DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.10
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.10  Manage Cryptographic Keys

Establish and manage cryptographic keys for cryptography employed in organizational systems.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

SC.L2-3.13.10 governs the keys that make cryptography work. It requires that cryptographic keys be established and managed for the cryptography employed in organizational systems, so that the encryption protecting CUI rests on keys that are properly generated, protected, and maintained. It is a one-point requirement and may be deferred on a plan of action.

Encryption is only as strong as the keys behind it. A key that is generated weakly, stored insecurely, shared carelessly, or never rotated undermines the cryptography it supports, no matter how strong the algorithm. This control requires that cryptographic keys be established, generated and distributed properly, and managed, protected, rotated, and retired over their life, wherever cryptography is employed. The two assessment objectives are establishing keys and managing them.

The requirement · NIST SP 800-171 Rev 2, 3.13.10

Establish and manage cryptographic keys for cryptography employed in organizational systems.

The requirement is to establish and manage cryptographic keys wherever cryptography is used. Establishing keys means generating and distributing them securely; managing them means protecting, rotating, and retiring them over their lifecycle. The assessment objectives correspond to these two: keys are established whenever cryptography is employed, and keys are managed whenever cryptography is employed. Proper key management is what keeps the encryption trustworthy.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.13.10 into two objectives: establish keys and manage keys.

[a]

Cryptographic keys are established whenever cryptography is employed. Keys are generated and distributed properly.

MeetsKeys are established through secure generation and distribution.
FailsKeys are generated or distributed insecurely.
[b]

Cryptographic keys are managed whenever cryptography is employed. Keys are protected, rotated, and retired.

MeetsKeys are managed over their lifecycle, protected, rotated, and retired.
FailsKeys are unprotected, never rotated, or not retired.

The two objectives are establishment and management. The common gap is at objective [b], where keys are generated but not protected, rotated, or retired, so a compromised or stale key persists. The assessor looks for keys both established and managed wherever cryptography is used.

3Failure Patterns

The failures are about keys that are poorly established or unmanaged.

Keys stored insecurely

Keys kept in the clear or alongside the data they protect are exposed. Protecting keys as part of management keeps them secure.

Keys never rotated or retired

Keys that are never changed or retired accumulate risk over time. Rotation and retirement are part of managing keys over their life.

Weak generation or distribution

Keys generated weakly or distributed insecurely undermine the cryptography from the start. Proper establishment produces trustworthy keys.

The common root
This control fails when the algorithm gets attention but the keys do not. Strong encryption with poorly managed keys is weak encryption, because the key is the secret the whole scheme depends on. Establishing and managing keys properly is what makes the cryptography actually protect the data.

4Ownership

This is an IT and security-owned technical control.

RoleResponsibility for this control
IT and securityEstablishes and manages cryptographic keys over their lifecycle. Owns the key management evidence.
System administratorApplies key protection, rotation, and retirement on systems.
Security or compliance leadConfirms keys are established and managed wherever cryptography is used.
See also: This control underpins the encryption of SC.L2-3.13.8 and the FIPS-validation requirement of SC.L2-3.13.11.

5Tooling

The control is delivered by key management practices and systems.

ObjectivesToolingWhat it provides
[a]Secure key generation and distributionKeys established properly.
[b]Key management system, rotation and retirement processKeys protected, rotated, and retired.

The caveat is that management has to cover the full lifecycle, protection, rotation, and retirement, wherever cryptography is used. Keys established well but never managed still degrade over time. The assessor examines establishment and management, so both objectives have to hold.

6Evidence

The satisfied version of 3.13.10 shows keys established and managed.

EvidenceWhat it demonstrates
Key management proceduresObjectives [a], [b]. Keys established and managed.
Key protection and rotation recordsObjective [b]. Keys protected, rotated, and retired.

The evidence should show cryptographic keys established through secure generation and distribution and managed over their lifecycle. The key management procedures together with protection and rotation records are the clearest demonstration of the control.

Strong encryption with weak key management is weak encryption

The key is the secret the whole scheme depends on, so this control asks that cryptographic keys be established and managed wherever cryptography is used. Building proper key management is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.10. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.10[a] and 3.13.10[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.9 · Terminate Network Connections
Next in System and Communications Protection →
SC.L2-3.13.11 · FIPS-Validated Cryptography
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.10 · Edition 2026.1 · Last reviewed July 12, 2026