Blog · 2026-08-12 · Launch series

Graviton and arm64 hardened AMIs for STIG and CIS workloads

FinOps wants Graviton. Security wants the same STIG or CIS story you already run on x86. Platform wants one layout, not a second partition fight. StigReady ships Base and Applied on arm64 so you can move compliance fleets without inventing a new hardening path.

Same STIG-aligned layout on arm64 as on x86

Every StigReady AMI — x86_64 or arm64 — is built from the official OS ISO with the same install-time LVM story: separate /home, /tmp, /var, /var/log, /var/log/audit, and /var/tmp under vg_root, plus the usual root, boot, and swap mounts. Architecture changes the CPU; it does not change the disk layout you already planned for OpenSCAP partition checks.

That is the point of STIG disk layout that won't fight you: bake the mounts once at install, then remediate on a disk that already matches the profile. You do not re-carve partitions when you pick a Graviton instance type.

Applied arm64: scored CIS/STIG plus evidence

StigReady Applied arm64 cells are CIS Level 1/2 or DISA STIG remediated images, scored in-build against the raw SSG profile, with a published score on the Applied table. The evidence bundle (ARF, HTML, POA&M, SBOM, CVE scan) travels with the AMI the same way it does on x86 — see OpenSCAP evidence bundles auditors actually open.

Scores and factory gates are engineering proof for buyers and auditors. They are not certification, authorization, or accreditation — and StigReady is not endorsed by DISA or DoD.

Base arm64: layout and hardening, bring your own roles

StigReady Base on arm64 is the same foundation without day-one CIS/STIG remediation: STIG-aligned partitions, patched ISO build, Nitro boot-tested, SSH key-only, IMDSv2, SSM Agent. Attach your Ansible / Packer pipeline — including public StigForge *-cis / *-stig roles — on Graviton the same way you would on x86. RHEL Base remains BYOL; we do not sell Red Hat licenses.

Not sure which tier fits? Read Base vs Applied: which do you actually need?

When Graviton wins for compliance fleets

arm64 is a strong default when the workload is already multi-arch friendly and you care about steady cost and scale:

Stay on x86_64 when the dependency story is not ready: proprietary agents without arm packages, older ISVs, or build chains that still pin amd64 only. Hardening does not fix a missing arm64 RPM or container layer — validate the app matrix first, then move the compliance AMI with it.

Catalog tip: filter Base and Applied for arm64

On stigready.com, open the Base or Applied catalog and use the arm64 (Graviton) architecture filter. That narrows the matrix to cells we actually build — OS family, arch, and (for Applied) profile — without hunting AMI IDs on a marketing page. We do not publish AMI IDs here; subscribe and launch from Marketplace when listings are live for your cell.

Pricing is the same on both arches

Software fee does not change when you pick Graviton:

That is the Marketplace software fee on top of normal EC2 (Graviton instance rates still apply on the AWS side). See pricing for the full story, including annual contracts and Private Offers.

Next steps

Filter Base or Applied for arm64, compare tiers on pricing, and contact us for early access while Marketplace listings roll out. You can also browse our AWS Marketplace seller profile — we do not publish per-SKU Marketplace listing URLs here.

Related reading:

Questions? contact@stigready.com