This product has charges associated with it for DISA STIG security hardening. Madarson IT's DISA STIG-hardened Red Hat Enterprise Linux 10 AMI for AWS EC2, pre-configured for federal and DoD security compliance in regulated cloud environments.
This is a repackaged software product wherein additional charges apply for DISA STIG security hardening.
Madarson IT RHEL 10 - DISA STIG Hardened AMI
This AWS EC2 AMI delivers Red Hat Enterprise Linux 10 pre-hardened to align with Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs). Built by Madarson IT, this image is designed to help federal agencies, Department of Defense (DoD) contractors, and security-conscious organizations accelerate their path to an Authority to Operate (ATO) while reducing manual hardening effort.
What This AMI Delivers
This image arrives with DISA STIG security controls pre-applied, so your team can launch a compliance-ready instance in minutes rather than spending days manually configuring hardening settings. The configuration addresses operating system-level STIG requirements including:
Restricted services and disabled unnecessary daemons
Hardened authentication and access control policies
System auditing and logging configured per STIG guidance
File system permissions and ownership aligned to STIG benchmarks
Network stack hardening and firewall rule enforcement
Attack surface reduction through removal of non-essential packages
Key Benefits
DISA STIG Alignment: Built to address DISA's technical security controls for RHEL 10, supporting federal and DoD system authorization requirements.
Secure-by-Default Configuration: Implements hardened system settings, restricted services, and tight access controls from first boot.
Risk Mitigation: Helps defend against unauthorized access, data breaches, and advanced persistent threats by reducing the attack surface.
Audit Readiness: Supports FISMA, RMF, and other federal security mandates requiring STIG validation. Run OpenSCAP or SCAP-compliant tools against this image to verify compliance posture.
Continuous Updates: Madarson IT maintains and updates this image to reflect evolving STIG benchmarks and newly disclosed vulnerabilities.
Deployment Overview
This AMI is available for deployment on AWS EC2. After launching the instance, organizations should validate the STIG compliance posture using SCAP scanning tools and apply any environment-specific configurations required by their security authorization boundary.
Getting Started
Launch the AMI on a supported EC2 instance
Connect via SSH to validate the hardened configuration
Run an OpenSCAP scan to confirm STIG compliance status
Apply any mission-specific configurations for your authorization boundary
Document compliance posture for your ATO package
Requirements and Limitations
This is a repackaged software product with additional charges for DISA STIG security hardening.
Buyers should verify compatibility with their target EC2 instance types before deploying at scale.
Application-layer STIGs and any CAT I findings requiring manual action remain the buyer's responsibility.
Confirm whether a separate Red Hat subscription is needed for your use case or if RHEL licensing is included via the AWS Marketplace subscription.
About Madarson IT
Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Our DISA STIG-hardened images help organizations meet federal cybersecurity requirements efficiently and reliably.
Disclaimer
Red Hat, Inc. holds the trademarks for Red Hat Enterprise Linux (RHEL) and associated branding. Madarson IT does not provide commercial licenses for Red Hat products.
Highlights
Pre-Applied DISA STIG Controls for RHEL 10: This AMI ships with operating system-level STIG security controls already configured, including hardened authentication policies, restricted services, system auditing, file permission enforcement, and network stack hardening. Launch a compliance-ready instance and validate with OpenSCAP or SCAP-compliant scanning tools rather than spending days manually applying individual STIG findings.
Accelerated Path to Authority to Operate (ATO): Designed for federal agencies, DoD contractors, and organizations operating in regulated environments. This pre-hardened image reduces the manual effort required to prepare systems for FISMA, RMF, and DISA STIG assessments, helping security teams focus on mission-specific configurations rather than baseline hardening tasks.
Continuously Updated and Maintained by Madarson IT: Madarson IT monitors evolving STIG benchmarks and newly disclosed vulnerabilities to keep this image current. The hardened configuration addresses attack surface reduction, vulnerability management, and cybersecurity compliance requirements, with updates released to reflect the latest DISA guidance and Red Hat security advisories.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for this hardened Red Hat Enterprise Linux 10 image. Pricing follows the AWS EC2 instance type you choose, so there are no fixed tiers. Each dimension maps to one instance size within a family. General-purpose (m and t), compute-optimized (c), memory-optimized (r), storage-optimized (d and i), and GPU (g and p) families are all covered. Larger instances within a family carry a higher hourly rate. You add EC2 infrastructure charges separately. Billing scales with how many hours each instance runs, letting you match cost to your workload size.
Top-of-mind questions for buyers
What does one hour of billing cover for this hardened image?
You pay per hour that each chosen EC2 instance runs the image. One hour equals one running instance for 60 minutes. Each instance size you launch meters separately. The rate is set by the instance type you select, not by users or data volume.
Am I charged the software rate when an instance is stopped or paused?
The hourly software charge applies only while an instance runs. Stopped or paused instances do not accrue software charges. You may still owe AWS for attached storage and other resources while stopped. The software license meters running time only.
What is included in the price beyond the operating system image?
You get a Red Hat Enterprise Linux 10 image hardened to DISA STIG security standards. Images are validated and updated regularly with security patches and compliance configurations. EC2 infrastructure charges are billed separately by AWS and are not part of this hourly software rate.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Red Hat Enterprise Linux 10 -- Hardened for DISA STIG Compliance.
Additional details
Usage instructions
Allow inbound SSH access in your security group (TCP port 22)
To connect to your instance using the Amazon EC2 console:
Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/.
In the navigation pane, choose Instances.
Select the instance and choose Connect.
Choose the EC2 Instance Connect tab.
For Connection type, choose Connect using EC2 Instance Connect.
Access the ec2 with the default username: "ec2-user"
Madarson IT provides support for this DISA STIG-hardened RHEL 10 AMI covering configuration questions, STIG compliance guidance, audit support, and troubleshooting.
Questions about the STIG-hardened configuration and applied controls
Guidance on validating compliance posture with OpenSCAP or SCAP tools
Audit support and compliance documentation assistance
Private offer requests and custom deployment needs
Troubleshooting issues related to the hardened image configuration
Getting Help:
Contact Madarson IT via email for any issues including product usage questions, compliance needs, or to request a refund. For private offers or enterprise deployment discussions, reach out directly to the team.
Please include your AWS account ID and instance details when reporting technical issues to help expedite resolution.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
For North America and regions outside EMEA, optimized and pre-configured for performance with AWS-specific profiles, Red Hat Enterprise Linux combines production stability with developer agility.
This product has charges associated with it for seller support. Red Hat Enterprise Linux 10 (RHEL 10) delivers a robust platform for enterprise-level cloud applications, providing unmatched stability, security, and performance. With advanced kernel optimizations and enhanced performance monitoring, RHEL 10 enables organizations to efficiently manage workloads and streamline operations in the AWS EC2 environment. Its built-in container tools, like Podman and Buildah, facilitate seamless application deployment and scaling. Users benefit from long-term support and a comprehensive ecosystem of certified partners and solutions, making it the ideal choice for enterprises migrating to cloud infrastructures. RHEL 10 also emphasizes compliance, ensuring regulatory requirements are met while protecting sensitive data. Leverage the power of Red Hat's globally trusted platform to optimize your cloud strategy and drive operational excellence.
This product has charges associated with it for DISA STIG security hardening. Madarson IT pre-hardened RHEL 9 AMI for DISA STIG compliance. Launch a security-optimized EC2 instance ready for DoD and federal workloads out of the box.
This product has charges associated pay-as-you-go charges. No upfront commitment or contracts. The DISA STIG Hardened Red Hat Enterprise Linux 9.6 AMI is pre-configured to meet Department of Defense (DoD) Security Technical Implementation Guide (STIG) requirements. Ideal for organizations seeking a secure and compliant foundation on AWS.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.