SecurityIndependently confirmed2 publishers3 min readPublished
TCG writes down what "quantum-safe TPM" means, and buyers finally get a document to argue with
The Trusted Computing Group's baseline is PTP 1.07, with two readiness labels and a certification tier still to come. Until that lands, verification means reading a vendor's evidence packet.
The Watch · Security desk
What happened
- TCG has published requirements setting out what a TPM must do before anyone calls it quantum-safe, so buyers can request vendor evidence against a written baseline.
- The baseline is the PC Client Platform TPM Profile 1.07, which pins the required PQC elements drawn from TPM 2.0 Library Specification 1.85.
- Two designations now describe hardware state: PQC-ready TPMs implement 1.07, PQC-upgradable ones do not yet but can be brought to it.
Why it matters
- constraint With no certified tier yet, the verification work sits with the buyer's own reviewers reading a vendor evidence packet, not with an independent lab result they can file.
- decision Specifications now have to name the optional algorithms a fleet actually needs, because asking only for PQC-ready buys a floor whose contents vary between suppliers.
- exposure The 90% of businesses TCG says have no formal PQC roadmap are the constituency expected to use this, and without a roadmap there is no schedule to hang the evidence request on.
- contradiction The two write-ups cite different underlying version numbers for TPM 2.0, so an RFP that names a library version instead of PTP 1.07 risks pointing at the wrong document.
A TPM holds a machine's keys and records measurements of its firmware, so the platform can later prove it has not been altered [8]. That is why a single algorithm name was never a useful answer to a procurement question. Platform identities, attestation keys and firmware measurements are three different objects that have to survive the same transition, and TCG says they may need to remain secure for decades [9]. TCG president Joe Pennisi frames the requirement as looking "beyond individual algorithm support" to "the broader requirements for quantum-safe identities, attestation, and hardware-anchored trust" [11]. The failure mode TCG names is more specific than that: TPMs that advertise compliance while failing to provide full, end-to-end security capabilities [10].
The profile behind the new guidance was not drafted narrowly. Infosecurity Magazine reports that TCG brought together almost 90 contributors in March 2026, from government, academia, semiconductor companies and computing hardware providers including Intel, Google, Hewlett Packard Enterprise, Microsoft, NVIDIA, Lenovo and STMicroelectronics, to develop PTP 1.07 [13]. So the vendors a buyer will now ask for evidence are substantially the vendors who set the bar. That is normal for hardware standards, and it is also the case for the certification tier: an evidence request answered by the author of the requirement carries less weight than a result from a third party. About five months separated the drafting work from the guidance that tells buyers how to check against it [19].
Scale is what makes the interval matter. TPM 2.0 is part of the Windows 11 system requirements [c14a], so the chip in question is not specialist inventory, and refresh cycles will keep moving whether or not the certified tier exists. TCG's own advice points at the lifecycle rather than the purchase order: recognise the risk in platforms and TPMs that are not yet PQC-ready, plan for it, and work out where quantum-safe primitives are genuinely required and where transition planning is enough [15]. Read that way, the upgradable designation is worth only as much as the vendor's upgrade commitment, which is a contract term, not a chip property.
The sequencing is the part to hold onto. Designations arrived first; certification requirements for a TCG-certified PQC-ready TPM come only after TCG finishes enhancing its programs [7]. Hardware bought in between will be judged on evidence packets measured against a public document, which is a real improvement on an adjective and is not a test result [18]. The written baseline does not verify anything by itself. It just means that when a vendor says quantum-safe, there is now a specific document number the answer can be checked against, and a specific silence when the answer avoids it.
What to watch
- Publication of the TCG-certified 'TCG PQC-ready TPM' requirements, and whether certification covers the whole profile or only selected parts of it.
- Whether vendors disclose which optional PQC algorithms they implement above the 1.07 floor, or leave 'PQC-ready' as the only line on the datasheet.
- Whether silicon shipping now is declared PQC-upgradable with a dated, contractual firmware path rather than a stated intention.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence54
- Adoption22
- Hype gap+24
- Incentives66
- Confidence57
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe, so buyers can ask a vendor for evidence against a written baseline and avoid TPMs that advertise compliance without full capability.
- [2]
TCG released the new guidance on August 24, and it accompanies PTP 1.07 by helping businesses verify whether their TPMs meet the profile's requirements, according to Infosecurity Magazine.
- [3]
TCG states the critical requirement for a PQC-ready TPM is implementation of the TCG PC Client Platform TPM Profile (PTP) 1.07, which is the baseline for a PQC-ready TPM.
- [4]
PTP 1.07 defines the required PQC-specific elements from the recently published TPM 2.0 Library Specification Version 1.85, and defines TPM 2.0 implementations that support PQC algorithms.
- [5]
PTP 1.07 outlines the minimum requirements for PQC-ready TPMs; vendors developing TPMs may choose to implement additional optional PQC algorithms in their designs.
- [6]
TCG has defined two transition designations: a 'TCG PQC-ready TPM' implements PTP 1.07, and a 'TCG PQC-upgradable TPM' does not presently support PTP 1.07 but has the capability to be upgraded to that support.
- [7]
TCG has announced plans to enhance its certification programs to certify TPMs that meet the requirements of PTP 1.07; once completed, it will define and provide the requirements for a TCG-certified 'TCG PQC-ready TPM'.
- [8]
A TPM is the chip that holds a machine's keys and records measurements of its firmware, so the platform can later prove it has not been altered.
- [9]
Key security elements such as platform identities, attestation keys, and firmware measurements may need to remain secure for decades.
- [10]
Not all TPMs currently on the market provide quantum-safe encryption options, and some advertise 'compliance' yet fail to provide full, end-to-end security capabilities.
- [11]
TCG President Joe Pennisi said businesses will need to look beyond individual algorithm support and understand the broader requirements for quantum-safe identities, attestation, and hardware-anchored trust.
- [12]
TCG's guidance states that 90% of businesses still lack a formal PQC roadmap.
- [13]
In March 2026 TCG brought together almost 90 contributors from government, academia, semiconductor companies and computing hardware providers, including Intel, Google, Hewlett Packard Enterprise, Microsoft, NVIDIA, Lenovo and STMicroelectronics, to develop PTP 1.07.
- [15]
TCG advises organizations to recognize the risks facing platforms and TPMs that are not yet PQC-ready, plan for that risk as part of a broader security lifecycle, and understand where quantum-safe primitives are required and where transition planning is needed.
- [16]
Because the designations describe hardware capability while the certification requirements are still to be defined, a PQC-ready claim today is vendor evidence measured against a published document rather than a third-party test result.
- [17]
Since PTP 1.07 is a minimum and optional PQC algorithms are left to vendor discretion, two TPMs that both qualify as PQC-ready need not implement the same algorithm set.
- [18]
Hardware purchased between the guidance release and the arrival of the certified tier will be assessed on vendor evidence against PTP 1.07 rather than on certification.
- [19]
Roughly five months separated the March 2026 development of PTP 1.07 from the August 24 release of the guidance for verifying against it.
- [20]
Infosecurity Magazine states that TCG has published version 1.2 of its specifications for second-generation TPMs (TPM 2.0).
- [21]
The two reports cite different version numbers around TPM 2.0: one says PTP 1.07 draws its PQC elements from TPM 2.0 Library Specification 1.85, the other says TCG published version 1.2 of its TPM 2.0 specifications.
Sources
2 independent publishers whose own reporting we read for this story.
- helpnetsecurity.comNew TCG guidance gives buyers a way to test PQC-ready TPM claims
1 article · August 24, 2026
- infosecurity-magazine.comNew Guidance Helps Businesses Verify Quantum-Safe Hardware Claims
1 article · August 24, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Vendor Claim VerificationFollow
- Hardware Root of Trust and AttestationFollow
- Security Standards and CertificationFollow
- Post-Quantum CryptographyFollow
Entities
- GoogleFollow
- STMicroelectronicsFollow
- MicrosoftFollow
- Trusted Computing GroupFollow
- TCG PC Client Platform TPM Profile (PTP) 1.07Follow
- NvidiaFollow
- Trusted Platform ModuleFollow
- Joe PennisiFollow
- Windows 11Follow
- LenovoFollow
- Hewlett Packard EnterpriseFollow
- TPM 2.0 Library Specification Version 1.85Follow
- IntelFollow