VMware Cloud Foundation 9: A modern private cloud operating model
Most enterprise IT teams already run VMware. The harder question today is whether the way they operate it can meet what the business now expects from a private cloud: automation, strong governance, security, resilience, and infrastructure delivered as a service instead of provisioned by hand.
Recent shifts in VMware licensing, support, and platform strategy have many organizations reassessing their roadmap, which we cover in our earlier article on the VMware shift.
VMware Cloud Foundation (VCF) 9 answers that operating model question. It brings the VMware infrastructure stack together into one private-cloud platform with unified lifecycle management. VCF 9 is the platform generation. VCF 9.1 introduced significant advancements to that foundation, and VCF 9.1.1, generally available as of September 2026, is the latest release in the 9.1 line. This article covers the VCF 9 platform and the capabilities organizations should consider as they evaluate the current 9.1 release line.
What is VMware Cloud Foundation 9? VMware Cloud Foundation 9 is VMware's strategic private-cloud platform. It brings compute, storage, networking, security, operations and automation together under one operating model with unified lifecycle management. VCF 9 is the platform generation; VCF 9.1 advanced that foundation across areas such as operational efficiency, cyber resilience, programmable infrastructure and production AI, while VCF 9.1.1 builds on those capabilities with additional security, operations, AI and application-delivery enhancements.
What is VMware Cloud Foundation 9?
VMware Cloud Foundation 9 packages the VMware infrastructure stack and the operations that run it into one standardized private cloud. The difference that matters is between owning the individual pieces of virtualization and operating them as one platform. Many teams have assembled compute, storage, and networking over the years, each with its own tools and upgrade cycles. VCF 9 runs those components as a coordinated system, with shared operations and a single lifecycle.
At a decision-useful level, VCF 9 brings the core infrastructure services enterprises already run together into one platform, and each maps to an operating outcome:
- Compute, through vSphere, runs the virtual machines your workloads already depend on.
- Software-defined storage, through vSAN, pools capacity and applies policy to it, so storage decisions follow the workload rather than the hardware.
- Networking and security, through NSX, move segmentation and policy into software, which keeps governance consistent across the environment.
- Kubernetes, through vSphere Kubernetes Service, runs containerized and cloud-native applications alongside virtual machines on the same platform.
- Operations and automation, through VCF Operations and VCF Automation, give you one interface for monitoring, managing, and delivering infrastructure as self-service.
- Lifecycle management, handled through VCF Operations fleet management, coordinates patching, upgrades, identity, and licensing across the platform instead of component by component.
Run together, they become a private cloud you operate as one, rather than a stack of tools to keep in sync by hand.
How VCF 9 changes the private-cloud operating model
What changes day to day matters most to the people accountable for cost, risk, and delivery.
Standardized lifecycle management. Updates and version consistency are coordinated across the platform, reducing the drift and one-off maintenance of independently managed environments.
Policy and governance. Security and configuration policy apply consistently across domains, giving governance a single place to live.
Infrastructure automation. Common requests become standardized, repeatable delivery, freeing teams from manual provisioning for higher-value work.
Operational visibility. A shared operations view replaces the patchwork of separate consoles that grows over time.
Consistent service delivery. Infrastructure is delivered as a predictable service, the behavior the business associates with cloud.
In a traditional vSphere-centered environment, tools, domains, and processes are often managed independently. That works, and vSphere remains a strong compute layer. VCF 9 operates at a wider scope, organizing the full stack, including vSphere, into one managed platform. For executives, the outcomes that matter are less operational fragmentation, clearer governance, repeatable delivery, and a foundation for application modernization. Savings and performance depend on the environment, so those deserve evaluation.
VCF 9 compared with vSphere alone
| Consideration | vSphere on its own | VMware Cloud Foundation 9 |
| Scope | Compute virtualization | Full stack: compute, storage, network, security, operations, automation |
| Lifecycle | Managed per component | Coordinated across the platform |
| Governance | Applied tool by tool | Consistent policy across domains |
| Delivery | Largely manual provisioning | Standardized, automated service delivery |
| Operating model | Independent tools and processes | One platform and operating model |
How VCF 9 architecture works
You don't need a reference design to make a platform decision, but a few architectural ideas each carry an operating consequence.
Fleets and VCF instances
VCF 9 organizes a private cloud into a clear hierarchy. A VCF instance is a discrete deployment. A fleet is a collection of one or more instances, managed by a single set of fleet-level components: one VCF Operations instance and one VCF Automation instance that operate across every domain and instance in the fleet. At the top, a VCF private cloud can contain one or more fleets.
The fleet is where shared services and governance live. VCF Operations coordinates governance and lifecycle across all instances in the fleet, and a fleet can span one region or two. For leaders running several sites or business units, this is where consistency becomes real: one set of operational standards keeps environments from diverging as they grow.
Management and workload domains
Each VCF instance has a single management domain and can have one or more workload domains. The management domain is created first, hosts the core management components including the SDDC Manager appliance, and runs the platform rather than your applications. Workload domains are where applications run. Each has its own vCenter Server and its own or a shared NSX instance, and adding them is how you scale an instance.
That structure gives you deliberate control over isolation, availability, and ownership. Because workload domains separate different workload types, you can contain the effect of a failure or a change to one domain rather than the whole environment. There's no single correct topology; domain design should follow your availability, compliance, and operational needs.
How the platform layers fit together
Seen as layers, the platform shows its relationships: policy set once applies across the whole stack, and lifecycle work happens in coordination rather than component by component.
What VCF 9.1 and 9.1.1 add
VCF 9.1 advanced the VCF 9 platform across several areas relevant to enterprise planning, including operational efficiency, cyber resilience and security, programmable infrastructure, and support for production AI. VCF 9.1.1, generally available September 3, 2026, builds on that foundation with additional capabilities across security, AI, Kubernetes operations, automation, and deployment flexibility.
These advancements change how organizations plan and operate their environments. Operational efficiency improvements focus on workload density and the effort of running a large estate, which feeds capacity planning and staffing decisions. Cyber resilience and security move recovery, compliance, and patching toward continuous properties of the platform rather than periodic events, which changes risk posture and audit readiness. Programmable infrastructure lets teams define and redeploy application environments as code, affecting how quickly and consistently they deliver. And support for production AI changes what the platform can host as those initiatives move from pilot to production.
VCF 9.1.1 is the latest generally available release in the 9.1 line as of September 2026. Because Broadcom continues to update the platform, organizations should confirm patch-level capabilities and compatibility against current release notes when planning a deployment or upgrade.
For organizations evaluating the platform today, 9.1.1 adds another layer of operational improvements, including enhanced identity and certificate management, expanded Kubernetes observability, AI-assisted operations, new application-delivery capabilities and a more compact deployment option. These updates reinforce the broader direction established with VCF 9.1 rather than changing the fundamental VCF 9 operating model.
VCF 9 foundation and VCF 9.1 advancements
| VCF 9 foundation | VCF 9.1 advancement |
| Unified private-cloud platform and operating model | Next milestone on the same platform generation |
| Coordinated operations | Greater operational efficiency at scale |
| Platform security and resilience | Recovery, compliance, and patching as continuous platform properties |
| Automation of infrastructure delivery | Programmable infrastructure, defined and redeployed as code |
| Compute and container support | roader VM, container, and Kubernetes delivery, built on vSphere 9.1 |
| Foundation for modern applications | Support for production AI workloads |
VCF 9.1.1 builds on these advancements with additional enhancements across security, operations, AI, Kubernetes and automation.
Where VCF 9 fits, and where it may not
VCF 9 suits some environments better than others. Weigh it workload by workload against a set of signals, not one pass-or-fail test.
Strong-fit signals
VCF 9 tends to fit when several of these are true:
- You have a significant VMware estate and want to keep the skills and processes around it.
- You need control and governance over your VMware private cloud.
- You want to standardize operations across multiple sites or environments.
- You run regulated or latency-sensitive workloads that benefit from private-cloud control.
- Your teams want a structured path to modernization instead of a rebuild.
Treat these as evaluation signals, not automatic qualification: one strong signal is a reason to look closer, not a decision.
Questions that may point to another path
Some conditions suggest a different approach deserves consideration:
- Your scale is limited enough that a full platform may be more than you need.
- Your application strategy is moving cloud-native in a way that reduces dependence on VMware.
- Your team lacks the skills to run the platform and won't bring them in or partner for them.
- Your hardware or dependencies are incompatible with the platform's requirements.
- The economics of the full platform don't work for your workloads.
Even here, the unit of analysis is the workload; one criterion rarely makes an estate suitable or unsuitable.
Choose an adoption path
Four paths cover most situations, and they aren't mutually exclusive: many organizations combine them.
Deploy a new VCF environment
A clean, standardized deployment suits you when you want a known-good starting point without carrying forward old configuration. It requires migration and cutover planning, so the work shifts from rebuild to migration sequencing.
Convert or import existing infrastructure
Broadcom supports several pathways that preserve existing investments instead of rebuilding. You can converge an existing vCenter deployment into a VCF management domain, import an existing vSphere environment, or upgrade an earlier VCF 5.x instance to VCF 9. Compatibility, configuration, and sequencing all have to be validated first, and not every environment can be converged, imported, or upgraded. Our cloud migration services and planning team can assess which pathway applies before you commit.
Use hosted or managed VCF
Some organizations want to keep the control and familiarity of VMware while handing off infrastructure ownership, lifecycle work, or day-two operations. That's what a managed VMware cloud model does. With Flexential Hosted Private Cloud, you keep operating control and compliance support while shifting infrastructure, connectivity, and resilience responsibilities to a provider.
In-house or managed cloud: Which operating model fits?
Choosing VCF 9 is only part of the decision. Use the Private cloud operating model decision guide to assess your team's capabilities, control requirements, and priorities and determine whether an in-house or managed approach better fits your organization.
Use a hybrid operating model
Many estates land on a mix. A hybrid model places workloads across on-premises, hosted private cloud, colocation, and connected public-cloud services according to what each workload needs, with placement, data gravity, network design, resilience, compliance, skills, and cost as the inputs. Flexential cloud solutions support private, hosted, and public placement, and Flexential Cloud Fabric provides the connectivity between those environments.
Comparing the four adoption paths
| Path | Best-fit conditions | Primary planning questions | Operating responsibility |
| Deploy new | Want a standardized clean start | How do we migrate and cut over? | You, or a partner you choose |
| Convert or import | Want to preserve existing investment | Is our environment compatible, and in what sequence? | You, or a partner you choose |
| Hosted or managed | Want VMware control with less operational load | Which responsibilities do we hand off? | Shared with the provider |
| Hybrid | Workloads have mixed requirements | Where does each workload belong? | Distributed across environments |
Why execution and operating-model choice matter
Choosing VCF 9 is a platform decision. Adopting it well is an execution decision, and that's where the operating-model choice pays off.
Flexential supports the full adoption sequence: assessing the estate, designing the target architecture, planning and executing migration, hosting or connecting the environment, protecting critical workloads, and managing operations over time. Because we support more than one target model, the goal is the destination that fits you: on-premises, hosted, or hybrid.
A few proof points back that up. Flexential is a VMware Pinnacle tier partner and delivers VMware Hosted Private Cloud. Migration expertise moves the workloads, connectivity links the environments, and Disaster Recovery as a Service protects the critical ones as you migrate and operate.
The advantage is continuity: one partner across the whole sequence, which removes the handoffs where adoption plans usually stall.
Turn the platform decision into a roadmap
VCF 9 can modernize your private-cloud operating model, with VCF 9.1 and the current 9.1.1 release advancing that foundation across operations, security, automation and AI. Whether and how to adopt VCF comes down to a few concrete questions: architecture, workload fit, operating responsibility, sequencing and economics. Working through them in order is what turns interest into a plan you can fund and schedule.
The practical next step is the Fast-Track VCF 9 Assessment. At no cost or obligation, a Flexential Solutions Architect reviews your environment and gives you a baseline report with utilization and sizing recommendations, workload analytics to guide migration decisions, and best-practice guidance on whether to keep workloads on-premises or move them to private, public, or hybrid cloud.
If you already know your target model and want to move to design, an architect consultation is the faster route.
Frequently asked questions
What is the difference between VCF 9 and vSphere?
vSphere is the compute virtualization layer that runs your virtual machines. VMware Cloud Foundation 9 is the private-cloud platform and operating model built around it, adding software-defined storage, networking and security, Kubernetes, operations, automation, and unified lifecycle management. In short, vSphere virtualizes servers, while VCF 9 runs, governs, and delivers the whole environment as one private cloud with a single operating model.
What is the difference between VCF 9, VCF 9.1 and VCF 9.1.1?
VCF 9 is the platform generation: the broader private-cloud platform and operating model. VCF 9.1 advanced that foundation with capabilities focused on areas such as operational efficiency, cyber resilience, programmable infrastructure and production AI. VCF 9.1.1 builds on the 9.1 release with additional security, operations, AI, Kubernetes and automation enhancements. For organizations evaluating VCF today, the platform decision is VCF 9, while the specific release and patch level should be determined based on current capabilities, compatibility and deployment requirements.
Can an existing VMware environment be imported or converted to VCF 9?
Often, yes. Broadcom supports converging an existing vCenter deployment into a VCF management domain, importing an existing vSphere environment, and upgrading an earlier VCF 5.x instance to VCF 9. Which one fits depends on your environment, and compatibility, configuration, prerequisites, and sequencing all need validation first. An assessment confirms the right approach before you commit.
Can VCF 9 run on premises or as a hosted private cloud?
Yes. Models range from on-premises to hosted private cloud to hybrid combinations. The right choice depends on control requirements, compliance, connectivity, and how much operational responsibility you want to keep or hand off. The adoption-path section above covers the options.
What does a managed VCF operating model change?
A managed model changes who does what. You keep governance and control of your VMware environment while a provider takes on infrastructure ownership, lifecycle operations, monitoring, support, connectivity, and resilience. You define the division of responsibility, so it can be as hands-on or hands-off as your team needs.