Android Platform Google Pixel

Google Pixel & CSfC: the certification picture.

Google took a different route into government mobility than Samsung — no separate ruggedized product line, no bolt-on security platform, just the reference Android implementation on first-party silicon, certified hard and fast. As of April 2025 that route reached the CSfC Components List.

On the CSfC Components List
Android 15 — per VID 11545
Hardware root of trust
Titan M2 — CC certified EAL4+
Support window
7 years on Pixel 8 and later
Section 1 — Background

Google is both the platform maintainer and the OEM.

That sentence is the whole architectural argument. On a Pixel there is no carrier layer and no OEM skin between the Android Open Source Project and the shipped device — Google writes the platform and builds the phone. For an accreditor, that removes an entire class of question about who modified what.

Titan M2 — the strongest single credential in the portfolio

Titan M2 is a discrete, physically separate security chip soldered alongside the main processor. It serves as the hardware root of trust: verified boot, bootloader anti-rollback, lockscreen passcode verification with brute-force throttling, and hardware-backed StrongBox key storage.

What makes it notable is not the feature list but the assurance level. The chip — which Google identifies internally as H1D3 — holds an independent Common Criteria certification under the Netherlands NSCIB scheme at EAL4+ augmented with AVA_VAN.5. That augmentation is the meaningful part: AVA_VAN.5 is vulnerability analysis against attackers with high attack potential. Very few smartphone secure elements carry it. Certificates NSCIB-CC-2300073-01 and -03 cover the Pixel 6/7/8 and Pixel 9/10 generations respectively.

Tensor silicon and storage encryption

Google designs the Tensor system-on-chip, which maps to device generations as Tensor G1 for the Pixel 6 family, G2 for the Pixel 7 family, Pixel Fold and Pixel Tablet, G3 for the Pixel 8 family and G4 for the Pixel 9 family. Tensor's UFS Inline Storage Encryption Engine holds its own FIPS 140-3 validation and is what backs file-based encryption at rest.

Trusty TEE

Google's Trusted Execution Environment runs on the application processor but is hardware- and software-isolated from Android. It handles keystore operations, biometric template matching and DRM. Unlike most third-party TEEs it is open source, which matters for agencies that weigh supply-chain transparency.

Patch cadence and lifecycle

Google publishes monthly Pixel Update Bulletins in addition to the general Android Security Bulletin — the patch-level string they produce is what an assessor checks against the STIG. Support windows are the longest committed in Android: seven years of OS and security updates for Pixel 8 and later, five years for the Pixel 6 and 7 families. For federal refresh-cycle and lifecycle-cost analysis, that is a material number.

The Data-at-Rest layer you have to source yourself

Android's native file-based encryption is a sound outer Data-at-Rest layer. It is not two layers. Where Samsung ships an NSA-approved inner layer as part of Knox, Google does not — so on Pixel, an inner DAR layer comes from a third-party product listed under File Encryption or Software Full Drive Encryption on the Components List. That is a real line item in your budget, your integration plan and your registration package.

If nothing classified persists on the device, this may not apply to you at all. Make that a deliberate design decision rather than a discovery in month four.

Section 2 — Google Certifications

Six registries, and where to check each one.

These build on each other rather than sitting side by side: FIPS validates the cryptography, Common Criteria evaluates the product, NIAP runs that evaluation for the US, CSfC listing depends on NIAP validation, DoDIN APL governed network connection, and the STIG defines how you configure what you bought.

NIAP

National Information Assurance Partnership

The US Common Criteria scheme. Validation against the Mobile Device Fundamentals Protection Profile is the prerequisite for CSfC listing.

Android 15 (VID 11545) — validated 10 April 2025, evaluated by Gossamer against PP_MDF v3.3 plus modules for biometrics, Bluetooth, MDM Agents and WLAN clients. Covers 16 models from Pixel 6 through Pixel 9 Pro Fold plus Pixel Tablet.

Android 14 (VID 11419) — validated 27 March 2024, same PP configuration.

Google lists a further evaluation for Android 16 (VID 11647); Android 17 is submitted but not yet certified.

CSfC

Commercial Solutions for Classified

NSA's program for protecting classified data with layered commercial products. The Components List is the authoritative record of what may go into a registered solution.

Listed

Google LLC appears under End User Device / Mobile Platform at Android 15, dated 10 April 2025, referencing VID 11545. The listed models run from Pixel 7 through the Pixel 9 family plus Pixel Tablet and Pixel Fold.

Read the model list carefully. The Components List entry is narrower than the underlying NIAP evaluation — it does not name every model in VID 11545. Do not assume a model is eligible because it appears in the validation report.

CC

Common Criteria

The international standard (ISO/IEC 15408). NIAP is the US scheme within it; other national schemes certify components that then appear in US products.

Two distinct certifications matter here. The handset evaluations are the NIAP entries above — Protection Profile conformance, not EAL-rated.

The Titan M2 secure element is separately certified under the Netherlands NSCIB scheme as the H1D3 Secure Microcontroller, at EAL4+ augmented ATE_DPT.2, ALC_DVS.2 and AVA_VAN.5. Google identifies H1D3 as Titan M2; the certification documents use the internal name.

APL

DoDIN Approved Products List

DISA's list of products cleared to connect to the Department of Defense Information Network — historically a separate gate from CSfC.

Program sunset

Google announced in October 2025 that Pixel phones had been added to the DoDIN APL. Reporting indicates the listing covered Pixel 9 phones and related Android 15 models.

However, DISA sunset the APL program effective 30 September 2025, maintaining the repository through FY2026, with cybersecurity requirements moving to the DISA Vendor STIG program. Treat an APL listing as historical record rather than a forward-looking credential.

FIPS

FIPS 140-2 / 140-3

NIST's Cryptographic Module Validation Program. Validates that the cryptography is correctly implemented — the foundation every higher certification assumes.

Google holds a large active portfolio. Most relevant to Pixel: BoringCrypto (Cert. #5296), the Tensor 5th Gen UFS Inline Storage Encryption Engine (#5288), the Tensor G2 UFS module (#5254) and the Android Kernel Cryptographic Module (#4726).

Two things to get right. Certificate #4953 is marked Historical — federal agencies should not include it in new procurements. And Titan M2 and Trusty TEE hold CAVP algorithm validations, not CMVP module certificates — do not describe them as FIPS-validated modules. Titan M2's module-level assurance comes from Common Criteria.

STIG

DISA Security Technical Implementation Guide

Not a certification — a configuration standard. With the APL winding down, the STIG program becomes the primary DoD cybersecurity gate.

Google co-develops Android STIGs with DISA, and publishes them for Android 14, 15, 16 and 17, plus a separate BYOAD baseline for personally owned devices.

Scope matters: the Google Android STIG covers COBO and COPE deployments for unclassified data up to CUI — not classified. A CSfC deployment applies the STIG as its configuration baseline but derives its classified authority from the registered solution, not the STIG.

Verify before you build

  • VID 11647 (Android 16) — confirm in a browser whether it sits on the Compliant list or is still in evaluation. Google's index lists it; we could not independently confirm the certification date.
  • The exact model string in the CSfC entry — NSA's own table contains what appears to be a typographical inconsistency in one Pixel model name. Quote it as published rather than normalizing it.
  • Current STIG package version strings — DISA republishes on a quarterly cadence and filenames carry date tokens that change.

Sources: Google Pixel security certifications; NIAP Validation Reports for VID 11545 and VID 11419 (mirrored on the Common Criteria Portal); NSA CSfC Components List; NSCIB certification reports for the H1D3 secure microcontroller; NIST CMVP; NIST National Checklist Program. Current as of August 2026.