Skip to main content
GentryJr
Google Team
July 23, 2026
Security

Android 17 STIG is now live!

  • July 23, 2026
  • 4 replies
  • 1382 views

Hello,

 

For those who don’t know me, my name is Gentry and I’m part of the Android Enterprise Team. 

 

We are excited to share that the official Google Security Technical Implementation Guide (STIG) for Android 17 is now live!

 

Created in close collaboration with the Defense Information Systems Agency (DISA), this annual updated guide delivers an expert-vetted baseline to help organizations lock down their Android mobile deployments to the highest level of security. While designed with defense and government requirements in mind, it’s an invaluable blueprint for any enterprise operating in regulated sectors, such as FSI and Healthcare.

 

What is the STIG?

A Security Technical Implementation Guide is a comprehensive hardening blueprint.

Instead of relying on out-of-the-box configurations, the STIG provides exact, actionable instructions to tune operating system settings, toggle unneeded services, and close common attack vectors. By implementing these controls, you systematically reduce your device attack surface before threats can materialize.

 

Who should use the STIG?

While STIG compliance is mandatory for DoD (Department of Defense) and federal agencies, the Android STIG serves as a gold-standard baseline for commercial enterprises looking to elevate their mobile security.

The Android 17 STIG provides tailored configuration rules specifically for:

  • COBO (Corporate-Owned, Business-Only)
  • COPE (Corporate-Owned, Personally-Enabled)

 

Key benefits for your enterprise

  • Achieve the highest security posture: The guide closes configuration weaknesses and minimizes your system’s attack surface, dramatically improving your defence against threats and enhancing system resilience.
  • Ensure mandatory compliance: For federal and DoD-connected systems, STIG compliance is a non-negotiable step to meet the Risk Management Frameworks (RMF) and gain Authority to Operate (ATO).
  • Unlock a standardized and efficient management framework: It provides a single, expert-defined security baseline across all your devices, which simplifies system auditing, prioritizes critical fixes (using the CAT I, II, III severity levels) and streamlines auditing and reporting.

 

Time to strengthen your security posture!

You can download the full Android 17 STIG directly here to start evaluating and applying these baseline controls to your organization's device management policies today!

4 replies

Michel
Level: 4.1: Jelly bean
July 24, 2026

Awesome, nice! 

 

Do you have any plans to also work on a benchmark such as NIST or CIS for android? (not just pixel). This could be helpfull for NIS2 compliancy for example. 

Lizzie
Community Manager
August 3, 2026

Thanks for asking about this ​@Michel. Do you find that a lot of people look more to NIS2 in Europe over the STIG? or both? 

Welcome to the Community everyone!
Michel
Level: 4.1: Jelly bean
August 3, 2026

Yes, definitely! I've never heard someone talk about STIG, most of them don't even know it exists. STIG is great for the defense grade security, but its way to much for the average company. NIS2 is a guideline that basicly says you need to do what fits you in order to limit the risks without exactly telling what to configure.

 

STIG tells you exactly what to do, but it is way to heavy for most NIS2 compliance companies (think about water companies, eletrical etc). It could work for some workers with access to sensitive data, but for most workers the CIS benchmark is a better fit. Its a bit less heavy than the STIG guidelines, but still secure. Which fits the NIS2 rules a lot better in most cases. 

pedrojadir
New Member
August 7, 2026

Hi Gentry,

I’m new to the community and currently focusing on Android Enterprise security. I’ve been going through the Android 17 STIG and the discussion here around STIG, CIS and NIS2.


One thing I’m trying to better understand is the relationship between prescriptive hardening and runtime threat detection. The STIG includes requirements around security logging and Mobile Threat Detection (MTD), while Android 17 is also introducing capabilities such as Play Protect Live Threat Detection and dynamic signal monitoring using on-device AI.


For a COBO/COPE deployment aligned with the STIG, how should organizations think about the operational relationship between these native Android protections and an enterprise MTD solution?


For example, are they expected to operate as complementary detection layers, and is there recommended guidance for correlating behavioral detections, device posture and security telemetry into an enterprise SOC/threat detection workflow particularly for emerging or previously unseen malicious behavior?


I’d be interested in understanding how the Android Enterprise team sees that architecture evolving.

University Professor | Cybersecurity Research | Android Enterprise Security | Security Intelligence Lab