StigReady Base for AlmaLinux 8: STIG-aligned disk layout and EC2 cloud hardening on official media (v0.1.1), boot-verified on AWS Nitro. Published SBOM and CVE scan per build. Foundation before CIS/STIG remediation or StigReady Applied.
StigReady Base for AlmaLinux 8: STIG-aligned disk layout and EC2 cloud hardening on official media (v0.1.1), boot-verified on AWS Nitro. Published SBOM and CVE scan per build. Foundation before CIS/STIG remediation or StigReady Applied.
Who this is for:
Platform engineers and integrators who need a repeatable EC2 foundation with the STIG filesystem layout already in place - before applying your own profiles or subscribing to a scored StigReady Applied image.
What you get (StigReady Base tier):
Separate mounts for /home, /tmp, /var, /var/log, /var/log/audit, /var/tmp (applied at install; not retrofittable after launch)
EC2 cloud baseline: IMDSv2 required, no pre-installed SSH authorized_keys, PermitRootLogin and password SSH disabled, host keys regenerated on first boot
Built from official OS install media; patched at build time
Boot-verified on real AWS EC2 Nitro before release
Per-version evidence (SBOM + CVE scan): see Support below
Getting started:
Subscribe and launch in EC2 with your SSH key.
Connect as ec2-user; restrict security group TCP/22 to trusted IPs.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay an hourly software fee for this hardened AlmaLinux 8 image, billed per running instance. The 14 dimensions all map to arm64 (Graviton) EC2 instance types, not feature tiers. They span three families: t4g burstable sizes (micro through 2xlarge), m6g and m7g general-purpose sizes, and c6g compute-optimized sizes. The size you pick sets your hourly rate. Your normal EC2 compute charges are billed separately by AWS. The software fee stays the same regardless of runtime, scaling only with how many instances you run and their size.
Top-of-mind questions for buyers
What do I get with the hourly software fee, and what do I still have to bring myself?
You get a hardened AlmaLinux 8 image with the STIG partition layout, SSH hardening, and monthly-patched packages built from the official ISO. You supply your own security profiles, Ansible, and tooling. The image carries the disk layout, so profiles you apply have less to remediate.
Am I charged the software fee when an instance is stopped or powered off?
The software fee meters running instance-hours. Fully stopped or powered-off instances do not accrue the hourly software charge. Stopped instances may still incur AWS storage fees, billed separately by AWS. The software fee applies only while the instance runs.
How does my total cost break down between the software fee and the underlying compute?
Two charges apply at the same time on one invoice. The hourly software fee scales with the instance size you pick and how many instances run. Your EC2 compute cost is billed separately by AWS at its own rate. Both add together each hour.
stigready.com
Helpful?
Vendor refund policy
No refunds except as required by law.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
StigReady base AlmaLinux 8 v0.1.1
Additional details
Usage instructions
Subscribe in AWS Marketplace, then launch in EC2 with your SSH key pair. Connect via SSH as ec2-user. Open TCP port 22 only to trusted IP ranges in your security group (avoid 0.0.0.0/0 in production). This AMI requires IMDSv2-compatible instance metadata settings at launch. Documentation: https://stigready.com. Per-build SBOM and CVE scan metadata is listed in the public catalog at https://stigready.com/catalog.json (full factory evidence bundles are not web-public).
Listing copy revision: 2026-07-29b. Contact support@stigready.com and see https://stigready.com for documentation, evidence bundle access, and listing/version questions. Public product catalog:
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
StigReady Base for AlmaLinux 10: STIG-aligned disk layout and EC2 cloud hardening on official media (v0.1.0), boot-verified on AWS Nitro. Published SBOM and CVE scan per build. Foundation before CIS/STIG remediation or StigReady Applied.
Launch RHEL 10 with STIG-aligned partitions applied at install - a layout that cannot be retrofitted after launch, avoiding costly rebuilds when auditors flag disk-layout findings. StigReady Base adds EC2 hardening (v0.1.1), SBOM and CVE metadata per build, and Nitro boot verification.
Launch RHEL 9 with STIG-aligned partitions applied at install - a layout that cannot be retrofitted after launch, avoiding costly rebuilds when auditors flag disk-layout findings. StigReady Base adds EC2 hardening (v0.1.0), SBOM and CVE metadata per build, and Nitro boot verification.
Launch RHEL 8 with STIG-aligned partitions applied at install - a layout that cannot be retrofitted after launch, avoiding costly rebuilds when auditors flag disk-layout findings. StigReady Base adds EC2 hardening (v0.1.0), SBOM and CVE metadata per build, and Nitro boot verification.
Launch RHEL 8 with STIG-aligned partitions applied at install - a layout that cannot be retrofitted after launch, avoiding costly rebuilds when auditors flag disk-layout findings. StigReady Base adds EC2 hardening (v0.1.1), SBOM and CVE metadata per build, and Nitro boot verification.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.