Department of Defense (DoD) and its contractors, security has to hold up against a published baseline—not a general claim that systems are “secure. ” The Defense Information Systems Agency (DISA) defines that baseline in Security Technical Implementation Guides (STIGs), and STIG compliance is required for information systems that connect to DoD networks. In March 2026, the Defense Information Systems Agency (DISA) published a Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux (RHEL) 10. The scap-security-guide version 0.

82 STIG profile is now available, automating scanning and remediating RHEL 10 against DISA’s official STIG V1R2, bringing RHEL 10 to full STIG maturity. With the release of this compliance automation profile, organizations can benefit from: Accelerated Authority to Operate (ATO) pathways by simplifying compliance reporting and strengthening your documentation framework on the path toward an ATO.

*Note: While the updated profile automates the technical configuration requirements of the STIG, system administrators and security officers must still review findings within the context of their specific operational environment to achieve full compliance certification. For comprehensive configuration steps, implementation guides, and FIPS mode requirements, visit the official Red Hat DISA STIG compliance page . Use scap-security-guide version 0.

82 and select the RHEL 10 STIG profile ( stig or stig_gui ) in Red Hat Lightspeed (formerly Insights), Red Hat Satellite, or via the oscap command line interface to evaluate and remediate your systems against DISA STIG v1r2. To review the underlying official baseline documents, access the official DISA benchmark directly at the DoD Cyber Exchange . Marek Haičman is a Product Owner of the Security Compliance subsystem, dealing mostly with the SCAP ecosystem shipped with RHEL. He started at Red Hat as a Quality Engineer.