Non-profit Trusted Computing Group (TCG) has released new guidance to help organizations determine whether Trusted Platform Modules (TPMs) genuinely meet post-quantum cryptography requirements.
TCG warned that not all TPMs currently marketed as quantum-ready provide complete quantum-safe capabilities.
The guidance provides a way to verify hardware against TCG’s PTP 1.07 standard, developed earlier this year with input from nearly 90 contributors across government, academia and companies including Intel, Google, Microsoft, NVIDIA, Lenovo and HPE.
It establishes two classifications: “PQC-ready” for TPMs that already meet the standard and “PQC-upgradable” for hardware designed to support the requirements through future upgrades.
Denis Calderone, CTO, Suzu Labs Had This To Say:
“TCG just published what amounts to a nutrition label for quantum-ready hardware claims, and its much needed. Vendors have been marketing TPMs as quantum-safe that don’t actually implement the full PQC specification. TCG’s own language warns buyers to avoid TPMs that advertise “compliance” yet fail to provide full, end-to-end security capabilities. Their new verification guidance gives buyers a way to test those claims against PTP 1.07, the standard that nearly 90 contributors from Intel, Google, Microsoft, NVIDIA, and others developed earlier this year. That’s a welcome move, because the “quantum washing” problem in hardware is getting worse, not better.
“The backdrop here is real urgency. Nation-state adversaries are already running “harvest now, decrypt later” operations, intercepting and storing encrypted traffic today with the expectation that quantum computers will crack it open within the next decade. NIST finalized the first PQC algorithm standards in 2024, the Trump administration set hard federal migration deadlines of 2030 for encryption and 2031 for digital signatures, and NIST’s own deprecation roadmap phases out RSA and elliptic curve entirely by 2035. TPMs sit at the root of trust for the entire platform. If the chip that holds your keys and validates your firmware can’t do quantum-resistant crypto, everything built on top of it inherits that vulnerability.
“What’s worth understanding is what this guidance is and what it is not. PTP 1.07 gives buyers a written baseline to verify vendor claims against. That’s genuinely useful. But there is no independent lab certification behind it yet. As of right now, no TPM has achieved FIPS 140-3 validation with PQC algorithms. The first FIPS 140-3 Level 3 validated module to include PQC just arrived in August 2026, and that was an HSM from Thales, not a TPM. The leading TPM vendor in this space has FIPS 140-3 submission targeted for September 2026. TCG has announced plans to build a formal certification program for PQC-ready TPMs, but their own language says “once completed,” meaning it does not exist today. So right now, this verification guidance is a self-assessment tool, not a third-party certification. It puts power in the hands of educated buyers who know what questions to ask, but it requires you to know what you’re looking at.
“If you’re in procurement right now, particularly for federal or defense contract work, ask for the PTP 1.07 compliance evidence. If the vendor can’t produce it, you have your answer. And pay close attention to TCG’s distinction between “PQC-ready” and “PQC-upgradable.” Ready is a testable fact. Upgradable is a vendor roadmap promise about the future. Those are two very different things when you’re signing a purchase order.”
Organizations need to make their purchasing decisions accordingly and get hardware that doesn’t meet this guidance out of the hands of the users ASAP. It’s one important step to making their organization quantum ready.
Uber gets hit with €825 million GDPR fine
Posted in Commentary with tags EU, Uber on August 25, 2026 by itnerdThe Dutch Data Protection Authority fined Uber €825 million ($964 million), the second-largest GDPR fine ever issued, for violating GDPR’s ban on fully automated decision-making. Between 2018 and 2022, Uber used automated software to suspend driver accounts, sometimes permanently, without human review to catch errors, and failed to tell drivers the decisions were automated
Because losing access to Uber can immediately prevent drivers from earning money through the platform, regulators deemed that the case should fall under Article 22 of the EU GDPR, which restricts automated-only decision-making when it comes to having significant effects on individuals.
Ultimately, it means this is now the second-largest GDPR fine ever to have been issued, falling short of Meta’s 2023 €1.2 billion fine.
Arti Raman, CEO, Portal26
“The uncomfortable truth in this case is that most companies couldn’t tell you, today, everywhere AI is making consequential decisions across their organization. Uber’s violation ran for four years before regulators caught it. That’s not just a governance failure, it’s a visibility failure: you can’t govern what you can’t see. Before you can prove a human was in the loop, or that a decision followed policy, you need to know which systems are touching hiring, credit, insurance, or someone’s livelihood in the first place. Most enterprises running AI today don’t have that map.”
Companies who operate in the EU should take note because the EU isn’t playing around. Thus these organizations need to shape up their business practices or they may be next on the hit list.
Leave a comment »