The endpoint decides most of your architecture.
Capability Packages are written to be platform-neutral. Real deployments never are. What you can build, how long it takes, and what you have to buy separately all change depending on what is in the user's hand — and the differences are larger than most programs expect going in.
The constraint that surprises people
The Mobile Access Capability Package requires that End User Devices be selected from the CSfC Components List, or built from sub-components that are. A device can hold excellent NIAP validation, current FIPS certificates and a published DISA STIG, and still be ineligible as a CSfC end user device — because listing additionally requires the vendor to enter an agreement with NSA, and not every vendor has.
As of August 2026 the End User Device / Mobile Platform category is entirely Android. That single fact reshapes more programs than any technical consideration on this page.
01 — Management
Before the devices, the thing that configures them. In a CSfC architecture the management plane is not adjacent to the security boundary — it defines it.
02 — Mobility
Phones and tablets. This is where CSfC mobile deployments live, and where the platform choice has the sharpest consequences.
Android — Google Pixel CSfC listed
Listed on the Components List at Android 15. First-party silicon, a Common Criteria–certified secure element, and the fastest certification cadence in Android.
Android — Samsung Galaxy CSfC listed
Two Components List entries covering Android 14 and 15. Knox DualDAR supplies an NSA-approved inner encryption layer, plus purpose-built tactical hardware.
Apple iOS & iPadOS Not CSfC listed
Deep NIAP and FIPS credentials and a current DISA STIG — but absent from the CSfC Components List, which rules iPhone and iPad out as end user devices today.
What is true regardless of platform.
Every platform page answers the same five questions. If you are evaluating something not covered here, these are the questions to ask of it.
Is it on the Components List — at the version you intend to field?
Listings name specific OS versions. Being listed at Android 15 says nothing about Android 16. This question has a yes-or-no answer and it gates everything else.
Where does the second encryption layer come from?
Two independent layers, in transit and — if data persists — at rest. Some platforms supply the inner layer; on others you buy it. This is the biggest hidden cost difference between platforms.
Can your management tooling actually enforce the configuration?
A control you cannot push from your UEM is a control you will be arguing about at assessment. Prove it in a lab, on your hardware, before the purchase order.
Is there a current STIG, and who applies it?
The STIG is the configuration baseline and the evidence. Confirm one exists for your exact OS version, and that someone owns applying and maintaining it.
What happens at the next OS release?
Certifications, listings and STIGs all lag shipping software. Plan for the gap between what your users want to install and what your solution is registered against — and control updates from day one.
Choosing a platform right now?
Tell us whether data rests on the device, who manages the fleet, and where it gets used. Those three answers usually settle the platform question on their own.