This product includes charges for the pre-configured security hardening setup, along with ongoing image maintenance. Foundation Level 2 Hardened CentOS 9 builds on our Level 1 framework with additional and more stringent security controls, designed for organizations with heightened security requirements and sensitive workloads.
This CentOS 9 virtual machine image is fully preconfigured with Foundation Security's Level 2 hardening framework and deploys in minutes. Level 2 builds on our Level 1 secure baseline by adding additional and more stringent security measures intended for high-security and highly regulated workloads.
This enhanced profile includes stricter authentication policies, advanced logging and auditing, stronger access control rules, and additional system lockdown configurations to further reduce the attack surface. Foundation Level 2 is intended for environments where security requirements exceed standard enterprise baselines - such as workloads involving sensitive data, regulated industries, or mission-critical systems where risk tolerance is extremely low.
By applying these advanced controls prior to launch, this image eliminates the extensive engineering effort typically required to achieve such a hardened state on a baseline operating system. It reduces the risk of misconfiguration, enforces stricter security boundaries, and ensures a consistent, repeatable high-security posture from day one.
Foundation Security images are updated regularly to incorporate the latest security enhancements and to maintain alignment with evolving threat landscapes. This offering is ideal for organizations that require the highest practical level of operating system security while maintaining performance and operational stability.
Foundation Security has a team of industry experts with deep knowledge of advanced hardening, compliance, and secure system design, ensuring every image is built and maintained to the highest standards. The team also provides ongoing support to help customers maintain this advanced security posture over time
Foundation Security is a proud AWS Partner focused on delivering hardened operating system images for security-conscious organizations. Our images are trusted by several Fortune 500 companies and leading organizations in regulated industries, demonstrating the reliability and proven track record of our solutions.
Highlights
Maximum Security Baseline: Deploy a fully preconfigured CentOS 9 virtual machine image hardened with Foundation Level 2 controls in minutes. This profile enforces more stringent security measures than Level 1, designed for organizations with the highest security requirements.
Advanced Hardening Measures: Level 2 includes stricter authentication policies, enhanced logging and auditing, tighter access controls, and additional system lockdown settings to minimize risk in high-security environments.
Trusted Expertise: Built and maintained by Foundation Security, a proud AWS Partner delivering advanced hardened operating system images. Our images are trusted by Fortune 500 companies and regulated industries, and are continuously updated to stay ahead of emerging threats.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for a hardened CentOS 9 image, billed per running instance. Each dimension maps to a specific AWS EC2 instance type, so your rate depends on the instance you launch. Smaller instances like t3.nano or t2.micro carry lower hourly rates, while larger compute, memory, storage, GPU, and bare-metal types cost more. Pricing scales with the instance's size and capability, not with tiers or feature packages. The software configuration stays the same across every option; you choose the instance that fits your workload, and you are charged only for the hours you run.
Top-of-mind questions for buyers
What do I actually get for the hourly rate on each instance type?
You get a hardened CentOS 9 image running on the AWS EC2 instance type you select. The image is configured using industry hardening frameworks such as STIG and NIST. The instance type sets your compute, memory, storage, or GPU capacity, and your hourly rate reflects that instance's size.
Am I charged when an instance is stopped or paused?
The software charge meters running instance-hours only. When you stop an instance, the hourly software charge stops accruing. Stopped instances may still incur underlying AWS storage fees for attached volumes, but those are separate from this software's per-hour rate.
If I switch to a different instance type, does my rate change automatically?
Yes. Each instance type is priced independently by the hour. When you launch a different type, you pay that type's rate for the hours it runs. The software configuration stays the same across types, so only the hourly rate changes based on the instance you choose.
www.foundationvm.com
Helpful?
Vendor refund policy
Refunds through AWS are not available at this time. You will only be billed for actual time of instance use. As with all Foundation Security products, our aim is always 100 percent customer/member satisfaction.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
This is the initial release of the Foundation Level 2 Hardened CentOS 9 image by Foundation Security
Additional details
Usage instructions
Quick Start
Launch your CentOS 9 instance and connect using SSH on port 22. The default username is centos.
If you connect over SSH, configure your security group to allow access only from your trusted IP address.
This image has been fully hardened with Foundation Level 2 security controls applied and validated before release. No additional hardening steps are required after launch.
Once connected, you can immediately begin installing and running your applications on a secure, advanced-hardened baseline.
Our knowledgeable support team is readily available to answer any questions you may have regarding our virtual machine images. Please feel free to contact us if you need any further information - we are always here to help. Reach out directly at support@foundationvm.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product includes charges for the pre-configured security hardening setup, along with ongoing image maintenance. Foundation Level 2 Hardened CentOS 9 builds on our Level 1 framework with additional and more stringent security controls, designed for organizations with heightened security requirements and sensitive workloads.
AlmaLinux OS is an Open Source and forever-free enterprise Linux distribution, governed and driven by the community, focused on long-term stability and a robust production grade platform. AlmaLinux OS is binary compatible with RHEL®. The AlmaLinux OS Foundation was established as a 501(c)(6) non-profit to steward ownership and governance of the project. The foundation includes over 400 individual members, over 100 Mirror sponsors, and over 25 Corporate sponsors.
AlmaLinux OS is an Open Source and forever-free enterprise Linux distribution, governed and driven by the community, focused on long-term stability and a robust production grade platform. AlmaLinux OS is binary compatible with RHEL®. The AlmaLinux OS Foundation was established as a 501(c)(6) non-profit to steward ownership and governance of the project. The foundation includes over 400 individual members, over 100 Mirror sponsors, and over 25 Corporate sponsors.
AlmaLinux OS is an Open Source and forever-free enterprise Linux distribution, governed and driven by the community, focused on long-term stability and a robust production grade platform. AlmaLinux OS is binary compatible with RHEL®. The AlmaLinux OS Foundation was established as a 501(c)(6) non-profit to steward ownership and governance of the project. The foundation includes over 400 individual members, over 100 Mirror sponsors, and over 25 Corporate sponsors.
AlmaLinux OS is an open-source, community owned and governed, forever-free enterprise Linux distribution, focused on long-term stability, providing a robust production-grade platform. AlmaLinux OS is binary compatible with RHEL®.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.