Generate encryption keys with approved cryptographic methods, restrict and monitor access to them throughout their lifecycle, and rotate them through a planned migration. Do not destroy an older key until you have confirmed that it is no longer needed to decrypt data, restore backups, or recover systems.
Start with an inventory and a key-management policy
Before creating or replacing keys, identify where cryptography is used and what each key does. NIST treats key management as a lifecycle—not a one-time generation task—and warns that poor management can undermine strong cryptographic algorithms. Its key-management guidance covers the broader lifecycle; SP 800-57 Part 2 Revision 1 addresses organizational planning and documentation.
As an Amazon Associate I earn from qualifying purchases.
- Record the systems and data protected by each key, its purpose and status, and the people or services authorized to use it.
- Document how the key is generated or provisioned, where it is stored, how authorized systems use it, and what must happen before it is retired.
- Protect the inventory and related metadata: information about key ownership, location, or use can itself be sensitive.
- Set policy for access, review, recovery, rotation, and destruction that reflects the organization’s systems and obligations. NIST does not prescribe one inventory format or one universal rotation interval.
NIST’s 2020 announcement about SP 800-57 Part 1 Revision 5 highlights access control, identity authentication, inventory management for keys and certificates, and protection of key metadata.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsHow should encryption keys be generated?
Use a cryptographically appropriate, approved method rather than inventing a random-number generator or derivation scheme. NIST SP 800-57 Part 1 Revision 5 describes generating symmetric keys with an approved random-number generator or deriving them with an approved key-derivation function from a master key or key-derivation key.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
For NIST’s key-generation recommendations, SP 800-133 Revision 2 is the final publication identified here. NIST’s project page lists Revision 3 as a draft released April 17, 2026; draft guidance should not be described as a final standard. Check the NIST key-management project page for current publication status.
Choose a method appropriate to the key’s role and the cryptographic system using it. Follow that system’s applicable standards and implementation documentation; do not treat a key-generation method as interchangeable merely because two keys have the same length.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Where should encryption keys be stored?
Store keys in a controlled environment that limits who and what can access or change them. Apply identity authentication and authorization, grant only the access needed for a defined role, and retain audit information appropriate to the system. Protect key metadata as well as the key material itself.
A managed key-management service (KMS) or a hardware security module (HSM) may be an implementation option, but neither category is automatically right for every organization. Compare them—and any other proposed arrangement—against the responsibilities and requirements that matter in your environment:
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Custody and control: Who can access key material, and which responsibilities remain with your organization or its provider?
- Access and audit: Can you apply the necessary identity, authorization, and monitoring controls?
- Integration and availability: Does the option work with the systems that need to use keys, and can those systems reach it when required?
- Recovery and continuity: Can you maintain access to protected data through failures, restoration, or other recovery scenarios?
- Operational burden: Can your team reliably manage configuration, inventory, policy, and lifecycle tasks?
NIST’s guidance addresses key protection and organizational planning at a general level; it does not establish that a particular product or provider is suitable. Verify implementation details against current product documentation.
How do you rotate keys without losing access to data?
Rotation is a controlled transition between keys, not simply a replacement followed by deletion. Systems may still need an older key to decrypt existing data or recover information. Plan the transition around the key’s role and the data and services that depend on it.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Provision a replacement. Create or obtain the new key under the applicable generation, storage, and access controls.
- Update dependent systems. Change the systems that encrypt or decrypt so they use the replacement as intended. Confirm how each system handles data protected by the older key.
- Check retained data and recovery paths. Account for backups, replicas, and restoration processes that may still depend on the old key. Test the relevant recovery procedures before retiring it.
- Retire the older key deliberately. Confirm its remaining uses and retention needs, document its disposition, and destroy it only when doing so will not prevent required access or recovery.
NIST SP 800-57 Part 3 warns that prematurely destroying some private key-establishment keys can prevent recovery of plaintext. The safe retirement point therefore depends on the key’s function and the organization’s data-retention and recovery needs; there is no universal rotation schedule established by the guidance cited here.
Plan for retirement and suspected compromise
Routine rotation and suspected compromise are different situations. A routine migration can follow the documented lifecycle and transition plan. If compromise is suspected, follow your organization’s incident-response policy and the documentation for the affected cryptographic system; the NIST sources cited here do not prescribe a universal incident playbook.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
For every key, document who can authorize retirement, what dependencies must be checked, how recovery access is maintained, and how destruction is recorded. Keep access to retired keys controlled for as long as they must remain available for legitimate decryption or recovery, then dispose of them under the applicable policy.
Which NIST publications inform this guidance?
| Publication or resource | What it covers here | Status or date |
|---|---|---|
| SP 800-57 Part 1 Revision 5 | General key-management guidance across the lifecycle | Final; published May 2020 |
| SP 800-57 Part 2 Revision 1 | Organizational planning, policy, and practice statements | Final |
| SP 800-133 Revision 2 | Key-generation recommendations | Final; released June 4, 2020 |
| SP 800-57 Part 1 Revision 6 | Updated Part 1 guidance | Listed as an initial public draft for comment on December 5, 2025 |
| SP 800-133 Revision 3 | Updated key-generation recommendations | Listed as a draft released April 17, 2026 |
NIST SP 800-57 Part 1 Revision 5 states: “The proper management of cryptographic keys is essential to the effective use of cryptography.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.




