This product has charges associated with it for DISA STIG security hardening. Madarson IT pre-hardened RHEL 9 AMI for DISA STIG compliance. Launch a security-optimized EC2 instance ready for DoD and federal workloads out of the box.
This is a repackaged software product wherein additional charges apply for DISA STIG security hardening.
Madarson IT Hardened RHEL 9 - DISA STIG Compliant AMI
Launch a pre-hardened Red Hat Enterprise Linux 9 EC2 instance that is configured to help address DISA STIG security benchmarks from the moment it boots. Built for defense contractors, federal systems integrators, and organizations requiring stringent cybersecurity postures, this AMI eliminates the manual effort of hardening RHEL 9 to meet Department of Defense (DoD) security requirements.
What Is Included
Pre-configured RHEL 9 image with DISA STIG hardening measures applied
Security-optimized kernel parameters and system configurations
Hardened authentication, access controls, and audit logging aligned with STIG guidelines
Image built and maintained by Madarson IT with regular updates to reflect the latest STIG releases
Deployment Scenario
A defense contractor preparing an Authority to Operate (ATO) package for a DoD IL4/IL5 workload can launch this AMI, run an OpenSCAP or SCAP Compliance Checker (SCC) scan to generate compliance evidence, and attach the results directly to their ATO submission. Federal systems integrators can deploy hardened bastion hosts or application servers without spending days manually remediating STIG findings.
Key Benefits
Accelerate Time-to-ATO: Skip weeks of manual DISA STIG hardening. Launch a compliant instance and focus on application-layer security and documentation instead of OS-level remediation.
Reduce Security Risk: DISA STIG configurations are designed to mitigate vulnerabilities, prevent unauthorized access, and protect the integrity, confidentiality, and availability of critical systems and data.
Maintain Continuous Compliance: Madarson IT updates images to reflect new DISA STIG releases and emerging vulnerabilities, helping organizations maintain their security posture over time.
Simplify Auditing: Run SCAP-based scans against the deployed instance to produce audit-ready DISA STIG compliance reports for assessors and authorizing officials.
AWS Integration
This AMI runs on Amazon EC2 and integrates with standard AWS services including Amazon VPC for network isolation, AWS CloudTrail for API logging, and AWS Systems Manager for patch management and fleet operations. Deploy in AWS GovCloud (US) regions for workloads requiring additional data residency controls.
Getting Started
Subscribe to the product on AWS Marketplace.
Launch an EC2 instance using the Madarson IT Hardened RHEL 9 AMI.
Connect via SSH using your configured key pair.
Verify DISA STIG compliance by running an OpenSCAP scan against the DISA STIG for RHEL 9 profile.
Review scan results and address any application-specific or environment-specific findings as needed.
Requirements and Limitations
This is a repackaged software product with additional charges for DISA STIG security hardening.
Buyers should verify compatibility with their target EC2 instance types before deploying at scale.
Application-layer STIGs and any CAT I findings requiring manual action remain the buyer's responsibility.
Confirm whether a separate Red Hat subscription is needed for your use case or if RHEL licensing is included via the AWS Marketplace subscription.
About Madarson IT
Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Our DISA STIG-hardened images help organizations meet federal cybersecurity requirements efficiently and reliably.
Disclaimer
Red Hat, Inc. holds the trademarks for Red Hat Enterprise Linux (RHEL) and associated branding. Madarson IT does not provide commercial licenses for Red Hat products.
Highlights
Pre-Hardened for DISA STIG Compliance Out of the Box: This RHEL 9 AMI ships with DISA STIG hardening measures already applied, eliminating the need for manual OS-level remediation. Launch an EC2 instance and run a SCAP scan to generate audit-ready compliance evidence immediately. Designed for defense contractors, federal systems integrators, and any organization preparing Authority to Operate (ATO) packages for DoD workloads.
Compliance and Auditing: STIGs are critical for compliance with DoD cybersecurity policies. Organizations must regularly assess systems against STIG benchmarks to maintain their Authority to Operate (ATO), ensuring that they meet federal security requirements like the Federal Information Security Management Act (FISMA).
Continuous Updates and Automation: DISA regularly updates STIGs to reflect new vulnerabilities and evolving cybersecurity threats. Automation tools, such as SCAP (Security Content Automation Protocol) and Ansible STIG roles, help organizations efficiently apply and monitor STIG compliance across systems.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for this hardened Red Hat Enterprise Linux 9 image, billed per running EC2 instance. The price you pay depends on which EC2 instance type you launch. The dimensions map to standard AWS instance families: general purpose (m, t), compute-optimized (c), memory-optimized (r), storage-optimized (d, i, h), and GPU or accelerated (g, p). Larger sizes within each family carry higher hourly rates because they provide more compute, memory, or storage. You select the instance type that fits your workload, and software charges accrue only while the instance runs.
Top-of-mind questions for buyers
Am I charged the software fee when my EC2 instance is stopped?
Software charges accrue only while the instance runs. Fully stopped instances do not incur the hourly software fee. Note that stopped instances may still generate underlying AWS storage charges for attached volumes, but the software licence meters running time only.
What does the hourly rate cover beyond the base operating system?
The rate covers a Red Hat Enterprise Linux 9 image pre-configured for DISA STIG compliance. The vendor validates and updates the image regularly with security patches and compliance settings. You pay per running instance-hour, with the rate set by the EC2 instance type you launch.
Why does the same image cost different amounts across instance types?
The software fee is set per EC2 instance type. Types with more virtual CPUs, memory, or storage carry higher hourly rates. You pick the instance type matching your workload, and the software charge scales with that choice. AWS infrastructure charges apply separately alongside the software fee.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Hardened Red Hat Enterprise Linux 9 image with DISA STIG Benchmarks.
Additional details
Usage instructions
Allow inbound SSH access in your security group (TCP port 22)
To connect to your instance using the Amazon EC2 console:
Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/.
In the navigation pane, choose Instances.
Select the instance and choose Connect.
Choose the EC2 Instance Connect tab.
For Connection type, choose Connect using EC2 Instance Connect.
Access the ec2 with the default username: "ec2-user"
For questions about this product, private offers, audit needs, or compliance inquiries, contact us at info@madarsonit.com.
What We Can Help With
Product deployment and configuration questions
STIG compliance verification guidance
Private offer requests for volume or enterprise deployments
Audit and compliance consultation
Please include your AWS Account ID and a description of your issue or request when contacting us so we can assist you efficiently.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for PCI DSS security hardening. Madarson IT pre-hardened Red Hat Enterprise Linux 9 AMI with PCI DSS security benchmarks applied, ready to deploy for organizations handling payment card data.
This is a repackaged open source software product wherein additional charges apply for a pre-hardened, AWS-optimized image with verification reports. This AMI delivers Rocky Linux 9 hardened following DISA STIG guidance and tuned for EC2 by Easycloud-with before/after security scan reports, an SBOM, and an in-house compliance scanner.
This product has charges associated pay-as-you-go charges. No upfront commitment or contracts. Red Hat Enterprise Linux 9.6 Enterprise-Hardened Image. Optimized for Mission Critical Workloads. Hardened Red Hat Enterprise Linux 9.6 to Level 1 Benchmark.
This product has charges associated with it for technical support and maintenance provided by Sedetos. No upfront commitment or contracts. The DISA STIG Hardened Red Hat Enterprise Linux 9 AMI is pre-configured to meet Department of Defense (DoD) Security Technical Implementation Guide (STIG) requirements. Ideal for organizations seeking a secure and compliant foundation on AWS.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.