<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Compliance on</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/tags/compliance/</link><description>Recent content in Compliance on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Thu, 20 Nov 2025 08:04:00 +0000</lastBuildDate><atom:link href="https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/tags/compliance/index.xml" rel="self" type="application/rss+xml"/><item><title>Chainguard VMs compliance features</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/chainguard/vms/compliance-features/</link><pubDate>Thu, 20 Nov 2025 08:04:00 +0000</pubDate><guid>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/chainguard/vms/compliance-features/</guid><description>&lt;p&gt;Chainguard VMs provide pre-hardened, audit-ready Linux virtual machine images designed for regulated and high-assurance environments (federal, defense, healthcare, financial services, and suppliers to those sectors). These images combine the following features:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th style="text-align: left"&gt;Feature&lt;/th&gt;
&lt;th style="text-align: left"&gt;Description&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;strong&gt;FIPS 140-3 validated cryptography&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://www.nist.gov/"&gt;NIST&lt;/a&gt; CMVP-validated software modules and &lt;a href="https://csrc.nist.gov/pubs/sp/800/90/b/final"&gt;SP 800-90B&lt;/a&gt; compliant entropy, with runtime guardrails blocking non-FIPS crypto.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;strong&gt;STIG hardening&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;Pre-configured to DISA &lt;a href="https://edu.chainguard.dev/chainguard/containers/security-and-compliance/stigs/"&gt;STIG&lt;/a&gt; controls, delivered as production-ready images.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;strong&gt;CIS benchmark compliance&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;&lt;a href="https://www.cisecurity.org/cis-benchmarks/cis-benchmarks-faq"&gt;CIS&lt;/a&gt; Level 1 hardened variants, hybrid STIG + CIS baseline.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;strong&gt;Secure Boot&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;Secure Boot enabled by default across AWS, Azure, GCP, and on-prem.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;strong&gt;Compliance evidence &amp;amp; reporting&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;FIPS certificates, OpenSSL docs, Security Content Automation Protocol (SCAP) scan results, and POA&amp;amp;M-ready artifacts.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="text-align: left"&gt;&lt;strong&gt;CVE remediation SLA&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: left"&gt;7 days for critical CVEs, 14 days for high, medium, and low.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Chainguard FIPS 140-3 validated and hardened VM images serve as ready-to-use replacements for standard operating systems across AWS, Azure, and GCP, allowing organizations to maintain existing infrastructure and workflows while achieving immediate compliance. This guide outlines the compliance features of Chainguard VMs and how they can help reduce engineering toil for your organization.&lt;/p&gt;</description></item><item><title>SLSA compliance at Chainguard</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/compliance/slsa/slsa-chainguard/</link><pubDate>Wed, 23 Jul 2025 01:24:23 +0000</pubDate><guid>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/compliance/slsa/slsa-chainguard/</guid><description>&lt;p&gt;SLSA (pronounced &amp;ldquo;salsa&amp;rdquo;), or Supply chain Levels for Software Artifacts, is a security framework consisting of standards and controls that prevent tampering, improve integrity, and secure packages and infrastructure. It is described in depth in &lt;a href="https://www.chainguard.dev/supply-chain-security-101/what-is-slsa"&gt;What is SLSA?&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;All Chainguard products — including Chainguard Containers, Guarded VMs, and Chainguard Libraries — are SLSA Level 3 compliant to provide confidence in the security of these products.&lt;/p&gt;
&lt;p&gt;This page describes what we have done to bring Chainguard products into full SLSA Level 3 compliance.&lt;/p&gt;</description></item><item><title>PCI DSS at Chainguard</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/compliance/pci-dss-4/pci-dss-chainguard/</link><pubDate>Wed, 21 Aug 2024 14:05:09 +0000</pubDate><guid>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/compliance/pci-dss-4/pci-dss-chainguard/</guid><description>&lt;p&gt;Compliance with PCI DSS 4.0, or Payment Card Industry Data Security Standard, requires adherence to strong security standards. Rigorous requirements must be met in order to secure your networks, systems, storage, and access according to the guidelines.&lt;/p&gt;
&lt;p&gt;Chainguard doesn&amp;rsquo;t build images specifically for PCI DSS, but our images can help you meet the requirements in many ways, easing your burden in the process of achieving compliance. Securing your software supply chain provides a solid foundation for minimizing vulnerabilities.&lt;/p&gt;</description></item><item><title>CMMC at Chainguard</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/compliance/cmmc-2/cmmc-chainguard/</link><pubDate>Fri, 09 Aug 2024 19:10:09 +0000</pubDate><guid>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/compliance/cmmc-2/cmmc-chainguard/</guid><description>&lt;p&gt;Achieving Cybersecurity Maturity Model Certification (CMMC) 2.0 Level 2 or Level 3 certification can be a complex and resource-intensive process, particularly for organizations managing containerized environments and addressing vulnerabilities. Chainguard simplifies this journey by offering specialized solutions that drastically reduce the time and effort needed to meet compliance requirements. Our FIPS-compliant &lt;a href="https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/platform/fips/fips-images/"&gt;Federal Information Processing Standard&lt;/a&gt; images, combined with detailed SBOM (Software Bill of Materials) and STIG-hardened (Security Technical Implementation Guide) configurations, provide a strong foundation for meeting the requirements of CMMC 2.0.&lt;/p&gt;</description></item></channel></rss>