This product has charges associated with it for STIG security hardening. AWS EC2 image based on the latest Windows Server 2022 Base build, pre-configured to support DISA STIG compliance. Designed for U.S. Government, Department of Defense, and federal contractor workloads where elevated security baselines and the standard DoD warning banner are required from day one.
This is a repackaged software product wherein additional charges apply for DISA STIG security hardening.
Madarson IT Windows Server 2022 - DISA STIG Hardened AMI
This AWS EC2 image is built on the latest Windows Server 2022 Base and pre-hardened to align with Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs). It is designed to help organizations meet stringent federal security requirements, reduce exposure to cyber threats, and accelerate their path to an Authority to Operate (ATO).
Who This Is For
This image is purpose-built for U.S. Government agencies, Department of Defense programs, and federal contractors operating workloads that require elevated security baselines from day one. If your environment must comply with FISMA, RMF, or DoD cybersecurity policies, this hardened AMI provides a secure foundation without weeks of manual configuration.
Key Features and Buyer Outcomes
DISA STIG Alignment: Technical security controls are pre-applied to meet DISA guidance for Windows Server 2022, helping you pass compliance assessments with fewer findings.
Secure-by-Default Configuration: Ships with hardened system settings, restricted services, tight access controls, and the standard DoD login banner - ready for production without additional hardening effort.
Faster ATO Timelines: Pre-applied technical controls reduce the manual remediation steps typically required during the RMF process, compressing your path from deployment to authorization.
Audit Readiness: Supports FISMA, RMF, and other federal security mandates requiring STIG validation, with immutable audit configurations in place.
Risk Mitigation: Helps defend against unauthorized access, data breaches, and advanced persistent threats through enforced security baselines.
AWS Integration and Compatibility
EC2Launch v2: Pre-installed and validated for seamless instance initialization.
AWS Systems Manager (SSM): Fully compatible for patch management, inventory, and remote administration.
EC2 Image Builder: Use as a base image in automated image pipelines to maintain hardened configurations across your fleet.
AWS License Manager: Compatible for tracking and managing your Windows Server licensing.
How to Deploy
Subscribe to this product through AWS Marketplace.
Launch an EC2 instance using the hardened AMI with your preferred instance type.
Configure your VPC, security groups, and IAM roles according to your organization's requirements.
Verify STIG compliance post-launch using DISA STIG Viewer or a SCAP-compliant scanning tool.
Integrate with AWS Systems Manager for ongoing patch management and compliance monitoring.
Requirements and Limitations
This is a repackaged software product with additional charges for DISA STIG security hardening.
Buyers should verify compatibility with their target EC2 instance types before deploying at scale.
Application-layer STIGs and any CAT I findings requiring manual action remain the buyer's responsibility.
DISA STIG compliance requires more than technical controls at the operating system layer. Customers remain responsible for organizational, procedural, and additional infrastructure controls.
About Madarson IT
Madarson IT certified images are continuously updated, follow industry best practices, and are designed for rapid deployment in regulated cloud environments. They support a wide range of compliance frameworks out of the box, enabling teams to focus on mission workloads rather than baseline hardening.
Disclaimer
Microsoft, Windows, and Windows Server are registered trademarks of Microsoft Corporation. Madarson IT does not provide commercial licenses for Microsoft products.
Highlights
Accelerated ATO Readiness: This image ships with DISA STIG technical controls pre-applied to Windows Server 2022, compressing the typical weeks of manual hardening into a ready-to-deploy AMI. Organizations can move from subscription to a running, compliance-aligned instance in minutes rather than spending cycles on baseline remediation. The DoD-standard login banner, immutable audit configuration, and restricted services are active from first boot.
Continuous Compliance and Audit Support: Built to support FISMA, RMF, and DoD cybersecurity policy requirements. The hardened configuration is designed for validation with DISA STIG Viewer and SCAP-compliant scanning tools, helping your team demonstrate compliance posture during assessments and maintain Authority to Operate without manual re-hardening after each update cycle.
Native AWS Tooling Compatibility: Fully compatible with AWS Systems Manager (SSM) for patch management and remote administration, EC2 Image Builder for automated image pipelines, and AWS License Manager for tracking Windows Server licensing. EC2Launch v2 is pre-installed and validated, ensuring seamless instance initialization without conflicts from hardened security settings.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for this hardened Windows Server 2022 image. Pricing has no fixed tiers. Instead, your rate depends on the EC2 instance type you choose to run it on. The listing supports many instance families, including general purpose (m and t), compute optimized (c), memory optimized (r), storage optimized (d and i), and GPU (g and p) types. Larger instance sizes carry higher hourly rates because they provide more compute, memory, or storage. You match the instance size to your workload, and software charges scale with that choice.
Top-of-mind questions for buyers
What does one billed hour cover, and am I charged when the instance is stopped?
You pay the software rate for each hour the instance runs. A stopped or powered-off instance stops accruing software charges. Underlying AWS storage fees may still apply while the instance is stopped. Billing meters actual running time on the instance type you selected.
Does moving to a bigger instance size raise my software charge, or only the AWS compute cost?
Both change. The software rate is set per instance type, so a larger size carries a higher hourly software charge. Your AWS compute cost also rises with the size. If you resize down, both charges drop for the hours you run on the smaller instance.
What security hardening comes with this Windows Server 2022 image regardless of instance choice?
The image is hardened to DISA STIG standards for Windows Server 2022. Configurations align with recognized security and compliance frameworks. Images are validated and updated regularly with security patches, not left as a one-time snapshot. This hardening applies no matter which instance type you run it on.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Advanced-Hardened image for Microsoft Windows Server 2022 - DISA STIG Compliance
Additional details
Usage instructions
To connect to the Instance:
Allow inbound RDP access in your security group (TCP port 3389)
Sign in to the AWS Management Console, open the Amazon EC2 console, and choose your Windows Server instance.
Then, select Connect, then Get Password, and then Choose File (private key of the ec2 instance).
Connect to the instance: Use Remote Desktop Connection (RDP) to connect to the instance.
Access the ec2 with the default username: "Administrator" and the password provided
You can also use Systems Manager (SSM) to access the Windows ec2 instance
For questions about STIG hardening configuration, compliance documentation, private offers, or custom hardening requirements, contact the Madarson IT team at info@madarsonit.com.
Support Scope:
STIG hardening configuration questions
Private offer requests and custom requirements
Compliance documentation and audit support
Deployment guidance for SSM, EC2 Image Builder, and License Manager integration
Please include your AWS Account ID and instance details when reporting technical issues to help us assist you efficiently.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for RDP/GUI optimization. Madarson IT pre-configured RHEL 9 cloud virtual desktop AMI with RDP/GUI optimization - launch and connect to a graphical Linux desktop in minutes.
This product has charges associated with it for DISA STIG security hardening. Madarson IT pre-hardened Ubuntu 24.04 LTS AMI with DISA STIG benchmarks applied. Deploy a compliance-ready EC2 instance for DoD and federal security requirements.
This product has charges associated with it for Level 1 foundational security hardening. Madarson IT pre-hardened RHEL 9 AMI delivers a deploy-ready security baseline mapped to NIST CSF, PCI DSS, HIPAA, and ISO 27000 - reducing manual hardening effort for compliance-driven teams.
This product has charges associated with it for Level 2 advanced security hardening. Madarson IT pre-hardened RHEL 9 AMI with Level 2 advanced controls applied, built for teams needing compliance-ready infrastructure on AWS without manual hardening effort.
This product has charges associated with it for GUI and RDP pre-configuration. Pre-configured Ubuntu 24.04 LTS cloud desktop by Madarson IT. Launch on AWS EC2 and connect instantly via any RDP client - no VNC needed.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.