DI-SCRE-82524
System Key Management Plan (SKMP)
Specifies the format and content for a System Key Management Plan (SKMP) used by programs to facilitate key material ordering from the National Security Agency and provisioning of that keying material to the Contractor.
Approval DateApril 10, 2026
AMSC Number10642
Preparing Activity19
Project NumberSCRE-2026-003
OPR—
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The System Key Management Plan (SKMP) is used by programs to facilitate key material ordering from the National Security Agency (NSA) and provisioning of that keying material to the Contractor. This is accomplished by identifying the cryptographic equipment used by the system and defining the specific key material required.
The SKMP further describes the use and control of cryptographic products and services used by a cryptographic application (cryptographic engine, cryptographic module, or End Cryptographic Unit (ECU), or system) throughout its lifetime. The SKMP also identifies and documents the capabilities that the cryptographic application requires from the current and planned key management infrastructure.
When directed in the Statement of Work, the SKMP includes Annex 1, Cryptographic Security Plan (CSP). This Annex describes the protection and recovery measures put in place for any cryptographic equipment, components, or keying material that may come into contact with or be operated in the presence of unauthorized personnel during the system's life cycle or due to failed launch.
This DID contains the format, content, and intended use of information for the data deliverable resulting from the work task described in the solicitation.
Preparation Instructions
1.1Committee on National Security Systems Policy (CNSSP) No. 12, Cybersecurity Policy for Systems Used to Support National Security Missions, February 2018
2FormatThe Contractor's SKMP shall contain narrative content, diagrams, and technical detail addressing each of the topics delineated in the following major sections and subsections. Provide data using the electronic preparation instructions below.
2.1.3Referenced Documents
2.1.4Government Documents
2.1.5Non-Government Documents
2.2ABBREVIATIONS AND ACRONYMS
2.3KEY AND CERTIFICATE MANAGEMENT PLAN PROCESS
2.3.1Cryptographic Application Description and Security Services
2.3.2Description/Purpose of Cryptographic Application
2.3.3Level of Information the Cryptographic Application is Protecting
2.3.4Security Services the Cryptographic Application Provides
2.3.4.5Identification and Authentication
2.3.5Operational Environment
2.3.6Requirement for Allied/Coalition Interoperability
2.3.7Key Management Products and Services Requirements
2.3.7.1Key Management Products and Service Types
2.3.7.2Quantity/ECU to be Keyed
2.3.7.3Projected Quantity of ECUs
2.3.7.6Protective Techniques
2.4SKMP ANNEX 1-Cryptographic Security Plan (CSP) [WHEN DIRECTED]
2.4.1.3Program Reference Documents (Government and Non-Government)
2.4.1.4Program Compliance Documents (Government and Non-Government)
2.4.2ABBREVIATIONS AND ACRONYMS
2.4.3PROGRAM CRYPTOGRAPHIC SECURITY PLAN
2.4.3.1Description of Program Lifecycle (Schedule, Milestones, and Overlay of Same to Sections 3.2 - 3.10, below)
2.4.3.2Protection Measures: Cryptographic Equipment
2.4.3.3Recovery Measures: Cryptographic Equipment
2.4.3.4Protection Measures: Associated Components
2.4.3.5Recovery Measures: Associated Components
2.4.3.6Protection Measures: Keying Material
2.4.3.7Recovery Measures: Keying Material
2.4.3.8Description of Protection Measures: Access Control Procedures for Authorized Personnel
2.4.3.9Description of Protection Measures: Control / Prevention of Access by Unauthorized Personnel
2.4.3.10Description of Protection Measures: Action Plan for Failed Launch
2.4.3.11Description of Protection Measures: Action Plan for Deorbiting of Space Platform
2.4.3.12Contractor's Declaration of Implementation of Program Compliance Documents
2.4.3.13Contractor's Estimation of CSP Sufficiency and Assessment of Residual Risk
2.5SKMP/SKMP ANNEX 1 COMPLIANCE MATRIXThe Contractor's SKMP and SKMP Annex 1 (when directed) detailed in Requirements above, shall contain (either in the body of the document, or as an attachment to it) a complete Compliance Matrix that identifies where each line item is addressed in the SKMP. The "Requirement Met?" column (D) is to be left blank to be completed by the Government during its review.
Figures

Figure 1. System Key Management Plan (SKMP) Compliance Matrix

Figure 2. SKMP Annex 1-Cryptographic Security Plan (CSP) Compliance Matrix
Schema v3.0Community-maintained · Verify against ASSIST