“Supports thousands of devices” sounds useful because it compresses a complicated procurement decision into one number. It is also rarely sufficient.
The same model may behave differently across operating-system versions, security patches, chipsets, lock states and acquisition methods. A listed device may support only a narrow method. An acquisition may complete while missing the application or artifact that matters to the buyer.
Build a weighted device set
Use the organisation’s case history to create a representative test set:
- high-volume Android and iOS models;
- older devices that remain common in the field;
- high-risk devices or applications where failure is costly;
- locked and unlocked states that reflect actual work;
- known datasets with messages, media, accounts, locations and timestamps.
Weight the set. A method that performs well on the devices responsible for most real matters may be more valuable than a much larger nominal catalogue.
Test the complete route
An acquisition demo is not a workflow test. Evaluate the full route from intake to report:
| Stage | Questions to test |
|---|---|
| Qualification | Can the team identify prerequisites and likely limitations? |
| Acquisition | Are device-side actions, logs, warnings and outputs recorded? |
| Analysis | Can findings be traced to source records? |
| Export | Do timestamps, attachments and relationships survive? |
| Review | Can another examiner reproduce or challenge the interpretation? |
| Support | Is escalation responsive and technically accountable? |
Record misses, not only successes
Known-data testing is useful only when missing or misinterpreted artifacts remain visible. Record false positives, timezone errors, duplicate handling, unsupported stores and version-specific behaviour.
When a vendor updates a parser or acquisition method, decide whether the change requires targeted revalidation before case use.
Price the operating system, not just the licence
The realistic cost includes appropriate workstation or hardware, secure updates, annual support, implementation, examiner training, SOP changes, validation time and renewal exposure. It may also include a second tool for specific methods or independent checking.
A good procurement outcome is not “the longest feature list.” It is a documented fit between the organisation’s workload and a method the team can operate and defend.
Read the mobile forensic tools evaluation approach or start a licensing discussion.