diff --git a/configs/sandbox_defconfig b/configs/sandbox_defconfig
index dd33028f8d7ff5f15e493aab2832bfb61ff2a8f6..c8c888dd68713a3330101715eeba4d7726cd8c59 100644
--- a/configs/sandbox_defconfig
+++ b/configs/sandbox_defconfig
@@ -22,3 +22,4 @@ CONFIG_SYS_VSNPRINTF=y
 CONFIG_SYS_I2C_SANDBOX=y
 CONFIG_SANDBOX_SPI=y
 CONFIG_SPI_FLASH_SANDBOX=y
+CONFIG_TPM_TIS_SANDBOX=y
diff --git a/drivers/tpm/Kconfig b/drivers/tpm/Kconfig
index e69de29bb2d1d6434b8b29ae775ad8c2e48c5391..f408b8a81d1e7d2f438c1ce20590f8563920d002 100644
--- a/drivers/tpm/Kconfig
+++ b/drivers/tpm/Kconfig
@@ -0,0 +1,7 @@
+config TPM_TIS_SANDBOX
+	bool "Enable sandbox TPM driver"
+	help
+	  This driver emulates a TPM, providing access to base functions
+	  such as reading and writing TPM private data. This is enough to
+	  support Chrome OS verified boot. Extend functionality is not
+	  implemented.
diff --git a/include/configs/sandbox.h b/include/configs/sandbox.h
index 5f72f6a4c986fef3bb5f43f66ac06fc296449fa8..842fbe27072df1dfc2d6b8a095998cb2fbfc078a 100644
--- a/include/configs/sandbox.h
+++ b/include/configs/sandbox.h
@@ -145,8 +145,6 @@
 #define CONFIG_SHA1
 #define CONFIG_SHA256
 
-#define CONFIG_TPM_TIS_SANDBOX
-
 #define CONFIG_CMD_SANDBOX
 
 #define CONFIG_BOOTARGS ""
@@ -196,8 +194,6 @@
 #define CONFIG_LZO
 #define CONFIG_LZMA
 
-#define CONFIG_TPM_TIS_SANDBOX
-
 #define CONFIG_CMD_LZMADEC
 #define CONFIG_CMD_USB