AWS Becomes First Cloud Cleared for NATO Restricted Data

What happened
Amazon Web Services has been approved to process classified-tier information on its cloud across all NATO member states. It is the first cloud provider authorized to handle data at the "NATO Restricted" (NR) level.
The gating factor was compliance with NATO's technical guidance known as D32, which sets out the security requirements for handling NR information in a public cloud environment. Until now, that document has functioned as the practical barrier keeping commercial clouds out of alliance-level classified workloads.
Why it matters
Defense IT procurement inside NATO has historically been fragmented by nation. Even when member states used the same cloud platform, each country ran its own accreditation process — which turned data sharing in multinational operations into an administrative problem as much as a technical one. What makes this approval different is that AWS cleared a single alliance-wide standard rather than stacking up country-by-country certifications.
The timing tracks a broader shift: expanding European defense budgets and a push to modernize military IT. Command and control, intelligence analysis, and satellite or sensor data processing all demand compute at a scale that national defense data centers increasingly struggle to provide on their own. For cloud vendors, defense and intelligence agencies are premium customers with long contract cycles — and also the hardest market to enter.
The competitive picture
Government and defense cloud is already a contested field, with Microsoft Azure, Google Cloud, and Oracle competing through national certifications and "sovereign cloud" offerings. In Europe especially, demands that data stay in-region and be operated by in-region staff have pushed each vendor toward local entities and locally staffed operating models.
The real value of this NR clearance is less about technical superiority than about reference credibility. Defense procurement tends to concentrate repeat awards on vendors that have already passed accreditation, and buying agencies reduce their own review burden by choosing a provider NATO has already vetted. Rivals may well pursue the same route, but the time gap in between can shape which contracts land first.
It's worth resisting overstatement, though. NR sits at the lower end of NATO's classification hierarchy. Approval here does not extend to higher tiers such as NATO Confidential or NATO Secret. This is best read as the entry door to classified workloads, not full access to them.
What actually changes
For defense organizations, workloads that previously had to stay on-premises now have a credible cloud option. The likely first movers are sensitive-but-not-top-secret functions: logistics, personnel administration, and maintenance records.
There's a lesson for exporters too. Countries scaling up defense exports — South Korea among them, with rapidly growing sales to European buyers — increasingly find that data interoperability with customer militaries is a precondition for cooperation, and which cloud accreditations a partner holds becomes part of that conversation. The alliance-wide certification model is also a reference point for any government still designing its own public-sector cloud security framework.
For people working in the cloud industry, the takeaway is blunt: in defense and public-sector markets, competitive advantage is decided by how fast you clear accreditation, not by benchmarks or price lists.
Sources
- AWS, 업계 최초로 NATO 국방 클라우드 문턱 넘었다 — zdnet.co.kr
- AWS, 클라우드 최초로 NATO ‘제한 등급’ 정보 처리 승인 — ddaily.co.kr