NATO’s Ankara summit reframed cyber resilience as a line item within the Alliance’s core defense-investment target — a shift that stabilizes funding even as it raises new questions about accountability and vendor dependency.
By Vladimir Tsakanyan, PhD | Director, Center for Cyber Diplomacy and International Security (CCD-IS)
NATO’s 36th summit, held in Ankara on July 7–8, 2026, produced few new declaratory commitments on cyber defense specifically. What it confirmed instead was a structural shift already underway within the Alliance: cyber resilience is moving from a matter of voluntary pledges toward a quantified, budget-linked category inside NATO’s core investment framework. That shift, from pledge to procurement, is likely to shape the Alliance’s cyber posture more than any single announcement made in Ankara.
A Checkpoint on an Existing Target
The Ankara summit was widely framed as a checkpoint on delivering the defense-spending target agreed at the 2025 Hague summit: 5 percent of GDP by 2035, split between 3.5 percent for core military capability and 1.5 percent for what the Alliance terms “wider security,” a category that explicitly folds in infrastructure, cyber, and the defense-industrial base. Secretary General Mark Rutte’s stated aim for Ankara was to establish what he called a credible path toward that target rather than to announce a new figure. European Allies and Canada had already increased core defense investment by more than $139 billion in nominal terms in 2025, and at Ankara, Allies announced more than $50 billion in new procurement commitments, alongside a separate pledge of €70 billion in military assistance for Ukraine in 2026.
The significance for cyber policy sits in the accounting structure itself. Folding cyber defense into a GDP-linked spending target, rather than treating it as a standalone pledge, gives the Alliance a topline figure that is straightforward to track in aggregate — total spending measured against 5 percent of GDP — while leaving the internal allocation between infrastructure, cyber, and industrial capacity largely to national discretion. It is a framework built for aggregate visibility, not granular accountability.
Procurement as the New Instrument of Cyber Policy
That shift toward procurement was visible in the announcements accompanying the summit. At the NATO Summit Defence Industry Forum held alongside the leaders’ sessions on July 7, the NATO Communications and Information Agency signed a contract with Accenture for a Protected Business Network intended to provide a cloud-enabled, interoperable architecture for the Alliance’s classified digital operations. NATO’s Assistant Secretary General for Cyber and Digital Transformation, Jean-Charles Ellermann-Kingombe, described the agreement as a significant step in the Alliance’s continuing digital transformation, framing it as a means for Allies to reach and execute decisions more quickly and securely across a shared transatlantic cloud environment.
The Ankara Summit Declaration reinforces this direction, committing Allies to develop what it calls an interoperable transatlantic warfighting cloud and to adopt advanced AI models as part of the Alliance’s broader deterrence posture, alongside nuclear, conventional, and missile-defense capabilities. Allies also launched a NATO Front Door for Industry and agreed a Strategy for Industry-NATO Cooperation at the summit, formalizing the channels through which private contractors engage with Alliance procurement.
Together, these developments point to a NATO cyber posture increasingly built and delivered through commercial contracts rather than organic Alliance capability. That dependency is not new: NATO has historically maintained few organic cyber capabilities of its own, relying instead on capabilities that reside with individual Allied national security services and are made available to NATO when requested and agreed. What is new is the extent to which core, shared digital infrastructure — the classified networks Allies use to coordinate decisions — is now explicitly procured from a small number of commercial vendors under Alliance-level contracts. That concentration is worth monitoring as a structural feature of Alliance resilience, independent of the merits of any individual contract.
Institutional Lineage and Structural Limits
The Ankara-era procurement push builds on an institutional architecture assembled incrementally since 2014. NATO recognized cyberspace as an operational domain at the 2016 Warsaw summit and adopted its first Cyber Defence Pledge that same year. Allies enhanced the pledge at the 2023 Vilnius summit, committing to more ambitious national goals for critical-infrastructure protection and launching the Virtual Cyber Incident Support Capability, a voluntary, nationally resourced mechanism for assisting Allies recovering from significant cyber incidents. The 2021 Comprehensive Cyber Defence Policy folded cyber fully into the Alliance’s overall deterrence and defense posture, and the NATO Cyber Security Centre at Supreme Headquarters Allied Powers Europe in Mons, Belgium, continues to protect NATO’s own networks around the clock. At the 2024 Washington summit, Allies announced plans to develop that center into a NATO Integrated Cyber Defence Centre by 2028 — a milestone that will now arrive roughly midway through the 2035 investment horizon set at Ankara.
This lineage underscores a structural point that Ankara’s investment framework does not resolve: NATO’s cyber defense remains fundamentally a coordination function layered atop national capabilities, rather than a unified command capability the Alliance can deploy directly. Aggregate spending targets say little on their own about whether the capability gaps between Allies — long documented in independent assessments of the Alliance’s cyber posture — are actually narrowing.
The Verification Gap
A further complication is transparency. Topline figures such as the 5 percent target, the $139 billion investment increase, and individual procurement contracts are public and readily tracked. The specific national commitments Allies make under the Cyber Defence Pledge have historically remained classified, disclosed only in aggregate or on a voluntary basis at annual Pledge Conferences. That asymmetry — public spending targets paired with classified implementation — makes it difficult for outside observers, and arguably for Allies themselves, to assess whether the framework set at Ankara is translating into reduced capability gaps or primarily into higher reported spending under a broadened definition of “wider security.”
Outlook
The period between now and the planned 2028 delivery of the Integrated Cyber Defence Centre will be the practical test of the framework agreed at Ankara. The next Cyber Defence Pledge Conference and subsequent NATO Summit Defence Industry Forums will offer the clearest early indications of whether the 1.5 percent “wider security” allocation is closing documented capability gaps or largely formalizing existing national spending under a new accounting category. The growing role of commercial cloud and AI vendors in Alliance-level digital infrastructure also warrants continued attention, not as a question of any single contractor’s conduct, but as a structural feature of how collective cyber resilience is now being built. The accounting framework agreed at Ankara does not answer these questions on its own; the intervening Pledge Conferences and the 2028 Centre delivery date are where its practical effects will become visible.
About the Author Vladimir Tsakanyan, PhD, is a political scientist and strategic analyst specializing in cyber diplomacy and international security. He is Director of the Center for Cyber Diplomacy and International Security (CCD-IS). ORCID: 0000-0002-9349-1907.
Sources
- NATO, “The Ankara Summit Declaration” and “Overview – 2026 NATO Summit in Ankara” (July 2026)
- NATO News, “NATO builds a more agile and resilient digital infrastructure” (July 7, 2026)
- NATO topic page “Cyber defence” and NATO Allied Command Transformation, “Cyber Defence”
- Atlantic Council, “How NATO is facing mounting cybersecurity challenges”
- The Ops Con, “NATO’s Ankara summit: the 5% pledge and what the ‘security’ slice means for the sector”
- Congressional Research Service, “NATO: Issues for the July 2026 Ankara Summit”
- The Record (Recorded Future News), reporting on classification of national Cyber Defence Pledge commitments


Leave a comment