CITADELFind an image

AWS MARKETPLACE · PCI DSS

From first boot to PCI evidence in minutes, not weeks.

A maintained, PCI-focused baseline for the cloud provider of your choice. Patched monthly, x86 and ARM, backed by US-based support.

  • Okta
  • Cisco
  • BMW
  • Google
  • Apple
  • Facebook
  • JPMorgan Chase
  • Lockheed Martin
  • Northrop Grumman
  • GCHQ
  • U.S. Special Operations Command
  • NASA
  • Pfizer
  • Harvard University
  • Disney
  • Federal Reserve
  • Nintendo
  • Salesforce
  • BAE Systems

CUSTOMER TRUST · CITADEL CATALOG

Used where infrastructure has to hold up.

Citadel products run inside global technology companies, financial institutions, defense primes, research organizations, and government agencies.

100M+compute hours used
5,000+named customers
5 countriesgovernment agency use
Since 2023operating history

Used by Fortune 500 banks, defense primes, and government agencies across five countries.

Figures are based on Citadel customer and usage records; updated August 2026. Organization marks identify product users and do not imply endorsement, partnership, or a testimonial. All marks belong to their respective owners.
Monthlypatch cadence
x86 + ARM64architecture coverage
AWS Marketplaceavailable today
US-onlysupport team

01 · WHY CITADEL

The artifact is useful. The documented audit path is the product.

A benchmark tells you what a secure configuration should look like. A full compliance platform builds and monitors the entire environment. Citadel occupies the practical middle: a maintained PCI-focused OS baseline, procured self-service, with documentation for review and humans available when hardening meets your app.

A

BENCHMARK ARTIFACT

Define the baseline

Configuration guidance explains what secure should look like. Your team turns that guidance into a maintained image and assessor-ready evidence.

B

CITADEL · PRACTICAL MIDDLE

Deploy a maintained baseline

A PCI-focused AMI with monthly releases, evidence as published, Marketplace procurement, and support—without a platform engagement.

C

COMPLIANCE PLATFORM

Operate the full environment

Networks, identity, logging, security tooling, evidence automation, drift monitoring, and assessor workflows—more scope than every team needs.

02 · PCI-READY IMAGE CATALOG

One product focus: shorten the path through PCI review.

Every Citadel image is organized around PCI readiness. Product fees, architecture, operating-system details, and current release information live on each AWS Marketplace listing.

03 · ASSESSOR-READY EVIDENCE

Give your engineer and QSA something concrete to review.

Citadel is standardizing a per-image evidence pack for its PCI-ready images—the bridge between hardened configuration and assessor review. Availability is identified on each listing, so buyers can distinguish what ships today from what is still rolling out.

01

Control mapping

A plain-language map of the image-level safeguards and the PCI DSS requirements they can help address.

02

Security configuration standard

A reviewable hardening manifest that shows engineers and assessors exactly what differs from the base operating system.

03

Scan report + SBOM

Machine-readable software inventory and vulnerability context for the specific image release.

04

Patch history

A dated release trail that makes the monthly patch cycle visible instead of asking buyers to take it on faith.

SHARED RESPONSIBILITY

What the image can—and cannot—do

THE IMAGE CAN HELP

Establish a hardened OS baseline, reduce avoidable configuration work, document image-level changes, and support a repeatable patch process.

YOUR TEAM STILL OWNS

PCI scope, application security, AWS architecture, IAM, network controls, logging, operating procedures, evidence retention, and assessor validation.

04 · MARKETPLACE COVERAGE

AWS today. Azure and Google Cloud next.

Citadel is available for self-service procurement through AWS Marketplace now. Microsoft Azure Marketplace and Google Cloud Marketplace are on the roadmap—not yet available. The goal is one consistent hardening and evidence standard across clouds.

02PLANNED

Microsoft Azure Marketplace

Planned expansion of the Citadel image catalog and evidence standard to Azure workloads.

03PLANNED

Google Cloud Marketplace

Planned image delivery for teams running regulated workloads on Google Cloud.

CURRENT AWS CATALOG

Current Linux families. Both sides of AWS compute.

Choose x86_64 for broad compatibility or ARM64 for Graviton economics. Exact OS version, architecture, pricing, and release status belongs on the individual listing page.

Browse the current AWS catalog
Ubuntux86 / ARM
Debianx86 / ARM
Rocky Linuxx86 / ARM
Red Hat Enterprise Linuxx86 / ARM · view RHEL 9 PCI
Amazon Linuxx86 / ARM

05 · HUMAN SUPPORT

A trusted image should come with someone you can ask.

When a security setting meets an application dependency, customers can reach a US-only support team based in the United States—not a faceless image catalog.

US-BASED PRODUCT SUPPORT

Talk to people who know the images.

Ask about image selection, architecture, Marketplace launch, release cadence, and the practical effects of hardening on your workload.

Find your image on AWS
01US-only team

Customer support is staffed entirely by people based in the United States.

02Product context

Get answers from a team familiar with the catalog, architectures, and release process.

03Honest boundary

Support helps with the image; your team and QSA still own the broader compliance decision.

06 · DIRECT ANSWERS

Questions your engineer and assessor will ask.

How does a Citadel image accelerate PCI DSS readiness?

Citadel gives your team a maintained, PCI-focused operating-system baseline designed to help meet relevant PCI DSS requirements from first boot—so you can skip building, hardening, testing, and maintaining that layer yourself. Patched monthly and backed by US-based support, it lets your team focus on the application and cloud environment your assessor will review. You still own scope, architecture, identity, networking, logging, procedures, evidence, and assessor validation—but you no longer have to start the OS layer from scratch.

How is Citadel different from a benchmark image?

A security benchmark defines configuration guidance. Citadel turns that starting point into a maintained, PCI-focused AWS product: Marketplace delivery, monthly image releases, x86 and Graviton coverage, a standardized evidence-pack rollout, and human support when hardening meets application requirements. Citadel still does not replace your QSA or your broader PCI program.

How is Citadel different from a full compliance automation platform?

A full compliance platform can build and monitor networks, identity, logging, security tooling, policies, and evidence across an entire environment. Citadel is deliberately narrower: a self-service hardened operating-system baseline for teams that want to keep control of their AWS architecture and avoid a platform or consulting engagement.

How often are Citadel images patched?

Citadel publishes refreshed images on a monthly patch cycle. Each AWS Marketplace listing is the source for the currently available release and its specific usage details.

Does Citadel support AWS Graviton?

Yes. Citadel offers ARM64 images for AWS Graviton alongside x86 options across its operating-system matrix. Availability varies by operating system, so confirm the architecture on the specific Marketplace listing before launch.

Will hardening break my application?

Hardening can restrict services, protocols, permissions, or defaults that an application expects. Test the image in a non-production environment, compare the hardening manifest with application requirements, and contact Citadel support when a control needs operational context.

Why buy through AWS Marketplace?

Marketplace lets eligible buyers subscribe through an existing AWS account and apply the purchase to their cloud procurement workflow. Product fees and AWS infrastructure charges are shown on each listing; Citadel does not use teaser pricing on this site.

Who provides Citadel support?

Citadel customer support is provided by a US-only team based in the United States. Customers can reach people familiar with the image catalog for product, launch, architecture, and hardening questions. Citadel does not claim a response-time SLA unless one is explicitly published with the product terms.

DEPLOY ON YOUR AWS ACCOUNT

Own the environment.
Skip the manual baseline.

Subscribe through AWS Marketplace, test against your application, review the published evidence, and bring your QSA into the path early.

Explore Citadel on AWS