Your Trusted Platform Module (TPM) is the cornerstone of your platform's cryptographic security. It safeguards your machine's keys, checks firmware integrity, and ensures your system remains untampered. If your TPM can't handle quantum attacks, your entire security foundation is at risk.
The Trusted Computing Group has released PTP 1.07, which outlines what a post-quantum cryptography (PQC)-ready TPM must achieve. This guide helps you evaluate your current TPMs and plan your transition to quantum-safe hardware.
Prerequisites
Before starting your assessment, ensure:
- You have an inventory of all TPM-equipped systems (servers, workstations, payment terminals, HSMs).
- You know the deployed TPM firmware versions.
- You have vendor contact information for each TPM manufacturer.
- You understand which cryptographic keys need protection for decades (platform identities, attestation keys, firmware measurement signatures).
PQC-Ready TPM Assessment Checklist
1. Identify TPMs Implementing TCG PC Client Platform TPM Profile (PTP) 1.07
Ask your vendor: "Does this TPM implement PTP 1.07?" Get written confirmation with version numbers.
Good looks like: Vendor documentation shows the TPM supports TPM 2.0 Library Specification Version 1.85 with PQC-specific elements in PTP 1.07. The TPM has the "TCG PQC-ready TPM" designation.
2. Verify Support for Mandatory PQC Algorithms
PTP 1.07 specifies minimum algorithm requirements. Request a capabilities matrix from your vendor showing which PQC algorithms the TPM implements in hardware.
Good looks like: Vendor documentation lists specific post-quantum algorithms for key exchange, digital signatures, and key encapsulation mechanisms that the TPM supports natively.
3. Classify TPMs as Upgradable or Non-Upgradable
For TPMs not supporting PTP 1.07, determine if they can be upgraded.
Good looks like: Vendor confirms the TPM is "TCG PQC-upgradable" and provides a firmware upgrade path with a timeline. Document which systems can be upgraded and which require hardware replacement.
4. Map Keys Requiring Multi-Decade Protection
Identify keys that must remain secure for 20+ years: platform identity keys, attestation keys, and keys protecting firmware measurements.
Good looks like: You have a spreadsheet listing each long-lived key, its current TPM location, the TPM's PQC status, and the business impact if compromised by a quantum adversary in 2040.
5. Build a Transition Timeline Tied to Key Lifecycle
Don't replace all TPMs at once. Prioritize based on key longevity and exposure.
Good looks like: Your timeline includes Phase 1 (systems with 20+ year keys), Phase 2 (systems with 10-year keys), and Phase 3 (systems with shorter-lived keys). Each phase has a budget, vendor commitments, and a testing plan.
6. Request TCG Certification Evidence
Once TCG certifies TPMs that meet PTP 1.07, verify your vendor's TPMs carry official certification.
Good looks like: Vendor provides a TCG-issued certificate number for their "TCG PQC-ready TPM" product line. Add this requirement to your procurement standards.
7. Test Quantum-Safe Attestation in a Lab Environment
Before deploying PQC-ready TPMs in production, verify they work with your existing attestation infrastructure.
Good looks like: You've set up a test environment where a PTP 1.07-compliant TPM generates attestation quotes using post-quantum signatures, and your verifier successfully validates them. Document any changes needed to your attestation service.
8. Update Procurement Requirements
Add PTP 1.07 compliance to your hardware purchasing standards. Don't accept vague "quantum-safe" marketing claims.
Good looks like: Your RFP template includes: "TPM must implement TCG PC Client Platform TPM Profile (PTP) 1.07 and carry TCG PQC-ready TPM designation. Vendor must provide written confirmation of PTP 1.07 compliance with each quote."
9. Document Your PQC Roadmap
Having a formal PQC roadmap puts you ahead of most organizations.
Good looks like: You have a written plan covering current TPM inventory and PQC status, upgrade/replacement timeline, budget allocation by fiscal year, vendor commitments, testing milestones, and integration requirements for PQC-ready TPMs with existing systems.
10. Plan for Algorithm Agility
PQC standards will evolve. Your TPMs should support algorithm updates without hardware replacement.
Good looks like: Your vendor confirms the TPM's firmware can be updated to support additional PQC algorithms as NIST finalizes more standards. You've tested the firmware update process in your lab.
Common Mistakes
Assuming "quantum-resistant" equals "PQC-ready." Marketing materials often claim quantum resistance without meeting PTP 1.07's specific requirements. Demand written proof of PTP 1.07 compliance.
Ignoring Upgradable TPMs. If your current TPM qualifies as "TCG PQC-upgradable," you may avoid hardware replacement costs. Ask about upgrade paths before budgeting for replacements.
Treating All Keys Equally. Not every key needs quantum protection today. Prioritize keys that must remain secure for decades over ephemeral session keys.
Skipping Lab Testing. PQC algorithms have different performance characteristics. Test attestation latency and boot times with PQC-ready TPMs before production rollout.
Buying TPMs Without TCG Certification. Once TCG's certification program launches, uncertified TPMs claiming PTP 1.07 compliance become a red flag.
Next Steps
Start with inventory. Document every TPM in your environment with its firmware version and vendor within 30 days.
Then contact vendors. Ask about PTP 1.07 compliance and upgrade paths. Get commitments in writing.
Finally, build your roadmap. Map your keys to their required protection lifetimes, prioritize systems with the longest-lived keys, and establish a multi-year budget for upgrades and replacements.
The quantum threat isn't theoretical anymore. Your TPMs either meet PTP 1.07 or they don't. This checklist gives you a clear path to find out which category you're in and what to do about it.



