As cryptographic requirements evolve, organizations require a clear view of how Trusted Platform Modules (TPMs) support long‑term device identity, attestation, integrity and hardware‑anchored trust. PQC readiness must be part of broader lifecycle planning, especially for TPMs that will remain in service for years.
With cryptographically-relevant quantum computers on the horizon, one key question has emerged: what does it actually mean for a TPM to be post-quantum ready?
Now more than ever, it’s essential that businesses no longer treat PQC as a single feature, but actively assess current and planned TPM capabilities, secure update paths, identity, attestation and cryptographic agility. To do this successfully, they need a baseline to compare against: a minimum set of requirements for a PQC-ready TPM.
What are the requirements for a PQC-ready TPM?Simply put, the crucial element of a PQC-ready TPM is conformance to the TCG PC Client Platform TPM Profile 1.07 (PTP 1.07). A key security specification for TPM 2.0, PTP 1.07 will serve as the industry’s authoritative baseline for defining the minimum set of requirements for a PQC-ready TPM. It incorporates the post-quantum requirements defined in the Trusted Platform Module 2.0 v1.85 Library specification, and Errata. The specific PQC additions focus on support for the ML-KEM and ML-DSA standardized algorithms, and clearly distinguish between mandatory and optional commands and algorithm parameter sets.
Because the Trusted Computing Group (TCG) understands that this transition period to PQC is challenging, it is also working to bring clarity to it. From a functional standpoint, TCG is describing those TPMs that fully meet the PTP 1.07 specification as PQC-ready. However, we recognize that TPMs may exist in the market that don’t fully meet these requirements now but are capable of being upgraded in the field to full PQC-ready status. TPMs that do not currently meet the full PTP 1.07 capabilities, but can be securely upgraded in the field to meet them, are being described as PQC-upgradeable TPMs. This upgrade process itself must be quantum-safe to ensure that the upgrade process is immune to attacks on any compromised, non-PQC algorithms.
Therefore, in short:
Finally, TCG is actively updating its TPM certification program to certify TPMs that meet PTP 1.07 requirements. Once this is available, TCG PQC-ready TPMs can be evaluated for TCG certification by meeting the anticipated, formal TCG compliance and security evaluation criteria.
Providing the baseline for PQC-TPM readiness
This information provides organizations with a practical methodology to evaluate vendor claims and avoid misleading marketing. With these categories defined, procurement teams can identify their device requirements, ensuring that the systems they procure meet the necessary PQC functionality.
The transition to PQC is one of the most significant cryptographic shifts in decades. By clearly defining TPM PQC capabilities and updating the TCG TPM certification program, TCG is helping platform providers and customers with a simple, actionable framework for navigating this change.
FAQ section:
I have a TCG PQC-ready TPM – is my platform PQC-ready?
A TCG PQC-ready TPM only ensures that the TPM on your platform meets TCG’s PQC requirements for a TPM. Any other PQC requirements on your platform may be independent of the TPM capabilities.
Does the inclusion of additional PQC algorithms in my TCG PQC-ready TPM impact the PQC-ready claim?
No. Optional algorithms do not alter the TPM’s ability to claim being PQC-ready. The presence of optional algorithms, as defined in the PTP 1.07 specification, does not impact the TPM’s ability to claim compliance with this specification.
When will the TCG certification programs be available for certifying a TCG PQC-ready TPM?
TCG is continuing to work on updating the TPM Certification requirements to support TPMs that meet the PTP 1.07 specification. TCG will announce the availability of the TPM certification program for these TPMs once is it available.
Membership in the Trusted Computing Group is your key to participating with fellow industry stakeholders in the quest to develop and promote trusted computing technologies.
Standards-based Trusted Computing technologies developed by TCG members now are deployed in enterprise systems, storage systems, networks, embedded systems, and mobile devices and can help secure cloud computing and virtualized systems.
Trusted Computing Group announced that its TPM 2.0 (Trusted Platform Module) Library Specification was approved as a formal international standard under ISO/IEC (the International Organization for Standardization and the International Electrotechnical Commission). TCG has 90+ specifications and guidance documents to help build a trusted computing environment.