Don’t do SECURITY. Do business SECURELY.
Threat intel

PCI SSC publishes new key management standard and Secure SLC v2.0

The PCI Security Standards Council has published a new Key Management and Operations Standard, Secure Software Lifecycle Standard v2.0, and guidance on AI systems.

The PCI Security Standards Council (PCI SSC) has published three significant documents this month.

What has been published

  • Key Management and Operations (KMO) Standard v1.0 (14 September): a new standard covering the full life cycle of cryptographic keys, starting with PIN and P2PE keys, and allowing for cloud and remote HSMs. Assessor qualification requirements and compliance dates are still to be announced.
  • Security Considerations for AI Systems (15 September): a non-mandatory information supplement on using AI in payment environments and defending against AI-enabled attacks.
  • Secure Software Lifecycle (Secure SLC) Standard v2.0 (28 September): the first major revision, aligned with the Secure Software Standard v2.0 and adding requirements on development tools, including AI. A 12-month transition from v1.1 begins once training is available, expected in Q4 2026.

Payment processors, key-injection facilities, P2PE providers, and payment software vendors should review the new documents and plan their transition. Organisations in PCI DSS scope that are adopting AI will find the supplement a useful checklist.

Sources: PCI SSC: KMO Standard v1.0; PCI SSC: Security Considerations for AI Systems; PCI SSC: Secure SLC Standard v2.0

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe

More insights