Skip to main content
Category: NIST Standards & Publications

NIST SP 800-57

Also known as: SP 800-57, NIST Special Publication 800-57, Recommendation for Key Management, Key Management Guidelines
Simply put

NIST SP 800-57 is a set of guidance documents from the National Institute of Standards and Technology (NIST) that explains how to manage cryptographic keys, the secret values used to protect and unlock encrypted information. It describes general principles and best practices for handling keys throughout their life, from creation to retirement. The guidance is organized into multiple parts covering general concepts, organizational practices, and application-specific advice.

Formal definition

NIST SP 800-57, titled 'Recommendation for Key Management,' is a multi-part special publication maintained by NIST that provides cryptographic key-management guidance and best practices for the management of cryptographic keying material. Per NIST, the series consists of three parts: Part 1 (General) provides general guidance and best practices for key management; Part 2 addresses best practices for key management organizations; and Part 3 provides application-specific key management guidance. As of the evidence available, Part 1 Revision 5 was published in 2020, and a Part 1 Revision 6 Initial Public Draft was issued in 2025, indicating the guidance evolves across revisions. Part 3 Revision 1 remains an active 'Final' publication under review rather than withdrawn. Readers should verify the current revision status and effective text of each part against the official NIST CSRC publication pages, as scope, applicability, and content may change across revisions and agency tailoring.

Why it matters

Cryptographic keys are the linchpin of virtually every protection that relies on encryption, and the strength of an encryption algorithm provides little assurance if the keys that unlock it are poorly generated, stored, distributed, or retired. NIST SP 800-57 matters because it consolidates NIST's recommended principles and best practices for managing keying material across its life cycle, giving organizations a reference point for decisions that are easy to overlook until they cause a breach. For defense and public sector systems, where encryption is frequently invoked to protect Controlled Unclassified Information (CUI) and other sensitive data, sound key management is what makes those cryptographic protections meaningful in practice rather than nominal.

Who it's relevant to

Information System Security Managers and Security Engineers
Personnel responsible for designing and operating cryptographic protections can use NIST SP 800-57 as a reference for handling keying material throughout its life, from generation to retirement. Because the guidance is best-practice oriented rather than a contractual mandate on its own, they should confirm how specific requirements apply to their systems and consult current agency or program tailoring.
Compliance Officers and Auditors
Those assessing whether cryptographic controls are implemented soundly may reference NIST SP 800-57 to evaluate key-management practices, keeping in mind that it provides guidance and best practices rather than an authorization decision. They should verify which revision of each part applies and recognize that adherence to key-management guidance is one element of a broader security posture, not a substitute for it.
Government Contractors Protecting CUI
Contractors that rely on encryption to protect Controlled Unclassified Information can look to NIST SP 800-57 for principles on managing the keys behind those protections. They should confirm the specific obligations that flow from their contracts and applicable frameworks against current authoritative sources, since this publication does not by itself define contractual or clause-level requirements.

Inside SP 800-57

Multi-Part Structure
NIST SP 800-57 is a multi-part publication series on key management maintained by NIST. Part 1 (General) provides general guidance and best practices for cryptographic key management; Part 2 (Best Practices for Key Management Organizations) addresses organizational key management policy and practice statements; and Part 3 (Application-Specific Key Management Guidance) provides guidance for using cryptographic mechanisms in specific applications. Readers should verify the current revision status of each part against the official NIST CSRC publication pages.
Part 1 - General Guidance
Part 1 establishes general concepts and recommendations for cryptographic key management, including key types, key states, and protective measures throughout the key lifecycle. It generally serves as the foundational reference for the series.
Part 2 - Organizational Best Practices
Part 2 focuses on best practices for key management organizations, addressing the development of key management policy and key management practice statements at the organizational level rather than application-specific details.
Part 3 - Application-Specific Guidance
Part 3 (Revision 1) provides application-specific key management guidance for technologies and protocols. As of the applicable revision it remains an active Final publication that NIST has indicated is under review; it is not withdrawn. Confirm its current status against the official NIST CSRC listing.
Key Lifecycle Concepts
The series addresses cryptographic keys across their lifecycle, generally including generation, distribution, storage, use, rotation, and destruction, along with associated key states, to support sound key management practices.
Cryptoperiod Guidance
The series discusses the concept of a cryptoperiod, the time span during which a specific key is authorized for use, as one factor in determining when keys should be changed.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-57.

Does NIST SP 800-57 Part 3 remain valid, or has it been withdrawn?
SP 800-57 Part 3, Revision 1 (Application-Specific Key Management Guidance) has not been withdrawn. As of this writing it remains a Final publication that NIST has flagged as under review, meaning it is still available and citable while potentially subject to future revision or eventual retirement. Readers should not treat it as rescinded, but should verify its current status against the NIST Computer Security Resource Center (CSRC) before relying on it, since publications under review can change. Confirm the current revision and status directly at csrc.nist.gov.
Is SP 800-57 a single document, or does it consist of multiple parts?
SP 800-57 is a multi-part series, not a single document. It generally comprises Part 1 (General guidance on key management concepts, cryptoperiods, and algorithm/key-length recommendations), Part 2 (Best Practices for Key Management Organizations, addressing organizational and policy considerations), and Part 3 (Application-Specific Key Management Guidance). Citing 'SP 800-57' without specifying the part and revision is a common imprecision; each part addresses a distinct audience and scope, and each carries its own revision history. Verify the applicable part and revision at csrc.nist.gov.
Which part of SP 800-57 should I reference when setting cryptoperiods and selecting key lengths?
Cryptoperiod recommendations and key-length/algorithm strength guidance are generally found in Part 1 (General). Part 1 is typically the starting point for foundational key-management parameters, while Part 2 addresses organizational key-management practices and Part 3 addresses application-specific guidance. Because these recommendations are updated across revisions, confirm the values against the current revision of Part 1 rather than relying on figures from memory or older copies.
Is SP 800-57 mandatory for federal systems, or is it guidance?
SP 800-57 is guidance rather than a standalone mandate. In practice, its recommendations are frequently invoked through other authorities, for example, cryptographic controls in NIST SP 800-53 and validation requirements tied to FIPS 140 and approved algorithms (FIPS 197, FIPS 186, and related standards). Whether a specific SP 800-57 recommendation becomes binding generally depends on the controlling framework, agency tailoring, and any contractual requirements. Confirm applicability against the governing baseline and, for defense or CUI contexts, the relevant DoD or DFARS obligations.
How does SP 800-57 relate to FIPS 140 and the use of validated cryptographic modules?
SP 800-57 provides key-management guidance, such as how keys should be generated, protected, and retired, while FIPS 140 (in its applicable version) addresses validation of the cryptographic modules that implement cryptography. They are complementary but distinct: satisfying key-management recommendations in SP 800-57 does not by itself demonstrate module validation, and using a FIPS 140-validated module does not automatically mean key-management practices meet SP 800-57 guidance. Both dimensions typically need to be addressed, and readers should verify current requirements for each against the authoritative sources.
How should organizations account for SP 800-57 recommendations changing over time?
Because algorithm strength assessments, approved key lengths, and cryptoperiod guidance evolve across revisions, and because ongoing work on post-quantum cryptography may influence future recommendations, organizations should treat SP 800-57 as a living reference. In most implementations this means checking the current revision of the relevant part before finalizing key-management policy, avoiding reliance on cached values, and building in a review cadence so that superseded guidance is not carried forward. Always confirm the current text and revision at csrc.nist.gov.

Common misconceptions

SP 800-57 Part 3 has been withdrawn and should no longer be used.
SP 800-57 Part 3 (Revision 1) remains an active Final publication. NIST has indicated it is under review, but 'under review' is not the same as 'withdrawn.' Practitioners should verify the current status directly on the NIST CSRC publication page rather than assuming it has been retired.
SP 800-57 is a single document covering all key management topics.
SP 800-57 is a multi-part series. Part 1 covers general guidance, Part 2 covers best practices for key management organizations, and Part 3 covers application-specific guidance. Citing only one part can leave organizational or application-specific considerations unaddressed.
Following SP 800-57 by itself makes an organization compliant or secure.
SP 800-57 is guidance on key management practices; it is not, on its own, an authorization or a compliance determination. Compliance is not the same as security, and applicable requirements may derive from other authorities and control baselines. Readers should confirm how the guidance maps to their governing requirements against current official sources.

Best practices

Consult the specific part of the series relevant to your need, Part 1 for general guidance, Part 2 for organizational key management policy and practice statements, and Part 3 for application-specific guidance, rather than relying on a single document.
Verify the current revision and status of each part against the official NIST CSRC publication pages, particularly for Part 3, which remains Final but under review as of the applicable revision.
Define and document cryptoperiods for each key type, and establish processes to change keys at the end of their authorized period.
Manage keys across their full lifecycle, generation, distribution, storage, use, rotation, and destruction, consistent with the states and protections described in the series.
Develop organizational key management policy and practice statements informed by Part 2 rather than treating key management as a purely technical, application-level concern.
Confirm how SP 800-57 guidance aligns with your governing compliance requirements and control baselines, since the guidance itself does not constitute an authorization or compliance determination.