StigReady

STIG AMI & CIS hardened AMI
with published OpenSCAP scores

One hardened foundation — two ways to use it. All built from the official OS ISO, patched, and boot-tested on real EC2 Nitro. AWS Marketplace listings are rolling out.

StigForge
Public CIS / STIG Ansible roles
OpenSCAP-verified with published scores and evidence per release

Marketplace listings rolling out · x86_64 and arm64 (Graviton)

StigReady Base

The base that won't fight you

The structural work that's painful to retrofit — already done. Bring your own profiles, Ansible, and tooling.

STIG Partition Layout

Separate hardened mounts for /home, /tmp, /var, /var/log, /var/log/audit, and /var/tmp — identical across all OS families.

SSH Hardened

Password auth disabled, root login prohibited, host keys regenerated on first boot, no pre-installed keys — cloud-init injects your EC2 key pair.

Minimal & Patched

Built from the official OS ISO with a minimal footprint and fully updated packages on a monthly cadence — smaller attack surface, no surprise packages.

AWS-Native

IMDSv2 enforced. SSM Agent pre-installed. cloud-init handles EC2 key-pair injection. Boot-tested on real Nitro EC2 before any image ships. x86_64 and arm64 (Graviton).

Base Catalog

Release 1 · 24 images · Rocky / Alma / RHEL 8–10, Ubuntu 24.04 / 26.04, Amazon Linux 2023 · x86_64 + arm64

OS Arch
Loading catalog…

BYOL — Red Hat Enterprise Linux images are Bring Your Own License. You supply the Red Hat subscription; StigReady does not provide commercial Red Hat licenses. Red Hat, Inc. holds the trademarks for Red Hat® and Red Hat Enterprise Linux®.

Windows Server 2022 — planned for a future release. Not part of the initial 24-image rollout.

Partition Layout

GPT disk · LVM volume group vg_root · separate STIG filesystems on every base image

Mount Filesystem Options
/boot/efivfat
/bootext4 / xfs
/xfs
/homexfsnodev,nosuid
/tmpxfsnodev,nosuid,noexec
/varxfsnodev,nosuid
/var/tmpxfsnodev,nosuid,noexec
/var/logxfsnodev,nosuid,noexec
/var/log/auditxfsnodev,nosuid,noexec
swapswap

The separate-filesystem layout that DISA STIG and CIS benchmarks require — already in place, so the profile you apply has less to remediate.

How It Works

1

Pick your OS

Choose from the RHEL family (Rocky / Alma / BYOL RHEL 8–10), Ubuntu 24.04 or 26.04, or Amazon Linux 2023. x86_64 and arm64 available. Contact us for early access while Marketplace listings roll out, or watch our seller profile.

2

Launch

EC2 injects your key pair on first boot via cloud-init. Connect as ubuntu or ec2-user over SSH with key-based auth. No password logins, no pre-installed keys.

3

Apply your profiles

Run your own Ansible, OpenSCAP remediation, or auditd rules on a base that already carries the STIG layout — nothing to undo first.

StigReady Applied

Remediated, scored, and provable

The number your auditor asks for — published with every image. We score against the raw, unmodified SSG profile in-build. They don't.

Applied overview · scores and filters below

StigForge roles

Remediation is driven by StigForge — public CIS / STIG Ansible roles generated from SSG, OpenSCAP-verified, with published scores and evidence per release.

Scored in-build

Every image is scored against the raw, unmodified SSG profile during the build — not after, not on a different host. A 90% floor and a no-regression ratchet gate every release.

Auditor-grade evidence bundle

Every image ships with an OpenSCAP ARF result, an HTML report, a POA&M, an SBOM, and a CVE scan — everything your auditor needs, attached before you ever launch.

FIPS mode on STIG images

DISA STIG images run with FIPS mode enabled, using the OS vendor's FIPS 140-3 validated cryptographic modules (CMVP certificate numbers available on request).

Boot-verified on Nitro EC2

Every image boots on a real EC2 Nitro instance as a build gate. If it doesn't boot clean and pass the scan, it doesn't ship.

Applied Scores

All scores as of build 2026-07 · scored against the raw, unmodified SSG profile

OS Arch Baseline Score FIPS
Loading catalog…

BYOL — Red Hat Enterprise Linux images require you to supply your own Red Hat subscription. StigReady does not provide Red Hat commercial licenses.

Windows Server 2022 STIG hardening is planned. It is not part of the initial release and currently does not include a CVE scan or SBOM.

StigForge

Verified Ansible roles

Public CIS and STIG role exports — OpenSCAP-verified against the raw SSG profile, with published scores and immutable evidence per release. How-tos: Base + roles →

Roles

Public under github.com/stigready.

  • Loading…

Scores

OpenSCAP verify against the raw SSG profile.

Role Profiles Repo
Loading…

Role repos are public. The factory monorepo that builds them stays private.

Pricing

Software fee on top of your normal EC2 costs. Listings are rolling out on AWS Marketplace.

StigReady Base

$0.02/hr

or $149/yr per instance

EC2 instance costs billed separately by AWS

  • STIG partition layout & SSH hardening
  • Built from official ISO, fully patched
  • Boot-verified on real Nitro EC2
  • x86_64 and arm64 (Graviton)
  • Bring your own profiles and tooling
StigReady Applied

$0.08/hr

or $649/yr per instance

EC2 instance costs billed separately by AWS

  • Everything in Base
  • Full DISA STIG or CIS Level 1/2 remediation
  • Scored in-build against the raw SSG profile
  • 90% floor · no-regression ratchet
  • Evidence bundle: ARF, HTML report, POA&M, SBOM, CVE scan
  • FIPS mode enabled on STIG images

Annual contracts and Private Offers available. Contact us for early access, BYOL RHEL, volume pricing, or questions — or browse the seller profile.

FAQ

Pricing, OpenSCAP evidence, Graviton, RHEL BYOL, and Marketplace status.

Base vs Applied — what do I pay?
Base is $0.02/hr or $149/yr per instance (STIG layout + SSH hardening; bring your own profiles). Applied is $0.08/hr or $649/yr (CIS L1/L2 or DISA STIG remediation + OpenSCAP evidence). Both are software fees on top of normal EC2 costs.
What OpenSCAP evidence ships with Applied?
Every Applied image includes an OpenSCAP ARF result, HTML report, POA&M, SBOM, and CVE scan — scored in-build against the raw, unmodified SSG profile. We do not claim DISA/DoD endorsement, or certified / authorized / accredited status.
Do you support arm64 / Graviton?
Yes. Base and Applied build for x86_64 and arm64 (Graviton). Use the architecture filters in the catalogs above.
Are RHEL images BYOL?
Yes. RHEL is bring-your-own-license — you supply a Red Hat subscription. StigReady does not sell Red Hat licenses.
Are listings live on AWS Marketplace?
Listings are rolling out. Watch our seller profile or email contact@stigready.com for early access and Private Offers. We do not publish per-SKU Marketplace URLs or AMI IDs here.