"A sustained, multi-year effort," David Appel said, describing how Amazon Web Services won alliance-wide clearance to handle NATO data at the RESTRICTED level.
AWS cleared for NATO RESTRICTED data across all member states
Amazon Web Services has become the first cloud provider approved to handle information at the NATO RESTRICTED level for all alliance members, the company announced. NATO RESTRICTED is not classified but "requires safeguarding," the announcement said. AWS already handles sensitive military and intelligence data for many NATO members and operates nine data-center clusters, or regions, across Europe, including the U.K.
Spain’s National Cryptographic Centre (CCN) and the testing pathway
AWS credited its approval to coordinated testing with Spain’s National Cryptographic Centre, or CCN. The company said CCN tested AWS services against NATO security directives and then shared its findings with all member states. That process, AWS said, was part of what Appel called "a sustained, multi-year effort."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleNATO's shift toward commercial technology and rapid data sharing
The approval comes as NATO pursues a broader digital transformation strategy that leans on commercial information technology. The alliance is fusing radar, satellite, and even acoustic information to more easily detect Russian drones and other threats, and NATO-approved rapid data and information sharing is critical to those operations. Dylan Browne, general manager of the NATO Communications and Information Agency (NCIA), said, as quoted in Amazon’s statement, "Strengthening NATO’s ability to securely leverage commercial technology is key to building a more resilient and agile Alliance."
EU Data Act, data residency, and provider responses
The 2024 European Union Data Act requires cloud providers to protect EU data from other governments, "including the United States," and has practical implications for where data must be housed. In practice, the Act means housing data on European soil beyond the reach of U.S. court orders, although that is not an explicit requirement of the Act. AWS — like Microsoft and other enterprise cloud providers — has been investing in European versions of its cloud stacks to meet those Data Act requirements.
What this means for NATO members, U.S. cloud vendors, and EU regulators
- NATO members and allied cloud users: They will be able to share NATO RESTRICTED data more easily among members while retaining control over it, thanks to an alliance-wide clearance and AWS’s Europe-based regions.
- U.S. cloud vendors: AWS beat competitors — "primarily from other U.S. cloud providers such as Microsoft" — to win the alliance’s first blanket approval, a result that the company ties to multi-year testing and certification work.
- EU regulators and implementers of the Data Act: Regulators now confront an operational fact on the ground: U.S. cloud technology remains central to NATO operations, even as the Data Act presses providers to keep EU data under European protections; providers are responding by building European cloud stacks.
The announcement illustrates a specific tension at the heart of transatlantic technology and security: U.S. commercial cloud remains a core feature of NATO capability and its digital plans, even as European regulation demands stronger protections for EU data. The source noted that "White House rhetoric and executive orders suggest otherwise," yet the approval shows U.S. cloud companies can meet European data-protection requirements and secure alliance-wide trust.




