AWS Approved for Sensitive NATO Data Handling
The cloud provider has secured authorization to host RESTRICTED-level information for all member countries.
Updated on Sept. 22, 2026 in Data Centers

Live Poll
Do you trust foreign technology companies to handle sensitive data for your country's national security?
Amazon Web Services (AWS) has become the first cloud provider approved to manage information classified at the NATO RESTRICTED level across all alliance members. The authorization follows security assessments conducted by Spain's National Cryptographic Centre.
Why it matters
The move supports the alliance's goal to integrate commercial information technology into its strategic planning and coordination. This capability provides European militaries with the infrastructure necessary for rapid information sharing, such as detecting drone incursions and other regional threats.
AWS operates nine data-center clusters across Europe to support this mandate. Testing was performed by Spain's National Cryptographic Centre to ensure compliance with stringent NATO security directives.
The players
Amazon Web Services
A global cloud computing provider offering infrastructure-as-a-service, platform-as-a-service, and serverless computing through a network of international data-center clusters.
NATO
An intergovernmental military alliance that is currently modernizing its coordination and planning processes through the adoption of commercial cloud technologies.
National Cryptographic Centre
A Spanish government agency responsible for assessing the security and integrity of information technology systems against standardized defense directives.
The details
The approval process involved rigorous testing of AWS infrastructure against NATO's specific security directives. By leveraging these existing facilities, NATO aims to facilitate more efficient data synthesis across the alliance's distributed defense network. Spain's National Cryptographic Centre conducted these evaluations and shared the validation findings with all member states to establish a unified standard for cloud-based information handling.
Timeline
2024: The European Union Data Act mandated that cloud providers protect EU data from external governmental access.
September 22, 2026: Amazon officially announced the NATO security approval.
The Tech Race
This integration aligns with the requirements set by the European Union Data Act regarding cross-border data protection. It marks a significant shift in defense strategy as the alliance pivots from localized hardware to distributed commercial cloud environments.
This approval allows European militaries to immediately begin integrating NATO-level data into existing AWS European data-center clusters. The shift likely reduces the time required for cross-border tactical information sharing during defense operations.
The takeaway
The alliance's adoption of commercial cloud infrastructure indicates a permanent move toward rapid, digitized coordination in European defense. Industry observers should watch for subsequent authorizations regarding higher classification levels within NATO's information security framework.
Further reading
For more on how infrastructure providers manage high-security workloads, explore our Data Centers section.
Live Poll
Do you trust foreign technology companies to handle sensitive data for your country's national security?






