TCG Platform Requirements for Certificates and RIMs (PRCR)
The TCG Platform Requirements for Certificates and RIMs (PRCR) specification defines how platform suppliers provide Platform Certificates and Reference Integrity Manifests (RIMs) so customers can verify the integrity and composition of enterprise PC clients and servers.
What Problem PRCR Solves
Enterprise customers need to determine whether a system’s hardware or firmware has been modified in transit, and whether any approved customizations (including those performed by value-added resellers) are authentic and traceable. PRCR standardizes the artifacts that allow these integrity checks to be repeatable and scalable across vendors and fleets.
What Artifacts are Covered
PRCR focuses on two supplier-provided inputs used during verification:
- Platform Certificates that describe the platform’s hardware composition and associated supplier assertions.
- Platform and/or Component RIMs that describe expected firmware measurements and composition for the platform and relevant components.
Relationship to NIST Guidance
- PRCR supports the goals described in NIST SP 1800-34 (Validating the Integrity of Computing Devices) by standardizing supplier deliverables (certificates and manifests) that can be used in device integrity validation workflows.
- PRCR also builds on prior work aligned with NIST SP 800-155 (Initial Public Draft), whose further development was ended by NIST in October 2024.
- PRCR supersedes the TCG PC Client Platform Firmware Integrity Measurement (FIM) specification, expanding scope beyond PC clients to include servers and components, and clarifying how certificates and RIMs work together across the supply chain.
How PRCR is Used
Platform evidence (hardware composition and firmware integrity data) can be compared to the Platform Certificate and RIMs provided by the platform supplier (and optionally a VAR). PRCR does not define the verification tooling itself; it defines the supplier artifacts and requirements needed to enable interoperable verification workflows.
Related Specifications
- TCG Platform Certificate Profile Specification
- TCG PC Client Platform Firmware Profile Specification
- TCG Reference Integrity Manifest Information Model
- TCG PC Client Reference Integrity Manifest Specification
- TCG Component Reference Integrity Manifest Information Model
- TCG Component RIM Binding for SWID and CoSwid Specification
