CITADELFind an image

PRODUCTS · PCI-READY BY DESIGN

Choose the operating system and architecture your PCI-scoped workload needs.

Citadel is focused exclusively on maintained, PCI-ready cloud images for teams preparing PCI-scoped workloads. Every product combines a PCI-focused operating-system baseline, monthly releases, evidence as published, Marketplace procurement, and US-based support.

LAST REVIEWED · AUGUST 4, 2026

01 · PRODUCT MODEL

One product focus. A repeatable maintained-image operating model.

Citadel replaces a hand-built operating-system starting point with a repeatable, PCI-focused cloud image that is refreshed monthly. Select the operating system and architecture that fit your application, then validate the exact release against your workload.

Maintained monthly

New image releases are patched, tested, and published through an automated pipeline.

x86 and ARM

Architecture availability is identified on each cloud Marketplace listing.

Marketplace procurement

Subscribe and launch through the cloud account and purchasing path your team already uses.

US-based support

Product questions reach a US-only team based in the United States.

02 · PCI-READY IMAGES

PRODUCT FOCUS

Start the PCI review path with the OS layer already addressed.

PCI

Citadel is built for fintech, payments, SaaS, and other teams that need a hardened cloud baseline organized around PCI DSS requirements. It shortens the operating-system portion of the readiness program without pretending that one image makes the broader workload compliant.

Best fit

  • A PCI deadline is driving the infrastructure decision.
  • The team needs a reviewable OS baseline without building it from scratch.
  • Engineering wants self-service procurement rather than a consulting engagement.
  • The evaluator expects PCI-focused documentation and evidence status.

Product standard

  • PCI-focused operating-system configuration baseline.
  • Per-image evidence pack as published for the specific product.
  • Monthly refreshed images plus an expedited critical-update path.
  • x86 and ARM options where listed, with US-based product support.

03 · WHAT TO VERIFY

Choose by workload fit, then verify the exact product record.

Decision areaWhat to confirm
Operating systemThe OS family and version match application and support requirements
Architecturex86_64 or ARM64 / Graviton matches the planned AWS instance family
PCI focusThe product is built to help meet relevant PCI DSS operating-system requirements
EvidenceThe specific release identifies which evidence artifacts are currently published
MaintenanceMonthly image releases and the critical-update path fit the rollout process
ProcurementCurrent price, regions, terms, and subscription path are confirmed on Marketplace
SupportThe applicable product terms and US-based support scope match team expectations

04 · RESPONSIBILITY BOUNDARY

Citadel owns the maintained image. Your team owns the workload.

Citadel supplies and maintains the image-level baseline described by the selected product. Your team remains responsible for application security, cloud architecture, identity, networking, logging, deployment, operations, evidence retention, and any assessor or compliance decision.