The fruity cargo cult Apple released a story yesterday claiming that the iPhone and iPad can be used with NATO-restricted level classified information after meeting NATO’s information assurance requirements.
It claimed that no special software or settings were required, and Apple gear was just naturally secure enough. What was surprising, even for the minions in the Tame Apple Press, was that no one questioned the story.
The headline claim, “Certified for use with classified data in all NATO nations,” is technically possible and still wildly misleading in the way it will be read. Job’s Mob is talking about NATO RESTRICTED, the lowest rung of NATO classified information, not NATO SECRET, NATO CONFIDENTIAL or COSMIC TOP SECRET.
NATO RESTRICTED is not the stuff of spy thrillers. US guidance describes it as information that needs safeguards against public release and disclosure, and it is explicitly not at the higher NATO levels.
The “in all NATO nations” phrasing leans on NATO catalogue listing, not on every ministry in every member state suddenly letting staff fling restricted documents around unmanaged iPads. The NATO Information Assurance Product Catalogue is exactly that, a catalogue, and it carries a user caveat about security responsibilities, conditions and proper deployment.
NATO’s own listing for iOS 26 and iPadOS 26 ties approval to an “indigo configuration” and says approval applies when the security configuration requirements are met. That is not the same thing as “no special settings” in any environment that fancies itself as NATO-adjacent.
That leads to the next stretch, “No special software or settings are required.” It is a neat line for consumers and a headache for anyone who has ever had to pass an audit. You can avoid third-party security add-ons while still requiring a controlled operational environment, device supervision, policy enforcement, and specific configuration baselines. The German scheme write-up makes clear that this is evaluated against Common Criteria and includes operational requirements, not vibes. (
Now for the “German government security testing” mystery box. The German Federal Office for Information Security, the BSI, is the body named in coverage and in Job’s Mob’s own material, and the Common Criteria assurance level cited for iOS/iPadOS 26 is EAL4+. That is a solid, familiar certification framework, but it is not a magical cloak that turns every retail handset into a secure terminal everywhere it goes.
The “first and only consumer mobile products” boast is marketing with the serial numbers filed off. BlackBerry 10 received approval to handle NATO-restricted information in 2013, which makes “first ever” nonsense unless you narrow it to a specific definition of consumer hardware and the scope of the scheme.
Job’s Mob tries to inflate the moment with a slab of self-congratulation: “Apple designs security into all of its products from the start, ensuring the most sophisticated protections are built in across hardware, software, and Apple silicon. This unique approach enables Apple users to benefit from industry-leading security protections, including best-in-class encryption, biometric authentication with Face ID, and groundbreaking features such as Memory Integrity Enforcement. These same protections are now recognised as meeting stringent government and international security requirements, even for restricted data.”
But that is bollocks too. Certifications say “meets these defined requirements under these conditions for this scope”, and they do not hand out “best in class” trophies.
Apple, vice-president of security Ivan Krstić said: “This achievement recognises that Apple has transformed how security is traditionally delivered. Prior to the iPhone, secure devices were only available to sophisticated government and enterprise organisations after a massive investment in bespoke security solutions. Instead, Apple has built the most secure devices in the world for all its users, and those same protections are now uniquely certified under assurance requirements for NATO nations — unlike any other device in the industry.”
The only part of that quote grounded in checkable reality is the certification claim, and even that has a scope. Apple’s own support documentation frames the iOS/iPadOS 26 entry as an approval on the NATO RESTRICTED level under the BSI scheme, with certification and validation dates, and explicitly references Common Criteria at EAL4+.
The story glosses over what the catalogue entry is actually for. The line about “secure access to Mail, Calendar, and Contacts” is the real-world shape of the approval. It is about PIM access in restricted environments, not turning iPads into portable command posts.
So the accurate version is less “NATO clears iPhones for classified data” and more “iOS 26 and iPadOS 26, in an evaluated configuration, are approved at NATO RESTRICTED level based on BSI assessment and added to NIAPC”. That is still a notable milestone for a mass-market platform, but it is not the geopolitical mic drop the copy wants you to swallow.
Android has been in the NATO RESTRICTED world for ages, just usually via hardened Samsung-based platforms or specialist secure mobility products, while Apple is trying to sell “consumer kit, fewer add-ons” as a category win.
Android’s reality is more fragmented. There is no single “Android” that gets blessed; it is a specific vendor device, build, and configuration, often with a hardened mode, secure container, or dedicated secure comms stack layered on top. Samsung even documents a “Common Criteria Mode” tied to certification-driven deployments, which tells you how far this is from a generic consumer setup.







