Skip to content

BuildNot yet confirmed elsewhere1 publisher2 min readPublished

TCG hands hardware buyers a version number: PC Client TPM Profile 1.07

The Trusted Computing Group has turned post-quantum readiness into something a purchase order can check. It also coined a label that means the part is not compliant yet.

The Engineer · Build desk

How we use AISend a correction

What happened

  • The Trusted Computing Group has published requirements for judging whether a Trusted Platform Module is prepared for post-quantum cryptography.
  • PC Client Platform TPM Profile 1.07 is named as the minimum technical bar for a module to count as ready.
  • Two designations now exist: PQC-ready for modules implementing 1.07 today, and PQC-upgradable for those that could get there by firmware or software update.
  • TCG president Joe Pennisi frames algorithm support as one piece only, with the real requirement being a hardware-anchored root of trust for attestation and platform integrity.

Why it matters

  • capability A version number can be a contract term in a way an adjective cannot, so a buyer can now refuse a part on a datasheet check rather than argue about how a vendor uses the word quantum-safe.
  • exposure Anything bought as PQC-upgradable is non-conforming on delivery, and with no update schedule in the guidance, the timing risk sits with whoever signed the order.
  • constraint With certification still pending, the profile narrows the argument without settling it: buyers can name 1.07 but cannot yet point to an independent mark that proves it.
  • precedent Permitting optional algorithms above the baseline gives marketing somewhere new to stand, so expect claims of exceeding 1.07 in place of claims of meeting it.

The useful part of this is a string. "PC Client Platform TPM Profile 1.07" fits on a purchase order line, and a part either implements it or it does not. The profile also names what it sits on, the TPM 2.0 Library Specification version 1.85 [4], so a buyer ends up checking two version numbers against a datasheet instead of reading vendor prose about quantum safety, which is the stated point of publishing the requirements at all [2].

The second label is where the exposure sits. By the guidance's own definitions, a part sold as PQC-upgradable is a part that does not meet the profile on the day it lands on your dock [12]. That can still be a good deal, and it gives existing hardware a route forward, but the account of the guidance sets out no schedule for the update and no consequence if it never ships [15]. A promise of future firmware becomes a supplier obligation only when someone writes the designation, the profile version, and a date into the contract.

There is also a gap between the specification and the mark. TCG says it will extend certification to modules meeting the PQC-ready criteria, which concedes that conformance to 1.07 is currently a claim a vendor makes about itself [13]. No date appears for when those programs start operating [14]. Until they do, the profile number is a better question than the ones it replaces rather than an answer.

The easiest thing to underrate here is the attestation language. TCG's framing is that resilience is not one algorithm swapped for another, and that platform identities and attestation must hold their integrity over very long periods [11]. Identities minted this year may need to remain secure for decades [8], which outlasts the refresh cycle of nearly everything they are soldered into. The upgradable designation is exactly where that mismatch lands: a decades-long trust assumption resting on a firmware update that has not shipped.

One line in the write-up deserves less weight than the specification does. It states that a vast majority of businesses still lack a formal roadmap for the transition, with no figure, survey, or date attached [16]. The profile is checkable. That sentence is not.

What to watch

  • A start date for the expanded certification programmes, and whether the mark covers PQC-upgradable parts or only PQC-ready ones.
  • Whether TPM vendors publish which optional 1.07 algorithms they actually enable, or stop at quoting the profile number.
  • Whether any PC or server OEM writes Profile 1.07 into its own platform requirements, which is what would move the profile from guidance to purchasing reality.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence34
Adoption
Insufficient
Hype gap+32
Incentives62
Confidence42
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The Trusted Computing Group has established a new set of requirements to help organizations determine whether Trusted Platform Modules are prepared for the era of post-quantum cryptography.

    ReportedSupportedSource: dev.to account of TCG guidanceView cited source
  2. [2]

    The guidance is presented as a framework for businesses to verify security claims made by hardware manufacturers and to demand proof of protection, rather than accepting vendor compliance claims.

    ReportedSupportedView cited source
  3. [3]

    The PC Client Platform TPM Profile 1.07 serves as the minimum technical requirement for a module to be considered ready for post-quantum cryptographic challenges.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · August 25, 2026

    TPM Requirements for Post-Quantum Cryptography Readiness

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories