The PCI Security Standards Council (PCI SSC) has published three significant documents this month.
What has been published
- Key Management and Operations (KMO) Standard v1.0 (14 September): a new standard covering the full life cycle of cryptographic keys, starting with PIN and P2PE keys, and allowing for cloud and remote HSMs. Assessor qualification requirements and compliance dates are still to be announced.
- Security Considerations for AI Systems (15 September): a non-mandatory information supplement on using AI in payment environments and defending against AI-enabled attacks.
- Secure Software Lifecycle (Secure SLC) Standard v2.0 (28 September): the first major revision, aligned with the Secure Software Standard v2.0 and adding requirements on development tools, including AI. A 12-month transition from v1.1 begins once training is available, expected in Q4 2026.
Payment processors, key-injection facilities, P2PE providers, and payment software vendors should review the new documents and plan their transition. Organisations in PCI DSS scope that are adopting AI will find the supplement a useful checklist.
Sources: PCI SSC: KMO Standard v1.0; PCI SSC: Security Considerations for AI Systems; PCI SSC: Secure SLC Standard v2.0
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.