---
title: "Security standards\n    | Ubuntu"
description: Automate hardening for critical workloads and meet cybersecurity standards
  like NIST 800-53, FedRAMP, CMMC 2.0, and EU CRA with Ubuntu Pro.
url: https://ubuntu.com/security/security-standards?format=md
keywords: index, follow
---

# Security standards

Available with Ubuntu Pro

**Run Ubuntu in high-security environments**. Confidently deploy critical workloads while meeting rigorous cybersecurity standards like NIST 800-53, FedRAMP, and CMMC with Ubuntu Pro. As the publishers of Ubuntu, we’ve also developed automated hardening solutions enabling you to run Ubuntu in any environment.

[Contact us](https://ubuntu.com/security/contact-us)
[Learn more about Ubuntu Pro ›](https://ubuntu.com/pro)

FIPS 140-3 is now available for Ubuntu 22.04 LTS. Learn more [here](https://ubuntu.com/blog/fips-140-3-for-ubuntu-22-04lts).

---

## Supported standards

* ### [FIPS](https://ubuntu.com/security/fips)

  FIPS 140-2 & 140-3 certified modules are available for Ubuntu.
* ### [DISA-STIG](https://ubuntu.com/security/disa-stig)

  Simplify your DISA-STIG hardening process by taking advantage of the automation available with Ubuntu Security Guide (USG).
* ### [CIS](https://ubuntu.com/security/cis)

  Harden your systems to CIS benchmark standards using the automation available with USG.
* ### [EU Cyber Resilience Act](https://canonical.com/solutions/open-source-security/cyber-resilience-act)

  Learn how Canonical's security vulnerability management program enables you to comply with the requirements of the EU CRA.
* ### NIST 800-53

  Canonical provides hardening and compliance tools to help you meet NIST 800-53 requirements.
* ### [CMMC](https://ubuntu.com/security/cmmc)

  Canonical provides hardening tools, FIPS 140 certified cryptographic modules, and timely vulnerability patching that enable CMMC compliance.
* ### [FedRAMP](https://ubuntu.com/security/fedramp)

  Find security tools to help you achieve FedRAMP Authority To Operate.
* ### [PCI-DSS](https://ubuntu.com/security/pci-dss)

  Gain extra security and compliance guarantees needed to deploy applications in line with PCI-DSS requirements.
* ### HIPAA

  Canonical supports your path towards HIPAA compliance.
* ### [NIS2](https://ubuntu.com/security/nis2)

  Canonical can help you with your compliance needs related to EU NIS2.
* ### [UK Cyber Essentials](https://ubuntu.com/blog/meet-cyber-essentials-requirements-with-ubuntu-pro)

  Achieve Cyber Essentials through our robust security patching and hardening tools.

---

## Security compliance in action

### Ubuntu Pro helps Lucid Software meet FedRAMP compliance for government contracts

By deploying Ubuntu Pro, Lucid acquired AWS-compatible and FIPS 140-2 certified packages and became FedRAMP compliant.

---

[Read the case study ›](https://canonical.com/case-study/lucid-aws-fedramp-compliance-case-study)

### LaunchDarkly becomes the first FedRAMP-authorized feature management platform thanks to Ubuntu Pro

Learn how a SaaS provider achieved effortless FIPS compliance on AWS.

---

[Read the case study ›](https://assets.ubuntu.com/v1/b97b2df6-AWS%20LaunchDarkly%20Case%20Study%20v3%203.6.2024.pdf)

### How New Mexico State University accelerates compliant federal research with Ubuntu

When the stakes are high and national security is on the line, every decision matters. Just ask the team at New Mexico State University’s Physical Science Laboratory (PSL).

---

[Read the case study ›](https://ubuntu.com/blog/how-new-mexico-state-university-accelerates-compliant-federal-research-with-ubuntu)

---

## Compliance everywhere

### On-prem

[Ubuntu Pro](https://ubuntu.com/pro) enables compliance on Ubuntu desktops and servers in private clouds, Virtual Machines, and air-gapped environments.

---

### In the cloud

Get pre-hardened and compliant Ubuntu Pro images in the public cloud.

---

---

---

[Learn more  ›](https://ubuntu.com/aws)

---

---

[Learn more  ›](https://ubuntu.com/azure)

---

---

[Learn more  ›](https://ubuntu.com/gcp)

---

### On the Edge

Take advantage of Ubuntu Core, our new immutable Ubuntu designed for IoT and Edge deployments with [Ubuntu Pro for Devices](https://ubuntu.com/pro/devices).

---

## Automate compliance with USG

Manual compliance is time consuming and prone to human error. Ubuntu Security Guide (USG) automates hardening and auditing for CIS Benchmarks and DISA-STIG profiles, covering hundreds of individual configuration rules that would otherwise require manual implementation, testing, and ongoing verification. Teams managing compliance across tens or hundreds of Ubuntu systems can reclaim significant engineering time, which is better spent on security improvements than repetitive audit work.

[Calculate your time savings](https://ubuntu.com/security/compliance-automation-value-calculator)

---

## Resources

### [When an upstream change broke smartcard FIPS authentication – and how we fixed it](https://ubuntu.com/blog/when-an-upstream-change-broke-smartcard-fips-authentication-and-how-we-fixed-it)

This is the story of how Canonical’s Support team provided bug-fix support: we tracked down an upstream change in OpenSC that inadvertently broke FIPS compatibility, coordinated with...

### [How to build DORA-ready infrastructure with verifiable provenance and reliable support](https://ubuntu.com/blog/build-dora-ready-infrastructure-with-verifiable-provenance)

DORA requires organizations to know what they run, where it came from, and how it’s maintained. Learn how to build infrastructure with verifiable provenance.

### [Announcing FIPS 140-3 for Ubuntu Core22](https://ubuntu.com/blog/announcing-fips-140-3-for-ubuntu-core22)

FIPS compliance for IoT use cases in Federal space. In this article, we’ll explore what Ubuntu Core is, and how to use it with FIPS.

### [Sovereign clouds: enhanced data security with confidential computing](https://ubuntu.com/blog/sovereign-cloud-confidential-computing)

Increasingly, enterprises are interested in improving their level of control over their data, achieving digital sovereignty, and even building their own sovereign cloud. However, this means...

---

## Easily comply with the most stringent security standards with Ubuntu Pro

Ubuntu Pro is Canonical’s comprehensive subscription for open source security, support, and compliance. Get access to a trusted open source repository, hardened images and compliance profiles for security standards, and up to 15 years of timely and automated vulnerability fixes for your OS, infrastructure, and applications.

---

[Contact us](https://ubuntu.com/security/contact-us)
[Learn more about Ubuntu Pro ›](https://ubuntu.com/pro)
