1. Home
  2. Insights

What is PCI KMO? The new key management standard explained

  • PCI KMO
  • PCI PIN
  • P2PE

On 14 September 2026, the PCI Security Standards Council published a new standard: the PCI Key Management and Operations (KMO) Standard v1.0. If your organisation manages cryptographic keys that protect PINs or card data, it is worth understanding early.

What it is

PCI KMO sets security and testing requirements for organisations that operate and manage systems using cryptographic keys to protect account data. It covers the full key lifecycle, from generation and distribution to storage, use and destruction, along with the procedures, systems and equipment that manage those keys.

Why the Council created it

Key management requirements have lived inside separate standards, mainly PCI PIN Security and PCI P2PE. An organisation managing keys for both faced overlapping requirements and separate assessments. The first version of KMO brings PIN and P2PE key management together, so a single KMO assessment can validate both key types.

What's new

  • Cloud and remote HSMs. The standard explicitly addresses cloud-based and remote hardware security modules, reflecting how key management actually runs today.
  • Modular design. The Council describes an "assess once, use many" approach, so a KMO validation can be referenced by other PCI programmes, such as P2PE.
  • Room to grow. Future versions may extend to other data, such as that covered by the PCI Card Production standards.

Who should pay attention

In my view, the teams most affected are:

  • Key injection facilities and key management service providers.
  • Payment processors and acquirers running HSMs.
  • P2PE solution providers and PIN acquirers.
  • Organisations moving their HSMs to the cloud.

What is not known yet

The Council has not published transition timelines, and assessor qualification requirements are still to come. There is no need to panic, but there is good reason to prepare.

What to do now

Read the standard, compare your key management procedures against it, and note where cloud or remote HSM operations are poorly documented. In the assessments I have worked on, key custodian roles, dual control and key inventories are where evidence is usually weakest. Fixing those now will make your first KMO assessment far easier.

Share on LinkedIn All insights