Skip to main content

AWS Security Hub

AWS Security Hub Pricing

Unified security operations with pay-as-you-go pricing. No upfront commitments. One consolidated AWS bill.

Security Hub Plans

Security Hub offers a unified pricing model with an Essentials plan foundation, optional add-ons, and an Extended plan for curated partner solutions.

FOUNDATION

Essentials plan

Resource unit / mo
Pay-as-you-go


Unified security posture, vulnerability management, threat detection, risk analytics. Includes multicloud (Azure) coverage.

ADD-ONS

Threat Analytics + Lambda Code Scanning

Tiered by volume

Advanced ML-powered threat detection and code vulnerability scanning. In addition to Essentials.

 

FULL-STACK SECURITY

Extended Plan

Pay-as-you-go per partner

23 curated partner solutions across 10 security categories. PPA/EDP eligible. No long-term commitments.

 

Essentials Plan

Security Hub Essentials provides unified security posture management, vulnerability management, threat detection, identity analysis, risk analytics, and multicloud coverage across AWS and Azure environments. The following capabilities are included in the per-resource unit price:

  • Risk analytics, finding prioritization, and security resource graph
  • Exposure findings, AI inventory, network scanning, unused access findings
  • Findings ingestion and aggregation
  • Security Hub Automation Rules
  • Cloud Security Posture Management (Security Hub CSPM)
  • EC2 vulnerability scanning (Inspector)
  • ECR container image scanning (Inspector)
  • Lambda Standard Scanning (Inspector)
  • CIS Benchmark Assessments (Inspector)
  • Service Linked Config Recorder (AWS Config)

Pricing is pro-rated based on the time resources are monitored per month. For detailed information on how pricing is calculated, see our FAQ.

Pricing is anchored on Amazon EC2 instances and Azure Virtual Machines as 1 resource unit, with AWS Lambda functions and Azure Function Apps at 1/12 of a resource unit (12 functions = 1 resource unit), Amazon ECR container images and Azure container images at 1/18 of a resource (18 images = 1 resource unit), and AWS IAM users/roles and Azure identities at 1/125 of a resource (125 IAM resources = 1 resource unit). 

Even though all supported resources are monitored for security risk, per-resource pricing only applies to four primary resource types: EC2 instances, ECR container images, Lambda functions, and IAM users and roles. All other monitored resources are included. For Microsoft Azure, the same pricing applies to Azure equivalent resources, once you create an integration with Microsoft Azure.

Threat Analytics Add-on

Advanced ML-powered threat detection across CloudTrail management events, S3 data events (GuardDuty S3 Protection), VPC Flow Logs, DNS query logs, and EKS audit logs.

Lambda Code Scanning Add-on

Automated code vulnerability detection for AWS Lambda functions. Scans code on deployment and re-scans periodically.

 

Note: When you enable Security Hub, billing for included capabilities is consolidated through Security Hub streamlined pricing. All other AWS security service capabilities (including remaining Amazon GuardDuty and Amazon Inspector capabilities) not included in Security Hub plans retain their original service billing.

Security Hub Extended Plan

Curated enterprise security partner solutions across 10 security categories. Discover, evaluate, and deploy from the Security Hub console with pay-as-you-go pricing, no upfront commitments, and a single consolidated AWS bill. Purchases are eligible toward AWS Private Pricing Agreement (PPA) or Enterprise Discount Program (EDP) commitment.

23 Curated Partners

10 Security Categories

$0 Upfront Cost

 PPA / EDP Eligible

Prerequisite: The Security Hub Essentials plan must be enabled before activating Extended Plan solutions. Extended Plan charges are in addition to Essentials plan charges.

  • Endpoint
  • Endpoint

    CrowdStrike — Falcon for Cloud Security and Insight XDR — Unifies cloud workload protection and extended detection and response through a single lightweight sensor that deploys in minutes. AI-powered prevention stops threats before damage occurs across workstations, servers, VMs, containers, and serverless workloads on AWS, Azure, OCI, and GCP. Volume-based tiering rewards customers as deployments scale.

    Pricing by Workload Type and Tier — per endpoint per month

     

    Workload Type Tier 1 Tier 2 Tier 3 Tier 4 Tier 5 Tier 6
    Workstations $13.60 $9.90 $7.75 $5.20 $4.35 $4.20
    Servers $15.75 $12.00 $9.90 $7.20 $6.50 $6.30
    Cloud Hosts $21.25 $16.00 $13.00 $9.25 $8.10 $7.95
    Containers $49.65 $36.00 $27.85 $18.65 $15.50 $15.00
    Amazon Fargate $9.50 $7.75 $6.65 $5.35 $4.85 $4.85

    For volume tier definitions and endpoint-hour thresholds, see the Volume Tier Reference table below.

    Volume Tier Reference

     

    Tier Endpoint-Hours / Month Approximate Endpoints
    Tier 1 1 – 199,999 ~up to 278
    Tier 2 200,000 – 799,999 ~278 – 1,111
    Tier 3 800,000 – 1,999,999 ~1,111 – 2,778
    Tier 4 2,000,000 – 7,999,999 ~2,778 – 11,111
    Tier 5 8,000,000 – 41,999,999 ~11,111 – 58,333
    Tier 6 42,000,000+ ~58,333+

    All prices are per endpoint per month. Billing is pro-rated hourly based on active endpoints, so you pay only for what you use. Volume tiers are determined by aggregate endpoint-hours across all workload types within a billing period. Tiers are not blended. Your total endpoint-hours determine a single tier, and all usage is priced at that tier's rate. For example, 250,000 total endpoint-hours places all usage at the Tier 2 rate.

    SentinelOne - Singularity Endpoint and Cloud Workload Protection

    Workload Type
    Price per host/month
    Pods/Tasks

    $9.90

    Workstations

    $13.00

    Servers

    $16.50

    Containers

    $52.75

    SentinelOne Singularity Complete remediates threats faster, restoring systems in seconds with one- click rollback. This AI-native platform unifies endpoint and cloud to stop attacks at machine speed. Purple AI Foundations accelerates threat hunting, slashing MTTR from hours to seconds.

  • Identity
  • Identity

    Centralize IAM across your enterprise with authentication, privileged access, and governance.

    Category
    Curated partner solution
    Pricing dimension
    Price
    Identity Access Management (IAM)

    Okta (Workforce Identity for AWS)

    Per user per month

    $20 (10 users minimum)

    Privileged Access Management (PAM)

    Britive (Privilege Access Management)

    Per identity per month

    $26 (NHI 1/10 of an identity);
    10 minimum)

    Privileged Access Management (PAM)

    Palo Alto Networks Idira (Privileged Access Management)

    Per identity per month

    Workforce:
    $21/identity/mo (200 min); $18/identity/mo (1000 min)

    Identity:
    $177/identity/mo (25 min); $152/identity/mo (150 min)

    Identity Governance and Administration (IGA)

    SailPoint (Identity Security Accelerator)

    Per identity per month

    $5.65 (2,500 minimum)

    Identity Governance and Administration (IGA)

    Opti (AI-Native Identity)

    Per human identity per month

    $4.65 (2,000 human identity min;
    All NHI are no additional charge)

    Okta — Workforce Identity for AWS Unified identity solution securing employees, contractors, and partners through Single Sign-On, Phishing-Resistant MFA, and Universal Directory as a single source of truth across AD and HR systems. Includes Silver Support and five automated Workflows. 

    Britive — Privilege Access Management Cloud-native PAM for human, agentic AI, and non-human identities that enforces zero standing privileges through dynamic, ephemeral access that auto-revokes when tasks complete. No endpoint software or architecture changes required. 

    SailPoint — Identity Security Accelerator AI-powered solution combining governance engine with end-to-end application discovery, risk-based prioritization, and zero-touch onboarding. Bring hundreds of apps under governance in days, not months. 

    Opti — AI-Native Identity Continuously monitors, analyzes, and remediates excessive permissions across human, non-human, and agentic identities in real time. Delivers OCSF-compliant findings directly into Security Hub, eliminating manual access reviews.

    Palo Alto Networks — Privileged Access Management, known as Idira, provides End-to-end privileged access security for internal admins and third-party vendors across on-premises and cloud environments. Supports secure standing access and Just-in-Time (JIT) workflows to achieve Zero Standing Privileges (ZSP).

  • Email
  • Email

    Defend the email attack surface with advanced threat detection.

    Category
    Curated partner solution
    Pricing dimension
    Price
    Email

    Proofpoint (Collaboration Protection)

    Per user per month

    $5.00 (750 users minimum)

    Email

    Sublime (Email Security)

    Per mailbox per month

    250-2500 mailboxes:
    $8.75/box/month

    2500+ mailboxes:
    $6.25/box/month

    Required minimum of 250 boxes 90-day free trial (1-100 boxes)

    Proofpoint — Collaboration Protection Deploys in under 48 hours with 99.999% efficacy powered by the Nexus AI threat detection stack combining threat intelligence, ML, relationship graphs, LLMs, and computer vision. Stops BEC, AI-driven exploits, ransomware, email bombing, callback phishing, and advanced social engineering.

    Sublime Email Security Platform — Autonomous email protection for inbound, internal, and outbound email with organization-specific detection that expands continuously without vendor bottlenecks. Full transparency and control when needed.

  • Network
  • Network

    Secure access to private applications with zero trust architecture to mitigate lateral movement.

    Category
    Curated partner solution
    Pricing dimension
    Price
    Network

    Zscaler SSE (Private Access Platform)

    Per seat per month

    $545 (0-50 Flat fee);
    $10.50 (51-100 seats);
    $9.50 (101-1000 seats);
    $8.25 (1001+ seats)

    Zscaler SSE — Private Access AI-powered Zero Trust Network Architecture delivering direct connectivity to private applications while minimizing attack surface, eliminating lateral movement through AI-powered user-to-app segmentation, and protecting against sophisticated attacks with integrated traffic inspection.

  • Data
  • Data

    Discover, classify, & protect data across the environment with automated posture management.

    Category
    Curated partner solution
    Pricing dimension
    Price
    Data

    Cyera (DSPM + Datawatcher)

    Per TB per month

    $73 (250-500 TB);
    $65 (501-1000 TB);
    $53 (1001+ TB);
    Required minimum of 250 TB;
    Datawatcher 12% of total spend

    Data

    Varonis (Data Security Platform for AWS)

    Per TB per month

    $29 (150-499 TB);
    $25 (500-999 TB);
    $13 (1001+ TB)
    Required minimum of 150 TB

    Cyera DSPM + Datawatcher — Autonomously discovers and classifies sensitive data across IaaS and DBaaS, correlates access and exposure risk, and drives prioritized remediation at scale. Optional Datawatcher add-on provides expert-led risk analysis and ongoing support.

    Varonis Data Security Platform — Varonis secures AI and the data that powers it. The Varonis platform gives organizations automated visibility and control over their critical data in AWS and across multicloud, SaaS, and hybrid applications - helping reduce data exposure and stop AI-powered threats. Integrated with AWS Security Hub for centralized data security visibility.

  • Browser
  • Browser

    Protect your workforce with enterprise browser security that deploys in minutes.

    Category
    Curated partner solution
    Pricing dimension
    Price
    Browser

    Island (Safe browsing and AI protection)

    Per user per month

    $8.50

    Browser

    LayerX (Browser & AI Use Security Platform)

    Per user per month

    $8.50

    Island Safe Browsing and AI Protection — Transforms Chrome and Edge into secure work environments through a lightweight extension with inline URL categorization, real-time malware inspection, and advanced anti-phishing protection. AI Protection provides policy controls over AI apps, prompts, and behavior.

    LayerX Browser & AI Use Security Platform — LayerX secures all user and agentic interactions in both AI and non-AI applications, across browsers, IDEs, and desktop apps. LayerX's AI governance and usage control platform lets customers control every prompt and data exchange across any channel, without changing their network architecture or disrupting the user experience.

  • Cloud
  • Cloud

    Strengthen your cloud security posture with runtime-powered protection across your cloud infrastructure. Start with Cloud Security for posture management and add Sensors and Shift Left as your needs grow. Pay-as-you-go pricing applies with no upfront commitment — you pay only for what you use.

    Upwind Cloud Security — Cloud-native application protection with multi-cloud asset inventory, graph-based rules engine, compliance frameworks (CSPM), vulnerability scanning and management, external exposure analysis, zero-day response, secrets and malware scanning, identity visibility, workflow automation, and AI security posture management.

    Upwind Sensors — Runtime-powered cloud workload protection with real-time cloud and network topology mapping, AI detection and response (AI-DR), API security, runtime vulnerability prioritization, and cloud detection and response across cloud logs. Delivers active protection based on what's actually running in production.

    Upwind Shift Left — Proactive security across the development lifecycle with attack surface management, dynamic application security testing (DAST), CI pipeline scanning (SCA), infrastructure-as-code scanning, and Kubernetes admission controller for policy enforcement before deployment.

    Native — Cloud Security Control Plane Native is the cloud security control plane that makes secure-by-design architecture achievable for the enterprise. Security teams define their intent once in plain language and Native automatically generates and enforces the controls across your cloud environment, simulates the impact of every change before it goes live, and continuously stays current with every AWS service release and update.

    Category Curated partner solution Pricing dimension Price
    Cloud Upwind (Cloud Security) Per resource per month $3.75
    Cloud Upwind (Sensors) Per resource per month $7.00
    Cloud Upwind (Shift Left) Per resource per month $5.25
    Cloud Native (Cloud Security Control Plane) Per resource per month $3.75 - 30-day unlimited free trial for all new customers

     

    Resource Unit Equivalents

    Pricing is per resource unit per month. Resource units standardize billing across different resource types:

    Resource type Resource unit equivalent
    Amazon EC2 instance 1 resource unit
    Amazon ECR container images 18 images = 1 resource unit
    AWS Lambda functions 12 functions = 1 resource unit
    Fargate tasks (Sensors only) 10 tasks = 1 resource unit
    GCP / Azure / OCI VM 1 resource unit
    On-premises VM or bare metal 1 resource unit

     

  • Artificial Intelligence
  • Artificial Intelligence

    Secure AI models, pipelines, and runtime environments with purpose-built protection for AI & agents.

    Category
    Curated partner solution
    Pricing dimension
    Price
    Artificial Intelligence

    Noma (AI-SPM + Discovery) (Noma Red Teaming) (Noma Runtime Protection)

    Per resource per month; per test/month million tokens/mo

    $130 resource/month (125 minimum);
    $650 test/month (167 minimum);
    $8/million tokens/mo (hybrid)|(3,500 minimum);
    $16/million tokens/mo (hosted)|(1,750 minimum)

    Artificial Intelligence

    Oligo (AI Runtime Security)

    Per host per month

    $46 (100 host min)

    Artificial Intelligence

    Zenity (Observability & CTEM, AISPM, Red Teaming)

    Runtime Protection | AI Firewall, AIDR) (Guardrails for AWS)

    Per resource/month
    Per million tokens/month
    Per million tokens

    $130/resource/month
    $16/million tokens/month
    $2/per million tokens (hybrid)

    Noma AI-SPM + Discovery, Red Teaming, Runtime Protection  — AI security purpose-built for AI and agents across homegrown applications, SaaS agents, and developer environments. Three core capabilities: posture management to discover assets, red teaming to test against adversarial attacks, and runtime protection to block threats like prompt injection. 

    Oligo AI Runtime Security — Unified sensor combining AI Security Posture Management and AI Detection & Response for continuous monitoring of model behavior, supply chain risks, and runtime anomalies. Monitors agent tool calls in real time to detect adversarial manipulation and hallucination.

    Zenity AI Agent Security and Governance — Zenity is the AI security and governance platform that enforces how agents behave, what they access, and which tools they invoke across the modern environment. It unifies observability, posture management, as well as runtime threat detection and prevention to stop malicious actions before they execute.

  • Security Operations
  • Security Operations

    Accelerate threat detection and response with enterprise-grade SIEM and agentic response.

    Splunk — Enterprise Security Essentials Fuses AWS Security Hub's high-fidelity insights with Splunk's security monitoring and analytics, elevating AWS findings as native Splunk findings in near real-time. Enriches findings with a proprietary correlation engine, AI, and threat intelligence to significantly reduce mean time to detect.

    Ingest Volume Tier 1
    50 – 99 GB/day
    Tier 2
    100 – 999 GB/day
    Tier 3
    1,000 – 4,999 GB/day
    Tier 4
    5,000 – 9,999 GB/day
    Tier 5
    10,000+ GB/day
    Data ingest $193 $116 $93 $85 $77

    For volume tier definitions and ingest thresholds, see the Voume Tier Reference table below

    Additional Storage (beyond 90 days included)

    Storage Type Price per 500 GB/month
    Searchable (hot) $60
    Archival (cold) $25

    Example: An organization ingesting 200 GB/day pays the Tier 2 rate: 200 x $116 = $23,200/month, with 90 days of storage included.

     

    7AI - Agentic Security Platform — 7AI delivers autonomous security operations through dynamic AI agents that run full investigations in minutes with expert-level reasoning. Optimizes detection rules to reduce false positives and proactively hunts for threats across cloud, identity, endpoint, network, and DLP sources.

    Category Curated partner solution Pricing dimension Price
    Security Operations 7AI (Agentic Security Platform) Per alert analyzed per month $20
  • Supply Chain
  • Supply Chain

    Protect your software supply chain from malicious packages, dependency vulnerabilities, and open-source risks with proactive detection and verified, provenance-backed open-source components.

    Chainguard - Chainguard Libraries

    Malware-free catalog of open-source language dependencies that replaces direct access to public registries like npm, PyPI, and Maven Central. Every package is rebuilt from verified source in a SLSA L3-compliant build environment with full provenance and signed SBOMs, eliminating exposure to supply chain attacks inserted during build and distribution stages. 

    Socket - Socket Firewall + Socket SCA

    Blocks zero-day supply chain attacks by scanning every open-source package and update for malicious behavior across all major registries. Socket Firewall intercepts package manager requests and blocks malicious dependencies at install time. Socket SCA provides software composition analysis with reachability filtering, identifying which vulnerabilities are actually reachable from application code to reduce noise. 

    Category  Curated partner solution  Pricing dimension  Price
    Supply Chain  Chainguard (Chainguard Libraries)  Per developer per month  1-10 | $100 
    11-50 | $75 
    51-100 | $40
    101-200 | $18
    201-300 | $12
    301-500 | $9
    501-2,000 | $6.25
    2,001-5,000 | $5.50
    5,001-10,000 | $3.75
    10,000+ | $2.25
    Supply Chain  Socket (Socket Firewall + Socket SCA) 

    Firewall: Per unique artifact per month  

    SCA: Per user per month 

    Socket Firewall 
    0-150,000 | $0.26
    150,001-750,000 | $0.22
    750,001-2,000,000 | $0.18
    2,000,000+ | $0.14 

    Socket SCA
     
    $66/user/mo 

     

     

Estimate your costs before you start

Before enabling Security Hub, use the Security Hub Cost Estimator to understand your total estimated spend across your entire organization. This tool analyzes your actual AWS resources and current security service usage to provide accurate cost projections across all your accounts and regions. This estimator does not include Extended plan pricing. See how Security Hub streamlined pricing compares to your current individual service costs, identify potential savings, and plan your security budget with confidence—all before starting your free trial.

AWS Security Hub Free Trial Summary

Try AWS Security Hub at no cost with a 30-day free trial that includes Essentials plan capabilities. Every AWS account in each Region enabled with Security Hub receives a free trial, even if you previously used AWS Security Hub CSPM or Amazon Inspector free trials. Add-on capabilities (threat analytics powered by Amazon GuardDuty and AWS Lambda code scanning powered by Amazon Inspector) and the Extended plan are not included in the Security Hub free trial, though individual service free trials still apply if you have not used them previously. You can explore the Extended plan in the console.

To help you plan ahead, use the Security Hub Cost Estimator to calculate your expected costs before enabling the service. During the free trial, you can monitor your usage through your AWS billing console to estimate your ongoing costs based on actual usage during the free trial. Once you set up an integration with Microsoft Azure, Azure monitoring of Microsoft Azure resources includes its own independent 30-day free trial.

Benefits

The Security Hub Essentials plan is the default level of coverage you receive when you enable Security Hub and is required for all Security Hub functionality. It provides security capabilities including risk and exposure analytics, vulnerability management, security posture management, and security response management.

    Gain streamlined vulnerability management with unified resource pricing for EC2 instance scans (both agent based and agentless), unlimited CIS Benchmark assessments, predictable ECR container image monitoring costs, and flat monthly Lambda function monitoring rates. This consolidation eliminates the complexity of managing multiple pricing models while providing more comprehensive vulnerability coverage.

    Benefit from transitioning from usage-based to resource-based pricing while gaining more comprehensive vulnerability correlation capabilities, unlimited security checks and finding ingestions, and enhanced compliance monitoring against industry standards with automatic correlation to Amazon Inspector vulnerability data. This shift provides cost predictability while expanding security capabilities.

    The threat analytics powered by Amazon GuardDuty is available as an add-on that enhances your essentials plan by identifying active threats. When you enable the threat analytics plan, you benefit from the Security Hub consolidated pricing model while gaining enhanced risk context through automatic correlation of threat detection findings with vulnerability and compliance data from the essentials plan.

    The Extended plan adds curated partner solutions across ten security categories: endpoint, identity, email, network, data, browser, cloud, artificial intelligence, security operations, and supply chain security. Simplify procurement with one bill, consolidated support, and pay-as-you-go pricing with no upfront commitment. Enable solutions directly from the Security Hub console, start with what you need, and expand coverage as your security needs evolve, extending protection beyond AWS to your multicloud and on-premises environments.

    Beyond cost consolidation, the Security Hub essentials plan transforms security operations through automatic correlation of vulnerability findings with compliance checks, reducing alert noise through exposure prioritization. Security teams can focus on contextualized risks that combine threats and vulnerability severity with network exposure and misconfiguration gaps, all while benefiting from centralized operations, automated remediation workflows, and the flexibility to expand into more comprehensive coverage as security needs evolve.

Pricing Examples

See how Security Hub pricing works for different organization sizes and configurations.

Essentials Plan Examples

Example 1: Small to medium account

One AWS Region (US East), one account. Security Hub processes 2 million CloudTrail management events, 800 GB of security data, and monitors 500 EC2 instances.

Threat detection analytics: 2M events x $4.00/M $8.00    
Security data processing: 800 GB x $0.55/GB (first 1,000 GB tier) $440.00    
Security risk analytics: 500 EC2 instances x $3.75/resource unit $1,875.00    
Total monthly cost $2,323.00    
Example 2: Large organization

Large enterprise with 100M CloudTrail events, 500 TB of security data, and diverse resources: 1,000 EC2 instances, 5,000 Lambda functions, 2,000 container images, 3,000 IAM users.

Threat detection analytics: 100M events x $4.00/M $400.00    
Security data processing: 500 TB (tiered: 1K GB + 9K GB + 502K GB)  $53,000.00    
Security risk analytics: 2,233 resource units x $3.75 $8,374.99    
Total monthly cost $61,774.99    

EC2: 1,000 x 1 = 1,000 | Lambda: 5,000 x 1/12 = 417 | ECR: 2,000 x 1/18 = 111 | IAM: 3,000 x 1/125 = 24

NOTE: Discount eligible for committed spend. Contact your AWS account manager for details.

Extended Plan Examples

Mid-size startup - 500 endpoints + email protection
CrowdStrike Workstations x 300 (Tier 2 - $9.90/ep) $2,970/mo  
CrowdStrike Servers x 200 (Tier 2 - $12.00/ep) $2,400/mo  
Proofpoint Email x 800 users ($5/user) $4,000/mo  
Total monthly cost

$9,370.00/mo

(~$112,000/yr)

 

Cloud-native team - containers + data + AI security
CrowdStrike Containers x 1,500 (Tier 3 - $27.85/ep) $41,775/mo  
CrowdStrike Fargate x 800 (Tier 3 - $6.65/ep) $5,320/mo  
Upwind CSPM x 500 resources ($3.75/res) $1,875/mo  
Cyera DSPM 400 TB ($73/TB) $29,200/mo
 
Noma AI Runtime 5M tokens ($8/M) $40,000/mo  
Total monthly cost $118,170/mo (~$1,418,040/yr)  
Enterprise - full stack security (5,000 employees)
CrowdStrike Servers x 3,000 (Tier 4 - $7.20/ep) $21,600/mo  
Okta Identity x 5,000 users ($20/user) $100,000/mo  
Proofpoint Email x 5,000 ($5/user) $25,000/mo  
Zscaler Network x 5,000 seats (1,001+ - $8.25/seat) $41,250/mo  
Splunk SIEM 200 GB/day (Tier 2 - $116/GB) $23,200/mo  
Total monthly cost $211,050/mo (~$2,532,600/yr)  
     
*Tier determined by aggregate endpoint count: Tier 4 applies at 2,778-11,111 total endpoints across all workload types.    

FAQs

Open all

    Security Hub offers a 30-day free trial that includes Security Hub essentials plan capabilities, which uses resource-based pricing. Every AWS account in each Region receives a free trial, and you remain eligible even if you previously used AWS Security Hub CSPM or Amazon Inspector free trials. Add-on capabilities including threat analytics by Amazon GuardDuty and AWS Lambda code scanning powered by Amazon Inspector and the Extended plan are not included in the Security Hub free trial. After the free trial, costs are based on the AWS resources you monitor (EC2 instances, container images, Lambda functions, IAM users/roles) and threat analytics usage (CloudTrail events and log data volume).

    Security Hub offers the Essentials plan as the default, with the ability to add Threat Analytics or Lambda Code Scanning capabilities as needed. The Essentials plan includes risk analytics, vulnerability management, security posture management, and security response management. Threat Analytics adds Amazon GuardDuty-powered monitoring of AWS account activity, VPC flow logs, DNS logs, and other security data. The Extended plan adds enterprise security with curated partner solutions across endpoint, identity, email, network, data, browser, cloud, artificial intelligence, and security operations. See the plan details section for complete feature descriptions.

    The Security Hub essentials plan delivers security protection across four key areas:

    • Risk and exposure analytics - Automatically identifies and prioritizes your most critical security issues by correlating findings across your environment, helping you focus on what matters most and respond faster to threats.
    • Vulnerability management - Continuously scans your EC2 instances, container images, and Lambda functions for software vulnerabilities and configuration weaknesses, enabling you to remediate security gaps before they can be exploited.
    • Security posture management - Evaluates your AWS environment against industry security standards and best practices to identify misconfigurations, helping you maintain compliance and reduce your attack surface.
    • Security response management - Provides a centralized view of your security findings with automated workflows, enabling your team to investigate and remediate issues more efficiently across your entire AWS environment.

    Together, these capabilities help you reduce security risks, improve team productivity, and maintain a strong security posture across your cloud infrastructure.

    Yes, Security Hub monitors all relevant AWS resources in your environment to provide more comprehensive security coverage. Essentials plan pricing is based on four resource types: EC2 instances, ECR container images, Lambda functions, and IAM users and roles. This simplified pricing model makes it easier to estimate and manage your Security Hub costs.

    No, you don't need both plans. The Security Hub essentials plan is the default level of coverage you receive when you enable Security Hub and is required for all Security Hub functionality. It provides security capabilities including risk and exposure analytics, vulnerability management, security posture management, and security response management. The threat analytics plan is an add-on that enhances your essential plan with threat monitoring capabilities powered by Amazon GuardDuty.

    The threat analytics plan cannot be used alone - it requires the Security Hub essentials plan as its foundation. You can start with just the essentials plan and add threat analytics capabilities later as your security monitoring needs evolve.

    AWS provides a cost estimation tool to help you estimate Security Hub costs before enabling the service. This estimator covers the Essentials plan and add-on capabilities (Threat Analytics and Lambda code scanning) but does not include Extended plan pricing. See Security Hub Cost Estimator page for more details.

    The Security Hub essentials plan combines Amazon Inspector and AWS Security Hub CSPM capabilities into a single, predictable resource-based pricing model that simplifies costs while enhancing security operations.

    Existing Amazon Inspector customers gain streamlined vulnerability management with unified resource pricing for EC2 instance scans (both agent based and agentless), unlimited CIS Benchmark assessments, predictable ECR container image monitoring costs, and flat monthly Lambda function monitoring rates. This consolidation eliminates the complexity of managing multiple pricing models while providing comprehensive vulnerability coverage.

    Security Hub CSPM customers benefit from transitioning from usage-based to resource-based pricing while gaining more comprehensive vulnerability correlation capabilities, unlimited security checks and finding ingestions, and enhanced compliance monitoring against industry standards with automatic correlation to Amazon Inspector vulnerability data. This shift provides cost predictability while expanding security capabilities.

    Beyond cost consolidation, the Security Hub essentials plan transforms security operations for all customers through automatic correlation of vulnerability findings with compliance checks, reducing alert noise through exposure prioritization. Security teams can focus on contextualized risks that combine vulnerability severity with network exposure and compliance gaps, all while benefiting from centralized operations, automated remediation workflows, and the flexibility to expand into more comprehensive threat detection as security needs evolve.

    Existing billing for security services seamlessly transitions to Security Hub streamlined pricing with no action required. You'll receive consolidated charges under Security Hub instead of separate service bills for the capabilities included in Security Hub plans.

    Security Hub provides account-level flexibility within AWS Organizations. When you enable Security Hub in an account, that account receives streamlined pricing across security services. When you don't enable Security Hub in an account, that account uses individual service pricing for each security service. This means within a single AWS Organization, you can have some accounts using Security Hub streamlined pricing model while other accounts continue with individual service pricing, determined at the account level based on whether Security Hub is enabled in that specific account.

    EC2 instances: Average number of EC2 instances = (total hours of active instances / number of hours in a month, i.e., 720 hours). For example, you have 3 instances that were active for different amounts of time during a month: The first for 360 hours, the second for 350 hours, and the third for 10 hours, adding up to a total of 720 hours of active instances. Therefore, 720 hours total of instances being scanned that month / 720 hours in the month = 1 average EC2 instance.

    Container images: Number of container images scanned = Number of container images pushed to Amazon ECR each month plus number of container images that are in scope for re-scanning during the month, based on Amazon Inspector re-scan configuration. Amazon Inspector performs an initial scan of each container image pushed to Amazon ECR. Additionally, Amazon Inspector re-scans container images for new vulnerabilities based on the time frames you configure for image push date, image pull date, and image last in-use date. Example: You have 5,000 images in your Amazon ECR repository and push 500 additional images to Amazon ECR in a month. You have configured image monitoring for 14 days based on the last in-use date. During the month, 75 container images from the repository are deployed to Amazon ECS or Amazon EKS clusters. Amazon Inspector monitors and charges based on the actual duration each image is monitored within your configured window - this includes both the 75 active images while they remain in use and the 500 newly pushed images for their respective monitoring periods. Note that charges apply only for the time each image is actually monitored (up to 14 days by default), not necessarily for the entire month, and this monitoring period can be customized based on your needs.

    Lambda functions: Eligible Lambda functions are based on functions marked $LATEST and were invoked or updated in the last 90 days. Average number of Lambda functions = (total hours of Security Hub coverage for a Lambda function)/ (number of hours in a month, i.e., 720 hours). Security Hub coverage hours represent the time from when the Lambda function is deployed to the time it is deleted.

    Example: You have 3 deployed Lambda functions that were monitored by Security Hub for different amounts of time during a month: The first for 720 hours, the second for 350 hours, and the third for 10 hours, adding up to a total of 1,080 hours of deployed Lambda functions being scanned. Therefore, 1,080 hours total of Lambda functions being scanned that month / 720 hours in the month = 1.5 average Lambda functions.

    IAM users and roles: Average number of IAM users and roles = Number of IAM users or roles that existed during the month, prorated daily.

    Capabilities not explicitly listed in the Security Hub plans continue to be billed through their original services. For example, you will only receive GuardDuty billing for any remaining GuardDuty capabilities that are not included in the threat analytics plan.

    Yes, individual services like Amazon Inspector, GuardDuty, and Security Hub CSPM remain available with their standard pricing when Security Hub is not enabled.

    The Security Hub Extended plan adds enterprise security with curated partner solutions across endpoint, identity, email, network, data, browser, cloud, artificial intelligence, and security operations. Extended plan charges are based on the specific partner solutions you enable, with pricing varying by security category and usage dimension. Unlike the Essentials plan, which uses resource-based pricing anchored on AWS resources, Extended plan pricing is solution-specific and based on dimensions appropriate to each security category — such as per user, per endpoint, or per TB. You can add the Extended plan to enhance your Security Hub coverage beyond AWS environments to your entire organization.