Blog · 2026-08-12
OpenSCAP evidence bundles auditors actually open
Auditors do not accept vibes. They open ARF results, HTML reports, and a score tied to a named profile. If you cannot reproduce that evidence, “we hardened it” is just a story — and stories fail reviews.
Why “we hardened it” fails audits
Compliance buyers and platform leads get asked the same three questions: which profile, what score, and where is the machine-readable result? Without reproducible OpenSCAP evidence — typically an ARF result plus an HTML report, the profile ID (CIS L1/L2 or DISA STIG), and the published score — you are asking an auditor to trust a narrative. That is not how assessments work.
Hand-tuned images scored against a modified content set, or scored on a different host after the fact, create the same problem: the number on the slide does not match what an independent scan of the AMI would produce. Reproducible evidence means the scan ran against the raw, unmodified SSG profile, on the image under review, with artifacts you can hand over.
What Applied ships day one
StigReady Applied AMIs are CIS Level 1/2 or DISA STIG remediated images, scored in-build against the raw, unmodified SSG profile — not after launch, not on a different host. Each image ships an evidence bundle: OpenSCAP ARF, HTML report, POA&M, SBOM, and CVE scan. Published scores live on the stigready.com Applied table and the Applied overview.
Factory targets a ≥90% floor versus raw SSG, with a no-regression ratchet across releases. That is an engineering gate for what we ship — not a certification, authorization, or accreditation from DISA, DoD, CIS, or anyone else. You still run your own assessment program; Applied gives you auditor-grade artifacts on day one so that conversation starts with files, not slides.
StigForge evidence when you BYO remediation
If you bring your own Ansible, public StigForge roles (*-cis / *-stig on github.com/stigready) publish immutable OpenSCAP evidence under compliance/releases/ per role version. Factory CI verifies against the raw SSG profile with the same 90% floor story; published role scores sit on stigready.com/#stigforge.
Pair those roles with StigReady Base when you want the STIG disk layout and cloud hardening baked at install, then run remediation and re-scoring in your own pipeline. See the Base + StigForge overview and hands-on posts for RHEL 9 STIG and Ubuntu 24.04 CIS.
Evidence day one vs your own scoring pipeline
Need the scored AMI and bundle on day one → Applied ($0.08/hr or $649/yr). Prefer layout plus your own OpenSCAP pipeline → Base ($0.02/hr or $149/yr) with StigForge roles. For the full product decision, see Base vs Applied. For the install-time layout story, see STIG disk layout that won't fight you.
Next steps
Start from the Applied scores, Applied overview, and pricing on stigready.com when you need day-one proof. Questions: contact@stigready.com. AWS Marketplace listings are rolling out — watch our seller page or contact us for early access. We do not publish per-SKU Marketplace URLs here.
Related reading:
- Base vs Applied: which do you actually need?
- STIG disk layout that won't fight you
- StigReady Base + StigForge roles
- RHEL 9 Base +
rhel9_stig - Ubuntu 24.04 Base +
ubuntu24_cis
Questions? contact@stigready.com