Regulations and credentials

Every regulatory requirement, with its evidence alongside

A security committee or an accreditation authority does not buy adjectives: it asks which regulation applies, what it demands and how that is demonstrated. This page walks through the regulatory framework affecting mobility in defence, police and intelligence (ENS, CCN-STIC guides, CPSTIC catalogue, classified information, NIS2, GDPR) and the Samsung SDS EMM certifications that Blindium has verified against an official source.

Cyber defence operations room
Regulatory map

Which regulation applies, what it demands and how it is demonstrated

Reference framework for a mobility system in defence, police or intelligence in Spain. For each regulation we state what the platform covers, what the Blindium procedure covers and what is out of scope. Compliance is always assessed on the complete system, never on a product.

Regulation or frameworkWhat it demandsHow it is addressedScope and evidence
National Security Framework, ENS (Royal Decree 311/2022)Annex II measures by system category: access control, operations, protection of equipment and communications, activity logging.ENS control map against the platform: mp.eq, mp.com, op.acc, op.exp and op.mon in the High category. Policies, encryption, VPN and traceability from the console.Alignment
CCN-STIC mobile device guidesSecure device configuration and fleet management (450 series and the CCN guides for Android and Knox).The EMM policy baseline is documented control by control against the guide applicable to each Android and Knox version.Alignment
CPSTIC catalogue (CCN)Use of qualified or approved products in public-sector systems and in systems handling classified information.The Galaxy models and versions listed in the catalogue are identified with their family and level. No qualification is claimed for any component not listed.Alignment
Classified information (Law 9/1968, National Security Authority)System accreditation by the competent authority before handling classified information.Accreditable architecture: isolated network, Private Push, DualDAR, double tunnel and full traceability. Blindium prepares the technical documentation for the file; the authority accredits.Alignment
NIS2 (Directive (EU) 2022/2555) and critical infrastructure protectionRisk management, continuity, access control and incident notification in essential and important entities.Inventory, continuous compliance, per-app VPN to OT segments, kiosk and remote wipe as technical measures within the entity's plan.Alignment
GDPR and Spanish LOPDGDDSecurity of processing, minimisation, access control and impact assessment where applicable.Data and console on the organisation's infrastructure: no personal management data reaches a cloud vendor. Encryption, container and remote wipe as Article 32 measures.Alignment
Common Criteria ISO/IEC 15408: NIAP MDM-PP v4.0Independent evaluation of the mobile device management product under a protection profile.NIAP certification of "Samsung SDS EMM and EMM Agent for Android" version 2.2.5 (February 2020).Verified
DISA STIG "Samsung SDS EMM"Secure configuration required by the US Department of Defense for the product.Guide V1R3 (23 requirements) applied as the hardening baseline for the EMM server in every deployment.Verified
FIPS 140-2 and NSA CSfCValidated cryptographic modules and components admitted in commercial solutions for classified information.Declared by the manufacturer; the CMVP certificate and the component list are provided with each proposal.Per manufacturer
Alignment: the platform contributes to compliance and Blindium provides the control map; compliance or accreditation is assessed on the complete system. Verified: checked against an official source. Per manufacturer: appears only in Samsung SDS documentation.
For the file

What Blindium delivers for a committee, a tender or an accreditation

  • ENS control map per Annex II measure, with the owner of each control: platform, procedure or out of scope.
  • CCN-STIC mapping between the applicable guide and the EMM policy baseline, control by control.
  • CPSTIC scope statement with model, version, family and level of every component listed in the catalogue.
  • Original certificates NIAP, STIG and, per manufacturer, FIPS and CSfC, with the product version they refer to.
  • Accreditable architecture network diagrams, flows, encryption and traceability for the accreditation file.
  • Tender template technical requirements, objective evaluation criteria and evidence to be demanded from bidders.
Verifiable security

Credentials that can be presented to a security committee

Each credential links to its official source on the credentials page. References that appear only in the manufacturer's documentation are marked as such.

NIAP Common Criteria
MDM-PP v4.0
NIAP certification under the MDM Protection Profile v4.0 (February 2020) of the product "Samsung SDS EMM and EMM Agent for Android", version 2.2.5. First EMM solution to obtain it.
DISA
Samsung SDS EMM STIG
DISA Security Technical Implementation Guide for Samsung SDS EMM, version V1R3 (June 2022), applicable to the product version stated in the guide itself.
Android Enterprise
Gold Partner
Recognition by Google of a small group of EMM providers (May 2025).
NSA
CSfC programme
The manufacturer states that it was the first EMM provider in the Commercial Solutions for Classified programme (2015).
Cryptography
FIPS 140-2
FIPS 140-2 validated cryptographic module, as stated by the manufacturer. The applicable CMVP certificate and module version are identified in each project.
Spain
ENS and CCN-STIC
Architecture and policies aligned with the Esquema Nacional de Seguridad (ENS) and the CCN-STIC guides for mobile devices.
Alignment, not certification.
Isolated network
Air-gap with Private Push
Device management without an Internet connection through a private notification server.
Samsung Knox
Native integration
Knox Mobile Enrollment, DualDAR, E-FOTA and Galaxy Tactical Edition.

* Reference stated by the manufacturer in its public documentation; it does not replace the documentary evidence provided in each project. All certifications and validations cited refer to specific products, versions and modules, which are identified in each proposal.

View credentials and sources

Credentials

Credentials table and verification status

CredentialWhat it attestsDateStatusSource
NIAP Common Criteria, MDM-PP v4.0 Certification of the product "Samsung SDS EMM and EMM Agent for Android", version 2.2.5, under the Mobile Device Management Protection Profile v4.0 (ISO/IEC 15408). First EMM solution to obtain it. The certification refers to that evaluated version. February 2020 Verified Samsung SDS, official announcement
DISA STIG: Samsung SDS EMM Security Technical Implementation Guide from the Defense Information Systems Agency, version V1R3 with 23 requirements (4 CAT I, 17 CAT II, 2 CAT III). June 2022 Verified DISA / STIG Viewer
Android Enterprise Gold Partner Distinction awarded by Google to a small group of EMM providers for experience, product and results; listed in the Android Enterprise solutions directory. May 2025 Verified Samsung SDS, official announcement
NSA CSfC The manufacturer states that it was the first EMM provider in the NSA Commercial Solutions for Classified programme (2015). 2015 According to manufacturer Samsung SDS, product sheet
FIPS 140-2 The manufacturer states that its cryptographic module is FIPS 140-2 validated. The CMVP certificate number is provided in each project. According to manufacturer According to manufacturer Samsung SDS, product sheet
Air-gap with SDS Private Push Documented capability to manage devices without an Internet connection through a private notification server. Current Verified Samsung SDS, product sheet
Credentials marked "According to manufacturer" appear in the public documentation of Samsung SDS and could not be verified in an independent register accessible from this website. The source documents are provided with each proposal.
Spanish framework

Fit with ENS, CCN-STIC and public tenders

No EMM platform is "ENS certified" in itself: the ENS certifies information systems, not products. What Blindium provides is a control map indicating which requirement of the framework is covered by the platform, which is covered by procedure and which falls outside the scope.

Esquema Nacional de Seguridad

Map of Annex II controls (operational framework and protective measures) against the capabilities of the platform, with particular attention to mp.eq (equipment), mp.com (communications), op.acc (access control) and op.exp (operations) in the High category.

CCN-STIC guides

The secure configuration guides for mobile devices and fleet management are translated into the EMM policy baseline. The correspondence is documented control by control.

CPSTIC catalogue

The proposal indicates which components of the project are qualified or approved in the CCN catalogue and in which category. No qualification is claimed for any product that does not appear in the catalogue.

Public tenders

Blindium provides technical requirements, objective evaluation criteria and verifiable references so that the contracting authority can demand evidence rather than descriptions.

ENS and CCN-STIC: the architecture can be designed to contribute to compliance with ENS controls and to apply CCN-STIC guides; compliance is assessed on the complete system. Where CPSTIC products are mentioned, the model, version, family and level currently listed in the CCN catalogue are identified; that qualification does not extend to components not included.

Samsung Knox

Device platform certifications

The EMM controls rely on Samsung Knox, the security platform built into the hardware of Galaxy devices. Samsung maintains Common Criteria certifications for its devices and FIPS validations for its cryptographic modules; the details by model and version are found in the official Samsung Knox documentation and are included in each proposal.

Next step

Free MDM/EMM continuity assessment (45 minutes)

A technical session with a specialist to review your situation and return an actionable recommendation. No obligation.

  • Current architecture and number of devices
  • Data criticality and network constraints
  • Integration with Samsung Knox and mixed fleets
  • Transition options and deployment model (on-prem, private cloud or hybrid)

The assessment is a preliminary guidance session and does not constitute an audit, certification, accreditation, expert report or guarantee of compliance. Its conclusions depend on the information provided and must be technically validated within the scope of each project.