The CISA Known Exploited Vulnerabilities Catalog (KEV) policy checks container images for the specific vulnerabilities identified by CISA. The KEV list consists of vulnerabilities that are known to be exploited by attackers and pose a significant risk. This policy will detect and flag software identified as containing one of these vulnerabilities.
The CISA Known Exploited Vulnerabilities Catalog (KEV) consists of vulnerabilities that have been identified by CISA and are known to be exploited by attackers and pose a significant risk. This Anchore Enterprise policy will compare entries in the KEV list against the findings in SBOMs stored in Anchore Enterprise. Any vulnerabilities found that are also on the KEV list will be flagged.
SBOMs that have been identified as containing vulnerabilities also on the KEV list can be prevented from being deployed or warn security teams that the vulnerability has been detected.
Need Help?
If you have questions about our products, contact us at sales@anchore.com
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing uses a single contract dimension called Product Access (Units). You buy access to the product through this one option. Pricing scales with the number of units you commit to under your contract term. There are no separate tiers or usage add-ons to choose from here. The product delivers pre-built policy packs for United States federal standards, including FedRAMP, DoD, DISA STIG, NIST, and CIS Benchmarks. It automates compliance checks for containers and images. To get a quote for your unit quantity, you work with the vendor.
Top-of-mind questions for buyers
What does one unit of Product Access map to in practice?
The marketplace listing grants access through a single Product Access (Units) dimension. The listing does not define whether a unit maps to a set number of SBOMs per month, images, or hosts. Because unit scope is not spelled out here, confirm what one unit represents with the vendor before you commit.
What compliance policy packs do I get with this federal product access?
You receive pre-built policy packs for United States government standards. These include FedRAMP, DoD, DISA STIG, NIST 800-53, NIST 800-190, and CIS Benchmarks. The packs automate compliance checks against containers and images. Each rule maps to a specific control version to support reporting and evidence generation for auditors.
Can I deploy this in air-gapped or restricted federal environments?
Yes. The product is designed for United States federal environments. You can deploy on-premise with no internet connection to run in DoD IL-6 environments. It also meets FIPS requirements. This supports agencies that must operate isolated from public networks while still automating their compliance checks.
www.anchore.com+1
Helpful?
Vendor refund policy
Refunds are not offered for this product
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Anchore Enterprise is an SBOM-powered Software Composition Analysis (SCA) solution that provides scanning and continuous monitoring of cloud native applications enabling automated security and compliance across the entire software lifecycle (Code to Cloud).
Accenture deploys a security-hardened Amazon Bedrock and AgentCore foundation into your AWS account with IaC, guardrails, and federated identity aligned to NIST AI RMF and OWASP LLM Top 10.
Co-innovated with the AWS Generative AI Innovation Center (GenAIIC) Partner Agent Factory (PAF), Anchor Browser with agentic payments provides AI agents a production-grade cloud browser that can also autonomously pay for protected web resources. Spending is held, verified, and managed by Amazon Bedrock AgentCore payments capabilities.
Anchor Browser is agentic infrastructure for web automation, enabling AI agents to complete any web-based process by clicking, typing, navigating, and reasoning like a human in real time. It removes integration barriers across disconnected apps, making even complex manual workflows fully automatable.
Launch a ready to use Solana development server on Ubuntu 24.04 with Solana CLI, Rust, Anchor, Node.js, Yarn, Surfpool, and a starter workspace so you can build, test, and iterate faster without spending time on setup and dependency troubleshooting. This product has charges associated with it for the provision and deployment of the application and AMI support.
Solana Anchor Smart Contract Workbench with VS Code by Optick provides a ready to launch Ubuntu 24.04 development server for Solana smart contract work with Solana CLI, Anchor CLI, Rust, Node.js, Yarn, Surfpool, browser based VS Code, a managed local Solana validator, helper commands, first boot password generation, local development keypair generation, localnet SOL funding, and a compiled Anchor starter project. This product has charges associated with it for the provision and deployment of the application and AMI support.