deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Trusted Computing Group defines PQC-ready and PQC-upgradable TPM requirements

The Trusted Computing Group has published TPM requirements for post-quantum cryptography, splitting hardware into PQC-ready and PQC-upgradable designations tied to PC Client Platform TPM Profile 1.07.

Trusted Computing Group defines PQC-ready and PQC-upgradable TPM requirements

The Trusted Computing Group (TCG) has published a new set of requirements for judging whether Trusted Platform Modules (TPMs) are prepared for post-quantum cryptography, giving hardware buyers a concrete benchmark they can hold vendors to. According to a dev.to article covering the announcement, the guidance centers on the PC Client Platform TPM Profile 1.07, which now serves as the minimum technical bar for a module to be considered ready for quantum-era threats.

Profile 1.07 sets the baseline

The new profile builds on the existing TPM 2.0 Library Specification version 1.85 and folds in specific elements for quantum-safe protection, the dev.to article explains. The stated goal is verifiability: with a standardized requirement set, organizations can demand proof that a module actually implements the needed features, closing off a scenario in which vendors market products as compliant while shipping only part of the required capability.

Two labels for buyers

To simplify procurement decisions, TCG introduced two designations for modules. A PQC-ready TPM ships with the full Profile 1.07 requirements implemented and can handle the cryptographic demands of a post-quantum environment from day one. A PQC-upgradable TPM does not yet meet the profile but has the internal capability to reach that standard later through firmware or software updates.

According to dev.to, the split is aimed at lifecycle management and long-term procurement planning, letting organizations preserve the value of hardware they already own while scheduling upgrades. It also narrows the space for vague marketing: vendors have to map their products to the specific designations rather than make loose claims of readiness. The baseline is explicitly a floor rather than a ceiling — manufacturers remain free to add optional algorithms beyond the minimum, which the report argues could drive competition toward stronger implementations as legacy systems are phased out.

Not just an algorithm swap

TCG president Joe Pennisi emphasized, as reported by dev.to, that quantum-age security requires a broader view: support for individual algorithms is only one piece, and real protection comes from a root of trust anchored in hardware that can handle quantum-safe attestation and platform integrity. Data and identities established today may need to remain secure for several decades, and that long-term protection fails if the underlying hardware cannot withstand quantum decryption methods. The article also cites statistics indicating that a large majority of businesses still lack a formal roadmap for the transition.

Certification is coming

TCG is not stopping at definitions. The organization plans to expand its existing certification programs so that modules meeting the PQC-ready criteria can be officially certified, according to the report. Details of the testing and validation procedures are still being finalized, with more information promised as the work progresses. Once operational, certification would give IT professionals a definitive signal to look for instead of forcing them to audit vendor specifications by hand.

Why it matters

TPMs are the quiet foundation beneath secure boot and encrypted storage across modern devices, so their readiness largely determines whether platform trust survives the shift to quantum-resistant cryptography. Profile 1.07 turns a theoretical migration problem into a procurement question: buyers can now specify PQC-ready or PQC-upgradable hardware in contracts, and engineers get a fixed technical target when designing new systems or upgrading old ones. As quantum computers grow more capable, the window for retiring quantum-vulnerable cryptography keeps shrinking. A published baseline, with certification to back it up, gives the industry a shared vocabulary and a head start on keeping the foundation of digital trust solid.

  • #security
  • #cryptography
  • #post-quantum
  • #hardware
  • #standards
  • #tpm

Related posts