This product has charges associated with it for seller hardening and maintenance support. The Foundation DISA STIG Compliant Rocky Linux 9 is designed to help organizations meet the stringent requirements of the Defense Information Systems Agency Security Technical Implementation Guides (DISA STIG), enhancing the security of their systems..
The Defense Information Systems Agency Security Technical Implementation Guides (DISA STIG) provide a comprehensive set of guidelines for securing information systems and software used by the U.S. Department of Defense. Compliance with DISA STIG ensures that systems are equipped with robust security controls to protect against a wide range of cyber threats. This is critical for organizations operating in highly sensitive and secure environments, such as defense and government sectors.
This Rocky Linux 9 virtual machine image is hardened with hundreds of security controls built-in to ensure the confidentiality, integrity, and availability of sensitive data. With this preconfigured Rocky Linux 9 image, companies can easily deploy a DISA STIG-compliant environment, reducing the time and resources required for security implementation. Foundation Security's image is regularly updated to keep up with the latest security threats and compliance regulations, providing customers with confidence that their data is well-protected. This offering is ideal for organizations that require a secure and compliant environment to protect their sensitive information.
Foundation Security has a team of industry experts with deep knowledge of security and compliance regulations. This ensures that their virtual machine image is well-designed and implemented with the highest level of security standards. Additionally, their experienced team provides ongoing support to ensure their customers' security needs are met. As proud AWS Partners, Foundation Security's images are used by several Fortune 500 companies, demonstrating the reliability and trustworthiness of their solutions.
Highlights
Enhanced Security and Compliance: Foundation Security's VMs are hardened with hundreds of security controls and are regularly updated to comply with the latest security standards, ensuring robust protection for sensitive data.
Expert Support and Maintenance: Our team of industry experts provides ongoing support and maintenance, helping customers quickly deploy and manage compliant environments with minimal effort.
Trusted by Leading Organizations: As proud AWS Partners, our VMs are trusted and used by several Fortune 500 companies, offering a proven solution for secure and compliant virtual machine deployments.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for a hardened Rocky Linux 9 image built to DISA STIG standards. Pricing is tied to the EC2 instance type you run, so the software rate scales with the size and family of the instance you choose. Options span general-purpose, compute-optimized, memory-optimized, storage-optimized, GPU, accelerated, and high-performance families, from small burstable instances up to large multi-terabyte and bare-metal machines. Larger or more specialized instances carry higher hourly rates. You run only the instances you need and can start or stop them at any time, with no upfront commitment.
Top-of-mind questions for buyers
What does the hourly rate cover, and what do I pay AWS separately?
The hourly rate covers the DISA STIG hardened Rocky Linux 9 software license for the EC2 instance you run. You pay this software charge per instance-hour. AWS bills the underlying EC2 compute, storage, and network usage separately. Both appear on your AWS invoice.
Am I charged for instances that are stopped or powered off?
The software charge meters running instance-hours only. When you stop an instance, the hourly software charge stops accruing. You start or stop instances at any time with no upfront commitment. Note that AWS may still bill underlying storage for stopped instances, separate from this software license.
What determines my hourly software rate across the many instance types listed?
Your rate is tied to the specific EC2 instance type you launch. Each type has its own hourly software price. Larger or more specialized families, such as GPU, accelerated, high-performance, or bare-metal instances, carry higher rates than small burstable ones. You pay only for the instance types you actually run.
foundationvm.com
Helpful?
Vendor refund policy
Refunds through AWS are not available at this time. You will only be billed for actual time of instance use. As with all Foundation Security products, our aim is always 100 percent customer/member satisfaction.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
June 2026 maintenance release: latest OS security updates applied
Additional details
Usage instructions
Connect over SSH using the key pair selected at launch. The default user is shown above. See the listing's usage instructions for full details.
Our knowledgeable support team is readily available to answer any questions you may have regarding our virtual machine images. Please feel free to contact us if you need any further information - we are always here to help. Reach out directly at support@foundationvm.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for seller hardening and maintenance support. The Foundation DISA STIG Compliant Rocky Linux 9 is designed to help organizations meet the stringent requirements of the Defense Information Systems Agency Security Technical Implementation Guides (DISA STIG), enhancing the security of their systems.
DISA STIG hardened Rocky Linux 9 container image, rebuilt weekly with the latest patches and CVE remediations. Validated with OpenSCAP. RHEL-specific vendor controls documented as non-applicable exceptions. 10-day free trial available on request.
This product has charges associated with it for providing seller premium support. The Rocky Linux 9 instance is pre-configured and hardened to the Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) standard, delivering enhanced security over a baseline image. Benefit from a fully maintained hardened image with regular STIG updates, security patches, and hotfixes, along with limited premium OS support to assist with troubleshooting, optimization, and compliance guidance. This makes it an ideal choice for companies that require a secure, compliance-ready, production-quality OS backed by expert assistance.
This product has charges associated with it for providing seller premium support. The Rocky Linux 9 instance is pre-configured and hardened to the Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) standard, delivering enhanced security over a baseline image. Benefit from a fully maintained hardened image with regular STIG updates, security patches, and hotfixes, along with limited premium OS support to assist with troubleshooting, optimization, and compliance guidance. This makes it an ideal choice for companies that require a secure, compliance-ready, production-quality OS backed by expert assistance.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.