The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

PCR definitions

Prev Next

Here are descriptions of the individual registers:

Platform Configuration Registers (PCRs)

Description

PCR 0

This is the foundational measurement. It records the Core Root of Trust for Measurement (CRTM) - the very first code that executes on power-on. It also includes the system's UEFI/BIOS firmware and other essential platform code. Any firmware update from the PC's  manufacturer will change this value.

PCR 1

This register measures the static configuration of the computer's hardware. This includes data from the SMBIOS tables (describing components like the motherboard and RAM) and UEFI settings that define system behavior during startup. Essentially, it's a snapshot of the platform that the Windows operating system is running on.

PCR 2

This PCR measures any additional UEFI drivers that load before the main Windows boot loader. This typically includes drivers for add-on hardware like graphics cards, network adapters, or storage controllers that must initialize early in the boot process.

PCR 3

This register complements PCR 2 by measuring the configuration data and options used by the third-party UEFI drivers. This helps ensure that not only is the driver code correct, but its settings have not been maliciously altered.

PCR 4

This is a critical register for Windows systems. It measures the main Windows Boot Manager file (bootmgfw.efi). If this file is modified by a legitimate Windows OS update or by a malicious attack, the measurement in PCR 4 will change triggering Pre-Boot Authentication (PBA) with Drive Encryption.

PCR 5

This PCR records the configuration for the Windows Boot Manager, specifically the Boot Configuration Data (BCD) store. The BCD contains the settings that tell the boot manager how and where to find the Windows installation. It also measures the GUID Partition Table (GPT) of the boot drive, which defines the layout of the primary partition and others.

PCR 6

This register is reserved for use by the PC manufacturer (e.g., Dell, HP) for specific integrity checks that are independent of the Windows operating system.

PCR 7

This PCR is vital for systems using UEFI Secure Boot, a key Windows security feature. It measures the state of the Secure Boot policy, including the authorized cryptographic keys and the databases of allowed (db) and revoked (dbx) signatures. A change in this value indicates that the core security policy governing which software is allowed to run before Windows has been modified.

See article 000015304 before you enable PCR 7.