DI-MISC-82515
System Key Management Plan (SKMP)
The System Key Management Plan (SKMP) is used by the NRO to facilitate key material ordering from the NSA and provisioning of that keying material to the Contractor, identifying cryptographic equipment and required key material.
Approval DateMarch 12, 2026
AMSC Number10629
Preparing ActivityNRO
Project NumberMisc-2026-001
OPR—
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
PURPOSE: The System Key Management Plan (SKMP) is used by the NRO to facilitate key material ordering from the National Security Agency (NSA) and provisioning of that keying material to the Contractor. This is accomplished by identifying the cryptographic equipment used by the system and defining the specific key material required.
The SKMP further describes the use and control of cryptographic products and services used by a cryptographic application (cryptographic engine, cryptographic module, or End Cryptographic Unit (ECU), or system) throughout its lifetime. The SKMP also identifies and documents the capabilities that the cryptographic application requires from the current and planned key management infrastructure.
The optional SKMP Annex 1, Cryptographic Security Plan (CSP) will be prepared IAW and as directed in the DD Form 1423. When its completion is directed, this Annex describes the protection and recovery measures put in place for any cryptographic equipment, components, or keying material that may come into contact with or be operated in the presence of unauthorized personnel during the system's life cycle or due to failed launch.
Note: The SKMP shall be approved and accepted by the Government at least 90 calendar days prior to any transfer of operational key to the Contractor. Upon acceptance by the NRO, the SKMP shall be maintained current throughout the complete program lifecycle.
Preparation Instructions
1.1Reference Documents.In assembling the SKMP, the Contractor shall be broadly familiar with the reference document cited below (available from NRO/COMM/CPO/CSMD):
1.1.1National Reconnaissance Office, Preparation of Communications Security (COMSEC) Program Deliverables: Guidance for NRO Program Offices and Industry Partners (current version)
1.2Compliance Documents.In assembling the SKMP, the Contractor shall demonstrate, describe its approach for, and maintain compliance with each document cited below (available from NRO/COMM/CPO/CSMD).
1.2.1National Reconnaissance Office, NRO Communications Security Manual, Volume 1: The NRO Communications Security (COMSEC) Program (current version)
1.2.2National Reconnaissance Office, NRO Communications Security Manual, Volume 2: COMSEC Material Management for NRO COMSEC Responsible Officers (CRO) (current version)
1.2.3National Reconnaissance Office Acquisition Manual (NAM) Clause, Information Technology, Information Assurance, and Information Management Requirements (NAM 52.204-011) (current version)
2Format.The SKMP shall minimally contain narrative content, diagrams, and technical detail addressing each of the topics delineated in the following major sections and subsections. Provide Data using the electronic preparation instructions below.
2.1.3Referenced Documents
2.1.4Government Documents
2.1.5Non-Government Documents
2.2Abbreviations and Acronyms
2.3Key and Certificate Management Plan Process
2.3.1Cryptographic Application Description and Security Services
2.3.2Description/Purpose of Cryptographic Application
2.3.3Level of Information the Cryptographic Application is Protecting
2.3.4Security Services the Cryptographic Application Provides
2.3.4.5Identification and Authentication
2.3.5Operational Environment
2.3.6Requirement for Allied/Coalition Interoperability
2.3.7Key Management Products and Services Requirements
2.3.7.1Key Management Products and Service Types
2.3.7.2Quantity/ECU to be Keyed
2.3.7.3Projected Quantity of ECUs
2.3.7.6Protective Techniques
2.4SKMP Annex 1-Cryptographic Security Plan (CSP) [WHEN DIRECTED]
2.4.1.3Program Reference Documents (Government and/or Non-Government)
2.4.1.4Program Compliance Documents (Government and/or Non-Government)
2.4.2Abbreviations and Acronyms
2.4.3Program Cryptographic Security Plan
2.4.3.1Description of Program Lifecycle (Schedule, Milestones, and Overlay of Same to Sections 3.2-3.10, below)
2.4.3.2Protection Measures: Cryptographic Equipment
2.4.3.3Recovery Measures: Cryptographic Equipment
2.4.3.4Protection Measures: Associated Components
2.4.3.5Recovery Measures: Associated Components
2.4.3.6Protection Measures: Keying Material
2.4.3.7Recovery Measures: Keying Material
2.4.3.8Description of Protection Measures: Access Control Procedures for Authorized Personnel
2.4.3.9Description of Protection Measures: Control / Prevention of Access by Unauthorized Personnel
2.4.3.10Description of Protection Measures: Action Plan for Failed Launch
2.4.3.11Description of Protection Measures: Action Plan for Deorbiting of Space Platform
2.4.3.12Contractor's Declaration of Implementation of Program Compliance Documents
2.4.3.13Contractor's Estimation of CSP Sufficiency and Assessment of Residual Risk
2.5SKMP/SKMP Annex 1 Compliance MatrixThe SKMP and Annex 1 (when directed) detailed in Section II, above, shall contain (either in the body of the document, or as an attachment to it) a complete Compliance Matrix that identifies where each line item is addressed in the SKMP. The "Requirement Met?" column (D) will be completed by the Government during its review.
Figures

Figure Table 1. System Key Management Plan (SKMP) Compliance Matrix (page 1 of 3, items 1-13)

Figure Table 1. System Key Management Plan (SKMP) Compliance Matrix (page 2 of 3, items 14-24)

Figure Table 1. System Key Management Plan (SKMP) Compliance Matrix (page 3 of 3, items 25-33)

Figure Table 2. SKMP Annex 1-Cryptographic Security Plan (CSP) Compliance Matrix
Schema v3.0Community-maintained · Verify against ASSIST