October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

How to Generate, Store, and Rotate Encryption Keys Securely

A practical guide to generating encryption keys safely, controlling access and storage, and rotating old keys without breaking decryption or recovery.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Generate encryption keys with approved cryptographic methods, restrict and monitor access to them throughout their lifecycle, and rotate them through a planned migration. Do not destroy an older key until you have confirmed that it is no longer needed to decrypt data, restore backups, or recover systems.

Start with an inventory and a key-management policy

Before creating or replacing keys, identify where cryptography is used and what each key does. NIST treats key management as a lifecycle—not a one-time generation task—and warns that poor management can undermine strong cryptographic algorithms. Its key-management guidance covers the broader lifecycle; SP 800-57 Part 2 Revision 1 addresses organizational planning and documentation.

As an Amazon Associate I earn from qualifying purchases.

  • Record the systems and data protected by each key, its purpose and status, and the people or services authorized to use it.
  • Document how the key is generated or provisioned, where it is stored, how authorized systems use it, and what must happen before it is retired.
  • Protect the inventory and related metadata: information about key ownership, location, or use can itself be sensitive.
  • Set policy for access, review, recovery, rotation, and destruction that reflects the organization’s systems and obligations. NIST does not prescribe one inventory format or one universal rotation interval.

NIST’s 2020 announcement about SP 800-57 Part 1 Revision 5 highlights access control, identity authentication, inventory management for keys and certificates, and protection of key metadata.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should encryption keys be generated?

Use a cryptographically appropriate, approved method rather than inventing a random-number generator or derivation scheme. NIST SP 800-57 Part 1 Revision 5 describes generating symmetric keys with an approved random-number generator or deriving them with an approved key-derivation function from a master key or key-derivation key.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

For NIST’s key-generation recommendations, SP 800-133 Revision 2 is the final publication identified here. NIST’s project page lists Revision 3 as a draft released April 17, 2026; draft guidance should not be described as a final standard. Check the NIST key-management project page for current publication status.

Choose a method appropriate to the key’s role and the cryptographic system using it. Follow that system’s applicable standards and implementation documentation; do not treat a key-generation method as interchangeable merely because two keys have the same length.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Where should encryption keys be stored?

Store keys in a controlled environment that limits who and what can access or change them. Apply identity authentication and authorization, grant only the access needed for a defined role, and retain audit information appropriate to the system. Protect key metadata as well as the key material itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A managed key-management service (KMS) or a hardware security module (HSM) may be an implementation option, but neither category is automatically right for every organization. Compare them—and any other proposed arrangement—against the responsibilities and requirements that matter in your environment:

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Custody and control: Who can access key material, and which responsibilities remain with your organization or its provider?
  • Access and audit: Can you apply the necessary identity, authorization, and monitoring controls?
  • Integration and availability: Does the option work with the systems that need to use keys, and can those systems reach it when required?
  • Recovery and continuity: Can you maintain access to protected data through failures, restoration, or other recovery scenarios?
  • Operational burden: Can your team reliably manage configuration, inventory, policy, and lifecycle tasks?

NIST’s guidance addresses key protection and organizational planning at a general level; it does not establish that a particular product or provider is suitable. Verify implementation details against current product documentation.

How do you rotate keys without losing access to data?

Rotation is a controlled transition between keys, not simply a replacement followed by deletion. Systems may still need an older key to decrypt existing data or recover information. Plan the transition around the key’s role and the data and services that depend on it.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Provision a replacement. Create or obtain the new key under the applicable generation, storage, and access controls.
  2. Update dependent systems. Change the systems that encrypt or decrypt so they use the replacement as intended. Confirm how each system handles data protected by the older key.
  3. Check retained data and recovery paths. Account for backups, replicas, and restoration processes that may still depend on the old key. Test the relevant recovery procedures before retiring it.
  4. Retire the older key deliberately. Confirm its remaining uses and retention needs, document its disposition, and destroy it only when doing so will not prevent required access or recovery.

NIST SP 800-57 Part 3 warns that prematurely destroying some private key-establishment keys can prevent recovery of plaintext. The safe retirement point therefore depends on the key’s function and the organization’s data-retention and recovery needs; there is no universal rotation schedule established by the guidance cited here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Plan for retirement and suspected compromise

Routine rotation and suspected compromise are different situations. A routine migration can follow the documented lifecycle and transition plan. If compromise is suspected, follow your organization’s incident-response policy and the documentation for the affected cryptographic system; the NIST sources cited here do not prescribe a universal incident playbook.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

For every key, document who can authorize retirement, what dependencies must be checked, how recovery access is maintained, and how destruction is recorded. Keep access to retired keys controlled for as long as they must remain available for legitimate decryption or recovery, then dispose of them under the applicable policy.

Which NIST publications inform this guidance?

Publication or resource What it covers here Status or date
SP 800-57 Part 1 Revision 5 General key-management guidance across the lifecycle Final; published May 2020
SP 800-57 Part 2 Revision 1 Organizational planning, policy, and practice statements Final
SP 800-133 Revision 2 Key-generation recommendations Final; released June 4, 2020
SP 800-57 Part 1 Revision 6 Updated Part 1 guidance Listed as an initial public draft for comment on December 5, 2025
SP 800-133 Revision 3 Updated key-generation recommendations Listed as a draft released April 17, 2026

NIST SP 800-57 Part 1 Revision 5 states: “The proper management of cryptographic keys is essential to the effective use of cryptography.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.