The Trusted Computing Group (TCG) has released new guidance that establishes a baseline for what constitutes a "quantum-safe" Trusted Platform Module (TPM), enabling buyers to verify vendor claims of Post-Quantum Cryptography (PQC) readiness. This initiative aims to provide clarity for organizations seeking to implement PQC capabilities and avoid products that offer only partial security.
A TPM is a specialized chip designed to securely store cryptographic keys and measure firmware integrity, ensuring a platform has not been tampered with. The TCG's new requirements allow companies to request specific evidence from vendors to confirm that their TPM products genuinely meet essential PQC criteria, rather than merely advertising compliance without providing full, end-to-end security.
The TCG emphasizes that understanding what a PQC-ready TPM entails goes beyond individual algorithm support. It encompasses broader requirements for quantum-safe identities, attestation, and hardware-anchored trust, which are critical as cryptographic standards evolve. Key security elements like platform identities, attestation keys, and firmware measurements may need to remain secure for decades, necessitating a clear plan for PQC transition.
The foundational document for defining a PQC-ready TPM is the TCG PC Client Platform TPM Profile (PTP) 1.07. This profile specifies TPM 2.0 implementations that support PQC algorithms to deliver quantum-safe cryptographic protection. PTP 1.07 serves as the minimum baseline, outlining the PQC-specific elements derived from the recently published TPM 2.0 Library Specification Version 1.85. While PTP 1.07 defines the minimum, vendors may choose to integrate additional optional PQC algorithms into their designs.
To structure the transition to PQC, the TCG has defined two designations for a platform's ability to adopt PQC capabilities as specified by PTP 1.07. A "TCG PQC-ready TPM" is one that fully implements PTP 1.07. In contrast, a "TCG PQC-upgradable TPM" does not currently support PTP 1.07 but possesses the capability to be upgraded to meet these requirements.
The TCG also plans to enhance its existing certification programs to include specific certifications for TPMs that comply with PTP 1.07. Once these enhancements are complete, the organization will define and provide the requirements for a "TCG-certified PQC-ready TPM." This move is particularly relevant given that an estimated 90% of businesses currently lack a formal PQC roadmap, highlighting the urgent need for structured guidance in this area.






