PCI SSC publishes Key Management and Operations Standard v1.0
On September 14, 2026, the PCI Security Standards Council (PCI SSC) published the Key Management and Operations (KMO) Standard v1.0 and its Program Guide. KMO is a new PCI standard for organizations that operate cryptographic keys used to protect account data, starting with PIN and Point-to-Point Encryption (P2PE) keys.
This is a companion program, not a PCI DSS replacement. Typical merchants do not get new DSS requirements from this release. It matters if you run key-management systems, hardware security modules (HSMs), or HSM-as-a-service for PIN or P2PE.
What changed
KMO defines security requirements, testing procedures, and program rules for the cryptographic key lifecycle: generation, distribution, loading, use, archive, retirement, and destruction. It also covers the procedures, systems, and equipment used to manage those keys, including remote and cloud HSM deployments aligned with current PCI HSM requirements.
The Council’s aim is one shared key-management baseline that other PCI standards and programs can reference. In v1.0, that means aligning PIN and P2PE key-management expectations so one KMO assessment can cover both. A resulting KMO Listing can, where appropriate, be referenced by a PCI P2PE implementation.
Assessor qualification and public listings are not fully live yet. Assessor Qualification Requirements are expected soon, and the listings page currently shows “Coming Soon.” Payment brands and acquirers still decide who must validate to KMO.
What did not change
PCI DSS remains the current path for merchants and most service providers. Organizations that do not operate PIN or P2PE key-management systems are unaffected. Existing PIN and P2PE documents stay in force until those programs point to KMO for shared key-management content.
What to do now
- If you manage PIN or P2PE keys (including via HSM-as-a-service), download the KMO Requirements and Testing Procedures v1.0 and the Program Guide and map them to your controls.
- Ask your payment brand, acquirer, or P2PE sponsor whether they will require or accept a KMO Listing, and when.
- If you assess PIN or P2PE key environments, wait for KMO Assessor Qualification Requirements and training before promising KMO assessments.
- Keep validating PCI DSS against the version and Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC) path your accepting entity requires.
- See the PCI DSS page for the core path, and follow PCI DSS on this site for later Council program updates.
Sources
- Just Published PCI Key Management and Operations (KMO) Standard v1.0 (September 14, 2026)
- PCI Key Management and Operations (KMO) Requirements and Testing Procedures, Version 1.0 (September 14, 2026)
- PCI Key Management and Operations (KMO) Program Guide (September 14, 2026)
- Key Management and Operations (KMO) standard page (September 14, 2026)