Samsung has invested more heavily in government mobility certification than any other Android
vendor, and the paperwork trail is genuinely extensive. This page is the map: what Samsung has
actually achieved, and a direct link to the authoritative registry for every claim — so you can
verify rather than take anyone's word for it.
On the CSfC Components List
2 entries — Android 14 and Android 15
DAR CP approval
Knox File Encryption, June 2020
Field hardware
Tactical Edition phones and tablets
Background
Why Samsung shows up in nearly every CSfC mobile conversation.
Samsung's position in classified mobility rests on three things that took years to assemble: a
security platform built into the devices rather than bolted on, a purpose-built hardware line for
field use, and a certification program that keeps pace with both.
Knox: the platform underneath
Knox is Samsung's security architecture — hardware root of trust, Work Profile containerization,
attestation, and the policy surface that lets a UEM manage all of it. For CSfC purposes the
headline capability is Knox DualDAR, which applies two independent encryption
layers to data at rest: an outer layer executed by a hardware storage encryption module in the
System-on-Chip, and an inner layer executed by a kernel cryptographic module inside the Work
Profile.
That independence is what matters. In June 2020, NSA approved Samsung Knox File
Encryption as an independent cryptographic layer meeting the requirements of the Data-at-Rest
Capability Package — initially covering Android 9 with Knox File Encryption v1.0 and Android 10
with v1.2, with coverage extending through subsequent releases. Samsung states that DualDAR
enables storage of data classified up to Top Secret. That is Samsung's characterization; your
Authorizing Official and the registered solution determine what you can actually store.
Tactical Edition: hardware for the field
Samsung maintains a Tactical Edition line built specifically for military and first-responder
use: the Galaxy S23 Tactical Edition, the ruggedized Galaxy XCover6 Pro
Tactical Edition, and the Galaxy Tab Active5 Tactical Edition. These
carry IP68 and MIL-STD-810H ratings and add capabilities aimed squarely at dismounted operations
— Covert Lock for hardware-level radio shutdown, Stealth Mode for off-grid use, external GPS and
laser rangefinder support, drone video feeds, and tactical radio interoperability. They are built
to run ATAK, APASS, and BATDOK.
Certification as a continuing program
Samsung treats certification as an ongoing release cadence rather than a one-time milestone.
Galaxy devices carry Common Criteria validations tracking each Android version, FIPS-validated
cryptographic modules, DoDIN APL listings, published DISA STIGs, and national approvals across
Germany, the UK, Spain, Portugal, the Netherlands, Australia, Finland, Poland and elsewhere.
The six below are the ones that matter for a US classified deployment.
Certifications attach to exact combinations
Every approval below applies to a specific device model, on a specific OS version, with a specific
Knox version. "Samsung Galaxy is certified" is not a statement you can build a design on. Confirm
the exact triple you intend to field against the registry itself — which is why every card links
straight to the source.
Samsung Certifications
Six registries, and where to check each one.
These build on each other rather than sitting side by side: FIPS validates the cryptography,
Common Criteria evaluates the product, NIAP runs that evaluation for the US, CSfC listing depends
on NIAP validation, DoDIN APL governs network connection, and the STIG defines how you configure
what you bought.
NIAP
National Information Assurance Partnership
The US scheme that evaluates commercial products against Protection Profiles. NIAP validation is
the prerequisite for CSfC listing — no NIAP, no CSfC.
Samsung Galaxy devices are validated against the Mobile Device Fundamentals Protection
Profile with separate evaluations tracking each Android release. Knox File Encryption
holds its own validation as a distinct product.
NSA's program for protecting classified data with layered commercial products. The Components
List is the authoritative record of what may be used in a registered solution.
Listed
Samsung holds two current entries under End User Device / Mobile Platform — Galaxy
Devices on Android 14-Fall (VID 11539, listed 2024.12.23) and on Android 15-Spring
(VID 11593, listed 2025.07.09). Samsung separately reports nine Galaxy devices approved — including Galaxy S23 Ultra
5G, S22 Ultra 5G, S21 Ultra 5G, Z Flip and XCover Pro. Knox File Encryption is separately
approved as an independent cryptographic layer for the Data-at-Rest Capability Package.
The international standard for security evaluation (ISO/IEC 15408). Certificates issued under
the recognition arrangement are accepted across member nations — NIAP is the US scheme within it.
Samsung Galaxy devices have carried Common Criteria certification against the Mobile Device
Fundamentals Protection Profile since 2014, when Samsung became the first mobile vendor
to achieve MDFPP certification. Evaluations have tracked each Android release since.
DISA's list of products cleared to connect to the Department of Defense Information Network.
Separate from CSfC and separately required — a device can be CSfC-listed and still need APL
status to join the network.
Program sunset
Multiple Galaxy devices are listed, including Z Fold6, S24, S23, S22 and S21 families.
However, DISA sunset the APL program effective 30 September 2025, maintaining the
repository through FY2026, with cybersecurity requirements moving to the DISA Vendor STIG
program. Treat an APL listing as historical record rather than a forward-looking credential.
NIST's Cryptographic Module Validation Program. Validates that the cryptography itself is
correctly implemented — the foundation every higher certification assumes.
Under FIPS 140-3: SCrypto v2.7 (Cert. #4792) and SKC v2.3 (Cert. #4764). Under
FIPS 140-2: Samsung Kernel Cryptographic Module v2.2 (#4097), Flash Memory Protector
v3.0.1 (#4092), BoringSSL Cryptographic Module v1.5 (#3900) and SCrypto v2.5 (#3791).
Not a certification — a configuration standard. The STIG tells you how the device must actually
be set up on a DoD network, and it is what an assessor checks you against.
Current published baselines cover Samsung Android OS 17 with Knox 3.x and
Samsung Android 16 with Knox 3.x. Applying the STIG is where most of the real
implementation work lives.
Certification listings are precise, sprawling, and easy to misread. Tell us the devices you are considering and we will tell you exactly what is covered — and what is not.