This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
The CIS Hardened Image Level 2 on Microsoft Windows Server 2016 is a pre-configured image built by the Center for Internet Security (CIS®) for use on Amazon Elastic Compute Cloud (Amazon EC2). It is a pre-configured, security-hardened image that aligns with the robust security recommendations, the CIS Benchmarks, making it easier for organizations to meet regulatory requirements.
Not only is this image pre-hardened to the CIS Benchmarks guidance, but it is also patched monthly in alignment with the updates from the software vendor.
Key Benefits
Enhanced Security: Mitigates risks like malware, denial of service, and authorization issues by following globally-recognized secure configuration guidance to support your cloud security posture management (CSPM) program.
Compliance Readiness: Helps your organization comply with PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
Faster Deployment: Pre-configured according to CIS Benchmarks, allowing you to deploy secure virtual machine images.
Consistency Across Environments: Ensures consistent security configurations across development, testing, and production environments, reducing drift and compatibility risks.
Cost Efficiency: Lowers remediation efforts, reduces attack surface, and minimizes business loss from security incidents.
Easier Maintenance: Regular updates ensure that your systems are always in line with the latest security standards and software patches.
This image is hardened against the corresponding Level 2 profile which is intended for environments or use cases where security is paramount, acts as a defense in depth measure, and may negatively inhibit the utility or performance of the technology. No components are installed on or removed from this image outside of those already present on the base image or as recommended in alignment with the corresponding CIS Benchmark recommendations.
To demonstrate conformance to the CIS Microsoft Windows Server 2016 Level 2 Benchmark, industry-recognized hardening guidance, each image includes an HTML report from CIS Configuration Assessment Tool (CIS-CAT® Pro). Each CIS Hardened Image contains the following files:
Base_CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance before any change is made by CIS (e.g., software updates, CIS hardening).
CIS-CAT_Report.html - this provides a report of CIS-CAT Pro run against the instance after the corresponding CIS Benchmark was applied to the image.
Exceptions.txt - this provides a list of recommendations that are not applied because the configuration of those recommendations may inhibit the use of this image in this CSP, require environment-specific expertise, or hinder the integration of this image with CSP services or extensions.
These reports are located in C:\CIS Hardening Reports.
If this instance is used in a domain environment where policies are managed globally, the majority of the security settings will be changed and managed by domain policies.
Hardened according to a Level 2 CIS Benchmark that is developed in a consensus-based process and that is accepted by government, business, industry, and academia.
Helps with compliance to PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
Pre-configured to align with industry best practices that are developed and supported by CIS, this image has hardened account and local policies, firewall configuration, and computer-based and user-based administrative templates.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for this pre-hardened Windows Server 2016 image, with no upfront commitment. Billing follows usage, so charges stop when you stop the instance. Pricing is organized by AWS EC2 instance type, and each type carries its own hourly software rate. The list spans small general-purpose sizes through large compute-, memory-, storage-, and accelerated-computing instances, plus bare-metal options. Larger instances with more CPU, memory, or specialized hardware generally carry higher hourly rates. You choose the instance type that fits your workload, and the software charge scales with that selection. You also pay separate AWS infrastructure charges.
Top-of-mind questions for buyers
What does one hourly unit cover, and what do I get for that rate?
Each unit is one running EC2 instance of the chosen type, billed per hour. You receive the pre-hardened Windows Server 2016 image configured to the CIS Benchmark. The instance size determines the CPU, memory, and hardware you get, and each type carries its own software rate.
Am I charged when I stop or pause the instance?
The hourly software charge meters running time only. When you stop the instance, the software charge stops. Stopped instances may still incur AWS storage fees for attached volumes, but those are separate AWS infrastructure charges, not the image software rate.
Does my hourly rate change automatically if I switch to a larger instance type?
There is no automatic upgrade. You pick the instance type when you launch. If you launch a larger type, that type's own hourly software rate applies from launch. Switching means stopping one instance and starting another, so the new rate begins with the new instance.
www.cisecurity.org
Helpful?
Vendor refund policy
Refunds through AWS are not available at this time. You will only be billed for actual time of instance use. As with all CIS security products, our aim is always 100 percent customer/member satisfaction.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Monthly updates
Additional details
Usage instructions
Once the instance is running, choose Get Windows Password in the EC2 console then connect using a Remote Desktop Connection (RDP) client. The RDP client MUST be able to authenticate using NTLMv2. See https://technet.microsoft.com/en-us/library/cc738867%28v=ws.10%29.aspx for more information. Immediately apply latest security updates after launching the instance.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Image hardened according to CIS Benchmark Level 2 profile developed through consensus-based process and accepted by government, business, industry, and academia.
Regulatory Compliance Support
Supports compliance with PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, and select NIST publications.
Pre-configured Security Controls
Includes hardened account and local policies, firewall configuration, and computer-based and user-based administrative templates aligned with industry best practices.
Conformance Assessment and Reporting
Includes CIS-CAT Pro HTML reports documenting baseline configuration, post-hardening configuration, and exceptions to benchmark recommendations.
Regular Security Updates
Patched monthly in alignment with software vendor updates to maintain alignment with latest security standards.
FIPS 140-2 Certification
FIPS 140-2 certified kernel and cryptographic modules included out of the box with ongoing security updates
Extended Security Coverage
Security patches available for over 23,000 packages in the Ubuntu Universe repository with 10 years of support through Expanded Security Maintenance
Compliance Hardening Profiles
CIS and DISA-STIG hardening profiles accessible through Ubuntu Security Guide tooling for guided compliance configuration
Cryptographic Module Updates
Security updates provided for all packages including FIPS-certified cryptographic modules
Long-term Support
10 years of security coverage and maintenance for the operating system and included packages
Operating System Hardening
Amazon Linux 2 configured with STIG Benchmark High security standards developed by Defense Information System Agency (DISA) for system hardening and security posture improvement
EMR Compatibility
Tested and compatible with Amazon Elastic MapReduce (EMR) for distributed processing workloads
Security Configuration Standards
Implementation of Security Technical Implementation Guides (STIGs) configuration standards for system hardening
Continuous Security Updates
Availability of continuous security updates through new versions of the hardened image
Multi-Application Support
Capability to function with various applications beyond EMR deployments
Organization is wanting to use Inspector to validate that launched EC2s are adequately hardened. Further, they wanted to evaluate against Inspector's CIS benchmarks. Figured, "if I start from an official AMI, it ought to be a homerun to get a clean output from Inspector". Launch an EC2 from the AMI. Discover that the AMI is missing the AWS agent. Correct this gap. Run Inspector. Wait for report. Report comes back with nearly 40 "High" findings (nearly 30 if you ignore the DC-only and NG-only findings).
Notice, "oh, this AMI is built using the 1.3.0.2 benchmarks and Inspector is using the 1.1.0 benchmarks. Go back to AWSMP and click on the "view older versions" link under the AMI. Am simply taken back to the AMI's normal information page with no indication of availability of back-rev AMIs that I might need.
Report back issues to my organization. They note, "but those findings are all HIGH findings".