Blog · 2026-08-12 · Evergreen
Base vs Applied: which do you actually need?
One hardened foundation, two ways to buy it. Base at $0.02/hr (or $149/yr) is the STIG disk layout and cloud hardening — bring your own profiles. Applied at $0.08/hr (or $649/yr) is that same foundation plus scored CIS or DISA STIG remediation and an evidence bundle.
Side by side
| Base | Applied | |
|---|---|---|
| Software fee | $0.02/hr · or $149/yr | $0.08/hr · or $649/yr |
| What you get | STIG partition layout, SSH key-only, IMDSv2, SSM Agent, minimal patched OS | Everything in Base + full CIS L1/L2 or DISA STIG remediation |
| Scoring | None published for Base — you remediate and score yourself | Scored in-build against the raw SSG profile (90% floor, no-regression ratchet) |
| Evidence | Bring your own OpenSCAP / POA&M pipeline | Bundle: ARF, HTML report, POA&M, SBOM, CVE scan |
| Best when | You already run Ansible / Packer and want control | You need a scored AMI and proof on day one |
EC2 compute is billed separately by AWS either way. See pricing on stigready.com.
Choose Base when…
- You already have CIS / STIG Ansible (or will use public StigForge roles) and want the layout done at install.
- You need to tune exceptions, pin role tags, or bake the same role into Packer that you run on fleets.
- You want the lower software fee and will own scoring and evidence yourself.
Base is intentionally not a compliance score product. We do not publish OpenSCAP percentages or CVE counts for Base. Read more about the layout in STIG disk layout that won't fight you.
Choose Applied when…
- Auditors expect a remediated image and artifacts without wiring OpenSCAP in your pipeline first.
- You want FIPS-enabled STIG images and published scores on the Applied table.
- Time-to-evidence matters more than bringing your own roles.
Browse OS and profile coverage on the Applied page. We only show cells that exist in the published catalog — no invented scores.
A third path: Base + StigForge roles
If you want Base economics with public, OpenSCAP-verified roles, use Base + StigForge: launch Base, then pin a *-cis or *-stig role from github.com/stigready. That path is covered in the series overview and hands-on how-tos.
RHEL note
RHEL Base and Applied images are BYOL. You attach your own Red Hat subscription. StigReady does not sell Red Hat licenses.
How to get started
- Compare tiers on stigready.com — Base, Applied, Pricing
- AWS Marketplace is coming soon for public subscribe/launch — watch the seller profile or contact us for early access, volume, or Private Offers
Questions? contact@stigready.com