CITADELFind an image

EVIDENCE STANDARD · PCI-READY IMAGES

Evidence should show what the image does—not imply what it cannot prove.

Citadel is standardizing a per-image evidence pack for PCI-ready products. This page defines the target standard and distinguishes published material from work still in progress.

LAST REVIEWED · AUGUST 4, 2026

01 · THE STANDARD

Five artifacts, each answering a different audit question.

Control mapping

Maps image-level safeguards to the PCI DSS requirement areas they can help address, with scope and limitations stated.

Hardening manifest

Records the security configuration standard applied to the operating system, including material exceptions and cloud-specific adaptations.

Scan context

Identifies the assessment tool, baseline, release, date, and known exceptions. A scan result is evidence about that image—not a statement about the buyer’s workload.

Software bill of materials

Lists operating-system packages present in the published release so teams can evaluate dependencies and vulnerability findings.

Patch history

Connects each published image version to its release date, base operating system, and patch cycle.

02 · PUBLICATION STATUS

Planned does not mean published.

Until an artifact is linked from this site or the corresponding Marketplace record, buyers should treat it as unavailable.

ArtifactPublic statusCurrent source
Architecture and purchase recordPublishedRHEL 9 product record
Control mappingStandardizingThis page defines the publication standard
Hardening manifestStandardizingPer-image publication pending
Scan contextStandardizingPer-image publication pending
SBOMStandardizingPer-image publication pending
Patch historyPartialPublic changelog methodology

03 · HOW TO USE IT

Give the pack to engineering and the assessor early.

  1. 01
    Confirm the exact release and architecture.

    Evidence must match the image version being evaluated.

  2. 02
    Review exceptions before deploying.

    Hardening can affect services, authentication, logging, cryptography, and application assumptions.

  3. 03
    Map the image into the responsibility matrix.

    Use image evidence for the OS layer and retain separate evidence for the surrounding AWS environment.

04 · EVIDENCE BOUNDARY

An evidence pack narrows review. It does not complete it.

Application security, PCI scope, AWS architecture, IAM, networking, data flows, logging operations, incident response, evidence retention, and assessor validation remain customer responsibilities.

Independent verification

Customers and assessors should validate Citadel images using tools and procedures appropriate to their environment and assessment scope.