AWS Cleared for NATO Restricted Cloud Workloads Across Alliance
NATO has approved certain Amazon Web Services (AWS) capabilities for handling information marked NATO RESTRICTED, making the company the first cloud provider with an assessment available to all member countries.
NATO RESTRICTED is the alliance’s lowest classified information level; it covers material whose unauthorized disclosure could harm NATO’s interests.
The approval means NATO organizations, member countries, and defense contractors can use the assessed AWS services as a starting point for systems that handle restricted information.
Those services may run in AWS cloud regions located in NATO countries.
Each country must still complete its own authorization process for the systems it intends to use; the alliance-wide assessment does not automatically approve every national deployment.
To obtain the approval, AWS documented how its services meet D32, NATO’s security rules for handling restricted information in a public cloud.
Spain’s National Cryptographic Centre evaluated the services, and NATO then made the assessment available across the alliance.
AWS said it has 15 cloud regions in NATO member countries, including seven in mainland Europe.
AWS’s Defense Partnerships
The NATO approval follows other defense projects involving AWS.
In December 2025, Raytheon announced a collaboration to use AWS cloud services, including AI and machine learning tools, in satellite data processing and mission control for government and commercial customers.
In 2024, Australia partnered with AWS to build a cloud platform for its defense and intelligence agencies to handle Top Secret information.
Canberra committed at least $1.3 billion over a decade to the project, which it said would also support information sharing with the US.









