Explaining the strategic value, Dylan Browne, general manager, NATO Communications and Information Agency (NCIA), highlighted the importance of integrating private sector tools into defense operations. “Strengthening NATO’s ability to securely leverage commercial technology is key to build a more resilient and agile Alliance. The availability of commercial products that meet NATO’s security requirements expands the technology options available for the Alliance and supports our ability to adopt modern technologies while maintaining the security and resilience on which our operations depend,” Browne stated. By establishing an alliance-wide security foundation, individual sovereign states along with the Communications and Information Agency (NCIA) can now expedite their own regulatory sign-offs. Consequently, member nations save both money and hours during their individual verification procedures, even though each government retains ownership of its specific paperwork.
Rather than originating at headquarters, this alliance-wide authorization stemmed directly from an evaluation conducted in Madrid. Spain’s National Cryptologic Center (CCN) rigorously audited the platform to ensure it satisfied D32, a specialized NATO directive governing public cloud management for NATO Restricted (NR) material. Concurrently, the National Security Office (ONS) alongside the CCN—both operating under Spain’s National Intelligence Center (CNI)—granted authorization for the local server infrastructure situated in Aragón. This secondary validation allows the AWS Europe (Spain) zone to store sensitive domestic data marked as “Difusión Limitada” (DL), which serves as the local Spanish counterpart to NR classification.
Reaching this security standard required navigating multiple rigorous compliance steps, including attaining the top “High” classification within Spain’s National Security Scheme (ENS). Furthermore, 28 distinct cloud instruments and capabilities, incorporating S3 storage as well as EC2 computing resources, secured placement on the CCN’s list of recognized security tools. Physical facilities also underwent thorough safety audits to satisfy guidelines dictated by the ONS and the CCN-STIC-004 policy framework. Thanks to these reviews, software architectures handling NR data can now be deployed across 15 separate data centers in allied territory, seven of which operate within continental Europe.
With this landmark decision, Amazon Web Services becomes the pioneer among cloud vendors to achieve universal clearance for handling restricted defense communications across all allied territories. However, the official authorization explicitly covers only the underlying cloud vendor infrastructure rather than end-user applications. Defense organizations and public entities operating within Spain that wish to process DL or NR workloads must still secure separate credentials for their own software implementations. These client-side deployments remain subject to full accreditation under the matching ONS parameters and CCN-STIC-004 standards.



