Amazon Web Services (AWS) has become the first cloud service provider to receive approval to manage NATO restricted information across all alliance member states, with the process for this approval going through Madrid.
See also: PCPJack: Attack on 230 AWS, Google Cloud and Azure cloud servers

AWS has documented its compliance with D32, the NATO technical directive that defines security requirements for handling NATO Restricted (NR) information in the public cloud. The Spanish National Cryptographic Center (CCN) has assessed its services against this directive.
NATO has approved the findings and made them available to all its allies. AWS says the approved services can now be used to create NR-capable systems in any of its regions located in NATO countries, and it has 15 such regions, seven of which are in continental Europe.
A second approval was achieved as a result of the Spanish phase, with the CCN and the Office of National Security (ONS), part of the Spanish National Intelligence Center (CNI), giving their approval for the AWS Europe (Spain) region to handle information classified as “Difusión Limitada” (DL), the Spanish equivalent of NATO Restricted. The data centers for this region are located in Aragon.
The process involved several stages of certification. AWS had already achieved the Spanish National Security Plan (ENS) certification at the highest level “High”, and 28 of its security services and features, such as those for EC2 compute and S3 storage, were approved on the CCN list of approved security products. In addition, the company met the specific requirements for DL information as defined in policy CCN-STIC-004 and by the ONS, which required a security assessment of its data centers.
See also: iPhone and iPad: The first consumer devices for classified NATO data

The approval only applies to the AWS part of the agreement, not to its customers. Public sector and defense organizations accredited in Spain can now perform DL and NR operations in the Spanish territory. However, they must have their own systems running on this infrastructure, accredited according to the same CCN-STIC-004 policy and ONS requirements.
Since NATO delegates NR accreditation to member states as well as the NATO Communications and Information Agency (NCIA), each government continues to manage its own national process.
The company states that alliance-level approval provides a common, pre-approved security baseline and a faster path through this process, thereby reducing compliance time and cost.
“Strengthening NATO’s ability to securely leverage commercial technology is key to building a more resilient and agile Alliance. The availability of commercial products that meet NATO’s security requirements broadens the technology options available to the Alliance and supports our ability to adopt modern technologies while maintaining the security and resilience on which our operations depend,” said Dylan Browne, Director General of the NATO Communications and Information Agency (NCIA).
See also: Meta becomes Qualcomm's first customer for Dragonfly chips

The approval is valid throughout the Alliance; the documents required by any government wishing to use them remain the property of that government.
