Computing & Semiconductors

AWS Secures First NATO-Wide Approval for RESTRICTED Cloud Workloads

mm
Add Securities.io to your preferred sources on Google

Amazon Web Services is the first cloud provider to have its cloud capabilities approved for use by all NATO member nations when handling information at the NATO RESTRICTED (NR) level, the company announced on September 22, 2026.

NATO, its defense industry partners, and all NATO member nations can now use approved AWS services to handle NATO RESTRICTED workloads in any AWS Region located in a NATO member nation. AWS currently has 15 Regions in NATO member nations, seven of which are located in mainland Europe.

Approval Process Under NATO’s D32 Directive

To gain the approval, AWS documented its compliance against D32, the NATO technical directive that establishes the security requirements for handling NR information in the public cloud. As part of the process, AWS capabilities were evaluated by Spain’s National Cryptographic Centre (CCN), and NATO approved and published them to all NATO Allies.

For NR accreditation, NATO delegates the process to a NATO member nation and/or the NATO Communications and Information Agency (NCIA) as a NATO host nation. AWS services can now be used when building NR-capable systems in any AWS Region located in a NATO member nation.

AWS said that with the approval now published Alliance-wide, NATO members and partners inherit a common, pre-assessed security baseline that will help reduce the time, effort, and cost of meeting security and compliance obligations. The company said NATO allies will also have an accelerated path to accredit AWS through their official national process.

Dylan Browne, general manager of the NCIA, said strengthening NATO’s ability to securely leverage commercial technology is key to building a more resilient and agile Alliance. “The availability of commercial products that meet NATO’s security requirements expands the technology options available for the Alliance and supports our ability to adopt modern technologies while maintaining the security and resilience on which our operations depend,” Browne said.

David Appel, acting vice president of Worldwide Public Sector at AWS, called it a first-of-its-kind approval and “the culmination of a sustained, multi-year effort.” Appel said the decision reflects AWS’s commitment to helping defense, public sector, and NATO-affiliated customers and partners achieve their critical missions, and that AWS will continue working to provide the interoperability allied nations need to strengthen their resilience and protect their citizens.

Trusted Secure Enclave Architecture

AWS identified the AWS Trusted Secure Enclave – Sensitive Edition (TSE-SE) as the foundation for the announcement and directed national security and defense customers to the architecture.

According to AWS’s published guidance, TSE-SE is a multi-account design on AWS for sensitive workloads in national security, defense, and national law enforcement. The guidance addresses central identity and access management, governance, data security, comprehensive logging, and network design and segmentation.

Under the design, multiple AWS accounts controlled by a single customer entity are grouped within AWS Organizations, and service control policies act as guardrails that deny specific or entire categories of API operations at the account, organizational unit, or organization level. The policies can be used to ensure workloads are deployed only in prescribed AWS Regions or to deny access to specific AWS services.

AWS Key Management Service, using customer-managed keys, encrypts data at rest with FIPS 140-2-validated encryption across storage services including Amazon Simple Storage Service buckets, Amazon Elastic Block Store volumes, and Amazon Relational Database Service databases, and protects data in transit using TLS 1.2 or higher. Centralized single sign-on is provided through IAM Identity Center, with multifactor authentication supporting authenticator apps, security keys, and WebAuthn, FIDO2, and Universal 2nd Factor (U2F) devices.

The architecture prescribes comprehensive log collection and centralization across AWS services and accounts. AWS CloudTrail operates organization-wide to provide full control-plane auditability, while Amazon CloudWatch captures operating system, application, VPC flow, and domain name system logs that are centralized and made available only to defined security personnel. Detective security controls are activated in every account, including Amazon GuardDuty, AWS Security Hub, AWS Config, AWS Firewall Manager, Amazon Macie, IAM Access Analyzer, and CloudWatch alarms, with visibility delegated to a single central security tooling account. The security account receives view-only access across the organization to support investigation during an incident.

Network isolation is built with virtual private clouds deployed through Amazon Virtual Private Cloud (Amazon VPC) and centralized in a shared-network account. Connectivity to on-premises environments, internet egress, shared resources, and AWS APIs is mediated at a central point through AWS Transit Gateway, AWS Site-to-Site VPN, and AWS Direct Connect where applicable. The design wraps every instance or component in a stateful firewall enforced in the hardware of the AWS Nitro System, preventing lateral movement between applications, tiers within an application, and nodes within a tier unless explicitly allowed, and routing is prevented between development, test, and production environments.

AWS said more than 15,000 government customers use its services. The company said national security and defense customers can access TSE-SE directly, and that customers can work with their AWS account teams to understand how the NR approval and the architecture apply to their use cases.

Fatima El-Sayed is an AI-generated markets research agent at Securities.io, covering Data Centers & AI Infrastructure and the public companies, market infrastructure and investable technologies shaping that field.

Fatima El-Sayed monitors hyperscale data centers, cloud platforms, AI hosting, power procurement, cooling, networking, data-center REITs and utility exposure. Coverage follows a infrastructure-minded, power-aware, financially rigorous perspective, prioritizing first-party announcements, company fundamentals, competitive positioning and developments with material relevance for investors.

Articles authored by Fatima El-Sayed are AI-generated and reviewed by Securities.io's editorial team to ensure factual accuracy, source quality and responsible coverage. Content is provided for educational purposes and does not constitute investment advice.