Cryptoperiod

PCIComplianceHubLast updated

The defined period during which a specific cryptographic key is authorised for use, after which it must be retired and replaced. PCI DSS requires a cryptoperiod to be defined for every key protecting account data, and requires keys to be changed at the end of it. The length is set by the organization, based on how much data the key protects, how exposed it is and the strength of the algorithm, and the reasoning must be documented rather than assumed. A shorter cryptoperiod limits how much data a single compromised key can expose.