This product has charges associated with it for DISA STIG security hardening. Madarson IT pre-hardened Ubuntu 26.04 LTS AMI meeting DISA STIG requirements for U.S. Government, DoD, and defense contractor workloads - deploy audit-ready instances without manual remediation.
Madarson IT Hardened Ubuntu 26.04 LTS - DISA STIG Compliant Server
This is a repackaged software product. Additional charges apply for DISA STIG security hardening applied to the base Ubuntu image.
Deploy a pre-hardened Ubuntu 26.04 LTS (Resolute Raccoon) EC2 instance that maps directly to DISA STIG requirements - eliminating weeks of manual security remediation. Built for U.S. Government agencies, Department of Defense contractors, and organizations operating under federal security mandates who need compliant infrastructure on day one.
This image applies government-grade security controls so your team can focus on mission workloads rather than baseline hardening.
What Ships Out of the Box
DoD-required login banner displayed at every session start
Chrony time synchronization aligned to authoritative NTP sources
SSSD configuration ready for directory integration
Comprehensive auditd rules providing full audit trails for ISSO review
PAM hardening with smart card support readiness
SSH cipher and MAC algorithm restrictions enforcing only approved cryptographic methods
Strict password policy enforcement aligned with federal requirements
Immutable audit configuration preventing tampering with log integrity
Framework Coverage
This hardened image maps to multiple regulatory frameworks applicable to federal and defense environments:
DISA STIG for Ubuntu Linux
NIST SP 800-53 security controls
NIST Cybersecurity Framework (CSF)
FISMA requirements
FedRAMP baseline controls
Risk Management Framework (RMF) alignment
Organizations pursuing Authority to Operate (ATO) can use this image as a validated starting point that addresses foundational operating system controls across these frameworks.
How to Deploy
Subscribe to this listing on AWS Marketplace
Launch the AMI in your target VPC via the AWS Console or CLI
Configure your security group to allow only required inbound traffic (e.g., SSH on port 22 from authorized CIDR ranges)
Connect via SSH using your EC2 key pair
Verify the DoD login banner appears upon connection
Review auditd status with "sudo auditctl -l" to confirm rules are active
Customize SSSD and directory integration for your environment if required
Run your organization's SCAP scanner to validate STIG compliance against the Ubuntu STIG benchmark
Why Madarson IT
Madarson IT certified images are always up to date, follow industry standards, and are built to work right out of the box. Every image is validated before publishing and regularly updated to incorporate the latest security patches. This DISA STIG image builds on advanced hardening controls and applies additional government-grade security measures.
Madarson IT also offers Level 1 and Level 2 hardened Ubuntu images for organizations with different compliance requirements, allowing you to standardize on a single vendor across security tiers.
Disclaimer: Canonical Ltd. owns the trademarks for Ubuntu and its associated branding. Madarson IT does not provide commercial licenses on any third-party product. This hardened image should be considered a starting point. Organizations may need to customize configurations based on their specific security requirements and risk profile.
Highlights
Deploy-Ready Federal Security: This image ships fully hardened with DoD-standard login banner, immutable audit configuration via comprehensive auditd rules, PAM hardening with smart card readiness, SSH cipher and MAC restrictions, session timeout controls, strict password enforcement, chrony time synchronization, and SSSD configuration. Launch a compliant instance and connect - no manual STIG remediation required before your workload goes live.
Multi-Framework Compliance Mapping: Pre-configured controls map directly to DISA STIG for Ubuntu, NIST SP 800-53, NIST Cybersecurity Framework (CSF), FISMA, FedRAMP, and RMF requirements. Organizations pursuing Authority to Operate (ATO) can use this image as a validated baseline that addresses foundational OS-level controls across multiple federal frameworks simultaneously, reducing assessment scope and accelerating authorization timelines.
Validated and Continuously Updated: Every Madarson IT image is validated before publishing and regularly updated to incorporate the latest security patches. This DISA STIG image applies government-grade hardening controls. Run your SCAP scanner post-launch to confirm compliance against the Ubuntu STIG benchmark and maintain continuous monitoring for your ATO package.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for this hardened, DISA STIG-compliant server image. Pricing is usage-based, so charges accrue only while an instance runs. Each dimension maps to a specific AWS EC2 instance type, and the hourly rate scales with the compute resources that instance provides. General-purpose (m, t), compute-optimized (c), memory-optimized (r), storage-optimized (i, d), and GPU (g, p) families are all covered. Within each family, larger sizes carry higher hourly rates. Choose the instance type that fits your workload, and your software cost tracks the hours you actually use.
Top-of-mind questions for buyers
What does one hour of billing represent for a given instance type?
One billing hour equals one hour that a single running instance uses this hardened image. The software rate matches the instance type you launch, such as t3.medium or r5.4xlarge. Larger instance sizes carry higher hourly rates. You pay separately for each running instance.
Am I charged the software rate when my instance is stopped?
The software rate meters running time only. When you stop or terminate an instance, the hourly software charge stops accruing. Stopped instances may still incur underlying AWS storage fees for attached volumes, but those are separate from this listing's per-hour software charge.
What is included in this hardened image at every instance size?
Every instance type runs the same DISA STIG-aligned hardened Ubuntu 26.04 LTS image. The image ships with security configurations and receives regular patch and compliance updates. Only the instance size and its hourly rate change; the hardening and compliance baseline stays the same across all dimensions.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
DISA STIG Ubuntu 26.04 LTS - Government-Grade Hardened. Built on advanced hardening baseline with additional federal security controls.
Additional details
Usage instructions
Allow inbound SSH access in your security group (TCP port 22)
To connect to your instance using the Amazon EC2 console:
Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/.
In the navigation pane, choose Instances.
Select the instance and choose Connect.
Choose the EC2 Instance Connect tab.
For Connection type, choose Connect using EC2 Instance Connect.
Access the ec2 with the default username: "ubuntu"
For support inquiries, private offers, compliance documentation, or custom hardening requirements, contact the Madarson IT team at info@madarsonit.com.
Madarson IT provides assistance with deployment questions, post-launch configuration guidance, and compliance documentation requests for this DISA STIG hardened image.
If you require a custom hardening profile, private pricing arrangement, or need help integrating this image into your ATO package, reach out via email and the team will coordinate next steps.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for hardening, update maintenance, and seller support. Docker on Hardened Red Hat Enterprise Linux 8 (RHEL 8) (ARM) is rigorously secured following STIG guidelines, recognized through a consensus-driven process as the industry benchmark for secure configuration, optimizing both security and efficiency.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.