RLC Pro Hardened

Stop Linux threats: employ proactive security

RLC Pro Hardened delivers trusted Enterprise Linux that is delivered securely, always up to date, and proactively protects apps and services from malicious threats.

CIQ trusted by:

RLC Pro Hardened and compliance for regulated deployments

Meet BOD 26-04 and federal audit posture without rebuilding your Linux infrastructure. RLC Pro Hardened ships the cryptographic evidence and hardening your auditors require, pre-applied:

FIPS 140-3 validated cryptography

With active CMVP certificates

Pre-applied STIG profiles

Up to 95% DISA STIG compliance out of the box

FIPS container support

For Rocky Linux 9.6, 9.7, and 10.1 workloads

CIQ-engineered lockdown playbooks

For DISA STIG, CIS, and NIST 800-171

Real-time kernel threat detection (LKRG)

Complementing static compliance with active monitoring

Compliance-ready cryptography across every layer

RLC Pro Hardened delivers FIPS 140-3 validated cryptography, CAVP-certified post-quantum algorithms (ML-KEM, ML-DSA), and up to 95% DISA STIG compliance pre-applied, covering the requirements for CMMC, CNSA 2.0, and federal acquisition mandates in a single stack.

Organizations in defense, federal, financial services, healthcare, and critical infrastructure get the cryptographic evidence and hardening their auditors require, without assembling it from separate tools and vendors.

Runtime kernel protection

LKRG provides continuous monitoring required for dynamic security frameworks, complementing static configuration compliance with active threat detection.

Post-quantum cryptography

FIPS 140-3 validated PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) meet NSA CNSA 2.0 requirements and protect against future quantum computing threats. PQC for federal contractors

Enterprise Linux
built by the Rocky community;
optimized, hardened and supported by CIQ

Hardened packages

RLC Pro Hardened includes patches and configs for key packages like glibc where we remove unsafe environment variables when crossing a privilege boundary.

OpenSSH

RLC Pro Hardened hardens the OpenSSH package, reducing its attack surface through removal of non-essential libraries.

LKRG attack detection and response

RLC Pro Hardened adds Linux Kernel Runtime Guard (LKRG) to detect kernel vulnerability exploits and identifies/responds to unauthorized modifications of a running kernel and its security-critical data.

hardened_malloc

RLC Pro Hardened adds a security-focused general purpose memory allocator which implements secure heap allocation strategies and strengthens resistance against heap exploitation techniques.

Stronger passwords

RLC Pro Hardened includes passwdqc for stronger password policies and yescrypt hashing for enhanced resistance to GPU password cracking.

Accelerated CVE mitigation

The CIQ team delivers patches for especially important CVEs ahead of standard updates, significantly reducing exposure time.

Custom security controls

RLC Pro Hardened offers a control framework that includes a set of predefined capabilities for password security and reduced exposure of local privileged programs (such as SUID root).

Package validation

All packages are CIQ-verified and cryptographically signed, ensuring package integrity from verified CIQ repositories. In addition to a checksum, each image ships with an SBOM.
Meet CIQ Enterprise Linux Manager (ELM)

Control exactly what reaches your hardened hosts

CIQ Enterprise Linux Manager (ELM) comes with all RLC Pro subscriptions. Decide what each host installs and when, catch conflicts and CVEs before rollout, and run the whole lifecycle inside your perimeter, air-gapped when you need it.

See what ELM does

Advanced kernel protection with LKRG 1.0

Linux Kernel Runtime Guard (LKRG) adds real-time kernel integrity monitoring to RLC Pro Hardened. Operating as a kernel module, LKRG continuously validates critical kernel components and detects exploitation attempts as they occur.

Static patching alone can't prove a system wasn't compromised before the fix landed — see why BOD 26-04's three-day clock demands runtime kernel monitoring.

What LKRG monitors:

  • Vulnerabilities your team hasn't detected yet
  • Kernel memory structures and loaded modules
  • Process credentials and security contexts
  • CPU security features and enforcement
  • Control flow integrity

LKRG 1.0 delivers production-ready capabilities:

  • Support for Linux kernels 3.10 through 6.17
  • Enhanced container workload compatibility
  • Performance optimizations reducing overhead
  • Reduced false positives on modern kernels

Proven protection against real-world exploits:

  • CVE-2021-3490 (eBPF)
  • CVE-2022-0492 (container escape)
  • CVE-2024-1086 (nf_tables use-after-free)

Three days to remediate

Here's how RLC Pro Hardened closes the window

BOD 26-04 gives federal teams three days from KEV entry to remediate. See how pre-applied hardening and real-time kernel detection cover the gap.

Download the solution brief

Why RLC Pro Hardened?

As the speed, sophistication, and volume of attacks on corporate systems accelerate, CISOs and IT security teams struggle to apply an effective and consistent Linux security policy across all their servers.

With RLC Pro Hardened, you get Enterprise Linux and can be assured that it is delivered securely, configured correctly, and is proactively protecting your apps and services from malicious threats.

Proactive

Pre-configured against key threat vectors and delivers hardened memory and kernel integrity checking.

Current

Delivers the latest version of Rocky Linux and is actively updated with all updates and patches.

Speed

Use a pre-hardened Linux OS, so you eliminate the need to manually update a fleet of servers.

Security experts in your corner, protecting your infrastructure while your team drives results

RLC Pro Hardened comes with support from our team of experts who have decades experience securing Linux in some of the most demanding and stringent environments on the planet.

$8.8M

Avg. cost of a license violation.

CIQ indemnifies you against open source license compliance risk.

76%

of codebases contain at least one vulnerability.

CIQ provides CVE patch SLAs and hardened security.

Includes indemnification

RLC Pro Hardened comes with the protection and indemnification guarantees that eliminate your risk and liability in the case of legal issues against the open source software. CIQ is accountable and delivers the coverage to keep your legal and compliance teams satisfied.

Get RLC Pro Hardened

Also available on
Download the RLC Pro Hardened Guide

Download the RLC Pro Hardened guide

Download the RLC Pro Hardened guide and learn more about what CIQ added to Rocky Linux!

Read more about RLC Pro Hardened

View all posts
Routing LKRG runtime events into Wazuh from RLC Pro Hardened

Routing LKRG runtime events into Wazuh from RLC Pro Hardened

Why BOD 26-04's three-day window assumes runtime kernel monitoring

Why BOD 26-04's three-day window assumes runtime kernel monitoring

Rocky Linux or RLC Pro Hardened: what CISA's OSS guidance means for your kernel

Rocky Linux or RLC Pro Hardened: what CISA's OSS guidance means for your kernel

Three days to remediate: what BOD 26-04 asks of federal Linux teams

Three days to remediate: what BOD 26-04 asks of federal Linux teams