New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims

Written by

As organizations race to future-proof their systems against quantum-enabled attacks, questions remain around how to verify whether hardware is quantum-safe. A new industry benchmark aims to answer that question.

The Trusted Computing Group (TCG) released new guidance on August 24 that helps prove that trusted platform modules (TPMs) genuinely meet essential PQC requirements.

TCG is a nonprofit organization tasked with promoting vendor-neutral standards for hardware-based security products like TPMs.

TPMs are specialized security chips installed on a computer motherboard or processor that safely store passwords, digital certificates and encryption keys. TCG, the main standards body, has published the version 1.2 of it specifications for second-generation TPMs (TPM 2.0) – which are part of the Windows 11 system requirements.

TPMs will likely play an important role in some organizations’ PQC roadmap as they offer a robust solution to maintain trusted identities, platform integrity, attestation and hardware-anchored security over time.

With the potential evolution of PQC algorithms over time, these elements “may need to remain secure for decades,” TCG noted. Not all TPMs currently on the market provide quantum-safe encryption options and some advertise “compliance” yet fail to provide full, end-to-end security capabilities.

In March 2026, the nonprofit brough together almost 90 contributors from government, academia, semiconductor companies and computing hardware providers – including Intel, Google, Hewlett Packard Enterprise, Microsoft, NVIDIA, Lenovo, STMIcroelectronics and more – to develop a standard for PQ-ready TPMs, the TCG PC Client Platform TPM Profile (PTP) 1.07.

The TCG standard document outlines the minimum requirements for PQC-ready TPMs.

Now, TCG has released an accompanying document helping businesses to verify whether their TPMs meet the requirements of PTP 1.07.

It also designates two categories to describe how ready a TPM is for the transition to post-quantum cryptography (PQC):

  • ‘TCG PQC-ready TPM’ – a TPM that already supports the PQC capabilities defined in PTP 1.07
  • ‘TCG PQC-upgradable TPM’ – a TPM that does not yet support PTP 1.07 but is designed to be upgraded to support it

These designations provide a simple way to understand where a platform stands in its transition to PQC.

The nonprofit has also announced plans to enhance its certification programs to certify TCG PQC-ready TPM.

What’s Hot on Infosecurity Magazine?