Steve Miller's Blog

AWS Cleared for NATO Secrets: When Cloud Vendors Join the Clearance Queue

Two IT professionals collaborate over laptops in a modern office, viewed through glass with soft reflections, black-and-white corporate style.

Every alliance runs on paperwork before it runs on packets. The latest stamp that operators are talking about is not a new firewall appliance or a zero-trust slide deck—it is the AWS NATO RESTRICTED cloud workloads approval that Amazon Web Services says makes it the first commercial cloud provider cleared for NATO RESTRICTED (NR) information across all member nations. Treat it like the world’s most expensive security questionnaire: multi-year evidence packs, a national crypto authority as referee, and a published baseline every vendor suddenly wants so defense shops can stop juggling air-gapped exceptions for the same class of data.

NR is not the top of the classification ladder. It is the rung where safeguarding is mandatory and the ops tax of “we can’t put that in commercial cloud” has historically been highest. Alliance planners need shared radar tracks, logistics status, and planning artifacts to move faster than Russian drones and gray-zone probes. Air-gapping every RESTRICTED workload is a correlated failure waiting for a change window—slow failover, duplicated tooling, and ticket queues that never clear. A common, pre-assessed cloud baseline does not erase accreditation; it shortens the path to it.

What the AWS NATO RESTRICTED Cloud Workloads Approval Actually Covers

According to AWS’s announcement, NATO, its defense industry partners, and member nations can use approved AWS services for NR workloads in any AWS Region located in a NATO member country. The company cites 15 such Regions, seven of them in mainland Europe. That geographic constraint matters: the stamp is not a blank check for every global AZ. It is a region-scoped authorization tied to alliance territory.

The technical bar was NATO D32—the directive that defines security requirements for handling NR information in public cloud. Spain’s National Cryptographic Centre (CCN) evaluated AWS against that directive; NATO then approved and published the findings Alliance-wide. For NR accreditation, NATO already delegates work to a member nation and/or the NATO Communications and Information Agency (NCIA) as host. Spain played that host role here, which is why Madrid shows up in the process story almost as often as Brussels.

The Next Web’s reporting fills in useful Spanish side-details: CCN and Spain’s National Security Office (ONS), under the CNI, also cleared the AWS Europe (Spain) Region for “Difusión Limitada” (DL)—Spain’s national equivalent of NATO Restricted—with data centers in Aragón. AWS had already reached Spain’s ENS scheme at the High level, with dozens of services listed in CCN’s approved-products catalog, and had to satisfy CCN-STIC-004 plus on-site data-center evaluation for DL. That stack of national stamps is what made the Alliance-wide NR publication credible rather than a press-release flourish.

Shared Baseline, Not Shared Risk Ownership

Here is the part operators should tattoo on the runbook: the Alliance-wide approval covers the provider’s capabilities, not the customer’s system. Each government still owns its national accreditation of the actual workloads riding on that infrastructure. AWS’s pitch—and Dylan Browne of NCIA’s quoted support—is that allies inherit a common, pre-assessed security baseline so they spend less time reinventing the same evidence package and more time proving their own control planes, identity boundaries, and data flows.

In practice that looks like fewer custom VMs in a bunker for NR-class collaboration tools, and more disciplined use of commercial services that already survived D32 scrutiny—provided your national process accepts the stamp. It does not mean you skip logging, CMDB hygiene, or continuous monitoring. It means the “is the cloud itself allowed?” debate can stop blocking every sprint while you still harden the tenant.

Defense One frames the geopolitics cleanly: Europe’s digital autonomy rhetoric coexists with deep reliance on U.S. hyperscalers. AWS beat other U.S. competitors to the first blanket NR approval after what David Appel (AWS Worldwide Public Sector) called a sustained multi-year effort. For an operator in a NATO ministry or a defense contractor, the competitive angle matters less than the ops angle—you now have one published path instead of fifty one-off exceptions.

Why Operators Care About the Questionnaire Metaphor

Security questionnaires are despised because they ask the same hundred questions in slightly different fonts. Alliance-grade cloud certification is that questionnaire with lawyers, national crypto labs, and data-center walkthroughs attached. The payoff of publishing one answered pack Alliance-wide is exactly what you want from a good change advisory board: reduce variance, reuse evidence, kill snowflake waivers.

Before this stamp, teams often kept NR-adjacent collaboration on air-gapped or sovereign stacks while everything else lived in commercial cloud. That split brain creates monitoring gaps—you cannot correlate SIEM signals you cannot see—and it trains people to route around process. A shared NR-capable commercial path does not magically unify your observability stack, but it removes a structural excuse for keeping RESTRICTED workflows offline from the tools everyone else already uses.

Region placement still rules. If your national policy demands EU-soil residency, the Spanish (and other European) Regions are the relevant failure domains, not us-east-1. EU Data Act pressure already pushed hyperscalers toward European control planes and residency options; Defense One notes that AWS and peers have been investing in European stack variants for exactly that reason. Operators should map NR workloads to NATO-member Regions first, then layer national encryption, key custody, and identity federation requirements on top—never the reverse.

What Does Not Change Tomorrow Morning

Classification boundaries above NR do not dissolve. SECRET and above remain their own worlds. Customer systems still need accreditation under national policy. Shared responsibility is unchanged: AWS covers the evaluated services and facilities; you cover IAM sprawl, misconfigured buckets, poorly scoped roles, and the humans who click through MFA fatigue.

Competitors will chase the same stamp. Expect Microsoft and others to treat D32 plus a friendly host nation as a must-win checklist item. That is healthy for buyers—monopsony of one cleared cloud is a resilience smell—but until those stamps land, AWS sits alone on the Alliance-wide NR board. Procurement language will start citing “NATO RESTRICTED approved commercial cloud” the way FedRAMP High citations show up in U.S. RFPs. Update your templates before legal does it for you.

For defense industry partners building NR-capable systems, the actionable move is boring and correct: inventory which workloads are truly NR versus over-classified by habit; confirm which AWS services were in the evaluated set with your account team; align landing zones to NATO-member Regions; and feed the Alliance baseline into your national package instead of rewriting evidence from scratch. That is how you convert a press announcement into shorter accreditation cycles and fewer air-gap exceptions.

Alliance ops has always been half diplomacy and half infrastructure. Publishing a commercial cloud against D32 does not make NATO a SaaS customer overnight. It does give operators a shared rail for RESTRICTED-class work that used to live in exception hell. Stamp the questionnaire once, reuse the answers, and keep the higher classifications in the environments they already belong in. That is the kind of boring progress that actually ships.

Exit mobile version