Classify the job before the phone
A spare camera and a primary authenticator do not need the same risk tolerance. List the accounts, work profiles, passkeys, payment apps, and recovery methods that would depend on the device. Higher-impact use calls for a longer documented security window and faster patch cadence.
Require current model-scoped evidence
Use an exact model and region record backed by the manufacturer or an appropriate regulator. A device being able to install an app is not proof of firmware support. Record the installed patch level and compare it with the model or carrier release channel.
Plan for support changes
Leave enough supported life for procurement delays, travel, repair, and account migration. Enable automatic updates, but still review the patch level periodically. When a model moves from monthly to quarterly updates, record the cadence change rather than calling it immediately unsupported.
Protect recovery paths
Maintain recovery codes or a second approved authentication method somewhere separate from the phone. Before repair or replacement, back up necessary data, follow employer policy, and confirm that activation locks and managed profiles can be transferred safely.
Define a replacement trigger
Set a trigger before the security end date, not after it. A confirmed recall, unsupported required app, missing critical patch, or loss of authorized repair may justify earlier action. Verify each trigger against a current official source rather than a marketplace claim.
Primary sources
Android Open Source Project · checked 2026-09-04
Apple Support · checked 2026-09-04
Samsung Mobile Security · checked 2026-09-04
U.S. Consumer Product Safety Commission · checked 2026-09-04
Device support and safety information can change. Recheck the linked manufacturer and regulator evidence before making a purchase or safety decision.