PCI Key Management and Operations (KMO)™ Assessor Qualification
The KMO Assessor course provides instruction on how to perform assessments of entities in accordance with the PCI KMO Security Requirements and Testing Procedures (PCI KMO Standard). This training will provide you with an understanding of the requirements, test procedures, and guidance for entities involved in the operation and management of cryptographic keys and the systems that use them for the security of account data.
Upon completion of the course, you’ll be able to conduct PCI KMO Assessments, validate and attest to an entity’s PCI KMO Security Standard compliance status, and prepare appropriate compliance reports required by compliance accepting entities.
Course Highlights
The PCI KMO Standard provides a set of security requirements as well as assessment procedures for performing PCI KMO Assessments. The KMO Assessor training covers the PCI KMO Security Requirements and Testing Procedures (PCI KMO Standard). Candidates will learn how to:
-
Validate and confirm KMO scope as defined by the assessed entity.
-
Apply cryptography and key management principles in payment environments to PCI KMO assessments.
-
Apply independent judgement about whether the assessed entity meets the PCI KMO Security Standard.
-
Learn how to complete the KMO ROC and KMO AOC documentation required for submission of completed assessments.
-
Validate and attest to an entity’s PCI KMO Security Standard compliance status.
Benefits
-
Support your organizations or client’s ongoing security and compliance efforts through your knowledge of the PCI KMO Standard.
-
Gain recognition of your professional achievement with this industry credential.
-
Listing in a searchable directory on the PCI website.
-
Earn Continuing Professional Education (CPE) credits.
Right for You?
If you have at least three years of experience in cryptography and/or key management including these areas, consider the KMO qualification:
-
Cryptography and/or Key Management.
-
Cryptographic experience in the Payment Industry.
-
Network Security, Systems Security.
-
IT auditing or security assessments.
-
Physical security techniques for high-security areas.
Digital Badging
When you become a KMO Assessor, display your digital badge and represent your skills and gives you a way to share your abilities online in a way that is simple, trusted and can be easily verified in real time.
Schedule
2027 schedule coming soon
-
28-30 Sep 2026
18:00-22:00 ET (22:00-02:00 UTC)
Virtual Instructor-Led (vILT) This training is geared for the AP region
-
15-16 Oct 2026
09:00-17:30 (local time)
Edinburgh, UK*
-
3-4 Nov 2026
09:00-17:30 (local time)
Reston, VA
-
5-6 Nov 2026
09:00-17:30 (local time)
Kuala Lumpur, MY
-
24-25 Nov 2026
06:00-10:00 ET (11:00-15:00 UTC)
Virtual Instructor-Led (vILT) This training is geared for the Europe region.
Prices
| Course | Price | |
New KMO Training (In person & eLearning) |
$3,300 USD | |
Requalification KMO Training |
$1,975 USD | |
Knowledge Training Non-PO * |
$1,500 USD | |
Knowledge Training PO * |
$1,200 USD | |
Training class change fee |
$185 USD |
Please note: The training and exam will be delivered in English.
* Knowledge training does not lead to assessor status.
How to Prepare for the Exam
Prior to taking the KMO training and exam, candidates should familiarize themselves with information regarding the KMO Standard, the KMO program and supporting documents. These materials may be found in the Document Library.
Training Formats and Exam Information
New Training Offerings:
- Virtual Instructor-led training (vILT): Combination online training and instructor-led webinar with an exam offered via Pearson Vue within 30 days of webinar.
- Please see Schedule tab for dates of vILT trainings.
New Exam Specifics:
- All exams are closed book.
- Exam is 60 multiple choice questions with a 75-minute time limit.
- Results of Pearson Vue exams are delivered upon completion of the exam.
- 75% or higher to pass the exam; the only information that can be released concerning exams is your grade.
- If you fail the exam, you must take the training and exam from the beginning.
Registration Process
Step 1 – Review
Refer to the KMO Qualification Requirements for complete program description and requirements and to confirm that you are well suited for the program.
Then complete the KMO registration form online (see step 2).
KMO Qualification Requirements
Step 2 – Apply
Complete the online application form through PCI SSC’s secure portal. Application requirements include:
- Submit KMO registration form
- Complete company application (Primary Contact will gain access to the online application only after the KMO registration form has been approved by PCI SSC).
- Enroll professionals in KMO training (Primary Contact will have the ability to enroll professionals in KMO training through the portal only after the KMO Company application has been approved).
- Submit payment (training invoice will be emailed to Primary Contact within 2-3 business days of KMO training request approval). For more information about the training fees, please see the KMO Training Pricing page.
Step 3 – Train
Upon receipt of payment the primary contact will receive the details for the instructor-led class.
Step 4 – Enrollment
Once the application has been approved by the PCI Security Standards Council, and its designated KMO employees have attended and passed the KMO training, the KMO Company will receive confirmation of acceptance into the program, and the KMO employees will each receive a Certificate of Qualification. The KMO employees will be added to the Council’s database of certified KMO personnel, and the company may now perform its own security audits until the time comes to complete the annual Requalification training to maintain the certification.
Knowledge training does not offer qualification. Only those who have taken and passed the exam become KMO Assessors.
Requalification Process
In order to maintain the high standards set for this qualification, all KMO Assessors must requalify every year to continue to maintain their status and be listed on the PCI website. Requalification requirements help ensure that KMO Assessors remain current with technical and industry changes and demonstrate professionalism. To maintain active qualification status, KMO Assessors must abide by the PCI SSC Code of Professional Responsibility.
Requalification specifics:
- Approved assessors are allowed to register for requalification training as early as 90 days prior to their expiration date. Once registered, they will receive immediate access to the eLearning training.
- Registration must be submitted no later than the candidate’s expiration date.
- Exam access is given no earlier than four (4) weeks prior to expiration date AND invoice is paid.
- An Assessor who is not registered for requalification training before midnight Eastern Time on their qualification expiration date, or who does not achieve a passing score on the exam by the end of their qualification period, will be required to re-enroll as a new candidate.
Requalification exam:
- Non-proctored remote exam
- 35 multiple choice questions with a 75-minute time limit.
- 75% or higher to pass the exam; the only information that can be released concerning exams is the grade.
If you fail the exam, please have the primary contact email training@pcisecuritystandards.org for the next steps.
I thought the instructor was excellent and his insights and experience greatly helped towards the overall understanding.
Sub Title
It was very useful to see the QSA role from the perspective of the assessor rather than from the customer's viewpoint.
Sub Title
The way that the instructor was able to cover a vast amount of material in a relatively short time and make us remember it - without the training it would have taken weeks and weeks to get the same level of understanding.
Sub Title