Android Platform Samsung Galaxy

Samsung & CSfC: the certification picture.

Samsung has invested more heavily in government mobility certification than any other Android vendor, and the paperwork trail is genuinely extensive. This page is the map: what Samsung has actually achieved, and a direct link to the authoritative registry for every claim — so you can verify rather than take anyone's word for it.

On the CSfC Components List
2 entries — Android 14 and Android 15
DAR CP approval
Knox File Encryption, June 2020
Field hardware
Tactical Edition phones and tablets
Background

Why Samsung shows up in nearly every CSfC mobile conversation.

Samsung's position in classified mobility rests on three things that took years to assemble: a security platform built into the devices rather than bolted on, a purpose-built hardware line for field use, and a certification program that keeps pace with both.

Knox: the platform underneath

Knox is Samsung's security architecture — hardware root of trust, Work Profile containerization, attestation, and the policy surface that lets a UEM manage all of it. For CSfC purposes the headline capability is Knox DualDAR, which applies two independent encryption layers to data at rest: an outer layer executed by a hardware storage encryption module in the System-on-Chip, and an inner layer executed by a kernel cryptographic module inside the Work Profile.

That independence is what matters. In June 2020, NSA approved Samsung Knox File Encryption as an independent cryptographic layer meeting the requirements of the Data-at-Rest Capability Package — initially covering Android 9 with Knox File Encryption v1.0 and Android 10 with v1.2, with coverage extending through subsequent releases. Samsung states that DualDAR enables storage of data classified up to Top Secret. That is Samsung's characterization; your Authorizing Official and the registered solution determine what you can actually store.

Tactical Edition: hardware for the field

Samsung maintains a Tactical Edition line built specifically for military and first-responder use: the Galaxy S23 Tactical Edition, the ruggedized Galaxy XCover6 Pro Tactical Edition, and the Galaxy Tab Active5 Tactical Edition. These carry IP68 and MIL-STD-810H ratings and add capabilities aimed squarely at dismounted operations — Covert Lock for hardware-level radio shutdown, Stealth Mode for off-grid use, external GPS and laser rangefinder support, drone video feeds, and tactical radio interoperability. They are built to run ATAK, APASS, and BATDOK.

Certification as a continuing program

Samsung treats certification as an ongoing release cadence rather than a one-time milestone. Galaxy devices carry Common Criteria validations tracking each Android version, FIPS-validated cryptographic modules, DoDIN APL listings, published DISA STIGs, and national approvals across Germany, the UK, Spain, Portugal, the Netherlands, Australia, Finland, Poland and elsewhere. The six below are the ones that matter for a US classified deployment.

Certifications attach to exact combinations

Every approval below applies to a specific device model, on a specific OS version, with a specific Knox version. "Samsung Galaxy is certified" is not a statement you can build a design on. Confirm the exact triple you intend to field against the registry itself — which is why every card links straight to the source.

Samsung Certifications

Six registries, and where to check each one.

These build on each other rather than sitting side by side: FIPS validates the cryptography, Common Criteria evaluates the product, NIAP runs that evaluation for the US, CSfC listing depends on NIAP validation, DoDIN APL governs network connection, and the STIG defines how you configure what you bought.

NIAP

National Information Assurance Partnership

The US scheme that evaluates commercial products against Protection Profiles. NIAP validation is the prerequisite for CSfC listing — no NIAP, no CSfC.

Samsung Galaxy devices are validated against the Mobile Device Fundamentals Protection Profile with separate evaluations tracking each Android release. Knox File Encryption holds its own validation as a distinct product.

CSfC

Commercial Solutions for Classified

NSA's program for protecting classified data with layered commercial products. The Components List is the authoritative record of what may be used in a registered solution.

Listed

Samsung holds two current entries under End User Device / Mobile Platform — Galaxy Devices on Android 14-Fall (VID 11539, listed 2024.12.23) and on Android 15-Spring (VID 11593, listed 2025.07.09). Samsung separately reports nine Galaxy devices approved — including Galaxy S23 Ultra 5G, S22 Ultra 5G, S21 Ultra 5G, Z Flip and XCover Pro. Knox File Encryption is separately approved as an independent cryptographic layer for the Data-at-Rest Capability Package.

CC

Common Criteria

The international standard for security evaluation (ISO/IEC 15408). Certificates issued under the recognition arrangement are accepted across member nations — NIAP is the US scheme within it.

Samsung Galaxy devices have carried Common Criteria certification against the Mobile Device Fundamentals Protection Profile since 2014, when Samsung became the first mobile vendor to achieve MDFPP certification. Evaluations have tracked each Android release since.

APL

DoDIN Approved Products List

DISA's list of products cleared to connect to the Department of Defense Information Network. Separate from CSfC and separately required — a device can be CSfC-listed and still need APL status to join the network.

Program sunset

Multiple Galaxy devices are listed, including Z Fold6, S24, S23, S22 and S21 families.

However, DISA sunset the APL program effective 30 September 2025, maintaining the repository through FY2026, with cybersecurity requirements moving to the DISA Vendor STIG program. Treat an APL listing as historical record rather than a forward-looking credential.

FIPS

FIPS 140-2 / 140-3

NIST's Cryptographic Module Validation Program. Validates that the cryptography itself is correctly implemented — the foundation every higher certification assumes.

Under FIPS 140-3: SCrypto v2.7 (Cert. #4792) and SKC v2.3 (Cert. #4764). Under FIPS 140-2: Samsung Kernel Cryptographic Module v2.2 (#4097), Flash Memory Protector v3.0.1 (#4092), BoringSSL Cryptographic Module v1.5 (#3900) and SCrypto v2.5 (#3791).

STIG

DISA Security Technical Implementation Guide

Not a certification — a configuration standard. The STIG tells you how the device must actually be set up on a DoD network, and it is what an assessor checks you against.

Current published baselines cover Samsung Android OS 17 with Knox 3.x and Samsung Android 16 with Knox 3.x. Applying the STIG is where most of the real implementation work lives.

Certification details and links compiled from Samsung Knox certifications, Samsung's DAR CP approval announcement, and Samsung Government Solutions. Current as of August 2026. Registries are updated continuously — treat the linked source as authoritative and this page as a starting point.