Almost 90 contributors in March 2026 joined a concerted effort to set a practical bar for hardware that claims to be ready for post-quantum cryptography, and on August 24 the Trusted Computing Group (TCG) published guidance designed to let buyers verify those claims.
Trusted Computing Group releases verification guidance on August 24
TCG, a nonprofit that produces vendor-neutral standards for hardware security, released new guidance on August 24 to help prove that trusted platform modules (TPMs) genuinely meet essential post-quantum cryptography (PQC) requirements. The document accompanies the TCG PC Client Platform TPM Profile (PTP) 1.07 and is intended to make it easier for organizations to confirm whether a TPM implements the minimum requirements defined in that profile.
What TPMs are and why they matter for PQC
Trusted platform modules are specialized security chips built into a motherboard or processor that securely store passwords, digital certificates and encryption keys. TCG’s main standards body has published version 1.2 of its specifications for second‑generation TPMs (TPM 2.0) — which are part of the Windows 11 system requirements. TCG said TPMs will likely play an important role in some organizations’ PQC roadmaps because they offer a persistent anchor for trusted identities, platform integrity, attestation and hardware‑anchored security.
TCG emphasized the long timeframe involved: elements that protect identities and keys “may need to remain secure for decades,” the organization noted, creating pressure to ensure that hardware protections are both robust today and adaptable to future PQC algorithms.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildPTP 1.07: a standard forged by industry and research
In March 2026 TCG convened nearly 90 contributors from government, academia, semiconductor companies and computing hardware providers to develop PTP 1.07. Named participants included Intel, Google, Hewlett Packard Enterprise, Microsoft, NVIDIA, Lenovo and STMicroelectronics. The PTP 1.07 document sets minimum requirements for PQC‑ready TPMs — a baseline intended to make manufacturer claims verifiable and comparable.
Two simple readiness designations and verification steps
The new guidance pairs with PTP 1.07 by offering a way for businesses to determine whether a TPM meets the profile’s requirements. TCG also established two labels to describe readiness for the PQC transition:
- “TCG PQC‑ready TPM” — a TPM that already supports the PQC capabilities defined in PTP 1.07
- “TCG PQC‑upgradable TPM” — a TPM that does not yet support PTP 1.07 but is designed to be upgraded to support it
Those designations are intended to provide a simple signal of where a platform stands in its transition to PQC. The guidance responds to a concrete market problem TCG identified: not all TPMs currently on the market provide quantum‑safe encryption options and some advertise “compliance” yet fail to provide full, end‑to‑end security capabilities.
TCG has also announced plans to enhance its certification programs to certify TCG PQC‑ready TPMs, making a formal path from specification to validated product recognition.
How technologists, procurement leaders, and hardware vendors will react
- Technologists and security teams: They will use the PTP 1.07 checklist and the new verification guidance to test whether a platform’s TPM meets the stated PQC minimums and to distinguish between already‑ready TPMs and those that are upgradable by design.
- Procurement leaders and affected enterprises: Purchasing teams can adopt the two TCG designations as procurement criteria or contract language to reduce ambiguity when vendors claim quantum readiness.
- Semiconductor and hardware vendors named in the process: Companies such as Intel, Google, Hewlett Packard Enterprise, Microsoft, NVIDIA, Lenovo and STMicroelectronics — which participated in developing the profile — have a clear standard to reference; vendors whose products are not yet compliant have a defined upgrade category to communicate future capability.
The guidance narrows an important test to a few concrete labels and a verification process: is the TPM already supporting PTP 1.07, or is it designed to be upgraded to do so? TCG’s move to add certification for PQC‑ready TPMs completes the pipeline from specification to conformance recognition, but the practical measure will be whether vendors’ claims align with validated certificates and whether purchasers adopt the new labels in contracts and procurement.




