Non-profit Trusted Computing Group (TCG) has released new guidance to help organizations determine whether Trusted Platform Modules (TPMs) genuinely meet post-quantum cryptography requirements.
TCG warned that not all TPMs currently marketed as quantum-ready provide complete quantum-safe capabilities.
The guidance provides a way to verify hardware against TCG’s PTP 1.07 standard, developed earlier this year with input from nearly 90 contributors across government, academia and companies including Intel, Google, Microsoft, NVIDIA, Lenovo and HPE.
It establishes two classifications: “PQC-ready” for TPMs that already meet the standard and “PQC-upgradable” for hardware designed to support the requirements through future upgrades.
Denis Calderone, CTO, Suzu Labs Had This To Say:
“TCG just published what amounts to a nutrition label for quantum-ready hardware claims, and its much needed. Vendors have been marketing TPMs as quantum-safe that don’t actually implement the full PQC specification. TCG’s own language warns buyers to avoid TPMs that advertise “compliance” yet fail to provide full, end-to-end security capabilities. Their new verification guidance gives buyers a way to test those claims against PTP 1.07, the standard that nearly 90 contributors from Intel, Google, Microsoft, NVIDIA, and others developed earlier this year. That’s a welcome move, because the “quantum washing” problem in hardware is getting worse, not better.
“The backdrop here is real urgency. Nation-state adversaries are already running “harvest now, decrypt later” operations, intercepting and storing encrypted traffic today with the expectation that quantum computers will crack it open within the next decade. NIST finalized the first PQC algorithm standards in 2024, the Trump administration set hard federal migration deadlines of 2030 for encryption and 2031 for digital signatures, and NIST’s own deprecation roadmap phases out RSA and elliptic curve entirely by 2035. TPMs sit at the root of trust for the entire platform. If the chip that holds your keys and validates your firmware can’t do quantum-resistant crypto, everything built on top of it inherits that vulnerability.
“What’s worth understanding is what this guidance is and what it is not. PTP 1.07 gives buyers a written baseline to verify vendor claims against. That’s genuinely useful. But there is no independent lab certification behind it yet. As of right now, no TPM has achieved FIPS 140-3 validation with PQC algorithms. The first FIPS 140-3 Level 3 validated module to include PQC just arrived in August 2026, and that was an HSM from Thales, not a TPM. The leading TPM vendor in this space has FIPS 140-3 submission targeted for September 2026. TCG has announced plans to build a formal certification program for PQC-ready TPMs, but their own language says “once completed,” meaning it does not exist today. So right now, this verification guidance is a self-assessment tool, not a third-party certification. It puts power in the hands of educated buyers who know what questions to ask, but it requires you to know what you’re looking at.
“If you’re in procurement right now, particularly for federal or defense contract work, ask for the PTP 1.07 compliance evidence. If the vendor can’t produce it, you have your answer. And pay close attention to TCG’s distinction between “PQC-ready” and “PQC-upgradable.” Ready is a testable fact. Upgradable is a vendor roadmap promise about the future. Those are two very different things when you’re signing a purchase order.”
Organizations need to make their purchasing decisions accordingly and get hardware that doesn’t meet this guidance out of the hands of the users ASAP. It’s one important step to making their organization quantum ready.
Related
This entry was posted on August 25, 2026 at 2:18 pm and is filed under Commentary with tags TCG. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
New guidance aims to verify whether hardware is actually quantum-ready
Non-profit Trusted Computing Group (TCG) has released new guidance to help organizations determine whether Trusted Platform Modules (TPMs) genuinely meet post-quantum cryptography requirements.
TCG warned that not all TPMs currently marketed as quantum-ready provide complete quantum-safe capabilities.
The guidance provides a way to verify hardware against TCG’s PTP 1.07 standard, developed earlier this year with input from nearly 90 contributors across government, academia and companies including Intel, Google, Microsoft, NVIDIA, Lenovo and HPE.
It establishes two classifications: “PQC-ready” for TPMs that already meet the standard and “PQC-upgradable” for hardware designed to support the requirements through future upgrades.
Denis Calderone, CTO, Suzu Labs Had This To Say:
“TCG just published what amounts to a nutrition label for quantum-ready hardware claims, and its much needed. Vendors have been marketing TPMs as quantum-safe that don’t actually implement the full PQC specification. TCG’s own language warns buyers to avoid TPMs that advertise “compliance” yet fail to provide full, end-to-end security capabilities. Their new verification guidance gives buyers a way to test those claims against PTP 1.07, the standard that nearly 90 contributors from Intel, Google, Microsoft, NVIDIA, and others developed earlier this year. That’s a welcome move, because the “quantum washing” problem in hardware is getting worse, not better.
“The backdrop here is real urgency. Nation-state adversaries are already running “harvest now, decrypt later” operations, intercepting and storing encrypted traffic today with the expectation that quantum computers will crack it open within the next decade. NIST finalized the first PQC algorithm standards in 2024, the Trump administration set hard federal migration deadlines of 2030 for encryption and 2031 for digital signatures, and NIST’s own deprecation roadmap phases out RSA and elliptic curve entirely by 2035. TPMs sit at the root of trust for the entire platform. If the chip that holds your keys and validates your firmware can’t do quantum-resistant crypto, everything built on top of it inherits that vulnerability.
“What’s worth understanding is what this guidance is and what it is not. PTP 1.07 gives buyers a written baseline to verify vendor claims against. That’s genuinely useful. But there is no independent lab certification behind it yet. As of right now, no TPM has achieved FIPS 140-3 validation with PQC algorithms. The first FIPS 140-3 Level 3 validated module to include PQC just arrived in August 2026, and that was an HSM from Thales, not a TPM. The leading TPM vendor in this space has FIPS 140-3 submission targeted for September 2026. TCG has announced plans to build a formal certification program for PQC-ready TPMs, but their own language says “once completed,” meaning it does not exist today. So right now, this verification guidance is a self-assessment tool, not a third-party certification. It puts power in the hands of educated buyers who know what questions to ask, but it requires you to know what you’re looking at.
“If you’re in procurement right now, particularly for federal or defense contract work, ask for the PTP 1.07 compliance evidence. If the vendor can’t produce it, you have your answer. And pay close attention to TCG’s distinction between “PQC-ready” and “PQC-upgradable.” Ready is a testable fact. Upgradable is a vendor roadmap promise about the future. Those are two very different things when you’re signing a purchase order.”
Organizations need to make their purchasing decisions accordingly and get hardware that doesn’t meet this guidance out of the hands of the users ASAP. It’s one important step to making their organization quantum ready.
Share this:
Like this:
Related
This entry was posted on August 25, 2026 at 2:18 pm and is filed under Commentary with tags TCG. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.