I agree it's simple to use aws in this case. I meant specifically the claim that "No open source product will meet the requirement". It may not be the financially optimal solution, but that's not "open source" specific.
I see your POV, but I think the distinction is that RHEL
or OpenSSL aren’t vaults. They are components or tools. If RHEL includes a vault product, that would be different.
If I need to sit, I need a chair can support my weight. A box containing 2x4s, a hammer and box of nails doesn’t meet the need.
I’m not disparaging OSS — it just isn’t a good fit for use cases like this when you need to deal with bullshit like FIPS 140-2.