The challenge: STIG compliance without automation
For federal agencies and defense contractors operating in AWS GovCloud, Amazon Linux 2023 and Windows Server 2025 are rapidly becoming the standard operating systems for cloud workloads. But there's a gap: while DISA publishes the Security Technical Implementation Guide (STIG) for both, the official automated Security Content Automation Protocol (SCAP) content that enables tooling-based assessment is not yet available for the latest releases — the AL2023 V1R2 and V1R3 benchmarks, and the Windows Server 2025 benchmark.
This leaves security teams in a difficult position. FedRAMP requires secure configuration as a foundational component for both Rev5 and 20x certifications. STIG compliance has been used as a common implementation for meeting this control. Additionally, STIGs are a requirement for CMMC, and DoD authorization. Without automated content, teams must validate each rule manually — a process that can take days per system and could introduce human error at every step.
For organizations managing hundreds or thousands of instances across their cloud estate, manual STIG validation doesn't scale.
What Wiz delivers: automated STIG assessment, ahead of official SCAP content
Wiz now supports automated assessment for the DISA STIG Amazon Linux 2023 and DISA STIG Microsoft Windows Server 2025 benchmarks through Host Configuration Rules (HCR) — Wiz's agentless capability for evaluating operating system-level security configurations against industry benchmarks.
Wiz's compliance engineering team translated the majority of the AL2023 STIG into automated checks that run continuously across your cloud environment. The result: what previously required manual, system-by-system validation now happens automatically and continuously — surfacing findings in the Wiz Compliance Posture dashboard alongside your other frameworks, and re-checking them as configurations change over time. Windows Server 2025 support is rolling out now, with an initial set of rules automated and coverage expanding in upcoming releases — helping teams strengthen their hardening posture and support their compliance efforts.
Why this matters for federal and defense teams
Speed to compliance. STIG validation that previously took days per system now runs continuously across your entire fleet. New instances are assessed automatically as they're deployed.
Continuous monitoring, not point-in-time. Unlike traditional SCAP scanning that runs periodically, Wiz's Host Configuration Rules assess continuously — replacing one-time manual checks and keeping instances compliant as their configuration changes over time.
Closing the automation gap. For these releases, official SCAP content isn't available yet — Wiz delivers automated assessment now across both Linux and Windows, closing the gap between guidance and automation.
Unified compliance visibility. AL2023 and WIndows Server 2025 STIG findings appear in the same Compliance Posture dashboard as other common regulations. One view, one workflow, one platform.
Agentless. Wiz evaluates host configurations using agentless scanning — no extra assessment tools or scan credentials to manage across your fleet. It's available under your existing Wiz license — no additional license required.
How it works
Once a STIG framework is enabled in the Wiz portal, every matching instance — Amazon Linux 2023 or Windows Server 2025 — in your connected cloud accounts is automatically assessed against the benchmark.
Each STIG rule is mapped to a Wiz Host Configuration Rule that evaluates the relevant configuration state. Results are reported at the individual rule level, showing pass/fail status per instance, and rolled up into category and subcategory scores in the Compliance Posture view.
Teams can:
Filter by severity (CAT I, CAT II, CAT III) to prioritize high-impact findings
Drill into specific rules to see which instances fail and why
Track posture over time using the Compliance Posture Trend
Generate reports for auditors and authorization packages
Set automation rules to create tickets or trigger remediation workflows for failed checks
Getting started
The DISA STIG Amazon Linux 2023 and Microsoft Windows Server 2025 frameworks are available now in the Wiz Compliance Posture page for all Wiz for Government customers.
Navigate to Compliance Posture in the Wiz portal
Click Manage Frameworks
Search for "DISA STIG Amazon Linux 2023" or “DISA STIG Microsoft Windows Server 2025” and enable the benchmark
Assessment begins automatically for all connected instances
Wiz for Government is FedRAMP High authorized, delivering unified cloud security across Wiz Cloud, Wiz Code, and Wiz Defend for federal agencies and defense organizations.