Cybersecurity Insights | Blog | Foregenix

PCI Key Management Operations (KMO) Standard v1.0: What You Need to Know

Written by Valentin Averin | 9/22/26, 10:58 AM

The PCI Security Standards Council has published the PCI Key Management and Operations (KMO) Standard v1.0 designed for securing the systems, processes and devices used to manage cryptographic keys protecting account data. The Standard covers the cryptographic key lifecycle, from generation through to secure disposal and all aspects of using keys in cryptographic protection of PCI defined payment assets. Foregenix reviewed the Standard and here are the most important things you should know about it.

What is the PCI Key Management Operations (KMO) Standard?

PCI KMO covers the complete cryptographic key lifecycle, from generation and distribution through use, storage, compromise response, archival and destruction. Its initial focus is on consolidating, aligning and updating key management requirements associated with PCI PIN and PCI P2PE. Over time, it may also support additional PCI standards, programs and data types. However, initial version of the Standard covers PCI PIN and PCI P2PE.

The Standard is structured around four main Domains:

  • Core key management requirements.
  • Remote HSM and HSM-as-a-Service requirements.
  • Data and operation-specific controls, including PIN processing, CA/RA and signing operations.
  • Physical and logical environmental security.

PCI SSC describes KMO as a modular, “assess-once-use-many” framework which will help to consolidate PCI PIN and PCI P2PE programs as a first step. Therefore, a validated PCI KMO service may be referenced by other PCI assessments where permitted, reducing repeated assessment of the same key management operations.

Who Needs to Comply with the PCI KMO Standard?

The Standard is particularly relevant to:

  • Key-injection facilities
  • PIN processing services
  • P2PE decryption payment gateways
  • Signing service providers
  • Certification and registration authorities
  • POI manufacturers
  • HSM-as-a-Service providers
  • Organisations outsourcing key management functions to Third Parties

Why PCI KMO Matters: Key Benefits for Organisations

Consolidation of the key management scenarios and reducing the number of assessments

PCI SSC designed PCI KMO to cover the entire lifecycle of cryptographic keys for several PCI Standards and Programs. Starting with PIN and P2PE KMO soon may cover all cryptographic key management scenarios applicable to the organisation. By implementing PCI KMO, organisations currently maintaining both PCI PIN and PCI P2PE programs may avoid duplicated assessments and extend their PCI PIN certification validity from 24 to 36 months. 

Addressing new cloud HSM environments

In addition to traditional key management lifecycle controls, PCI KMO addresses risks associated with remote and shared cryptographic environments, including cloud HSM Service Providers. KMO defines and regulates the HSM-as-a-Service operating model and cover all aspects of using it securely.

 PCI KMO requires from cloud HSM Third-Party Service Providers:

  • Isolation of keys, hierarchies and operations between tenants
  • Unique tenant provisioning keys
  • Cryptographic authentication of tenant operations
  • Separation of tenant configuration changes
  • Tenant visibility of HSM configuration
  • Tenant approval of changes that could negatively affect key security
  • Tenant-specific traceability and logging
  • Secure erasure of tenant keys when processing elements leave service

This makes Key Injection Facilities, PIN Processing Services and other eligible for PCI PIN and PCI P2PE organisations rely on PCI KMO compliant Third-Party Service Providers and make sure the cloud HSM layer and secure tenant management were assessed against the defined security controls.

Scope extension beyond traditional PIN or P2PE keys

PCI KMO explicitly recognises services and cryptographic keys that were treated as supporting infrastructure rather than part of the main payment key management assessments. The secure key management requirements now explicitly cover software and firmware signing keys, HSM-administration and authentication keys, tenant provisioning keys. This makes sure all risk scenarios related to supporting keys will be covered during the assessment.

How Foregenix Can Help Your Organisation Transition to PCI KMO

Based on our extensive experience assessing PCI Crypto Standards such as PCI P2PE, PIN, and 3DS. We are confident that  we can provide the best support to help your organisation transition to the new KMO Standard. 

Our QSA-certified team provides the technical guidance needed to secure your environment while minimising your compliance overhead.

Get in touch with us today.