One hardened foundation — two ways to use it. All built from the official OS ISO, patched, and boot-tested on real EC2 Nitro. AWS Marketplace listings are rolling out.
Marketplace listings rolling out · x86_64 and arm64 (Graviton)
The structural work that's painful to retrofit — already done. Bring your own profiles, Ansible, and tooling.
Separate hardened mounts for /home, /tmp, /var, /var/log, /var/log/audit, and /var/tmp — identical across all OS families.
Password auth disabled, root login prohibited, host keys regenerated on first boot, no pre-installed keys — cloud-init injects your EC2 key pair.
Built from the official OS ISO with a minimal footprint and fully updated packages on a monthly cadence — smaller attack surface, no surprise packages.
IMDSv2 enforced. SSM Agent pre-installed. cloud-init handles EC2 key-pair injection. Boot-tested on real Nitro EC2 before any image ships. x86_64 and arm64 (Graviton).
Release 1 · 24 images · Rocky / Alma / RHEL 8–10, Ubuntu 24.04 / 26.04, Amazon Linux 2023 · x86_64 + arm64
| OS | Arch |
|---|---|
| Loading catalog… | |
BYOL — Red Hat Enterprise Linux images are Bring Your Own License. You supply the Red Hat subscription; StigReady does not provide commercial Red Hat licenses. Red Hat, Inc. holds the trademarks for Red Hat® and Red Hat Enterprise Linux®.
Windows Server 2022 — planned for a future release. Not part of the initial 24-image rollout.
GPT disk · LVM volume group vg_root · separate STIG filesystems on every base image
| Mount | Filesystem | Options |
|---|---|---|
| /boot/efi | vfat | — |
| /boot | ext4 / xfs | — |
| / | xfs | — |
| /home | xfs | nodev,nosuid |
| /tmp | xfs | nodev,nosuid,noexec |
| /var | xfs | nodev,nosuid |
| /var/tmp | xfs | nodev,nosuid,noexec |
| /var/log | xfs | nodev,nosuid,noexec |
| /var/log/audit | xfs | nodev,nosuid,noexec |
| swap | swap | — |
The separate-filesystem layout that DISA STIG and CIS benchmarks require — already in place, so the profile you apply has less to remediate.
Choose from the RHEL family (Rocky / Alma / BYOL RHEL 8–10), Ubuntu 24.04 or 26.04, or Amazon Linux 2023. x86_64 and arm64 available. Contact us for early access while Marketplace listings roll out, or watch our seller profile.
EC2 injects your key pair on first boot via cloud-init. Connect as ubuntu or ec2-user over SSH with key-based auth. No password logins, no pre-installed keys.
Run your own Ansible, OpenSCAP remediation, or auditd rules on a base that already carries the STIG layout — nothing to undo first.
The number your auditor asks for — published with every image. We score against the raw, unmodified SSG profile in-build. They don't.
Applied overview · scores and filters below
Remediation is driven by StigForge — public CIS / STIG Ansible roles generated from SSG, OpenSCAP-verified, with published scores and evidence per release.
Every image is scored against the raw, unmodified SSG profile during the build — not after, not on a different host. A 90% floor and a no-regression ratchet gate every release.
Every image ships with an OpenSCAP ARF result, an HTML report, a POA&M, an SBOM, and a CVE scan — everything your auditor needs, attached before you ever launch.
DISA STIG images run with FIPS mode enabled, using the OS vendor's FIPS 140-3 validated cryptographic modules (CMVP certificate numbers available on request).
Every image boots on a real EC2 Nitro instance as a build gate. If it doesn't boot clean and pass the scan, it doesn't ship.
All scores as of build 2026-07 · scored against the raw, unmodified SSG profile
| OS | Arch | Baseline | Score | FIPS |
|---|---|---|---|---|
| Loading catalog… | ||||
BYOL — Red Hat Enterprise Linux images require you to supply your own Red Hat subscription. StigReady does not provide Red Hat commercial licenses.
Windows Server 2022 STIG hardening is planned. It is not part of the initial release and currently does not include a CVE scan or SBOM.
Public CIS and STIG role exports — OpenSCAP-verified against the raw SSG profile, with published scores and immutable evidence per release. How-tos: Base + roles →
OpenSCAP verify against the raw SSG profile.
| Role | Profiles | Repo |
|---|---|---|
| Loading… | ||
Role repos are public. The factory monorepo that builds them stays private.
Software fee on top of your normal EC2 costs. Listings are rolling out on AWS Marketplace.
$0.02/hr
or $149/yr per instance
EC2 instance costs billed separately by AWS
$0.08/hr
or $649/yr per instance
EC2 instance costs billed separately by AWS
Annual contracts and Private Offers available. Contact us for early access, BYOL RHEL, volume pricing, or questions — or browse the seller profile.
Pricing, OpenSCAP evidence, Graviton, RHEL BYOL, and Marketplace status.