Amazon Web Services has become the first cloud service provider to receive clearance for handling NATO-restricted information across every member state of the alliance. Rather than following a direct route through NATO's own channels, the approval process took place in Madrid, where Spanish authorities conducted the assessment.

AWS demonstrated compliance with D32, NATO's technical directive establishing security standards for NATO Restricted (NR) data in public cloud environments. The Spanish National Cryptologic Center (CCN) evaluated the company's services against this directive, and NATO subsequently endorsed the findings for distribution to all member nations.

The company confirmed that its approved services can now support NR-capable systems across any of its regions within NATO countries. AWS operates 15 such regions globally, with seven situated in mainland Europe.

The Spanish assessment yielded a second certification as well. Both the CCN and Spain's National Security Office (ONS), operating under the National Intelligence Center (CNI), authorized the AWS Europe (Spain) region to process information marked "Difusión Limitada" (DL), Spain's classification equivalent to NATO Restricted. The region's data centers sit in Aragón.

Multiple certification layers

The approval process involved several distinct certification phases. AWS had previously obtained Spain's National Security Scheme (ENS) certification at the highest "High" level, and 28 of its security services and capabilities—including EC2 computing and S3 storage—had already earned spots in the CCN's approved security products catalog.

The company also satisfied particular requirements for DL information as outlined in the CCN-STIC-004 policy and by the ONS, which mandated a security evaluation of its data center facilities.

Customer responsibility remains

The clearance covers only AWS's infrastructure, not its customers' operations. Spanish public-sector and defense organizations with proper accreditation can now deploy DL and NR workloads on the Spanish region. However, these organizations must still ensure their own systems running on that infrastructure receive accreditation according to the same CCN-STIC-004 policy and ONS requirements.

NATO distributes NR accreditation both to member countries and to its Communications and Information Agency (NCIA), meaning each government retains control over its own national approval process. AWS notes that the alliance-wide approval gives governments a standardized, pre-assessed security foundation and accelerates their individual compliance pathways, cutting both time and expense.

Strengthening NATO's ability to securely leverage commercial technology is key to build a more resilient and agile Alliance. The availability of commercial products that meet NATO's security requirements expands the technology options available for the Alliance and supports our ability to adopt modern technologies while maintaining the security and resilience on which our operations depend.

Dylan Browne, general manager, NATO Communications and Information Agency (NCIA)

The clearance extends across the entire alliance, though the documentation each government needs to use it stays under that government's control.

Source: The Next Web