Key Management and Operations (KMO)
The PCI KMO standard and program defines the requirements for secure management and operation of key management systems, including all aspects of the cryptographic key lifecycle from generation and conveyance, through loading and use, to archive, retirement, and destruction. This includes the validation of remote and as-a-service based HSM implementations. The initial focus of the PCI KMO standard and program is on cryptographic keys used for securing PIN and P2PE data.
Intended Audience
Entities involved in the management of cryptographic keys that are intended for use with PIN or P2PE data. This includes entities operating HSM-as-a-Service systems which may operate on those keys.
Listings
Coming Soon.
Professionals
KMO Assessors are qualified and trained by PCI SSC to perform independent assessments of environments where cryptographic keys are managed, in accordance with the PCI KMO Security Requirements and the PCI KMO Program Guide.
Training Information
The KMO Assessor course provides instruction on how to perform assessments of entities in accordance with the PCI KMO Security Requirements and Testing Procedures (PCI KMO Standard).
Knowledge Training courses are designed to bridge the knowledge gap between organizations and assessors by providing learning opportunities for individuals to take the same training and exam as the Assessor. Upon successful completion of training, learners will be given an acknowledgement of completion as well as the option to complete the exam and receive a digital badge.
Whether an entity is required to comply with or validate compliance to a PCI SSC standard is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity. Visit our FAQ page for more information.






