BuildNot yet confirmed elsewhere1 publisher2 min readPublished
TCG hands hardware buyers a version number: PC Client TPM Profile 1.07
The Trusted Computing Group has turned post-quantum readiness into something a purchase order can check. It also coined a label that means the part is not compliant yet.
The Engineer · Build desk
What happened
- The Trusted Computing Group has published requirements for judging whether a Trusted Platform Module is prepared for post-quantum cryptography.
- PC Client Platform TPM Profile 1.07 is named as the minimum technical bar for a module to count as ready.
- Two designations now exist: PQC-ready for modules implementing 1.07 today, and PQC-upgradable for those that could get there by firmware or software update.
- TCG president Joe Pennisi frames algorithm support as one piece only, with the real requirement being a hardware-anchored root of trust for attestation and platform integrity.
Why it matters
- capability A version number can be a contract term in a way an adjective cannot, so a buyer can now refuse a part on a datasheet check rather than argue about how a vendor uses the word quantum-safe.
- exposure Anything bought as PQC-upgradable is non-conforming on delivery, and with no update schedule in the guidance, the timing risk sits with whoever signed the order.
- constraint With certification still pending, the profile narrows the argument without settling it: buyers can name 1.07 but cannot yet point to an independent mark that proves it.
- precedent Permitting optional algorithms above the baseline gives marketing somewhere new to stand, so expect claims of exceeding 1.07 in place of claims of meeting it.
The useful part of this is a string. "PC Client Platform TPM Profile 1.07" fits on a purchase order line, and a part either implements it or it does not. The profile also names what it sits on, the TPM 2.0 Library Specification version 1.85 [4], so a buyer ends up checking two version numbers against a datasheet instead of reading vendor prose about quantum safety, which is the stated point of publishing the requirements at all [2].
The second label is where the exposure sits. By the guidance's own definitions, a part sold as PQC-upgradable is a part that does not meet the profile on the day it lands on your dock [12]. That can still be a good deal, and it gives existing hardware a route forward, but the account of the guidance sets out no schedule for the update and no consequence if it never ships [15]. A promise of future firmware becomes a supplier obligation only when someone writes the designation, the profile version, and a date into the contract.
There is also a gap between the specification and the mark. TCG says it will extend certification to modules meeting the PQC-ready criteria, which concedes that conformance to 1.07 is currently a claim a vendor makes about itself [13]. No date appears for when those programs start operating [14]. Until they do, the profile number is a better question than the ones it replaces rather than an answer.
The easiest thing to underrate here is the attestation language. TCG's framing is that resilience is not one algorithm swapped for another, and that platform identities and attestation must hold their integrity over very long periods [11]. Identities minted this year may need to remain secure for decades [8], which outlasts the refresh cycle of nearly everything they are soldered into. The upgradable designation is exactly where that mismatch lands: a decades-long trust assumption resting on a firmware update that has not shipped.
One line in the write-up deserves less weight than the specification does. It states that a vast majority of businesses still lack a formal roadmap for the transition, with no figure, survey, or date attached [16]. The profile is checkable. That sentence is not.
What to watch
- A start date for the expanded certification programmes, and whether the mark covers PQC-upgradable parts or only PQC-ready ones.
- Whether TPM vendors publish which optional 1.07 algorithms they actually enable, or stop at quoting the profile number.
- Whether any PC or server OEM writes Profile 1.07 into its own platform requirements, which is what would move the profile from guidance to purchasing reality.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+32
- Incentives62
- Confidence42
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The Trusted Computing Group has established a new set of requirements to help organizations determine whether Trusted Platform Modules are prepared for the era of post-quantum cryptography.
- [2]
The guidance is presented as a framework for businesses to verify security claims made by hardware manufacturers and to demand proof of protection, rather than accepting vendor compliance claims.
- [3]
The PC Client Platform TPM Profile 1.07 serves as the minimum technical requirement for a module to be considered ready for post-quantum cryptographic challenges.
- [4]
Profile 1.07 builds upon the existing TPM 2.0 Library Specification Version 1.85, adding specific elements for quantum-safe protection.
- [5]
The PQC-ready TPM designation applies to any module that currently implements the full requirements of the PC Client Platform TPM Profile 1.07.
- [6]
The PQC-upgradable TPM designation covers hardware that does not currently support the 1.07 profile but has the internal capability to receive firmware or software updates to meet those standards later.
- [7]
TCG president Joe Pennisi says individual algorithm support is only one piece of the puzzle, and that real security comes from a hardware-anchored root of trust able to handle quantum-safe attestation and platform integrity.
ReportedSupportedSource: Joe Pennisi, president, Trusted Computing Group, as reported by dev.toView cited source - [8]
Data and identities established today may need to remain secure for several decades.
- [9]
TCG has announced plans to expand its existing certification programs so that modules meeting the PQC-ready criteria can be officially certified.
- [10]
While the 1.07 profile defines the baseline, manufacturers are free to include additional optional algorithms beyond the minimum requirements.
- [11]
The guidance holds that security in the quantum age is more than swapping one mathematical algorithm for another, and requires maintaining the integrity of platform identities and attestation over very long periods.
- [12]
A part carrying the PQC-upgradable designation is, by definition, a part that does not meet Profile 1.07 at the time of purchase or delivery.
- [13]
Because certification of PQC-ready modules is announced as a future expansion rather than an operating programme, conformance to Profile 1.07 currently rests on vendor self-declaration.
- [14]
The source material gives no date for when the expanded certification programmes will be operational.
- [15]
The source material sets out no schedule for PQC-upgradable parts to receive their updates and no stated consequence if the update never arrives.
- [16]
The write-up states that current statistics indicate a vast majority of businesses still lack a formal roadmap for the post-quantum transition, without giving a figure, a survey, or a date.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toTPM Requirements for Post-Quantum Cryptography Readiness
1 article · August 25, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Standards and CertificationFollow
- Hardware Root of Trust and AttestationFollow
- Security Procurement and Lifecycle PlanningFollow
- Post-Quantum CryptographyFollow