Valentin Averin
3 min read
PCI Key Management Operations (KMO) Standard v1.0: What You Need to Know
4:46

The PCI Security Standards Council has published the PCI Key Management and Operations (KMO) Standard v1.0 designed for securing the systems, processes and devices used to manage cryptographic keys protecting account data. The Standard covers the cryptographic key lifecycle, from generation through to secure disposal and all aspects of using keys in cryptographic protection of PCI defined payment assets. Foregenix reviewed the Standard and here are the most important things you should know about it.

What is the PCI Key Management Operations (KMO) Standard?

PCI KMO covers the complete cryptographic key lifecycle, from generation and distribution through use, storage, compromise response, archival and destruction. Its initial focus is on consolidating, aligning and updating key management requirements associated with PCI PIN and PCI P2PE. Over time, it may also support additional PCI standards, programs and data types. However, initial version of the Standard covers PCI PIN and PCI P2PE.

The Standard is structured around four main Domains:

  • Core key management requirements.
  • Remote HSM and HSM-as-a-Service requirements.
  • Data and operation-specific controls, including PIN processing, CA/RA and signing operations.
  • Physical and logical environmental security.

PCI SSC describes KMO as a modular, “assess-once-use-many” framework which will help to consolidate PCI PIN and PCI P2PE programs as a first step. Therefore, a validated PCI KMO service may be referenced by other PCI assessments where permitted, reducing repeated assessment of the same key management operations.

Who Needs to Comply with the PCI KMO Standard?

The Standard is particularly relevant to:

  • Key-injection facilities
  • PIN processing services
  • P2PE decryption payment gateways
  • Signing service providers
  • Certification and registration authorities
  • POI manufacturers
  • HSM-as-a-Service providers
  • Organisations outsourcing key management functions to Third Parties

Why PCI KMO Matters: Key Benefits for Organisations

Consolidation of the key management scenarios and reducing the number of assessments

PCI SSC designed PCI KMO to cover the entire lifecycle of cryptographic keys for several PCI Standards and Programs. Starting with PIN and P2PE KMO soon may cover all cryptographic key management scenarios applicable to the organisation. By implementing PCI KMO, organisations currently maintaining both PCI PIN and PCI P2PE programs may avoid duplicated assessments and extend their PCI PIN certification validity from 24 to 36 months. 

Addressing new cloud HSM environments

In addition to traditional key management lifecycle controls, PCI KMO addresses risks associated with remote and shared cryptographic environments, including cloud HSM Service Providers. KMO defines and regulates the HSM-as-a-Service operating model and cover all aspects of using it securely.

 PCI KMO requires from cloud HSM Third-Party Service Providers:

  • Isolation of keys, hierarchies and operations between tenants
  • Unique tenant provisioning keys
  • Cryptographic authentication of tenant operations
  • Separation of tenant configuration changes
  • Tenant visibility of HSM configuration
  • Tenant approval of changes that could negatively affect key security
  • Tenant-specific traceability and logging
  • Secure erasure of tenant keys when processing elements leave service

This makes Key Injection Facilities, PIN Processing Services and other eligible for PCI PIN and PCI P2PE organisations rely on PCI KMO compliant Third-Party Service Providers and make sure the cloud HSM layer and secure tenant management were assessed against the defined security controls.

Scope extension beyond traditional PIN or P2PE keys

PCI KMO explicitly recognises services and cryptographic keys that were treated as supporting infrastructure rather than part of the main payment key management assessments. The secure key management requirements now explicitly cover software and firmware signing keys, HSM-administration and authentication keys, tenant provisioning keys. This makes sure all risk scenarios related to supporting keys will be covered during the assessment.

How Foregenix Can Help Your Organisation Transition to PCI KMO

Based on our extensive experience assessing PCI Crypto Standards such as PCI P2PE, PIN, and 3DS. We are confident that  we can provide the best support to help your organisation transition to the new KMO Standard. 

Our QSA-certified team provides the technical guidance needed to secure your environment while minimising your compliance overhead.

Get in touch with us today.

Subscribe to our Blog

Request more information

Contact Foregenix for strategic advisory 

Valentin Averin
Valentin Averin

Head of PCI PIN and PCI 3DS Practice at Foregenix. He is an experienced professional in information security and payment security, who has more than 17 years of a strong track record in the financial services security industry and compliance. His expertise spans across: - Payment & data security for both traditional and emerging payment instruments (mobile wallets, real-time payments, digital assets, and tokenized payment solutions). - PCI Security Standards family: PCI DSS, P2PE, PIN Security, PCI 3DS, PCI TSP. - ISO 27001 & Cybersecurity Governance in banking and payment ecosystems. - Risk & Compliance Management across regulated financial environments.

See All Articles
SUBSCRIBE

Subscribe to our blog

Security never stops. Get the most up-to-date information by subscribing to the Foregenix blog.