The National Institute of Standards and Technology has identified 23 distinct cybersecurity challenges that emerge when organizations use multiple cloud service providers, according to a new report published August 21. The US government agency warns that multi-cloud architectures—defined as using two or more cloud providers—make it harder for companies to maintain uniform security policies, apply consistent controls, and enforce strong authentication compared to single-cloud or on-premises setups. The difficulties stem largely from the fact that different providers operate with their own security models, tools, configurations, and shared responsibility frameworks.
The 23 challenges span four critical areas: identity and access controls, vulnerability management, incident response and disaster recovery, and data protection. Security teams struggle to verify whether multi-factor authentication or biometric verification has been deployed uniformly across all their cloud providers' systems, each of which has unique native architectures, the report notes. Vulnerability management becomes more complicated because cloud providers deliver vulnerability reports in different timeframes and formats, making unified patch management across an enterprise impossible. Customers often can't conduct independent vulnerability scans due to lack of direct access to providers' information systems. On incident response, some cloud providers fail to send timely and comprehensive incident data to customers, and the information arrives in varied formats rather than a standardized schema. Disaster recovery planning faces similar hurdles, as providers frequently withhold contingency planning policies from customers and typically don't share results of disaster recovery plan tests.
According to the NIST report, these access control challenges are "exacerbated by the need to verify the access control policies and implementations of other vendors or third parties that are used by the CSPs." The institute also finds that customers in multi-cloud environments face significant risk of violating data protection regulations in different jurisdictions because of inconsistent implementation of security measures like encryption among cloud providers. Organizations often struggle to obtain information system security documentation from all providers involved in protecting their data, creating difficulty in proving compliance with laws such as the EU's General Data Protection Regulation.
The report emphasizes that addressing multi-cloud security will require robust governance frameworks, centralized visibility, consistent policy enforcement, and a strong focus on automation and standardization—all of which demand collaborative effort across the cybersecurity community. NIST aims to provide "a structured problem statement and shared vocabulary that can inform future research, procurement, standards development, and solution design across government, industry, and academia," the report states. The institute is accepting public comments on the report through October 5, 2026, inviting input from federal agencies, industry partners, researchers, and the broader cybersecurity community. While multi-cloud strategies offer the advantage of reducing reliance on a single provider—allowing organizations to continue operating if one provider suffers an outage or cyber-attack—the security trade-offs are now coming into sharper focus. The tension between operational resilience and security complexity may force chief information security officers to reconsider whether distributing workloads across multiple clouds justifies the governance overhead, particularly for organizations without mature security operations.

