All Services
Security & IAM
AWS Audit Manager
AWS Audit Manager organizes automated and manual evidence against control frameworks for existing customers; it entered maintenance mode on April 30, 2026 and can no longer be set up in new accounts.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Audit Manager.
Compliance evidence scope and assessment cost
AWS Audit Manager Pricing & Evidence Collection
Audit Manager collects evidence and maps it to control frameworks; it does not detect misconfigurations itself. Cost tracks the number of resource assessments an active assessment performs, which makes framework and scope selection the real cost lever.
Official AWS sources reviewed 2026-08-29.
What is AWS Audit Manager?
Audit Manager continuously collects evidence and maps it to controls in prebuilt or custom frameworks, then produces assessment reports for standards such as HIPAA, PCI DSS, and SOC 2. It organizes audit evidence; it does not perform the audit or certify compliance.
What is AWS Audit Manager?
What drives AWS Audit Manager pricing?
When an assessment based on a framework runs, Audit Manager performs a resource assessment for each in-scope resource such as an EC2 instance, RDS instance, S3 bucket, or VPC subnet, and billing follows the number of resource assessments. Narrow account, Region, and framework scope to control it.
Official AWS Audit Manager pricing
How is it different from Config and Security Hub?
AWS Config records resource configuration and evaluates rules, and Security Hub aggregates and prioritizes findings. Audit Manager consumes evidence from those services and from CloudTrail, then arranges it against control frameworks. The underlying services stay enabled and billed separately.
AWS Audit Manager concepts and terminology
Related AWS services for this plan
- AWS Config — AWS Config supplies configuration evidence, and its recorder and rules are billed on their own dimensions.
- AWS Security Hub — Security Hub findings become evidence, so control coverage depends on which standards are enabled there.
- AWS CloudTrail — CloudTrail provides the user-activity evidence auditors ask for alongside configuration snapshots.
- AWS Organizations — Delegate an Audit Manager administrator in AWS Organizations to assess member accounts centrally.
AWS Audit Manager pricing and cost programs
Pricing model: Evidence collection usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Resource assessments · Evidence collected · Assessment activity
Programs and modes: Standard and custom frameworks · Automated evidence collection
Assessment resource scope and evidence collection drive charges.
Free Tier: Service-specific — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS pricing
Official AWS sources reviewed 2026-07-21.
Why implement AWS Audit Manager?
- For accounts that had already enabled it, collects and organizes evidence from sources such as AWS Config, CloudTrail, Security Hub, and API calls against assessment controls.
- Provides standard and custom frameworks, delegated control reviews, manual evidence, evidence search, and assessment reports for audit preparation.
- Reduces evidence-gathering effort while keeping review, interpretation, and auditor collaboration explicit.
How to implement AWS Audit Manager
- First verify the service was enabled in the relevant account, organization, and Region before April 30, 2026; new accounts cannot set it up, so new designs should use AWS Config-centered compliance data and reporting alternatives.
- For eligible existing use, define scope, owners, framework and control mappings, evidence sources, review cadence, S3 report destination, encryption, access, retention, and manual-evidence procedures.
- Create the assessment, review evidence quality and exceptions with control owners, add approved manual evidence, generate reports, store durable audit records outside transient workflows, and deactivate finished assessments.
AWS Audit Manager best practices
- Do not start a new architecture around Audit Manager: AWS says it is in maintenance mode and unavailable for setup in new accounts after April 30, 2026.
- Treat collected evidence as inputs, not a compliance verdict; AWS explicitly states Audit Manager does not assess compliance and is not a substitute for legal counsel or compliance experts.
- Minimize assessment scope and evidence access, verify source mappings and timestamps, document manual review and exceptions, encrypt reports, and plan an orderly migration to supported compliance workflows.
AWS Audit Manager use cases and server impact
- Existing-account audit evidence collection
- Control-owner review and delegation
- Assessment report preparation during migration
For existing customers it replaces parts of a custom audit-evidence collector, but control design, compliance judgment, missing evidence, remediation, record retention, and migration planning remain yours.
Official implementation resources
Commonly paired AWS services