This product has charges associated with it for NIST 800-171 security hardening. Pre-hardened RHEL 10 AMI addressing NIST 800-171 control families for organizations handling controlled unclassified information (CUI) on AWS EC2.
This is a repackaged software product wherein additional charges apply for NIST 800-171 security hardening.
Madarson IT RHEL 10 - Hardened for NIST 800-171 Compliance
This AWS EC2 AMI delivers Red Hat Enterprise Linux 10 pre-hardened to support organizations meeting NIST Special Publication 800-171: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. Deployed by Madarson IT, this image applies security configurations aligned with the standard's 14 control families, reducing manual hardening effort and accelerating your path to compliance.
Who This Image Is For
NIST 800-171 applies to defense contractors, research institutions, grant recipients, and any non-federal entity that stores, processes, or transmits Controlled Unclassified Information (CUI) under U.S. government contracts. If your organization must demonstrate DFARS 252.204-7012 compliance or prepare for CMMC assessment, this image provides a strong technical foundation.
Key Security Controls Implemented
Access Control Enforcement: Least privilege policies, session timeouts, account lockout thresholds, and role-based access management configured out of the box.
Audit and Accountability: System logging, audit trail generation, and monitoring configurations to support auditability of CUI-related activities.
System and Communications Protection: Encryption configurations for data in transit and at rest, secure network parameter settings, and boundary protection controls.
Incident Response Readiness: Hardened logging, alerting controls, and forensic-ready configurations to support rapid detection and recovery.
Configuration Management: Baseline security settings enforced to reduce attack surfaces and prevent unauthorized software execution.
Identification and Authentication: Strong password policies, multi-factor authentication support, and secure credential storage.
Getting Started
Subscribe to this product through AWS Marketplace.
Select your target EC2 instance type and configure your VPC, security group, and key pair.
Launch the instance from the AMI.
Verify hardening is active by reviewing applied security configurations and running compliance scans.
Why Madarson IT
Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Our hardened images help organizations meet federal cybersecurity requirements efficiently and reliably.
Madarson IT also offers hardened and custom images across AWS, GCP, and Azure Marketplace, covering multiple operating systems and compliance frameworks.
Requirements and Limitations
This is a repackaged software product with additional charges for NIST 800-171 security hardening.
This image addresses technical security controls. Organizational controls such as personnel security and physical protection require separate implementation by the deploying organization.
This image supports but does not guarantee NIST 800-171 compliance. Organizations remain responsible for their complete security program and assessment.
Madarson IT does not provide commercial licenses for Red Hat products. Buyers should ensure appropriate Red Hat subscription coverage for their deployment.
Buyers should verify compatibility with their target EC2 instance types before deploying at scale.
Application-layer controls and any findings requiring manual action remain the buyer's responsibility.
About Madarson IT
Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Our hardened images help organizations meet federal cybersecurity requirements efficiently and reliably.
Disclaimer
Red Hat, Inc. holds the trademarks for Red Hat Enterprise Linux (RHEL) and associated branding. Madarson IT does not provide commercial licenses for Red Hat products.
Highlights
Built for Organizations Handling Controlled Unclassified Information (CUI): This RHEL 10 AMI is designed for defense contractors, research institutions, and non-federal entities required to comply with NIST 800-171 under DFARS 252.204-7012 or CMMC assessments. Pre-applied security configurations address all 14 NIST 800-171 control families at the operating system level, reducing the manual hardening work needed to establish a compliant technical baseline for CUI environments.
Key Security Controls Active from First Boot: Access control enforcement including least privilege policies, session timeouts, and account lockout thresholds is pre-configured. Audit logging and forensic-ready settings are active from launch. Encryption for data in transit and at rest, secure network parameters, and strong authentication controls are applied - giving your team a compliance-ready foundation without post-launch remediation.
Multi-Cloud Hardened Image Portfolio from Madarson IT: Madarson IT publishes hardened and custom images across AWS, GCP, and Azure Marketplace, covering multiple operating systems and compliance frameworks. Images are continuously updated to reflect evolving threat landscapes and framework revisions, ensuring your deployed instances maintain current hardening baselines without requiring in-house framework expertise.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the security-hardened Red Hat Enterprise Linux 10 image, billed based on the EC2 instance size you choose. Each dimension maps to a specific instance type, so your rate scales with the compute, memory, storage, or GPU capacity of that instance. General-purpose (t2, t3, m3, m4, m5), compute-optimized (c3, c5, c5a), memory-optimized (r3, r5), storage-optimized (i2, i3, d2, d3), and GPU (g2, g3, g5, p2, p3) families are all available. Larger instances within a family carry higher hourly rates. There is no upfront commitment; you pay only for hours the instance runs.
Top-of-mind questions for buyers
What does one billing unit represent for this hardened Red Hat Enterprise Linux 10 image?
One unit is one running EC2 instance measured per hour. Each instance you launch meters its own hours separately. Your rate depends on the instance type you choose, so a larger instance carries a higher hourly software charge than a smaller one in the same family.
Am I charged when the instance is stopped or paused?
The software charge meters running hours only. A fully stopped instance does not accrue the hourly software fee. Note that AWS may still bill underlying storage costs, such as attached volumes, while the instance is stopped. Those are separate AWS charges, not the software rate.
What security hardening comes with the Red Hat Enterprise Linux 10 image at every hourly rate?
Each image ships pre-configured with NIST 800-171 aligned security controls. The vendor validates and updates images regularly with security patches, so it is not a one-time snapshot. The hardening is the same across all instance types; only the hourly rate changes with instance size.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Red Hat Enterprise Linux 10 Image -- Hardened for NIST 800-171 Compliance
Select the instance and choose Connect.
Choose the EC2 Instance Connect tab.
For Connection type, choose Connect using EC2 Instance Connect.
Access the ec2 with the default username: "ec2-user"
For questions about this product, including deployment issues, image configuration, private offers, audit assistance, or compliance consultations, contact Madarson IT at info@madarsonit.com.
Scope of Support
Madarson IT provides assistance with image-related issues including boot problems, hardening configuration questions, and compliance mapping inquiries. For Red Hat product licensing or subscription support, contact Red Hat directly as Madarson IT does not provide commercial Red Hat licenses.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
For North America and regions outside EMEA, optimized and pre-configured for performance with AWS-specific profiles, Red Hat Enterprise Linux combines production stability with developer agility.
For North America and regions outside EMEA, Red Hat® OpenShift® is an enterprise Kubernetes container platform with full-stack automated operations to manage applications across hybrid cloud, multicloud, and edge deployments. Red Hat OpenShift improves developer productivity and promotes innovation.
For North America and regions outside EMEA, Red Hat® OpenShift® Platform Plus builds on the capabilities of enterprise Kubernetes platform Red Hat OpenShift with advanced multi-cluster security features, day-2 management capabilities, integrated data management, and a global container registry-to protect, manage, and provide security for applications in a consistent way throughout the software life cycle across clusters.
For the EMEA region, optimized and pre-configured for performance with AWS-specific profiles, Red Hat Enterprise Linux combines production stability with developer agility.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.