AWS has become the first cloud provider approved for NATO RESTRICTED workloads across all NATO member nations, giving allies and defense industry partners access to approved AWS services across 15 regions and a common security baseline designed to streamline national accreditation processes.
NATO allies gain access to approved AWS cloud services
This milestone indicates that NATO, its defense industry partners, and all member nations can use approved AWS services to handle NATO RESTRICTED information across 15 AWS regions in NATO member countries.
“Defense and public sector customers need to move fast, and the security requirements they work under are rigorous. Meeting both is the job,” said Matt Garman, CEO of AWS. “Allies and defense industry partners now have a common assessed baseline to build from, instead of each nation working through much of the same evaluation independently.”
Further, this approval gives NATO allies a commercial cloud infrastructure to modernize and protect critical missions together.
“This first-of-its-kind approval is the culmination of a sustained, multi-year effort,” said David Appel, Acting Vice President of Worldwide Public Sector at AWS. “It reflects our commitment to helping defense, public sector, and NATO-affiliated customers and partners achieve their critical missions. We believe governments, and the citizens they serve, deserve access to the same infrastructure and services driving innovation in the private sector.”
Appel continued: “We will continue working to provide the interoperability allied nations need to strengthen their resilience and protect their citizens.”
What NATO RESTRICTED approval means for partners
This approval means that NATO members inherit a common, pre-assessed security baseline that will help to reduce the time, effort, and cost of meeting security and compliance obligations.
Following AWS’ NR approval, NATO allies will have an accelerated path to accreditation through their official national processes.
“Strengthening NATO’s ability to securely leverage commercial technology is key to building a more resilient and agile Alliance,” said Dylan Browne, general manager of the NATO Communications and Information Agency (NCIA).
“The availability of commercial products that meet NATO’s security requirements expands the technology options available for the Alliance and supports our ability to adopt modern technologies while maintaining the security and resilience on which our operations depend,” adds Browne.
AWS undergoes D32 security assessment
AWS documented its compliance against D32, a technical directive that establishes the security requirements for handling NR information in the public cloud.
As part of the approval process, AWS capabilities were evaluated by Spain’s National Cryptographic Centre (CCN), and NATO approved and published them to all NATO Allies.
NATO delegates the NR accreditation process to a NATO member nation and/or the NCIA as a NATO host nation.
Currently, over 15,000 government customers use AWS to lower costs, increase resilience, and innovate.




