Skip to content

SecurityIndependently confirmed2 publishers3 min readPublished

TCG writes down what "quantum-safe TPM" means, and buyers finally get a document to argue with

The Trusted Computing Group's baseline is PTP 1.07, with two readiness labels and a certification tier still to come. Until that lands, verification means reading a vendor's evidence packet.

The Watch · Security desk

How we use AISend a correction

What happened

  • TCG has published requirements setting out what a TPM must do before anyone calls it quantum-safe, so buyers can request vendor evidence against a written baseline.
  • The baseline is the PC Client Platform TPM Profile 1.07, which pins the required PQC elements drawn from TPM 2.0 Library Specification 1.85.
  • Two designations now describe hardware state: PQC-ready TPMs implement 1.07, PQC-upgradable ones do not yet but can be brought to it.

Why it matters

  • constraint With no certified tier yet, the verification work sits with the buyer's own reviewers reading a vendor evidence packet, not with an independent lab result they can file.
  • decision Specifications now have to name the optional algorithms a fleet actually needs, because asking only for PQC-ready buys a floor whose contents vary between suppliers.
  • exposure The 90% of businesses TCG says have no formal PQC roadmap are the constituency expected to use this, and without a roadmap there is no schedule to hang the evidence request on.
  • contradiction The two write-ups cite different underlying version numbers for TPM 2.0, so an RFP that names a library version instead of PTP 1.07 risks pointing at the wrong document.

A TPM holds a machine's keys and records measurements of its firmware, so the platform can later prove it has not been altered [8]. That is why a single algorithm name was never a useful answer to a procurement question. Platform identities, attestation keys and firmware measurements are three different objects that have to survive the same transition, and TCG says they may need to remain secure for decades [9]. TCG president Joe Pennisi frames the requirement as looking "beyond individual algorithm support" to "the broader requirements for quantum-safe identities, attestation, and hardware-anchored trust" [11]. The failure mode TCG names is more specific than that: TPMs that advertise compliance while failing to provide full, end-to-end security capabilities [10].

The profile behind the new guidance was not drafted narrowly. Infosecurity Magazine reports that TCG brought together almost 90 contributors in March 2026, from government, academia, semiconductor companies and computing hardware providers including Intel, Google, Hewlett Packard Enterprise, Microsoft, NVIDIA, Lenovo and STMicroelectronics, to develop PTP 1.07 [13]. So the vendors a buyer will now ask for evidence are substantially the vendors who set the bar. That is normal for hardware standards, and it is also the case for the certification tier: an evidence request answered by the author of the requirement carries less weight than a result from a third party. About five months separated the drafting work from the guidance that tells buyers how to check against it [19].

Scale is what makes the interval matter. TPM 2.0 is part of the Windows 11 system requirements [c14a], so the chip in question is not specialist inventory, and refresh cycles will keep moving whether or not the certified tier exists. TCG's own advice points at the lifecycle rather than the purchase order: recognise the risk in platforms and TPMs that are not yet PQC-ready, plan for it, and work out where quantum-safe primitives are genuinely required and where transition planning is enough [15]. Read that way, the upgradable designation is worth only as much as the vendor's upgrade commitment, which is a contract term, not a chip property.

The sequencing is the part to hold onto. Designations arrived first; certification requirements for a TCG-certified PQC-ready TPM come only after TCG finishes enhancing its programs [7]. Hardware bought in between will be judged on evidence packets measured against a public document, which is a real improvement on an adjective and is not a test result [18]. The written baseline does not verify anything by itself. It just means that when a vendor says quantum-safe, there is now a specific document number the answer can be checked against, and a specific silence when the answer avoids it.

What to watch

  • Publication of the TCG-certified 'TCG PQC-ready TPM' requirements, and whether certification covers the whole profile or only selected parts of it.
  • Whether vendors disclose which optional PQC algorithms they implement above the 1.07 floor, or leave 'PQC-ready' as the only line on the datasheet.
  • Whether silicon shipping now is declared PQC-upgradable with a dated, contractual firmware path rather than a stated intention.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence54
Adoption22
Hype gap+24
Incentives66
Confidence57
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe, so buyers can ask a vendor for evidence against a written baseline and avoid TPMs that advertise compliance without full capability.

  2. [2]

    TCG released the new guidance on August 24, and it accompanies PTP 1.07 by helping businesses verify whether their TPMs meet the profile's requirements, according to Infosecurity Magazine.

  3. [3]

    TCG states the critical requirement for a PQC-ready TPM is implementation of the TCG PC Client Platform TPM Profile (PTP) 1.07, which is the baseline for a PQC-ready TPM.

Sources

2 independent publishers whose own reporting we read for this story.

  1. helpnetsecurity.com

    1 article · August 24, 2026

    New TCG guidance gives buyers a way to test PQC-ready TPM claims
  2. infosecurity-magazine.com

    1 article · August 24, 2026

    New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories