Google took a different route into government mobility than Samsung — no separate ruggedized
product line, no bolt-on security platform, just the reference Android implementation on
first-party silicon, certified hard and fast. As of April 2025 that route reached the CSfC
Components List.
On the CSfC Components List
Android 15 — per VID 11545
Hardware root of trust
Titan M2 — CC certified EAL4+
Support window
7 years on Pixel 8 and later
Section 1 — Background
Google is both the platform maintainer and the OEM.
That sentence is the whole architectural argument. On a Pixel there is no carrier layer and no
OEM skin between the Android Open Source Project and the shipped device — Google writes the
platform and builds the phone. For an accreditor, that removes an entire class of question about
who modified what.
Titan M2 — the strongest single credential in the portfolio
Titan M2 is a discrete, physically separate security chip soldered alongside the main processor.
It serves as the hardware root of trust: verified boot, bootloader anti-rollback, lockscreen
passcode verification with brute-force throttling, and hardware-backed StrongBox key storage.
What makes it notable is not the feature list but the assurance level. The chip — which Google
identifies internally as H1D3 — holds an independent Common Criteria
certification under the Netherlands NSCIB scheme at EAL4+ augmented with AVA_VAN.5.
That augmentation is the meaningful part: AVA_VAN.5 is vulnerability analysis against attackers
with high attack potential. Very few smartphone secure elements carry it. Certificates
NSCIB-CC-2300073-01 and -03 cover the Pixel 6/7/8 and Pixel 9/10 generations respectively.
Tensor silicon and storage encryption
Google designs the Tensor system-on-chip, which maps to device generations as Tensor G1 for the
Pixel 6 family, G2 for the Pixel 7 family, Pixel Fold and Pixel Tablet, G3 for the Pixel 8 family
and G4 for the Pixel 9 family. Tensor's UFS Inline Storage Encryption Engine
holds its own FIPS 140-3 validation and is what backs file-based encryption at rest.
Trusty TEE
Google's Trusted Execution Environment runs on the application processor but is hardware- and
software-isolated from Android. It handles keystore operations, biometric template matching and
DRM. Unlike most third-party TEEs it is open source, which matters for agencies
that weigh supply-chain transparency.
Patch cadence and lifecycle
Google publishes monthly Pixel Update Bulletins in addition to the general Android Security
Bulletin — the patch-level string they produce is what an assessor checks against the STIG.
Support windows are the longest committed in Android: seven years of OS and
security updates for Pixel 8 and later, five years for the Pixel 6 and 7 families. For federal
refresh-cycle and lifecycle-cost analysis, that is a material number.
The Data-at-Rest layer you have to source yourself
Android's native file-based encryption is a sound outer Data-at-Rest layer. It is not two
layers. Where Samsung ships an NSA-approved inner layer as part of Knox, Google does not — so on
Pixel, an inner DAR layer comes from a third-party product listed under File Encryption or
Software Full Drive Encryption on the Components List. That is a real line item in your budget,
your integration plan and your registration package.
If nothing classified persists on the device, this may not apply to you at all. Make that a
deliberate design decision rather than a discovery in month four.
Section 2 — Google Certifications
Six registries, and where to check each one.
These build on each other rather than sitting side by side: FIPS validates the cryptography,
Common Criteria evaluates the product, NIAP runs that evaluation for the US, CSfC listing depends
on NIAP validation, DoDIN APL governed network connection, and the STIG defines how you configure
what you bought.
NIAP
National Information Assurance Partnership
The US Common Criteria scheme. Validation against the Mobile Device Fundamentals Protection
Profile is the prerequisite for CSfC listing.
Android 15 (VID 11545) — validated 10 April 2025, evaluated by Gossamer against
PP_MDF v3.3 plus modules for biometrics, Bluetooth, MDM Agents and WLAN clients. Covers
16 models from Pixel 6 through Pixel 9 Pro Fold plus Pixel Tablet.
Android 14 (VID 11419) — validated 27 March 2024, same PP configuration.
Google lists a further evaluation for Android 16 (VID 11647); Android 17 is submitted but
not yet certified.
NSA's program for protecting classified data with layered commercial products. The Components
List is the authoritative record of what may go into a registered solution.
Listed
Google LLC appears under End User Device / Mobile Platform at Android 15, dated
10 April 2025, referencing VID 11545. The listed models run from Pixel 7 through the
Pixel 9 family plus Pixel Tablet and Pixel Fold.
Read the model list carefully. The Components List entry is narrower than the underlying
NIAP evaluation — it does not name every model in VID 11545. Do not assume a model is eligible
because it appears in the validation report.
The international standard (ISO/IEC 15408). NIAP is the US scheme within it; other national
schemes certify components that then appear in US products.
Two distinct certifications matter here. The handset evaluations are the NIAP entries
above — Protection Profile conformance, not EAL-rated.
The Titan M2 secure element is separately certified under the Netherlands NSCIB scheme as
the H1D3 Secure Microcontroller, at EAL4+ augmented ATE_DPT.2, ALC_DVS.2 and
AVA_VAN.5. Google identifies H1D3 as Titan M2; the certification documents use the internal
name.
DISA's list of products cleared to connect to the Department of Defense Information Network —
historically a separate gate from CSfC.
Program sunset
Google announced in October 2025 that Pixel phones had been added to the DoDIN APL.
Reporting indicates the listing covered Pixel 9 phones and related Android 15 models.
However, DISA sunset the APL program effective 30 September 2025, maintaining the
repository through FY2026, with cybersecurity requirements moving to the DISA Vendor STIG
program. Treat an APL listing as historical record rather than a forward-looking credential.
NIST's Cryptographic Module Validation Program. Validates that the cryptography is correctly
implemented — the foundation every higher certification assumes.
Google holds a large active portfolio. Most relevant to Pixel: BoringCrypto (Cert.
#5296), the Tensor 5th Gen UFS Inline Storage Encryption Engine (#5288), the
Tensor G2 UFS module (#5254) and the Android Kernel Cryptographic Module
(#4726).
Two things to get right. Certificate #4953 is marked Historical — federal agencies
should not include it in new procurements. And Titan M2 and Trusty TEE hold CAVP algorithm
validations, not CMVP module certificates — do not describe them as FIPS-validated modules.
Titan M2's module-level assurance comes from Common Criteria.
Not a certification — a configuration standard. With the APL winding down, the STIG program
becomes the primary DoD cybersecurity gate.
Google co-develops Android STIGs with DISA, and publishes them for Android 14, 15, 16 and
17, plus a separate BYOAD baseline for personally owned devices.
Scope matters: the Google Android STIG covers COBO and COPE deployments for unclassified
data up to CUI — not classified. A CSfC deployment applies the STIG as its configuration
baseline but derives its classified authority from the registered solution, not the STIG.
VID 11647 (Android 16) — confirm in a browser whether it sits on the Compliant list or is still in evaluation. Google's index lists it; we could not independently confirm the certification date.
The exact model string in the CSfC entry — NSA's own table contains what appears to be a typographical inconsistency in one Pixel model name. Quote it as published rather than normalizing it.
Current STIG package version strings — DISA republishes on a quarterly cadence and filenames carry date tokens that change.
Sources:
Google Pixel security certifications;
NIAP Validation Reports for VID 11545 and VID 11419 (mirrored on the Common Criteria Portal);
NSA CSfC Components List;
NSCIB certification reports for the H1D3 secure microcontroller;
NIST CMVP;
NIST National Checklist Program. Current as of August 2026.
The listing is at Android 15 and the model list is narrower than the evaluation. Tell us which devices you are buying and we will tell you whether they are actually covered.