Quantum-Ready Hardware May Not Be What It Seems: What IT Buyers Need to Verify

A conceptual image of a security chip highlights the growing push to make hardware ready for post-quantum cryptography.

A conceptual image of a security chip highlights the growing push to make hardware ready for post-quantum cryptography. Image: Generated via Google’s Nano Banana

Written By
Ken Underhill
Ken Underhill
Aug 28, 2026
5 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The race to prepare enterprise systems for quantum computing has created a new problem: hardware labeled “quantum-ready” may not actually deliver everything the term implies.

The Trusted Computing Group (TCG) has released new verification guidance designed to help organizations determine whether Trusted Platform Modules, or TPMs, genuinely support post-quantum cryptography requirements. According to the nonprofit standards group, some TPMs advertised as quantum-ready may not provide the complete capabilities organizations expect.

TPMs help anchor device security by protecting cryptographic material and supporting functions related to device identity, attestation, platform integrity, and hardware-backed trust.

Organizations should consider cryptographic capabilities when purchasing systems with long service lives. Those decisions could matter well before quantum computers are powerful enough to break widely used public-key cryptography. 

TCG draws a line between ‘ready’ and ‘upgradable’

TCG's guidance centers on its PTP 1.07 specification, published earlier this year as the organization's baseline for defining the minimum requirements of a PQC-ready TPM.

The specification incorporates post-quantum requirements defined in TCG's TPM 2.0 Library Specification Version 1.85 and its errata, with specific PQC additions to support the NIST-standardized ML-KEM and ML-DSA algorithms.

The framework establishes two important classifications.

A “PQC-ready” TPM already satisfies the requirements laid out by PTP 1.07. A “PQC-upgradable” TPM does not currently meet those requirements but can be securely upgraded in the field to conform with the specification. TCG says the upgrade process itself must also be quantum-safe.

That may sound like a small distinction, but it could have significant consequences for companies making hardware purchases today.

Denis Calderone, CTO at Suzu Labs, described TCG's new guidance as something akin to a “nutrition label” for quantum-ready hardware claims.

Calderone said the industry has reached a point where buyers need a way to distinguish between TPMs that actually implement the necessary post-quantum functionality and products whose claims of quantum readiness depend on future development.

Advertisement

“Ready is a testable fact,” Calderone told eWeek in a statement. “Upgradable is a vendor roadmap promise about the future.”

For IT procurement teams evaluating machines that may remain deployed for five, seven or even 10 years, that difference deserves scrutiny. Hardware purchased today could still be operating as organizations move deeper into their post-quantum cryptography transitions.

A quantum-ready TPM does not make the entire system quantum-ready

There is another important distinction buried beneath the terminology.

TCG cautions that having a PQC-ready TPM does not automatically mean an entire computer or platform is ready for the post-quantum era. The designation only establishes that the TPM meets TCG's PQC requirements. Other components across the platform may have their own cryptographic requirements and dependencies that organizations will need to evaluate separately.

For IT leaders, that means PQC readiness cannot be reduced to finding a single compliant chip within a device.

The distinction also creates a potential procurement trap. A vendor may accurately advertise a component as PQC-ready without that claim establishing that the entire product is protected against future quantum threats.

For buyers, the question therefore needs to shift from “Is this device quantum-ready?” to “Which parts of this device are quantum-ready, and which ones still depend on future migration?”

The bigger concern is what sits underneath enterprise security

Post-quantum cryptography is designed to protect data against attacks from sufficiently powerful quantum computers, which could eventually undermine widely deployed public-key cryptography.

The migration is already underway. NIST finalized its first post-quantum cryptography standards in 2024, setting the stage for governments and businesses to begin replacing vulnerable cryptographic systems.

Calderone pointed to another reason organizations are being pushed to prepare early: so-called “harvest now, decrypt later” attacks. In that scenario, an adversary collects encrypted information today and stores it, hoping to decrypt it once sufficiently powerful quantum technology becomes available.

That makes long-lived sensitive information particularly important. Intellectual property, government data, financial information, and other material with a long security shelf life could remain valuable years after they are initially intercepted.

Advertisement

TPMs become part of that conversation because of their role in establishing hardware-backed trust within computing platforms.

“If the chip that holds your keys and validates your firmware can't do quantum-resistant crypto, everything built on top of it inherits that vulnerability,” Calderone said.

His broader point underscores why organizations need to understand what their current hardware can support as cryptographic requirements change. A TPM is only one component of a larger security architecture, but organizations still need to understand whether deployed hardware can support the cryptographic requirements they expect to adopt over its service life.

‘PQC-ready’ does not yet mean independently certified

There is another important limitation for buyers. TCG's guidance provides organizations with a baseline to assess vendor claims against PTP 1.07, but organizations should not confuse that designation with independent TCG certification.

TCG says it is currently updating its TPM certification program to cover TPMs meeting PTP 1.07. Once that program becomes available, qualifying PQC-ready TPMs will be able to undergo formal TCG compliance and security evaluation.

Until then, organizations can use the specification and accompanying guidance to scrutinize the evidence vendors provide for their claims and make more informed procurement decisions. 

Instead of simply asking a vendor whether a TPM is “quantum-safe,” enterprise buyers can ask a much narrower question: What evidence demonstrates that this TPM satisfies PTP 1.07?

The answer may reveal more than the marketing language.

What enterprise buyers should ask before their next hardware refresh

For CIOs, CISOs, infrastructure teams and procurement leaders, the practical takeaway is that post-quantum planning may need to move further down the technology stack.

Organizations developing PQC migration strategies are likely to spend considerable time examining certificates, software libraries, VPNs, identity systems and encryption protocols. Hardware roots of trust should increasingly be part of that inventory.

Before signing off on systems advertised as quantum-ready, buyers can press vendors on several points: whether the TPM satisfies PTP 1.07 today, which post-quantum capabilities are already implemented, whether additional functionality depends on future upgrades, how those upgrades will be securely delivered and what evidence the vendor can provide to substantiate its claims.

Advertisement

The “PQC-upgradable” designation deserves particular attention. Upgradability may be perfectly acceptable for some deployments, but it introduces another dependency. Enterprises are relying on the promised upgrade becoming available, the hardware remaining supported, and the upgrade being deployable across their environments when needed.

That means lifecycle planning matters just as much as cryptographic support.

A three-year laptop refresh and a decade-long industrial system deployment carry very different risks. Organizations handling government workloads, critical infrastructure, or long-lived sensitive data may also have less room to rely on capabilities promised for some future date.

TCG's guidance gives procurement teams something they previously lacked: a more concrete benchmark against which they can question quantum-readiness claims.

The emerging lesson for enterprise buyers is simple: “quantum-ready” should be the beginning of the procurement conversation, not the end.

As organizations prepare for a cryptographic transition that could span years, the hardware beneath their security stack will have to make that journey too. Asking vendors for evidence today could prevent a supposedly future-proof hardware purchase from becoming tomorrow's migration problem.

Also read: As enterprises scrutinize their hardware dependencies, SpaceX’s decision to go all-in on Nvidia for AI compute shows how much strategic weight companies are placing on the technology underneath their systems.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.