This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
The CIS Hardened Image Level 2 on Microsoft Windows Server 2019 is a pre-configured image built by the Center for Internet Security (CIS®) for use on Amazon Elastic Compute Cloud (Amazon EC2). It is a pre-configured, security-hardened image that aligns with the robust security recommendations, the CIS Benchmarks, making it easier for organizations to meet regulatory requirements.
Not only is this image pre-hardened to the CIS Benchmarks guidance, but it is also patched monthly in alignment with the updates from the software vendor.
Key Benefits
Enhanced Security: Mitigates risks like malware, denial of service, and authorization issues by following globally-recognized secure configuration guidance to support your cloud security posture management (CSPM) program.
Compliance Readiness: Helps your organization comply with PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
Faster Deployment: Pre-configured according to CIS Benchmarks, allowing you to deploy secure virtual machine images.
Consistency Across Environments: Ensures consistent security configurations across development, testing, and production environments, reducing drift and compatibility risks.
Cost Efficiency: Lowers remediation efforts, reduces attack surface, and minimizes business loss from security incidents.
Easier Maintenance: Regular updates ensure that your systems are always in line with the latest security standards and software patches.
This image is hardened against the corresponding Level 2 profile which is intended for environments or use cases where security is paramount, acts as a defense in depth measure, and may negatively inhibit the utility or performance of the technology. No components are installed on or removed from this image outside of those already present on the base image or as recommended in alignment with the corresponding CIS Benchmark recommendations.
To demonstrate conformance to the CIS Microsoft Windows Server 2019 Level 2 Benchmark, industry-recognized hardening guidance, each image includes an HTML report from CIS Configuration Assessment Tool (CIS-CAT® Pro). Each CIS Hardened Image contains the following files:
Base_CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance before any change is made by CIS (e.g., software updates, CIS hardening).
CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance after the corresponding CIS Benchmark was applied to the image.
Exceptions.txt - this provides a list of recommendations that are not applied because the configuration of those recommendations may inhibit the use of this image in this CSP, require environment-specific expertise, or hinder the integration of this image with CSP services or extensions.
These reports are located in C:\CIS Hardening Reports.
If this instance is used in a domain environment where policies are managed globally, the majority of the security settings will be changed and managed by domain policies.
Hardened according to a Level 2 CIS Benchmark that is developed in a consensus-based process and that is accepted by government, business, industry, and academia.
Helps with compliance to PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
Pre-configured to align with industry best practices that are developed and supported by CIS, this image has hardened account and local policies, firewall configuration, and computer-based and user-based administrative templates.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for this pre-hardened Windows Server 2019 virtual machine image. Pricing is usage-based, so you are billed only for the hours each instance runs. The many dimensions map to specific AWS EC2 instance types, from small shared instances to large compute-, memory-, and storage-focused sizes and bare-metal options. The software rate ties to the instance type you pick. Larger or more specialized instances carry different hourly rates. You scale cost by choosing instance size and running quantity. There is no upfront commitment or fixed term with this hourly model.
Top-of-mind questions for buyers
What do I actually get for the hourly software rate on each instance type?
You get a virtual machine image of Windows Server 2019 pre-configured to the CIS Benchmarks Level 2 recommendations. The image runs on the AWS EC2 instance type you select. The hourly rate covers the hardened software layer; the instance size sets the compute, memory, and storage you receive.
Am I charged the software rate when an instance is stopped or powered off?
The hourly software charge meters running time only. A stopped or powered-off instance does not accrue the software rate. Underlying AWS storage fees for the attached volume may still apply while the instance is stopped, but those are separate from the software charge.
What drives my total cost across these instance-type dimensions?
Two factors drive cost. First, the instance type you pick sets the hourly software rate. Second, the number of hours each instance runs, multiplied by how many instances you run. The charges bill per instance per hour. Larger or specialized instance types carry different hourly rates.
www.cisecurity.org
Helpful?
Vendor refund policy
Refunds through AWS are not available at this time. You will only be billed for actual time of instance use. As with all CIS security products, our aim is always 100 percent customer/member satisfaction.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Monthly updates
Additional details
Usage instructions
Once the instance is running, choose Get Windows Password in the EC2 console then connect using a Remote Desktop Connection (RDP) client. The RDP client MUST be able to authenticate using NTLMv2. See https://technet.microsoft.com/en-us/library/cc738867%28v=ws.10%29.aspx for more information. Immediately apply latest security updates after launching the instance.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Image hardened according to CIS Benchmark Level 2 profile developed through consensus-based process and accepted by government, business, industry, and academia.
Regulatory Compliance Support
Supports compliance with PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, and select NIST publications.
Pre-configured Security Controls
Includes hardened account and local policies, firewall configuration, and computer-based and user-based administrative templates aligned with CIS Benchmark recommendations.
Conformance Assessment and Reporting
Includes CIS-CAT Pro HTML reports documenting baseline configuration, post-hardening configuration, and exceptions to benchmark recommendations.
Regular Security Updates
Patched monthly in alignment with software vendor updates to maintain alignment with latest security standards.
FIPS Certification
FIPS 140-2 certified kernel and cryptographic modules included out of the box with ongoing security updates
Extended Security Coverage
Security patches available for over 23,000 open source packages in the Ubuntu Universe repository with 10 years of support through Expanded Security Maintenance
Compliance Hardening Profiles
CIS and DISA-STIG hardening profiles accessible through Ubuntu Security Guide tooling for guided compliance configuration
Cryptographic Module Updates
FIPS-certified cryptographic components with continuous security updates maintained throughout the support lifecycle
Long-term Support
10-year security coverage period for the operating system and included packages
Operating System Hardening
Amazon Linux 2 configured with STIG Benchmark High standard for enhanced security posture
Security Standards Compliance
Implementation of Defense Information System Agency (DISA) Security Technical Implementation Guides (STIGs) for system hardening
EMR Compatibility
Tested and compatible with Amazon Elastic MapReduce (EMR) for distributed computing workloads
Continuous Security Updates
Access to continuous security updates available through new versions of the image
Multi-Application Support
Suitable for deployment across various applications beyond EMR environments
Best practices developed that is the Center for Internet Security (CIS) Benchmarks is great at assisting security practitioners in implementing and managing their cybersecurity defenses. Also we may install the most recent software packages and tools safely in a server environment to use in our environment and enable secure file sharing thanks to this service that allowed for the deployment of an operating system. If you have the skills for distributing software in a server environment, your options are virtually endless.
What do you dislike about the product?
The lack of a properly organised SDN in Microsoft Windows Server 2019's architecture is the only disadvantage I can think of. The lack of a useful centrally managed framework makes it difficult for us to shift from one network control plane to another.
What problems is the product solving and how is that benefiting you?
Windows Server 2019 is used to install Amazon Fargate instances, which is a crucial component. We are able to establish all VPN connections without any licencing restrictions because the maximum RRAS connection is infinite. It is compatible with our.NET framework 4.7.1, eliminating our compiler dependency problems even if we forget to install some components or if the incorrect device drivers cause it to become damaged.
Safina L.
What an awesome Project Product. I enjoyed using it.
Reviewed on Mar 12, 2023
Review provided by G2
What do you like best about the product?
What was awesome about it was it helped me make proper auditing decisions, even it were for hypothetically.
What do you dislike about the product?
I didn't like the number of times I had to hit different keys.
What problems is the product solving and how is that benefiting you?
It helps me do a pretend audit for the purposes of planning a wedding and it helps me do a pretend audit for the purposes of knowing what I still need to look at
Infosys
secure but unpractical and unsupported
Reviewed on Jan 31, 2022
Review from a verified AWS customer
The pre-hardened image by CIS helps solving the Inspector vulnerabilities, however there is no effective support - you can only raise a generic question not linked to your AWS account, you'll get a generic answer. The CIS team doesn't feel committed to this product. Also, they do not provide any guidance on upgrading to newer versions - having asked them via support request, the answer was simply "it's up to you". I am unsatisfied but I have no other options - hardening a Windows system takes too much time which the my project plan can't afford.
CDT
Mentioned Level 1 in description?
Reviewed on Feb 03, 2021
Review from a verified AWS customer
It is of benchmark level 2 but mentioned the same description that of level 1 image. It would be great if the description provides a deference from level 1.