In November 2017, AWS announced that its Secret Region would be available beyond the Intelligence Community (IC), but access was conditional: non-IC U.S. government customers needed appropriate Secret-level network access and their own contract vehicles. The announcement did not mean every agency could automatically use the cloud hosted at CIA premises.
What was the CIA’s on-prem Amazon cloud?
It was an AWS cloud region installed in CIA data centers rather than operated as an ordinary public-internet cloud service. A November 21, 2017, Data Center Knowledge report described the original deployment as not connected to the internet and attributed to it three availability zones across three geographically dispersed data centers. Those are figures from the 2017 report, not a statement of AWS’s current topology. Read the report.
AWS worldwide public sector vice president Teresa Carlson called it “the first air-gapped commercial cloud,” as quoted in that report. In this context, air-gapped describes the reported separation of that original deployment from the public internet; it should not be taken to mean every AWS classified service has the same architecture.
The CIA’s CIO, John Edwards, praised the deployment in the same report, saying, “It’s the best decision we’ve ever made,” and calling it “the most innovative thing we’ve ever done.” Those are attributed comments from 2017, not independent technical evaluations or evidence of present-day service performance.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Who could access the Secret Region under the 2017 announcement?
AWS’s November 20, 2017, announcement described different routes for IC and non-IC government customers. The distinction matters: eligibility depended on the organization, network access, and contract arrangement.
| Customer | 2017 access terms | Contract route |
|---|---|---|
| Intelligence Community members | AWS said the Secret Region was available to the IC for Secret, Sensitive, and Unclassified data classifications. | The IC used the region through its C2S contract with AWS. |
| Non-IC U.S. government customers | AWS said customers needed appropriate Secret-level network access. | They needed their own contract vehicles; those vehicles were outside C2S. |
AWS stated that the Secret Region “also will be available to non-IC U.S. Government customers with appropriate Secret-level network access and their own contract vehicles for use of the AWS Secret Region.” See AWS’s November 20, 2017 announcement.
Rank #2
So the answer to “Could other agencies use it?” is yes, in the terms AWS announced—but not simply by being a government agency. The announcement does not identify a universal sign-up path, show that any particular agency obtained access, or establish today’s procurement route.
Was the non-IC route part of the CIA’s C2S contract?
No. The 2017 announcement said IC members used the AWS Secret Region through the IC’s C2S contract. For non-IC government customers, it specified their own contract vehicles, separate from C2S.
Rank #3
A later draft 2020 C2E statement of work gives procurement context, not proof that a named agency received access. It describes C2E as a follow-on portfolio to the IC’s cloud modernization effort and discusses multi-award cloud service provider acquisitions for IaaS, PaaS, and SaaS, alongside cloud integration and multi-cloud management. It says other U.S. government, contractor, and federally funded research and development center elements could gain access after approval by the Executive Agent and/or a sponsoring IC agency. Review the draft C2E statement of work.
Because that document is a draft from 2020, it does not establish present eligibility, current contract terms, or approval for any specific customer. The currently applicable route for a non-IC customer is not established by the sources cited here.
Rank #4
How does AWS describe its Secret Cloud today?
AWS’s current service page describes AWS Secret Cloud as intended for classified mission workloads and says it is authorized for workloads up to Secret under DoD Cloud Computing Security Requirements Guide Impact Level 6 and ICD 503. AWS also mentions dedicated connectivity through AWS Direct Connect. This is AWS’s current service description; it does not show that today’s service is identical to the CIA-premises deployment described in 2017. See AWS Secret Cloud.
AWS GovCloud is a separate offering, not another name for the CIA’s on-premises cloud or the Secret Region. AWS’s GovCloud FAQ says qualified customers need separate account credentials and a customer agreement specific to GovCloud. See the AWS GovCloud FAQ.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

