Begin closer to the requirement.
Start with a PCI-focused configuration baseline instead of turning a general-purpose image into one control by control.
AWS MARKETPLACE · PCI-READY · RHEL 9
Keep the enterprise Linux your team knows. Skip rebuilding a security baseline from a general-purpose image. Citadel delivers architecture-specific RHEL 9 images through AWS Marketplace, refreshed monthly and backed by a US-only support team based in the United States.
Purchase through your AWS account · Live pricing and terms on AWS Marketplace
This image is designed to help meet relevant PCI DSS requirements. It does not independently make a workload or organization compliant.Product information reviewed August 4, 2026.
CUSTOMER TRUST · CITADEL CATALOG
Citadel products run inside global technology companies, financial institutions, defense primes, research organizations, and government agencies.
Used by Fortune 500 banks, defense primes, and government agencies across five countries.
Figures are based on Citadel customer and usage records; updated August 2026. Organization marks identify product users and do not imply endorsement, partnership, or a testimonial. All marks belong to their respective owners.WHY PURPOSE-BUILT
Citadel narrows the operating-system work between a standard RHEL image and an assessor-ready record, while your team keeps control of the application and AWS environment.
Start with a PCI-focused configuration baseline instead of turning a general-purpose image into one control by control.
Give engineering, security, and the QSA one named product record across x86_64 and Graviton deployments.
Move to a refreshed Marketplace image on a monthly cycle instead of recreating the hardening standard every time the base OS changes.
The enterprise operating system your team already knows.
Test the image against your real application and environment.
Automated release pathApplies all available OS patches, tests the resulting image, and completes image-level audit checks before publication.
Critical hotfix pathCritical security fixes can trigger an out-of-cycle release and are prioritized for publication as quickly as operationally possible.
BEST FIT
This product is built for teams that need a defensible RHEL 9 starting point now, want to buy self-service, and prefer to keep procurement inside AWS.
ONE IMAGE STANDARD · THREE OPERATIONAL GAINS
Start from a running PCI-focused RHEL image in about five minutes instead of constructing the operating-system baseline first.
Citadel publishes refreshed images monthly. Your team chooses when to test, approve, and promote each release.
Use x86_64 or Graviton while keeping one defined PCI-focused hardening intent across the product family.
Five minutes refers to a running image ready for workload validation. Running instances do not patch themselves, and the image does not make the surrounding AWS workload PCI compliant.
01 · CHOOSE YOUR ARCHITECTURE
Pick the architecture your workload actually runs. The two AMIs have separate AWS Marketplace subscriptions and should not be treated as interchangeable.
For broad software compatibility across mainstream EC2 instance families.
For workloads whose applications, agents, and dependencies support ARM64.
BUY THROUGH AWS MARKETPLACE
The transaction happens on AWS Marketplace, using your AWS account. Citadel does not insert a separate checkout or publish teaser pricing here.
x86_64 for Intel/AMD EC2, or ARM64 for AWS Graviton.
Confirm current price, regions, instance compatibility, and release details.
Accept the Marketplace terms, then launch first in a non-production environment.
02 · EVIDENCE PATH
This page is the stable product identity. The evidence pack is being standardized per image release; status is explicit below so planned artifacts are never presented as already downloadable.
03 · DEPLOYMENT BOUNDARY
Security configuration changes can affect services, permissions, protocols, cryptography, and system defaults. Treat the image like a new production dependency.
Citadel supplies the RHEL 9 image-level baseline, monthly refresh policy, Marketplace delivery, architecture-specific builds, and a route to human support.
You retain responsibility for the application, cloud design, identity, networking, logging, operations, exceptions, evidence retention, and QSA validation.
BEFORE PRODUCTION
04 · US-BASED SUPPORT
Citadel customer support is staffed entirely by a US-based team. Ask about RHEL 9 product selection, AWS launch, architecture, release cadence, and how hardening may interact with your workload.
US-ONLY SUPPORT TEAM
You keep control of the workload and compliance program. We help you understand the product you are evaluating and the operating-system layer we deliver.
Choose architecture & buyThe customer-facing support team is US-only and US-based.
Bring questions about the image family, architecture, monthly pipeline, and Marketplace launch.
We support the image; your engineers and QSA retain ownership of the full environment and audit.
05 · DIRECT ANSWERS
No. The image provides a hardened operating-system baseline designed to help meet relevant PCI DSS requirements. Your application, AWS architecture, identity, network, logging, processes, evidence, and assessor validation remain your responsibility.
A general-purpose RHEL 9 image gives your team a flexible operating system and leaves the security baseline, documentation, release process, and ongoing maintenance to you. Citadel packages that operating-system work into a PCI-focused AWS Marketplace product with architecture-specific builds, monthly image refreshes, an evidence path, and human support.
Choose x86_64 for Intel- or AMD-based EC2 instances and the broadest software compatibility. Choose ARM64 for AWS Graviton instances after confirming that your application, agents, and dependencies support ARM. Each architecture has its own AWS Marketplace subscription.
Use the architecture-specific AWS Marketplace listing. It is the source of truth for current product fees, AWS infrastructure charges, regions, compatible instance types, and release details. Citadel does not publish a lower teaser price on this page.
It can. A hardened baseline may restrict services, protocols, permissions, or defaults that an application expects. Launch the image in a non-production environment, run your real bootstrap and deployment process, and test the complete workload before production use.
Citadel customer support is provided by a US-only team based in the United States. Customers can ask about product selection, AWS Marketplace launch, architecture, release cadence, and how the image-level hardening may affect a workload. Support does not replace your QSA or a broader compliance program.
READY TO EVALUATE