CITADELBuy x86_64 on AWS

AWS MARKETPLACE · PCI-READY · RHEL 9

Purpose-built RHEL 9 for PCI on AWS.

Keep the enterprise Linux your team knows. Skip rebuilding a security baseline from a general-purpose image. Citadel delivers architecture-specific RHEL 9 images through AWS Marketplace, refreshed monthly and backed by a US-only support team based in the United States.

Purchase through your AWS account · Live pricing and terms on AWS Marketplace

This image is designed to help meet relevant PCI DSS requirements. It does not independently make a workload or organization compliant.Product information reviewed August 4, 2026.

MAINTAINED BASELINELIVE ON AWS
citadel-rhel9-pciRHEL 9 · PCI IMAGE
MONTHLY
x86_64
x86_64
ARM64
x86_64
ARM64
ARM64
One named baseline. Every new instance starts from the same release.CONSISTENT
  • Okta
  • Cisco
  • BMW
  • Google
  • Apple
  • Facebook
  • JPMorgan Chase
  • Lockheed Martin
  • Northrop Grumman
  • GCHQ
  • U.S. Special Operations Command
  • NASA
  • Pfizer
  • Harvard University
  • Disney
  • Federal Reserve
  • Nintendo
  • Salesforce
  • BAE Systems

CUSTOMER TRUST · CITADEL CATALOG

Used where infrastructure has to hold up.

Citadel products run inside global technology companies, financial institutions, defense primes, research organizations, and government agencies.

100M+compute hours used
5,000+named customers
5 countriesgovernment agency use
Since 2023operating history

Used by Fortune 500 banks, defense primes, and government agencies across five countries.

Figures are based on Citadel customer and usage records; updated August 2026. Organization marks identify product users and do not imply endorsement, partnership, or a testimonial. All marks belong to their respective owners.
RHEL 9operating system
PCI-readyproduct focus
2architectures
Monthlyimage refresh policy

WHY PURPOSE-BUILT

Engineering should deploy the workload—not rebuild its OS baseline.

Citadel narrows the operating-system work between a standard RHEL image and an assessor-ready record, while your team keeps control of the application and AWS environment.

01

Begin closer to the requirement.

Start with a PCI-focused configuration baseline instead of turning a general-purpose image into one control by control.

02

Make the OS standard repeatable.

Give engineering, security, and the QSA one named product record across x86_64 and Graviton deployments.

03

Consume a maintained release.

Move to a refreshed Marketplace image on a monthly cycle instead of recreating the hardening standard every time the base OS changes.

SHORTER PATH TO A HARDENED BASELINEQUALITATIVE WORKFLOW COMPARISON
START WITHRHEL 9

The enterprise operating system your team already knows.

PURPOSE-BUILT FORPCI ON AWS
ACCESSAUDITSERVICESCRYPTO
BEGIN WITHWorkload validation

Test the image against your real application and environment.

TIME TO A RUNNING PCI-FOCUSED IMAGE24+ weeks → about 5 minutes
About five minutes means a running image ready for workload validation—not PCI compliance or a completed audit.AWS LAUNCH TIME CAN VARY
AUTOMATED MONTHLY IMAGE PIPELINE REPEATING RELEASE
BASE
PATCH
TEST
AUDIT
PUBLISH

Automated release pathApplies all available OS patches, tests the resulting image, and completes image-level audit checks before publication.

Critical hotfix pathCritical security fixes can trigger an out-of-cycle release and are prioritized for publication as quickly as operationally possible.

Each publication is a refreshed image release—not a promise that running instances patch themselves.RHEL 9 · TEST BEFORE PROMOTION

BEST FIT

Your PCI deadline is closer than your compliance hire.

This product is built for teams that need a defensible RHEL 9 starting point now, want to buy self-service, and prefer to keep procurement inside AWS.

  • Preparing a PCI-scoped AWS workload for assessor review
  • Need x86_64 or Graviton without maintaining two baselines
  • Want the OS layer—not a consulting engagement or full compliance platform
Choose architecture & buy

ONE IMAGE STANDARD · THREE OPERATIONAL GAINS

Move faster. Stay current. Keep one standard across AWS.

Choose architecture
01 · TIME

Reach workload evaluation sooner.

Start from a running PCI-focused RHEL image in about five minutes instead of constructing the operating-system baseline first.

02 · MAINTENANCE

Adopt a maintained release.

Citadel publishes refreshed images monthly. Your team chooses when to test, approve, and promote each release.

03 · CHOICE

Preserve architecture choice.

Use x86_64 or Graviton while keeping one defined PCI-focused hardening intent across the product family.

Five minutes refers to a running image ready for workload validation. Running instances do not patch themselves, and the image does not make the surrounding AWS workload PCI compliant.

01 · CHOOSE YOUR ARCHITECTURE

One product family. Two native builds.

Pick the architecture your workload actually runs. The two AMIs have separate AWS Marketplace subscriptions and should not be treated as interchangeable.

ARM64AVAILABLE

AWS Graviton

For workloads whose applications, agents, and dependencies support ARM64.

  • Native 64-bit ARM image
  • Use with compatible AWS Graviton EC2 instances
  • Independent Marketplace subscription and release trail
Subscribe on AWS — Graviton Live pricing and release details are shown on AWS Marketplace.

BUY THROUGH AWS MARKETPLACE

From product page to running evaluation in three steps.

The transaction happens on AWS Marketplace, using your AWS account. Citadel does not insert a separate checkout or publish teaser pricing here.

  1. 01
    Choose the CPU architecture

    x86_64 for Intel/AMD EC2, or ARM64 for AWS Graviton.

  2. 02
    Review the live AWS terms

    Confirm current price, regions, instance compatibility, and release details.

  3. 03
    Subscribe and test

    Accept the Marketplace terms, then launch first in a non-production environment.

02 · EVIDENCE PATH

Give engineering and the QSA the same record.

This page is the stable product identity. The evidence pack is being standardized per image release; status is explicit below so planned artifacts are never presented as already downloadable.

IMAGE-LEVEL SAFEGUARDSRHEL 9 · PCI
Access + password policyOS LAYER
System auditingOS LAYER
Service configurationOS LAYER
Cryptographic settingsOS LAYER
Exact requirement mapping belongs in the published evidence pack.BOUNDARY VISIBLE
ArtifactWhat it answersStatus
Product facts + compliance boundaryWhat the image is—and what remains customer-ownedAvailable here
Marketplace release recordWhich architecture and release can be deployedAvailable on AWS
PCI DSS control mappingWhich image-level safeguards can support which requirementsPublishing standard
Hardening manifest / SCSWhat differs from the base RHEL 9 configurationPublishing standard
SBOM + scan contextWhat software is present and what was observed at releasePublishing standard

03 · DEPLOYMENT BOUNDARY

Hardened does not mean application-neutral.

Security configuration changes can affect services, permissions, protocols, cryptography, and system defaults. Treat the image like a new production dependency.

RESPONSIBILITY STACKWHAT SITS UNDER THE WORKLOAD
Your in-scope workloadYOURS
Compatibility validationBEFORE PRODUCTION
PCI DSS hardeningOS LAYER
ACCESSAUDITSERVICESCRYPTO
RHEL 9BASE OS
Citadel delivers the image layer. Your team owns the workload and environment.
THE IMAGE HELPS WITH

A maintained operating-system starting point.

Citadel supplies the RHEL 9 image-level baseline, monthly refresh policy, Marketplace delivery, architecture-specific builds, and a route to human support.

YOUR TEAM OWNS

The workload and the compliance decision.

You retain responsibility for the application, cloud design, identity, networking, logging, operations, exceptions, evidence retention, and QSA validation.

BEFORE PRODUCTION

Run the real workload, not a hello-world test.

  1. 01Launch the chosen architecture in a non-production AWS account.
  2. 02Apply your actual bootstrap, agents, packages, and deployment pipeline.
  3. 03Test service startup, ports, permissions, logging, monitoring, and recovery.
  4. 04Document necessary exceptions and review them with your security lead or QSA.

04 · US-BASED SUPPORT

Questions should reach someone who knows the image.

Citadel customer support is staffed entirely by a US-based team. Ask about RHEL 9 product selection, AWS launch, architecture, release cadence, and how hardening may interact with your workload.

US-ONLY SUPPORT TEAM

Human help, without a consulting engagement.

You keep control of the workload and compliance program. We help you understand the product you are evaluating and the operating-system layer we deliver.

Choose architecture & buy
01Based in the United States

The customer-facing support team is US-only and US-based.

02Familiar with the release

Bring questions about the image family, architecture, monthly pipeline, and Marketplace launch.

03Clear scope

We support the image; your engineers and QSA retain ownership of the full environment and audit.

05 · DIRECT ANSWERS

RHEL 9 deployment questions.

Does this RHEL 9 image make my workload PCI compliant?

No. The image provides a hardened operating-system baseline designed to help meet relevant PCI DSS requirements. Your application, AWS architecture, identity, network, logging, processes, evidence, and assessor validation remain your responsibility.

How is this different from a general-purpose RHEL 9 image?

A general-purpose RHEL 9 image gives your team a flexible operating system and leaves the security baseline, documentation, release process, and ongoing maintenance to you. Citadel packages that operating-system work into a PCI-focused AWS Marketplace product with architecture-specific builds, monthly image refreshes, an evidence path, and human support.

Should I choose x86_64 or ARM64?

Choose x86_64 for Intel- or AMD-based EC2 instances and the broadest software compatibility. Choose ARM64 for AWS Graviton instances after confirming that your application, agents, and dependencies support ARM. Each architecture has its own AWS Marketplace subscription.

Where can I find the current price and release?

Use the architecture-specific AWS Marketplace listing. It is the source of truth for current product fees, AWS infrastructure charges, regions, compatible instance types, and release details. Citadel does not publish a lower teaser price on this page.

Will the hardening affect my application?

It can. A hardened baseline may restrict services, protocols, permissions, or defaults that an application expects. Launch the image in a non-production environment, run your real bootstrap and deployment process, and test the complete workload before production use.

Who answers support questions about this image?

Citadel customer support is provided by a US-only team based in the United States. Customers can ask about product selection, AWS Marketplace launch, architecture, release cadence, and how the image-level hardening may affect a workload. Support does not replace your QSA or a broader compliance program.

READY TO EVALUATE

Choose the architecture. Test the whole workload.