Amazon Web Services has become the first cloud provider authorized to handle NATO RESTRICTED workloads across all member nations, according to Channel Insider. The approval allows NATO, its defense industry partners, and all member countries to use designated AWS services for managing NATO RESTRICTED information across 15 AWS regions located in NATO member states. The authorization establishes a shared security baseline designed to simplify national accreditation procedures.
The approval covers 15 AWS regions in countries that belong to NATO, granting allies access to approved cloud services for handling sensitive NATO RESTRICTED data. More than 15,000 government customers currently rely on AWS to reduce expenses, boost resilience, and drive innovation. AWS documented its adherence to D32, a technical directive that sets security requirements for processing NATO RESTRICTED information on public cloud platforms. Spain's National Cryptographic Centre evaluated AWS capabilities as part of the approval process, with NATO then approving and distributing the results to all allied nations.
Matt Garman, CEO of AWS, said "Defense and public sector customers need to move fast, and the security requirements they work under are rigorous." He added that allied nations and defense industry partners now possess a shared assessed foundation to build upon, rather than each country independently conducting much of the same evaluation. David Appel, Acting Vice President of Worldwide Public Sector at AWS, characterized the authorization as "the culmination of a sustained, multi-year effort" reflecting the company's commitment to supporting defense, public sector, and NATO-affiliated customers. Dylan Browne, general manager of the NATO Communications and Information Agency, noted that strengthening NATO's capacity to securely use commercial technology is essential for building a more resilient and agile alliance.
The approval means NATO members receive a common, pre-assessed security baseline that the report indicates will reduce the time, effort, and cost of fulfilling security and compliance requirements. Following AWS's NATO RESTRICTED approval, allied nations gain an accelerated route to accreditation through their official national processes. The availability of commercial products meeting NATO's security standards expands technology options for the alliance and supports adoption of modern technologies while preserving the security and resilience that operations require. NATO delegates the accreditation process for NATO RESTRICTED workloads to a member nation or the NATO Communications and Information Agency serving as a host nation.
The authorization provides NATO allies with commercial cloud infrastructure to modernize and safeguard critical missions collectively. AWS will continue working to deliver the interoperability that allied nations need to strengthen their resilience and protect their populations. The shared security baseline eliminates redundant evaluation work that previously required each country to independently assess much of the same security controls, allowing defense organizations to deploy cloud capabilities more rapidly while meeting stringent requirements. The alliance between NATO's security framework and commercial cloud infrastructure positions defense organizations to balance operational speed with the rigorous security standards that classified information demands, though success will depend on how effectively member nations implement their accelerated accreditation processes.

