In an era marked by the rapid advancement of quantum computing, organizations are increasingly prioritizing the need to secure their systems against potential threats from quantum-enabled attacks. In light of these developments, a significant question arises: How can organizations verify whether their hardware is indeed quantum-safe? The Trusted Computing Group (TCG) has stepped in to provide clarity, with a new industry benchmark aimed at addressing this concern.
On August 24, TCG published groundbreaking guidance designed to validate that trusted platform modules (TPMs) meet critical post-quantum cryptography (PQC) requirements. The TCG is a nonprofit organization dedicated to establishing vendor-neutral standards for hardware-based security products, including those crucial TPMs.
TPMs serve as specialized security chips embedded within a computer’s motherboard or processor, playing a vital role in securely storing passwords, digital certificates, and encryption keys. TCG has released version 1.2 of its specifications for second-generation TPMs (TPM 2.0), which are now integral to the system requirements for Windows 11. This development underscores TPMs’ essential role in bolstering security protocols across organizations as they seek to safeguard sensitive information.
The increasing prominence of TPMs can be attributed to their robust capabilities in maintaining trusted identities, platform integrity, and hardware-anchored security over extended periods. TCG highlighted that, as PQC algorithms are expected to evolve, the components involved must remain secure for decades. However, it’s important to note that not all TPMs on the market currently offer quantum-safe encryption options. Some might even claim “compliance” without providing comprehensive, end-to-end security capabilities.
In March 2026, TCG undertook a significant collaborative initiative, gathering nearly 90 contributors from diverse sectors, including government, academia, semiconductor firms, and computing hardware providers. Notable participants included giants like Intel, Google, Hewlett Packard Enterprise, Microsoft, NVIDIA, and Lenovo, among others. This collective effort was instrumental in the development of a standard aimed at PQ-ready TPMs, encapsulated in the TCG PC Client Platform TPM Profile (PTP) 1.07.
The recently released TCG standard document not only outlines the minimum requirements for PQC-ready TPMs but also introduces critical parameters for further evolution in the industry. In conjunction with this release, TCG published an accompanying guide to assist businesses in verifying whether their TPMs satisfy the specifications of PTP 1.07.
To facilitate clearer understanding and navigation through this landscape, TCG has established two distinct categories to delineate the readiness of TPMs for transition to post-quantum cryptography. The first designation, “TCG PQC-ready TPM,” applies to those modules that are fully compliant and already support the PQC capabilities described in PTP 1.07. The second classification, “TCG PQC-upgradable TPM,” refers to those units that do not currently meet the criteria of PTP 1.07 but are designed with the ability to be upgraded to achieve that compliance.
These classifications offer organizations a straightforward mechanism to gauge where they stand in the transition toward PQC, enabling them to make informed decisions regarding their security infrastructure. Furthermore, TCG has announced plans to bolster its certification programs aimed specifically at certifying TCG PQC-ready TPMs, ensuring that businesses can confidently adopt hardware that meets rigorous quantum-security standards.
The initiative from TCG represents a significant leap forward in the ongoing battle against potential threats posed by quantum computing. By providing a roadmap for organizations to assess the PQC capabilities of their TPMs, TCG is helping to pave the way for a more secure digital future. As quantum technology continues to evolve, the importance of such standards will only become more pronounced, underscoring the necessity for proactive measures in safeguarding sensitive data against potential vulnerabilities.
As organizations navigate the complexities of integrating quantum safety into their operational frameworks, TCG’s guidance offers a timely and essential resource, promoting a collective shift towards enhanced security and resilience in an increasingly uncertain technological landscape.
