Overview
Why StigReady Base for AlmaLinux 9: STIG-required disk partition layouts must be in place at install time. Standard and many CIS-hardened AMIs lack that structure, leaving permanent findings on your PoA&M or forcing a full rebuild. StigReady Base delivers the layout and cloud baseline on official media so instances are ready for your scanning workflow.
Who this is for: Platform and DevSecOps teams building regulated workloads on AWS - use this AMI as a golden image foundation before your own profiles or a scored StigReady Applied listing.
What you get (StigReady Base tier):
- Separate mounts for /home, /tmp, /var, /var/log, /var/log/audit, /var/tmp (applied at install; not retrofittable after launch)
- EC2 cloud baseline: IMDSv2 required, no pre-installed SSH authorized_keys, PermitRootLogin and password SSH disabled, host keys regenerated on first boot
- Built from official OS install media; patched at build time
- Boot-verified on real AWS EC2 Nitro before release
- Per-version SBOM and CVE scan metadata (public catalog; see Support)
- Not a fully remediated DISA STIG or CIS score - see StigReady Applied for OpenSCAP-scored remediation
How this differs: Standard marketplace AMIs ship without STIG-aligned partitions. Post-launch STIG remediation cannot fix disk layout. StigReady Base addresses layout and EC2 hardening at the image; StigReady Applied adds scored ansible-lockdown remediation.
Getting started:
- Subscribe and launch on a Nitro instance with your SSH key.
- Connect as ec2-user; restrict security group TCP/22 to trusted IPs.
- Verify layout with lsblk; see https://stigready.com for documentation and catalog.
Marketplace OS metadata may show CentOS family for API compatibility; the image is AlmaLinux from official media.
Support: support@stigready.com | https://stigready.com
Listing copy revision: 2026-07-29d
Not affiliated with or endorsed by DISA, DoD, NIST, CIS, Red Hat, or Canonical. All trademarks are the property of their respective owners.
Highlights
- Closes install-time partition gaps: STIG-aligned mounts applied at image build, not retrofittable after launch - avoids rebuilds for layout-related findings
- Per-build SBOM and CVE metadata in the public product catalog - less manual artifact gathering for assessors
- EC2 hardening from first boot: IMDSv2 required, no baked-in SSH keys; boot-verified on AWS Nitro before release
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/hour |
|---|---|
t3.medium Recommended | $0.02 |
t3.micro | $0.02 |
t3.small | $0.02 |
t3.large | $0.02 |
t3.xlarge | $0.02 |
t3.2xlarge | $0.02 |
m5.large | $0.02 |
m5.xlarge | $0.02 |
m5.2xlarge | $0.02 |
m5.4xlarge | $0.02 |
Vendor refund policy
No refunds except as required by law.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
StigReady base AlmaLinux 9 v0.1.0
Additional details
Usage instructions
Subscribe in AWS Marketplace, then launch in EC2 with your SSH key pair. Connect via SSH as ec2-user. Open TCP port 22 only to trusted IP ranges in your security group (avoid 0.0.0.0/0 in production). This AMI requires IMDSv2-compatible instance metadata settings at launch. Documentation: https://stigready.com . Per-build SBOM and CVE scan metadata is listed in the public catalog at https://stigready.com/catalog.json (full factory evidence bundles are not web-public).
Resources
Vendor resources
Support
Vendor support
Listing copy revision: 2026-07-29d. Documentation and deployment guides: https://stigready.com . Email support@stigready.com for AMI build issues, STIG partition layout questions, and per-version SBOM/CVE metadata (public catalog: https://stigready.com/catalog.json ). Scope covers the StigReady Base AMI image, not application-layer STIG tailoring or third-party scanner configuration. Subscription or refund questions: same email or AWS Marketplace buyer support.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.