Amazon Web Services has become the first cloud provider approved to process NATO RESTRICTED information across all 32 NATO member states. The authorization gives governments and defense organizations a NATO-recognized security baseline for eligible AWS services, but it does not permit unrestricted use of AWS for classified data.

The approval applies only to AWS services accepted under the scheme and operated in AWS Regions located within NATO member states. AWS currently has 15 Regions in member countries, including seven in continental Europe. Organizations must still complete applicable national accreditation processes and use approved configurations before handling NATO RESTRICTED workloads.

AWS demonstrated compliance with NATO D32, the technical directive governing the protection of NATO RESTRICTED information in public-cloud environments. Spain’s Centro Criptológico Nacional evaluated the AWS capabilities before NATO accepted and published the approval for the Alliance’s members.

The deployment model also draws on AWS Trusted Secure Enclaves – Sensitive Edition, an architecture designed for government and defense organizations working with sensitive data. AWS Europe (Spain) had already received approvals for NATO RESTRICTED workloads and Spain’s national Difusión Limitada classification.

What NATO RESTRICTED covers

NATO RESTRICTED is the entry level in the Alliance’s four-tier classified-information system. It covers information requiring protection where unauthorized disclosure could harm NATO interests or activities; it is not an authorization to handle NATO SECRET or COSMIC TOP SECRET material.

For member-state institutions, the practical effect is that part of the underlying cloud-security assessment has already been completed at NATO level. That could reduce duplicated technical evaluation, time and cost, while leaving national authorities in control of accreditation and classified-data rules.

The move also sets a notable precedent for public cloud in defense infrastructure. A hyperscale provider’s public-cloud platform can now form part of the approved chain for processing a defined category of NATO classified information, rather than requiring every deployment to be built entirely on dedicated national infrastructure. The key remaining limitation is that access depends on each country’s authorization of the relevant AWS services, regions and customer configurations.

SOURCEaboutamazon.com
Previous articleHuawei Watch D3 Focuses on Long-Term Blood Pressure Tracking as Survey Finds Daily Checks Remain Rare
Next articleGoogle, OpenAI and Other AI Leaders Sign Voluntary White House Safety Pact