HSM.
Follows PCI Key Management and Operations (KMO) Standardv1.0·verified Sep 2026— assessor qualification requirements not yet published as of the verified date
Use test data only. All calculations run locally in your browser — PayProbe never sees, transmits, or stores your PAN, CVV, keys, PINs, or cryptographic inputs. How we handle data →
What is PCI KMO?
The PCI Key Management and Operations (KMO) Standard v1.0, published by the PCI Security Standards Council on 14 September 2026, defines security requirements, test requirements, and guidance for entities that operate and manage systems using cryptographic keys to protect account data.
It covers the entire lifecycle of a cryptographic key — from generation and conveyance, through loading and use, to archive, retirement, and destruction — plus the security of the procedures, systems, and equipment used to manage and operate those keys.
Scope includes keys that secure PINs, account data, and other sensitive assets, including other cryptographic keys used as storage, transport, or derivation keys — the same key types the TR-31 and TR-34 tools on this site already model.
Why it exists
Key-management requirements for handling PIN and P2PE keys and data types used to live separately inside the PCI PIN and PCI P2PE standards, with real overlap: an entity operating both often faced two assessments of much the same HSMs, generation ceremonies, and destruction procedures.
KMO's initial focus consolidates, aligns, and updates that overlapping ground into one document, built for an "assess-once, use-many" model: a single KMO assessment can produce a Listing that other PCI programs reference instead of re-testing the same controls.
At a glance
Source
PCI Security Standards Council, "Just Published: PCI Key Management and Operations (KMO)™ Standard v1.0" (14 September 2026). See also PCI PTS & SSF for how KMO sits alongside PCI's other device and software standards, and the TR-31 / TR-34 guide for the technical key-block format KMO's conveyance stage tests against.