Mgmt & Governance
AWS Config
AWS Config records supported resource configurations and relationships, retains configuration history, evaluates rules and conformance packs, aggregates results across accounts and Regions, and can trigger remediation workflows.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Config.
AWS Config pricing and cost programs
Pricing model: Configuration recording and evaluation usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Configuration items · Rule evaluations · Conformance pack evaluations · Advanced queries
Programs and modes: Configuration recorder · AWS Config rules · Conformance packs
Recorded items and rule or conformance-pack evaluations are metered separately.
Free Tier: Service-specific — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement AWS Config?
- Creates a time-ordered configuration inventory and relationship history for supported AWS resources without custom polling databases.
- Evaluates managed or custom rules and conformance packs continuously or periodically and supports organization-wide aggregators.
- Integrates findings, change notifications, advanced queries and remediation with Security Hub, Control Tower, EventBridge, Systems Manager and audit workflows.
How to implement AWS Config
- Define accounts, Regions, resource types, recording frequency, global-resource strategy, controls, exceptions, retention, delivery, aggregation, remediation ownership, evidence and cost requirements.
- Enable a service-linked recorder with the intended resource scope and a protected delivery channel, create an organization aggregator, deploy versioned rules or conformance packs, and constrain remediation roles and parameters.
- Verify the recorder is actively recording and delivering snapshots, test compliant and noncompliant resources, route findings to owners, require approval for risky remediation, and monitor recorder status, evaluation delays, failures and spend.
AWS Config best practices
- Do not equate configured resources with working coverage: continuously confirm both delivery channels and recorders exist, are enabled, and are actually recording the intended types in every Region.
- Use organization aggregators and version-controlled conformance packs for consistent visibility, but retain account and Region ownership because aggregation does not itself remediate or authorize access.
- Scope high-frequency recording and rules to useful evidence, document suppressions and exceptions, test remediation idempotency and permissions, and protect the S3, SNS and IAM delivery path.
AWS Config use cases and server impact
- Configuration history and change investigation
- Continuous compliance rules and conformance packs
- Cross-account and cross-Region resource inventory
Replaces configuration polling, history and rule-evaluation infrastructure, while control design, coverage verification, exception governance, remediation safety, evidence interpretation, and cost management remain yours.
Official implementation resources
Commonly paired AWS services
- AWS CloudTrail — API audit logging
- AWS Organizations — Multi-account mgmt
- AWS Security Hub — Security posture
- Amazon Simple Storage Service — Object storage
- Amazon Simple Notification Service — Pub/sub messaging
- Amazon CloudWatch — Metrics & logs
- AWS Control Tower — Multi-account landing zones
Planning guides that use AWS Config
- AWS Audit Manager planning guide — AWS Config supplies configuration evidence, and its recorder and rules are billed on their own dimensions.