The Trusted Computing Group (TCG) has released new guidance to help organizations verify whether Trusted Platform Modules (TPMs) marketed as quantum-safe actually meet post-quantum cryptography requirements. The guidance is built around the PC Client Platform TPM Profile 1.07 (PTP 1.07), published earlier in 2026, which defines baseline requirements for TPM 2.0 implementations supporting post-quantum algorithms and references the TPM 2.0 Library Specification Version 1.85.
TCG said the move is intended to address vendor claims that do not deliver full end-to-end quantum-safe capability and to give buyers a clearer basis for demanding evidence before procurement. The framework introduces two labels—TCG PQC-ready TPM for modules that already support PTP 1.07, and TCG PQC-upgradable TPM for modules that can be updated to meet it—and TCG said it plans to expand its certification programs to formally certify TPMs against those requirements.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
TCG said it plans to enhance its certification programs to certify TPMs that meet PTP 1.07 requirements. The organization also said it will define requirements for a TCG-certified 'TCG PQC-ready TPM' once that certification work is completed.
As part of the new guidance, TCG introduced two transition designations: 'TCG PQC-ready TPM' for TPMs that already implement PTP 1.07 and 'TCG PQC-upgradable TPM' for TPMs designed to be upgraded to support it. The labels were created to clarify a platform's status in the transition to post-quantum cryptography.
On August 24, 2026, the Trusted Computing Group released guidance to help organizations verify whether TPMs meet post-quantum cryptography requirements tied to PTP 1.07. The guidance was intended to help buyers demand evidence from vendors and avoid unsupported compliance claims.
In March 2026, the Trusted Computing Group assembled nearly 90 contributors from government, academia, semiconductor companies, and hardware providers to develop the PC Client Platform TPM Profile 1.07 standard. The standard defined minimum requirements for post-quantum-cryptography-ready TPMs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.