Why? What compliance reasons make Ubuntu LTS work and RHEL not work?
In the end, we just went with ubuntu for those nodes, and they all passed the certification. Shrug.
Since then, we don't even need the OS to be certified, since we are using confidential computing, and we stuck with ubuntu for our k8s nodes etc -- but we are forbidden from using rhel anywhere by our legal / compliance people now.
The bottom line really is plenty of auditors I've seen don't know how to check for vulnerabilities other than by checking a version... That's it.. Their tools or reporting only know package must have a version greater than x.y.z.