LIVE · cybersecurity feed
Live wire
security

New TCG guidance gives buyers a way to test PQC-ready TPM claims

The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the platform can later prove it has not been altered. Buyers can now ask a vendor for evidence against a written baseline. TCG’s requirements for Trusted Platfor

zeroday.news ·

The Trusted Computing Group (TCG) has released new guidance that establishes a baseline for what constitutes a "quantum-safe" Trusted Platform Module (TPM), enabling buyers to verify vendor claims of Post-Quantum Cryptography (PQC) readiness. This initiative aims to provide clarity for organizations seeking to implement PQC capabilities and avoid products that offer only partial security.

A TPM is a specialized chip designed to securely store cryptographic keys and measure firmware integrity, ensuring a platform has not been tampered with. The TCG's new requirements allow companies to request specific evidence from vendors to confirm that their TPM products genuinely meet essential PQC criteria, rather than merely advertising compliance without providing full, end-to-end security.

The TCG emphasizes that understanding what a PQC-ready TPM entails goes beyond individual algorithm support. It encompasses broader requirements for quantum-safe identities, attestation, and hardware-anchored trust, which are critical as cryptographic standards evolve. Key security elements like platform identities, attestation keys, and firmware measurements may need to remain secure for decades, necessitating a clear plan for PQC transition.

The foundational document for defining a PQC-ready TPM is the TCG PC Client Platform TPM Profile (PTP) 1.07. This profile specifies TPM 2.0 implementations that support PQC algorithms to deliver quantum-safe cryptographic protection. PTP 1.07 serves as the minimum baseline, outlining the PQC-specific elements derived from the recently published TPM 2.0 Library Specification Version 1.85. While PTP 1.07 defines the minimum, vendors may choose to integrate additional optional PQC algorithms into their designs.

To structure the transition to PQC, the TCG has defined two designations for a platform's ability to adopt PQC capabilities as specified by PTP 1.07. A "TCG PQC-ready TPM" is one that fully implements PTP 1.07. In contrast, a "TCG PQC-upgradable TPM" does not currently support PTP 1.07 but possesses the capability to be upgraded to meet these requirements.

The TCG also plans to enhance its existing certification programs to include specific certifications for TPMs that comply with PTP 1.07. Once these enhancements are complete, the organization will define and provide the requirements for a "TCG-certified PQC-ready TPM." This move is particularly relevant given that an estimated 90% of businesses currently lack a formal PQC roadmap, highlighting the urgent need for structured guidance in this area.

ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

Cybersecurity jobs available right now: August 25, 2026

Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency requests, process subpoenas, warrants, and court orders, and provide authorized subscriber, location, and call record information while acting as custodian of

CVE-2026-69414

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection […]

nation-statecritical

US sanctions Iranian cyber actors as UK discloses power plant attack

The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

cloud

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.

CVE-2026-73570

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.

security

You don't want this Sleepwalker backdoor on your Windows machine

Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'