RLC Pro Hardened 9.6 LTS from CIQ combines proactive security hardening with Long-Term Support, offering hardened packages, backported security patches, and extended maintenance through November 2029. This product has charges associated with it for security hardening, LTS security fixes, and included access to CIQ basic support.
This is a repackaged open source software product wherein additional charges apply for the development of the included security components, on-going LTS security updates by CIQ to back port security fixes which would otherwise not be available from the community, and for access to CIQ support for basic support engagements via email or ticket.
As the speed, sophistication, and volume of attacks on corporate systems accelerate, CISOs and IT security teams struggle to apply an effective and consistent Linux security policy across all their servers. With Rocky Linux from CIQ Pro - Hardened (RLC-H) with Long-Term Support, you get Enterprise Linux that is delivered securely, configured correctly, locked to a stable minor release, and proactively protecting your apps and services from malicious threats - with backported security patches through November 2029.
RLC-H LTS comes pre-configured against key threat vectors, and delivers hardened kernel and memory integrity checking in runtime. The operating system is pre-hardened and offers further options to apply OpenSCAP policies in compliant environments like DISA-STIG and CIS. FIPS 140-3 validated packages are available and can be enabled as a configuration step. Going beyond reactive security, RLC-H LTS takes a proactive approach to keeping your operating environment safe, and eliminates manual work spent tuning and applying security profiles so you can meet corporate and audit requirements easily and effectively.
Packages with security issues marked as Important or Critical may be eligible for backports. Generally, this applies to packages with a CVSS score of 7.0 or higher. Other security-related backports and bug fixes are at CIQ discretion. Review our CVE Dashboard under Learning Resources for a transparent view of available fixes.
This offer includes Basic Support from CIQ. See the Support Details for information on the available scope of support and how to access our support team, and review the CIQ Support Overview under Learning Resources for more information on the scope of this included support product. CIQ offers SLA-backed Standard and Premium support tiers which are available via Private Offer. View the CIQ Support Overview under Learning Resources to learn more and contact us to request a personalized quote.
Highlights
Hardened Packages with LTS: Hardened packages including glibc, OpenSSH, and hardened_malloc reduce the attack surface through removal of non-essential libraries and unsafe environment variables, with defense against heap exploitation - all maintained and patched through November 2029.
LKRG Attack Detection, FIPS, and Compliance: Linux Kernel Runtime Guard detects kernel vulnerability exploits and responds to unauthorized modifications of a running kernel. FIPS 140-3 validated packages are available, and OpenSCAP policies support DISA-STIG and CIS compliance.
Stronger Security and Extended Stability: passwdqc and yescrypt hashing increase resistance to GPU password cracking. CIQ cryptographically validates all packages, provides an SBOM with each image, and delivers patches for critical CVEs ahead of standard updates - locked to Rocky Linux 9.6 through November 2029.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for each running instance, with the rate set by the EC2 instance type you choose. Every dimension maps to a specific instance size across families like general purpose (m-series, t-series), compute-optimized (c-series), memory-optimized (r-series, x-series), storage (i-series, d-series), and accelerated computing (g-series, p-series, inf, trn). Larger instances within a family cost more per hour, reflecting added CPU, memory, or GPU capacity. You run only the sizes you need and add or remove instances as workloads change. All instances carry the same hardened Rocky Linux 9 software.
Top-of-mind questions for buyers
Am I charged for instances that are stopped or powered off?
Software charges apply per running instance hour. When you stop or power off an instance, the hourly software charge stops. Stopped instances may still incur AWS storage fees for attached volumes, but the hourly software rate meters running time only.
What do I actually get for the hourly rate on each instance type?
You get the hardened Rocky Linux 9.6 LTS operating system running on the EC2 instance size you select. This includes FIPS 140-3 validated cryptography, pre-applied STIG profiles, LKRG kernel runtime monitoring, hardened packages, and CIQ support. The instance type sets the underlying CPU, memory, or GPU capacity.
If I move a workload to a bigger instance size, how does my charge change?
The software charge is billed per instance-hour at the rate tied to the instance type you run. Switching to a larger size within a family raises the hourly rate to reflect added capacity. The change takes effect when the new instance runs; the old one stops accruing once terminated.
ciq.com
Helpful?
Vendor refund policy
No refunds are available, but you may cancel your subscription at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
This version of Rocky Linux 9 from CIQ Pro Hardened LTS 9.6 is up-to-date with the latest security patches and software updates as of 06/01/2026.
Additional details
Usage instructions
Connect to the instance over SSH using the instance public IP, with username "rocky" and the private key generated when you launched the instance.
Example command: $ ssh -i ./ssh-private-key.pem rocky@PublicIPAddress
When you are logged in as "rocky", you can use the sudo command to run administrative tasks. Note that the specific command you use to connect to the instance may vary depending on the operating system and ssh client you are using on your end. By default, the instance is secured by AWS network security configuration; you may optionally install your choice of a local firewall such as firewalld after launch.
Support
Vendor support
This Rocky Linux AMI provided by CIQ includes access to repositories for dnf/rpm updates and is regularly refreshed. This offer includes Basic Support from CIQ, which offers ticket and email-based support covering user accounts, product inquiries, bug reports, onboarding, and basic installation and configuration assistance. More comprehensive SLA-backed Enterprise Support plans at the Standard or Premium level are available from CIQ for additional charges. See the CIQ Support Overview under Learning Resources for full details, or contact us for further information. Contact support@ciq.com for further information. CIQ is committed to providing a working image which meets the highest quality standards. If you have a question or encounter a problem related to deploying the software in this listing into your cloud environment, a question regarding the EULA, or if you are in interested in adding an enterprise support agreement via private offer for help managing your Rocky Linux operating system, contact CIQ Cloud Marketplace Support at cloudmarketplace@ciq.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.