awssecurity-hubsecuritycost-optimization

AWS Security Hub cost: per security check and per finding

Security Hub bills per security check evaluated against your resources and per finding ingested from integrated services, both tiered. Large accounts with many resources and chatty integrations drive the bill. Here is the model.

The C3X Team··4 min read

Quick answer

Security Hub bills per security check evaluated against your resources (from enabled standards like CIS and AWS Foundational) and per finding ingested from integrated services, both tiered so unit rates fall at volume. Large accounts with many resources run many checks, and chatty integrations ingest many findings, so enabling only the standards and integrations you act on is the main lever.

AWS Security Hub aggregates security findings and runs automated compliance checks across your accounts. Its two cost components, checks and finding ingestion, both scale with the size and activity of your environment, so the cost grows with resource count and integration volume rather than being a flat fee.

Checks and findings

ComponentBills for
Security checksPer check evaluated against resources, tiered
Finding ingestionPer finding ingested from integrations, tiered

Enabled security standards (CIS, AWS Foundational Security Best Practices, and others) run automated checks against your resources, billed per check, so an account with many resources runs and pays for many checks. Findings ingested from integrated services (GuardDuty, Inspector, third parties) bill per finding. Both rates fall in tiers at volume.

What drives the bill

Resource count drives check volume: more resources means more checks per standard per evaluation. Integration activity drives finding volume: a chatty integration producing many findings ingests many. Enabling every standard and every integration across a large multi-account environment multiplies both, which is where the cost grows.

Controlling Security Hub cost

Enable only the security standards you actually act on, integrate only the finding sources you use, disable checks that are not relevant to your environment, and manage findings so noisy integrations do not ingest volume you ignore. The value of Security Hub is acting on its output, so aligning what you enable with what you remediate keeps cost proportional to value, the same enable-what-you-use discipline as GuardDuty.

FAQ

How is AWS Security Hub priced?

By security checks (per check evaluated against your resources from enabled standards like CIS and AWS Foundational Security Best Practices) and finding ingestion (per finding ingested from integrated services), both tiered so unit rates fall at volume. Cost grows with resource count and integration activity.

What drives Security Hub cost?

Resource count drives check volume, since more resources mean more checks per standard per evaluation, and integration activity drives finding volume, since chatty integrations ingest many findings. Enabling every standard and integration across a large multi-account environment multiplies both, which is where cost grows.

How do I reduce Security Hub cost?

Enable only the security standards you actually act on, integrate only the finding sources you use, disable checks not relevant to your environment, and manage noisy integrations so you do not ingest findings you ignore. Aligning what you enable with what you remediate keeps cost proportional to value.

Do more resources increase Security Hub cost?

Yes. Security checks are billed per check evaluated against resources, so an account with more resources runs more checks per enabled standard and pays proportionally more. This makes resource count a primary cost driver, especially across large multi-account environments with multiple standards enabled.

Does finding ingestion cost extra in Security Hub?

Yes. Findings ingested from integrated services like GuardDuty, Inspector, and third-party tools bill per finding, tiered at volume. A chatty integration producing many findings ingests, and bills for, many, so integrating only the sources you act on avoids paying to ingest findings you ignore.

Does C3X estimate Security Hub cost?

Security Hub cost is driven by check and finding volume, which scale with resource count and integrations, usage inputs. C3X prices the surrounding infrastructure, and you model resource count and integration activity to estimate the security-posture charges.

What to do next

Estimate the infrastructure around your security posture before you deploy. C3X reads your Terraform and prices your resources against a live catalog. Start with the quickstart.

Try C3X on your own Terraform

Free and open source. No API key required. One command to install, one command to estimate.