The bill that shows up later
AWS Config does not look expensive when you click Enable. It charges for every configuration item it records (a resource changing) and every rule evaluation. In an account that deploys often, those two meters run all day, in every region you left recording on.
Security Hub makes this worse in a way that is easy to miss: turning
on a Hub standard deploys Config rules for you. You are now paying
Config and Hub. AWS’s own docs now tell you to
stop recording AWS::Config::ResourceCompliance
if you only turned Config on for Hub — Hub does not need that CI —
and to
disable global-resource controls in every region but one.
What actually drives the cost
- Resource types. Default recorders cover a huge catalog. An S3-only account does not need EC2/RDS/Lambda CIs.
- Regions. Recording in 17 regions multiplies the same global IAM resources over and over unless you pin them to one region.
- Churn. CI/CD that updates 50 resources per deploy, 10 times a day, is 500 CIs/day before any rules run.
- Standards. Extra Hub standards (PCI in a sandbox, NIST everywhere) each add rule evaluations you will never act on.
On a busy multi-account org this becomes thousands of dollars a month. On a two-account SaaS it is more often “why is Config $80?” Either way it is usually a surprise, because the enablement wizard does not show the meter.
Cut it without buying anything
- Record global IAM resources in one region only (usually your home region).
- Switch most types to daily / periodic recording unless you truly need continuous.
- If Config exists only to feed Security Hub, exclude
AWS::Config::ResourceCompliance. - Disable Hub controls you will never remediate — especially CloudWatch-alarm controls if you already use GuardDuty.
- Turn Config off in regions that have no workloads.
That is the whole playbook for most small accounts. Do it before you shop for a CSPM. AWS also has a Security Hub cost estimator in the console now; use it.
When you do not need Config at all
Config is a change recorder plus a rule engine. If what you want is “tell me if an S3 bucket is public, a security group is 0.0.0.0/0, or an access key is 200 days old,” you do not need a recorder. A periodic read-only API scan is enough: Prowler, ScoutSuite, or a hosted scanner.
Keep Config if you need resource history for forensics, or you already run Security Hub org-wide and the aggregation is doing real work. Skip it if you have one or two accounts and the only reason Config is on is that a blog said to enable Security Hub.
Where PostureRadar fits
PostureRadar does not use your Config recorder. You deploy a read-only IAM role (List/Get/Describe only). We scan every enabled region and email the findings, weekly, for $39 per AWS account per month. There is no dashboard and no findings archive — the email is the product.
That is the wrong tool if you need attack-path graphs, runtime sensors, or a Hub that aggregates GuardDuty and Inspector. It is the right tool if Config/Hub is a line item you enabled out of guilt and never look at.
Related: Public S3 buckets · Stale IAM access keys · Security Hub finding noise
