When the data is classified, the rules change.
Everything below the classified threshold is a configuration problem. Above it, you are building a registered solution — two of every encryption layer, every component drawn from an approved list, and a compliance package NSA reviews. This is the harder path, and most of its cost is decided in the first month.
Four things that only apply above the classified line.
If you have run a CUI mobility program, most of your instincts carry over. These four do not, and each one is a schedule risk if it surfaces late.
Every component must be on the Components List
Not "NIAP validated." Listed. Listing requires the vendor to hold an agreement with NSA on top of validation, and plenty of excellent products have the validation but not the agreement. This single rule eliminates entire platforms — see the gate below.
Two independent encryption layers, from different manufacturers
Inner and outer VPN for data in transit. If classified data rests on the device, two Data-at-Rest layers as well. Repeating a vendor collapses two layers into one shared failure mode, and the design will not register.
The solution is registered, not just accredited
You request a Compliance Checklist Workbook and work it against your design. Registration is where optimistic architectures meet the actual requirement text — and it is far cheaper to design against the checklist than to retrofit toward it.
The STIG is necessary but not sufficient
Published mobile STIGs are scoped to unclassified data up to CUI. You still apply one as your configuration baseline, but your authority to hold classified data comes from the registered solution, not the STIG. Teams conflate these constantly.
The gate most programs hit first
As of August 2026, the End User Device / Mobile Platform category of the CSfC Components List contains only Android devices — Google Pixel and Samsung Galaxy. There is no Apple entry in any category.
If your workforce runs iPhones and your mission now requires classified mobility, that is not a configuration change. It is a second device fleet. Better to know in week one than month six.
What you can actually build on.
Samsung Galaxy CSfC listed
Two Components List entries, Android 14 and 15. Knox DualDAR supplies an NSA-approved inner Data-at-Rest layer — the piece you otherwise buy separately — plus a hardware line built for the field.
Google Pixel Listed, but blocked
On the End User Device list at Android 15 — yet no listed File Encryption or SWFDE product runs on Android outside Samsung, and the VPN Client category has no Pixel entry. Being listed is necessary, not sufficient.
Apple iOS & iPadOS Not eligible
Excellent certifications, absent from the Components List. Cannot serve as the end user device in a registered CSfC solution today — though it remains fully viable for high-security work below the classified line.
Assemble it from the Components List.
Every component in a registered CSfC solution must come off the Components List. Work through these and you will see very quickly how narrow the current field actually is — three of the categories a mobile solution needs contain only Samsung products.
Get the data classification in writing
From the authority that owns the data. If it is not actually classified, you are on the wrong page — and an entire component stack drops out of scope.
Pick your Android vendor
Apple is not an option — iOS and iPadOS appear in no category of the Components List. That leaves two realistic Android vendors, and they are not equally viable.
Choose your Data-at-Rest inner layer
Only needed if classified data actually rests on the device. The DAR Capability Package requires the inner layer to be a listed File Encryption or Software Full Drive Encryption product — there is no third option.
Choose your two encryption layers
These are the components that run on the device. They must come from different manufacturers — repeating a vendor collapses two layers into one shared failure mode. The gateways and servers they terminate against are separate infrastructure choices, made from their own Components List categories.
Why Cisco AnyConnect and Aruba VIA appear here Archived
Both were genuinely CSfC-listed IPsec VPN Clients — Aruba VIA 3 until 23 March 2021, Cisco AnyConnect 4.6/4.7 for Android and iOS until 31 August 2021. Neither vendor’s successor client has been re-listed, though both hold current NIAP validation.
They remain in live service because NSA permits it: archived components may continue in an already-registered solution until it is renewed, modified, or a security risk forces a change. That is why a practitioner will tell you these are used in CSfC while the current list shows only Samsung — both statements are true. See the Archived Components List.
Choose your UEM/MDM
The management plane sits inside the solution boundary, so it has to be listed too. This is the shortest category on the entire Components List — one row.
Every option below can be deployed on premises. That is not a preference, it is a structural requirement: the UEM lives inside the boundary, behind both encryption layers, in an enclave the vendor cannot reach. A SaaS-only platform has no deployment model that fits — which is why cloud-only products such as Microsoft Intune are not offered here at all.
Components and integrators are two different lists Easy to conflate
A component is a NIAP-validated product on the Components List. A Trusted Integrator is a company NSA has approved to design and build registered solutions out of those components. Being on one list says nothing about the other.
This is where most "isn’t X on the CSfC list?" questions come from. General Dynamics is a good example — both GDIT and General Dynamics Mission Systems are Trusted Integrators, and neither appears in any Components List category. Roughly 100 firms are on that list, including Booz Allen, CACI, Leidos, Lockheed Martin, ManTech, Northrop Grumman, SAIC and Motorola Solutions.
Apply the STIG
The registered solution grants your authority to hold classified data. The STIG is still how the device itself must be configured, and it is what an assessor checks you against.
Complete the steps above.
Email yourself this configuration
We rebuild the report from your selections and send it as a formatted summary, with the caveats attached to each choice. A copy reaches us so we can follow up if you want it walked through.
Component lists transcribed from the NSA CSfC Components List, August 2026, with layer rules per the Data-at-Rest Capability Package v5.1.0 and Mobile Access Capability Package v2.8.0. The list changes continuously — confirm every component against the source before designing around it.
What the two-layer rule actually costs.
Not a price list — a list of the line items that surprise people, because "two layers" sounds like one extra product and is closer to a doubled architecture.
- Two VPN clients and two gateways, from different manufacturers, each listed, each licensed, each with its own support contract and patch cadence.
- Two certificate authorities in most designs, because the layers must not share a trust root.
- An inner Data-at-Rest layer if anything classified persists on the device. Samsung includes one; on other platforms it is a separate listed product.
- Gray and Red management infrastructure — the management plane sits inside the solution boundary, not on the internet. That is real infrastructure, not a SaaS tenant.
- Registration effort — the Compliance Checklist Workbook is substantial, and answering it requires the design to be settled.
- Version discipline forever — your solution is registered against specific OS and component versions. Uncontrolled updates move you outside it.
The single largest cost reduction available to most programs is answering one question honestly at the start: does classified data actually need to rest on the device? If the answer is no, an entire Capability Package and its component stack drop out of scope.
The upside worth remembering
This is still dramatically faster than the alternative. CSfC exists so that agencies can field classified mobility on commercial hardware in months rather than waiting years for purpose-built equipment. The rules are demanding because the shortcut is enormous.
High-Security Mobility
If your data is CUI or sensitive-but-unclassified, most of the above does not apply — and your platform options are considerably wider. Start there instead.
The registries that govern all of this
Capability Packages, the Components List, NIAP, FIPS and the STIG library — what each one decides and where to check it.
Scoping a classified deployment?
Tell us whether data rests on the device, what your users carry today, and who manages the fleet. Those three answers determine most of the cost — and we can usually tell you in one conversation.