started · updated
Quantum-safe security guidance released for businesses
The Trusted Computing Group (TCG) has released new guidance to help businesses evaluate whether electronic device vendors provide genuine protection against quantum-enabled attacks. The requirements for Trusted Platform Modules (TPMs) aim to ensure products meet essential Post-Quantum Cryptography (PQC) standards, moving beyond simple algorithm support to include quantum-safe identities, attestation, and hardware-anchored trust.
Simultaneously, Microsoft researchers are advising organizations to expand their threat-modeling exercises to prepare for the quantum era. They emphasize the need to build complete cryptographic inventories to identify dependencies that could leave data vulnerable. Because automated scanning may overlook controls provided by operating systems, cloud platforms, or hardware, Microsoft suggests that deep threat modeling is necessary to trace data movement, identify trust boundaries, and document specific protocol versions and key sizes used across systems.