Wiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025

Automating DISA STIG Compliance for Amazon Linux 2023 and Windows Server 2025, giving defense and federal teams immediate and continuous hardening validation.

The challenge: STIG compliance without automation

For federal agencies and defense contractors operating in AWS GovCloud, Amazon Linux 2023 and Windows Server 2025 are rapidly becoming the standard operating systems for cloud workloads. But there's a gap: while DISA publishes the Security Technical Implementation Guide (STIG) for both, the official automated Security Content Automation Protocol (SCAP) content that enables tooling-based assessment is not yet available for the latest releases — the AL2023 V1R2 and V1R3 benchmarks, and the Windows Server 2025 benchmark.

This leaves security teams in a difficult position. FedRAMP requires secure configuration as a foundational component for both Rev5 and 20x certifications. STIG compliance has been used as a common implementation for meeting this control. Additionally, STIGs are a requirement for CMMC, and DoD authorization. Without automated content, teams must validate each rule manually — a process that can take days per system and could introduce human error at every step.

For organizations managing hundreds or thousands of instances across their cloud estate, manual STIG validation doesn't scale.

What Wiz delivers: automated STIG assessment, ahead of official SCAP content

Wiz now supports automated assessment for the DISA STIG Amazon Linux 2023 and DISA STIG Microsoft Windows Server 2025 benchmarks through Host Configuration Rules (HCR) — Wiz's agentless capability for evaluating operating system-level security configurations against industry benchmarks.

Wiz's compliance engineering team translated the majority of the AL2023 STIG into automated checks that run continuously across your cloud environment. The result: what previously required manual, system-by-system validation now happens automatically and continuously — surfacing findings in the Wiz Compliance Posture dashboard alongside your other frameworks, and re-checking them as configurations change over time. Windows Server 2025 support is rolling out now, with an initial set of rules automated and coverage expanding in upcoming releases — helping teams strengthen their hardening posture and support their compliance efforts.

Why this matters for federal and defense teams

  • Speed to compliance. STIG validation that previously took days per system now runs continuously across your entire fleet. New instances are assessed automatically as they're deployed.

  • Continuous monitoring, not point-in-time. Unlike traditional SCAP scanning that runs periodically, Wiz's Host Configuration Rules assess continuously — replacing one-time manual checks and keeping instances compliant as their configuration changes over time.

  • Closing the automation gap. For these releases, official SCAP content isn't available yet — Wiz delivers automated assessment now across both Linux and Windows, closing the gap between guidance and automation.

  • Unified compliance visibility. AL2023 and WIndows Server 2025 STIG findings appear in the same Compliance Posture dashboard as other common regulations. One view, one workflow, one platform.

  • Agentless. Wiz evaluates host configurations using agentless scanning — no extra assessment tools or scan credentials to manage across your fleet. It's available under your existing Wiz license — no additional license required.

How it works

Once a STIG framework is enabled in the Wiz portal, every matching instance — Amazon Linux 2023 or Windows Server 2025 — in your connected cloud accounts is automatically assessed against the benchmark.

Each STIG rule is mapped to a Wiz Host Configuration Rule that evaluates the relevant configuration state. Results are reported at the individual rule level, showing pass/fail status per instance, and rolled up into category and subcategory scores in the Compliance Posture view.

Teams can:

  • Filter by severity (CAT I, CAT II, CAT III) to prioritize high-impact findings

  • Drill into specific rules to see which instances fail and why

  • Track posture over time using the Compliance Posture Trend

  • Generate reports for auditors and authorization packages

  • Set automation rules to create tickets or trigger remediation workflows for failed checks

Getting started

The DISA STIG Amazon Linux 2023 and Microsoft Windows Server 2025 frameworks are available now in the Wiz Compliance Posture page for all Wiz for Government customers.

  • Navigate to Compliance Posture in the Wiz portal

  • Click Manage Frameworks

  • Search for "DISA STIG Amazon Linux 2023" or “DISA STIG Microsoft Windows Server 2025” and enable the benchmark

  • Assessment begins automatically for all connected instances

Request a demo

Wiz for Government is FedRAMP High authorized, delivering unified cloud security across Wiz Cloud, Wiz Code, and Wiz Defend for federal agencies and defense organizations.

Continue reading

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management