Overview
- The Trusted Computing Group published guidance tied to its PTP 1.07 profile that defines the minimum Post‑Quantum Cryptography (PQC) elements a TPM 2.0 implementation must have to be considered PQC‑ready.
- TCG introduced two market labels — “TCG PQC‑ready TPM” for modules that implement PTP 1.07 and “TCG PQC‑upgradable TPM” for designs that can be upgraded to meet the profile.
- The guidance gives purchasers a clear way to ask vendors for specific evidence that a TPM meets the written PTP 1.07 baseline, reducing reliance on vague or unverified ‘quantum‑safe’ marketing claims.
- TCG said it will expand its certification programs to formally validate PQC‑ready TPMs, but the detailed certification criteria and roll‑out schedule are still being developed.
- TPMs act as a hardware root of trust for device identity and attestation, major vendors joined the PTP 1.07 effort, and many organizations still need formal PQC roadmaps to manage long‑term protection of keys and platform identities.