NIST SP 800-57
NIST SP 800-57 is a set of guidance documents from the National Institute of Standards and Technology (NIST) that explains how to manage cryptographic keys, the secret values used to protect and unlock encrypted information. It describes general principles and best practices for handling keys throughout their life, from creation to retirement. The guidance is organized into multiple parts covering general concepts, organizational practices, and application-specific advice.
NIST SP 800-57, titled 'Recommendation for Key Management,' is a multi-part special publication maintained by NIST that provides cryptographic key-management guidance and best practices for the management of cryptographic keying material. Per NIST, the series consists of three parts: Part 1 (General) provides general guidance and best practices for key management; Part 2 addresses best practices for key management organizations; and Part 3 provides application-specific key management guidance. As of the evidence available, Part 1 Revision 5 was published in 2020, and a Part 1 Revision 6 Initial Public Draft was issued in 2025, indicating the guidance evolves across revisions. Part 3 Revision 1 remains an active 'Final' publication under review rather than withdrawn. Readers should verify the current revision status and effective text of each part against the official NIST CSRC publication pages, as scope, applicability, and content may change across revisions and agency tailoring.
Why it matters
Cryptographic keys are the linchpin of virtually every protection that relies on encryption, and the strength of an encryption algorithm provides little assurance if the keys that unlock it are poorly generated, stored, distributed, or retired. NIST SP 800-57 matters because it consolidates NIST's recommended principles and best practices for managing keying material across its life cycle, giving organizations a reference point for decisions that are easy to overlook until they cause a breach. For defense and public sector systems, where encryption is frequently invoked to protect Controlled Unclassified Information (CUI) and other sensitive data, sound key management is what makes those cryptographic protections meaningful in practice rather than nominal.
Who it's relevant to
Inside SP 800-57
Common questions
Answers to the questions practitioners most commonly ask about SP 800-57.