DISA STIGApplies. Published mobile STIGs are explicitly scoped to unclassified data up to CUI, for corporate-owned deployments. This is your configuration baseline and your evidence at assessment.
NIAP validationApplies. The device should be validated against the Mobile Device Fundamentals Protection Profile. Listing on the CSfC Components List is not required.
FIPS 140 cryptographyApplies. Federal use of cryptography for sensitive information requires CMVP-validated modules. Watch for certificates marked Historical.
Mobile device managementApplies. You need enforcement, not just policy on paper. Any capable UEM works — the single-product CSfC constraint does not bind here.
Two independent encryption layersDoes not apply. One properly validated layer, correctly configured, is the requirement. This is the largest single cost difference.
CSfC Components ListDoes not apply. Which is why your platform options widen considerably — see below.
Solution registration with NSADoes not apply. You accredit through your own process with your Authorizing Official.