The source code in this case is available both to the NSA testers trying to hack it as well as to customers. "Security through obscurity" isn't good enough to get that level of EAL certification. It requires going through each line of code and proving that its secure, even to someone who knows exactly how it works. It would be theoretically possible to do it with open source, but it would require an extreme degree of organization and discipline compared to normal open source projects.