The Trusted Computing Group has established a new set of requirements to help organizations determine if Trusted Platform Modules are prepared for the era of post-quantum cryptography.
This guidance provides a technical benchmark for evaluating whether hardware vendors can protect electronic devices against the future threat of quantum-enabled cyber attacks.
Establishing the Post-Quantum Baseline The newly released guidance provides a framework for businesses to verify the security claims made by hardware manufacturers.
By creating a standardized set of requirements, the organization ensures that companies can demand proof of protection.
This prevents a situation where vendors might claim their products are compliant without offering the full suite of necessary security features.
A primary focus of this initiative is the PC Client Platform TPM Profile 1.07.
This profile serves as the minimum technical requirement for any module to be considered ready for the next generation of cryptographic challenges.
It builds upon the existing TPM 2.0 Library Specification Version 1.85 to include specific elements for quantum-safe protection.
Organizations must understand that security in the quantum age involves more than just swapping out one mathematical algorithm for another.
True resilience requires a comprehensive approach to hardware-anchored trust.
This includes maintaining the integrity of platform identities and attestation over very long periods.
Data and identities established today may need to remain secure for several decades.
If the underlying hardware is not built to withstand quantum decryption methods, that long-term security is at risk.
Current statistics indicate that a vast majority of businesses still lack a formal roadmap for this transition.
The Trusted Computing Group president, Joe Pennisi, emphasizes that businesses must look at the broader picture of security.
Individual algorithm support is only one piece of the puzzle.
Real security comes from a hardware-anchored root of trust that can handle the complex demands of quantum-safe attestation and platform integrity.
Defining Readiness and Upgradability To simplify the transition for IT managers and developers, the organization has introduced two specific designations for hardware modules.
These categories help clarify exactly what a piece of hardware is capable of at the time of purchase or deployment.
This categorization is vital for lifecycle management and long-term procurement planning.
The first designation is the PQC-ready TPM.
This label applies to any module that currently implements the full requirements of the PC Client Platform TPM Profile 1.07.
These devices are prepared out of the box to handle the specific cryptographic demands of a post-quantum environment.
The second designation is the PQC-upgradable TPM.
This category includes hardware that does not currently support the 1.07 profile but has the internal capability to receive firmware or software updates to meet those standards later.
This distinction helps businesses protect their existing investments while planning for future security needs.
By using these clear definitions, the organization aims to bring a sense of order to the market.
Vendors can no longer use vague marketing terms to describe their readiness.
Instead, they must align with these specific technical designations to prove their hardware can withstand modern and future threats.
This structured approach also allows vendors to innovate beyond the minimum requirements.
While the 1.07 profile defines the baseline, manufacturers are free to include additional optional algorithms.
This competition can lead to even stronger security implementations over time as the industry moves away from vulnerable legacy systems.
The shift toward these new standards is a critical step for global digital infrastructure.
As quantum computers become more powerful, the window for transitioning traditional encryption shrinks.
Having a clear path for hardwa