Building the next generation of trusted computing experts

Date Published: September, 23, 2026

As the cybersecurity workforce faces a growing mismatch between available talent and the practical skills organizations need, education around trusted computing has never been more important.

With cyberattacks growing more complex and increasingly targeting the foundational layers of modern computing systems – from firmware and boot processes to hardware supply chains – the cybersecurity frameworks being taught to students must now extend beyond application security, cloud security, or threat detection to cover the key trust mechanisms that underpin foundational secure computing.

This is where we hope the Trusted Computing Group (TCG) can make an impact. Through a combination of university engagement, hands-on training courses through our multi-year partnership with OpenSecurityTraining2 (OST2) and the provision of other opportunities, we are helping to shape the next generation of security professionals who will not only understand how to defend systems but also ensure they are trustworthy too.

Trusted computing in the classroom

Our visit to the University of North Carolina Wilmington earlier this year demonstrates this mission perfectly. During our time on the campus, TCG member Thorsten Stremlau delivered an insightful, practical introduction to trusted computing, connecting academic cybersecurity curriculum to real-world security implementations.

Instead of focusing solely on the available standards, our presentation addressed a critical gap in traditional cybersecurity teachings. While most courses emphasize applications, networks and general cloud security, we instead focused on the root of all these measures – the importance of trust, and how it must be established long before operating systems boot up.

By explaining concepts such as measured boot, secret sealing and attestation workflows, students were introduced to Hardware Roots of Trust (RoTs) like the Trusted Platform Module (TPM), Device Integrity Composition Engine (DICE) and Block Integrated Trust (BIT) – as well as Platform Configuration Registers (PCRs) – and capabilities such as device identity and remote attestation. The session reinforced the message that cybersecurity must move beyond the prevention of attacks to focus on ensuring verifiable integrity and other cornerstones of trusted computing.

Additionally, it also emphasised that developing skills in these areas can help the students differentiate themselves professionally, especially as potential employers are increasingly seeking expertise in firmware security, supply chain trust and system integrity.

The current threat landscape

As mentioned, this is because hackers now target the integrity of systems as well as any software vulnerabilities. Firmware tampering, supply chain compromise, and attacks operating below the visibility of the operating system can take effect before conventional defense systems even load up. For example, third party and supply chain breaches doubled to 30% of all incidents in 2025 – a 100% year‑over‑year increase.

This is why TCG is pushing for the inclusion of trusted computing material within courses – if students can learn to configure and utilize the capabilities afforded through TPM, DICE and BIT usage, then their employers will in turn benefit from more secure cryptographic identities, protected key storage, measurement capabilities, and remote attestation – all of which enable devices systems to provide the assurance required that they are operating reliably in a trusted state, rather than having to assume so.

With TPMs now deployed in over 2 billion devices worldwide, the need for professionals who understand how to use them effectively has never been greater. However, implementing TPM based security still requires specialized knowledge that many developers and security professionals never encounter during formal education.

Establishing dedicated training courses

Consequently, TCG has been partnering with OST2 since 2024, utilizing their experience to develop and launch a series of foundational training courses on trusted computing. This collaboration has since expanded into a structured, practical learning pathway that guides newcomers into the ecosystem and aims to close the growing skills gap.

The first course introduced was Trusted Computing 1101, an introductory course that details the fundamentals of how a TPM works at the hardware level with hands-on experiences covering secure key storage, digital signing, and secret sealing. Following a positive reception to this offering, Trusted Computing 1102 was then developed to introduce more advanced concepts like Enhanced System Application Programming Interfaces (APIs), endorsement keys, TPM policies, and how to use PCRs for both machine learning and attestation applications.

In 2025, the curriculum was expanded to include TPM 2.0 programming using Python and the tpm2-pytss libraries, helping students move from understanding TPM concepts to actively building software that integrates trusted computing into real applications. More recently, the Trusted Computing course was expanded again to 1103, with an advanced focus on TPM backed application deployment. With this course, participants learn how to generate TPM protected keys, define TPM policies and build secure applications with greater speed and confidence.

The success of these courses will soon see other TCG specifications and technologies come under focus, so stay tuned for further updates from both organizations regarding this.

Expanding our educational materials

Of course, our commitment to education extends beyond professional courses. Last year, for example, we launched a series of educational overviews focused on several of our core trusted computing technologies. Found under our resources tab, these one-pagers act as a high-level yet authoritative resource to help people better understand foundational concepts and select the most appropriate security offerings for their requirements.

Our foundational specifications – including RoTs like the TPM (both physical and virtual) and DICE – are covered in order to provide some initial insights prior to any academic study or rapidly evolving industry practices. We are also creating sector-specific materials to highlight the role these specifications can play within key industries, but especially those which now find themselves increasingly under attack.

We are also engaging in landscape reporting to educate the ecosystem on key topics like post-quantum cryptography (PQC). Launched in November 2025, the ‘State of PQC Readiness’ report served as a wake-up call, using real industry data that highlighted how most organizations’ preparations for PQC remain uneven and incomplete. This evidence-based report will help the industry understand the urgency of PQC migration, and by educating people on these gaps, we aim to encourage organizations to take meaningful steps towards a secure future – one in which trusted computing will play a crucial role.

Looking ahead

TCG’s engagement at institutions like the UNC Wilmington provides evidence that the core trusted computing concepts can be brought directly into the classroom. By supporting educators as they introduce students to hardware‑rooted trust, secure system design, and security‑by‑design principles, TCG is helping equip the next generation with skills that are becoming essential across industries.

At the same time, the bank of educational materials we continue to develop is showcasing our organization’s importance across key areas of computing, including the emergence of AI infrastructure, confidential computing and PQC. Working together with OST2, involving more universities, and creating free educational materials all mean we are making sure that more people understand and adopt trusted computing principles. Only then can we build a global community capable of implementing them efficiently.

Join

Membership in the Trusted Computing Group is your key to participating with fellow industry stakeholders in the quest to develop and promote trusted computing technologies.

Join Now

Trusted Computing

Standards-based Trusted Computing technologies developed by TCG members now are deployed in enterprise systems, storage systems, networks, embedded systems, and mobile devices and can help secure cloud computing and virtualized systems.

Read more

Specifications

Trusted Computing Group announced that its TPM 2.0 (Trusted Platform Module) Library Specification was approved as a formal international standard under ISO/IEC (the International Organization for Standardization and the International Electrotechnical Commission). TCG has 90+ specifications and guidance documents to help build a trusted computing environment.

Read More