Resource Library
CIQ builds and supports the enterprise stack for AI, HPC, and mission-critical Linux workloads. Resources are organized by product and include solution briefs, migration guides, and technical references.

BOD 26-04 and federal contractors: what it means for FISMA scope
BOD 26-04 binds federal agencies, and the systems contractors run for them fall in scope. Here is how FISMA scope works and what to verify.' meta-title: 'BOD 26-04 for federal contractors: FISMA scope

The Quantum Clock Is Ticking
Post-quantum cryptography and the cryptographic compliance imperative: the harvest-now-decrypt-later threat, the FIPS 140-2 sunset, CNSA 2.0, and what enterprises must do before regulatory deadlines arrive.

Self-service purchasing is live: buy CIQ products in the portal, on your own terms

CIQ opens direct purchase of Enterprise Linux and removes procurement from the path to production

Optimize GPU, cost, and expertise with Fuzzball
A new AI launch can spike usage before anyone can trace the spend. See how Fuzzball optimizes GPU utilization, cost, and infrastructure expertise so teams get to the work faster, straight from the Fuzzball documentation.

Why we're building OpenWALDO
CIQ founder Gregory Kurtzer on why AI needs an open, community governed corpus of training data, and how OpenWALDO applies proven open source infrastructure to build it.

Sovereign AI, from desk to data center: a conversation with TechnologyInsider
CIQ CEO Gregory Kurtzer talks with TechnologyInsider about running AI in house: why starting is easy, why scaling is hard, and what is pushing European organizations toward sovereign AI.

FIPS 140-3 under BOD 26-04: what federal agencies actually need to prove
FIPS mode is not FIPS validation. Here is what FIPS 140-3 actually requires under federal review, and what counts as evidence for your Linux stack.

Rocky Linux founder Gregory Kurtzer builds OpenWALDO as a true collaborative open source community for AI

NASA’s Flight Sciences Lab runs its most demanding missions on RLC Pro
The Flight Sciences Lab at NASA’s Johnson Space Center runs 28,000 cores of mission critical HPC on Rocky Linux and RLC Pro, supporting Artemis II reentry modeling, ISS operations, and real time analysis for Mission Control.

A Fortune 500 digital payments company cut licensing costs without disrupting production
With more than 3,000 nodes in a mission critical Linux estate, a Fortune 500 global digital payments company moved to RLC Pro and cut OS licensing costs by more than 40%, with zero disruption to production.

Routing LKRG runtime events into Wazuh from RLC Pro Hardened
LKRG stops kernel attacks, but a blocked attempt is still an attempt. Here's why routing LKRG events into Wazuh gets the record off the host — and why the kernel-direct path matters when the box is going down.
Browse by product
What each product in the CIQ portfolio is for, and the briefs, guides, and portal links that go with it. Expand a product to see the detail.
OS Layer
CIQ's free tier, with variants purpose-built for major hardware ecosystems.
- RLC+ NVIDIA includes the complete NVIDIA AI and networking stack validated and ready out-of-the-box with CUDA Toolkit and DOCA-OFED pre-integrated, eliminating hours of driver setup before a single GPU-accelerated job runs.
- RLC+ AMD, coming soon, delivers AMD Instinct GPU drivers and ROCm support pre-integrated.
When requirements extend to LTS, FIPS validation, production SLOs, and indemnification, that is where RLC Pro begins.
A complete rethinking of what an Enterprise Linux vendor owes its customers. RLC Pro provides direct bug fixes, committed CVE timelines, Long-Term Support, and FIPS 140-3 as an all-inclusive subscription with no inventory tracking. Every enterprise requirement is treated as a baseline, not an add-on: binary compatibility, security, update SLAs, FIPS validation, indemnification, and support from engineers who helped build Rocky Linux.
A security-hardened variant of RLC Pro preconfigured for high-compliance environments. Ships 95%+ DISA STIG and 99% CIS compliant at first boot, no manual configuration required. Active defense is embedded directly in the OS: Linux Kernel Runtime Guard (LKRG) detects exploitation as it occurs, not after. Hardened memory allocator, hardened glibc and OpenSSH, cryptographically signed packages, and an SBOM per image provide layered protection against entire classes of vulnerabilities before they are known or disclosed.
Built with an AI-first mindset from the kernel layer up. The CIQ Linux Kernel (CLK), CUDA Toolkit, and DOCA-OFED ship commercially authorized and pre-integrated: drivers, kernel modules, and runtime dependencies validated together before release. PyTorch and vLLM combinations tested per release. The same validated stack runs identically on bare-metal, AWS, GCP, Azure, and sovereign on-premises infrastructure. Secure Boot, Confidential Computing, and a per-image SBOM included as standard.
Orchestration Layer
A cloud-native workload orchestration platform for AI and HPC that keeps data, models, and computation on infrastructure you control. Fuzzball unifies model training, fine-tuning, validation, and inference in a single portable workflow: on-premises, in the cloud, or hybrid. Integrates with existing Slurm and PBS Professional deployments.
Enterprise-grade stateless cluster provisioning. Warewulf Pro manages the full lifecycle of bare-metal compute nodes via a web UI. Nodes boot from a known image every time, so configuration drift does not accumulate and new clusters deploy in days rather than weeks.
Enterprise infrastructure automation built on AWX. Ascender Pro delivers workflow orchestration, configuration management, compliance reporting, and drift remediation at fleet scale. CVE dashboards and exportable audit records are generated as a byproduct of normal operations, not a separate staff project.
The leading open-source container runtime for HPC and scientific computing. Apptainer runs containers without root privileges and integrates natively into shared, multi-tenant cluster environments where Docker is not appropriate.
Platform Tools
A compatibility bridge enabling organizations to run RHEL-certified software on Rocky Linux without requalification. CIQ Bridge closes the gap between upstream Rocky Linux and certified enterprise software ecosystems, and provides a migration path from CentOS 7.
A searchable catalog of software and hardware verified compatible with CIQ's product portfolio. C3 gives architects and procurement teams a trusted reference for validated integrations, reducing evaluation risk when building on the CIQ stack.
The central hub for CIQ product access. Organizations use the CIQ Portal to manage licenses, download ISOs and installers, access documentation, and evaluate products before purchase, from a developer license to an enterprise trial to full production deployment.
Installation guides, configuration references, and release notes for every CIQ product, including FIPS certification status for RLC Pro. The canonical source engineers reach for once a product is deployed.
Troubleshooting articles, how-tos, and known-issue write-ups from CIQ's support engineers. Searchable answers to the questions customers actually open tickets about.