All Services
Security & IAM
Amazon Macie
Amazon Macie inventories Amazon S3 security and access posture and uses managed and custom data identifiers to discover and report sensitive data in S3 objects.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with Amazon Macie.
S3 data discovery scope and inspection cost
Amazon Macie Pricing & Sensitive Data Discovery
Macie is scoped to Amazon S3, not to databases or arbitrary file shares. Cost has three parts: buckets evaluated, objects monitored for automated discovery, and the volume of data actually inspected, so job scope is the control.
Official AWS sources reviewed 2026-08-29.
What is Amazon Macie?
Macie discovers sensitive data in Amazon S3 using machine learning and pattern matching, and reports the security posture of the buckets it inventories, including encryption status and public access. Its scope is S3 objects rather than databases or file systems.
What is Amazon Macie?
What drives Amazon Macie pricing?
Three dimensions: the number of S3 buckets continually evaluated for inventory and monitoring, the number of objects monitored for automated data discovery, and the quantity of data inspected by automated and targeted discovery jobs. Scope jobs to the buckets and prefixes that matter.
Official Amazon Macie pricing
How do I control what Macie reports?
Managed data identifiers detect common sensitive types such as credentials and financial or personal identifiers. Add custom data identifiers built from your own regular expressions and keywords, and use allow lists to suppress known-safe text so findings stay worth triaging.
Using managed data identifiers
Related AWS services for this plan
- Amazon Simple Storage Service — Macie evaluates S3 buckets and objects, so bucket count and object volume set both scope and cost.
- AWS Key Management Service — Macie needs access to the KMS keys protecting objects it must decrypt before inspecting them.
- AWS Security Hub — Route Macie findings into Security Hub so sensitive-data results join the rest of the security queue.
- Amazon EventBridge — Use EventBridge rules on Macie findings to trigger notification or remediation workflows.
Amazon Macie pricing and cost programs
Pricing model: S3 inventory and data classification usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Buckets evaluated · Objects monitored · Data inspected
Programs and modes: Automated discovery · Sensitive data discovery jobs
Bucket monitoring and content inspection are metered separately.
Free Tier: Available — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS pricing
Official AWS sources reviewed 2026-07-21.
Why implement Amazon Macie?
- Adds managed sensitive-data discovery for S3 without building custom object-sampling and classification pipelines.
- Combines bucket security posture, automated discovery, targeted jobs, managed identifiers, custom identifiers, allow lists, and findings.
- Supports multi-account administration and integration with Security Hub and EventBridge for triage and response.
How to implement Amazon Macie
- Enable Macie in every required Region through a delegated administrator, inventory in-scope buckets, ownership, KMS accessibility, data residency, unsupported formats, and cost constraints.
- Start with automated sensitive-data discovery or a narrowly scoped classification job, choose managed and tested custom identifiers and allow lists, set sampling and schedule, and estimate cost.
- Validate samples and findings with data owners, combine sensitivity with bucket exposure and business context, restrict access or remediate data, and rerun discovery to confirm the change.
Amazon Macie best practices
- Treat automated discovery as sampled, Region-scoped evidence rather than a complete inventory; track skipped objects, unsupported formats, inaccessible keys, and unmonitored Regions.
- Do not equate a sensitivity score with business criticality or legal classification; validate findings and join them with ownership, purpose, residency, and exposure.
- Use tightly scoped custom identifiers, protect classification results, review cost and coverage, centralize high-value findings, and minimize retention or duplication of sensitive samples.
Amazon Macie use cases and server impact
- Discovering PII and credentials in S3
- Monitoring bucket exposure and sensitive-data posture
- Targeted compliance and data-migration scans
Replaces much S3 classification scanner infrastructure, while coverage interpretation, business classification, false-positive review, access remediation, and data governance remain customer responsibilities.
Official implementation resources
Commonly paired AWS services