AWS closed Audit Manager. Here's what replacing it with Config yourself actually costs.
What changed
Audit Manager used to be the native way to turn your AWS posture into a report an auditor would accept. AWS is now retiring it, in plain language:
"Audit Manager is transitioning to maintenance mode and from April 30th 2026 customers will no longer be able to set up the service in new accounts... the service team will not build new features, nor add support for new frameworks or new versions of existing frameworks, nor add new region support." AWS Audit Manager availability-change documentation
Adopted AWS after that date? Spinning up a fresh account or a new region? Then you simply cannot switch Audit Manager on. The path AWS recommends instead is Config Conformance Packs. And AWS is refreshingly blunt about where that path falls short.
The gap, in AWS's own words
- No SOC 2 or GDPR. "AWS Config does not currently offer Conformance Pack templates for all of the frameworks supported by Audit Manager, including SOC2 and GDPR." (There is no ISO 27001 equivalent either.)
- No audit report. "AWS Config does not provide an audit reporting feature that is directly equivalent to the Audit Manager export."
- Thinner evidence. "AWS Config records only Configuration Items... it does not collect AWS CloudTrail logs, AWS Security Hub Controls or make API calls to target services."
- It even hands you off to a third party. For full compliance management, AWS suggests "partner solutions, such as those from Vanta and Drata."
So you really have three honest choices. Build the missing rules and reporting on Config yourself. Buy a full GRC platform. Or use a focused AWS-evidence tool. Let's price the first one, since it's the option that looks free.
The real cost of building it on Config yourself
1. The Config bill is the small number
Config is usage-priced: $0.003 per configuration item recorded and $0.001 per conformance-pack rule evaluation (first 100k per region, cheaper after that). Take one account with a few hundred resources across four enabled regions, running the packs for frameworks that do ship a template (PCI DSS, NIST 800-53, HIPAA). You are usually looking at something like $150 to $400 a month. That number climbs with every extra account, region and resource you add.
Rough estimate. Your real figure depends on resource count, change rate, regions and how many accounts you run. Either way, the dollars are the easy part. This spend still buys you nothing for SOC 2, GDPR or ISO 27001.
2. The engineering time is the big number
For the frameworks AWS doesn't template (SOC 2, GDPR, ISO 27001) there is no pack to deploy at all. You write the control-to-rule mappings yourself, usually as custom, Lambda-backed Config Rules. Then, because there is no report, you build an evidence-export pipeline on top (Config Advanced Queries, Athena, get-resource-config-history). Realistically:
- Templated frameworks (PCI, NIST, HIPAA): hours to deploy the pack, then days to wire up evidence export.
- Untemplated (SOC 2, GDPR, ISO 27001): figure two to six weeks of senior AWS engineering per framework to map controls, write and test the custom rules, and package the evidence. Then it needs upkeep as the standards and your stack keep moving.
- Still not there: a signed, tamper-evident report an auditor or customer can verify independently. You'd have to build that too.
Put a loaded engineering rate on that and the first SOC 2 plus ISO pipeline lands somewhere around $10,000 to $25,000 of one-time work, maintenance on top. All to arrive roughly where a purpose-built tool already starts.
3. Side by side
| Build it yourself on AWS Config | CloudProof | |
|---|---|---|
| SOC 2 / GDPR / ISO 27001 | No. No conformance-pack template (AWS's own words), so you author every rule | Yes. Mapped out of the box |
| Direct AWS cost | $0.003 per config item plus $0.001 per rule eval. A few hundred dollars a month for one multi-region account, and it grows per account, region and resource | Flat subscription |
| Time to first evidence | Days for templated frameworks. Weeks to author custom rules and an export pipeline for SOC 2 or ISO | About 10 minutes |
| Auditor-ready signed report | No. Build it yourself (Athena and Config queries out to CSV or JSON) | Yes. Signed and verifiable at /verify |
| All regions | Deploy and pay per region | Yes. Every enabled region, included |
| Upkeep as frameworks change | You own it | Yes. Managed |
What CloudProof does
CloudProof connects to your AWS account read-only. No write access, ever. It runs 118 automated checks across 55 AWS services in every enabled region and produces a signed, timestamped evidence report mapped to CIS, AWS FSBP, PCI DSS, NIST, SOC 2, HIPAA, ISO 27001 and more. Whoever needs to check it (your auditor, a customer's security team) can confirm it's genuine and unedited at /verify.
It's EU-hosted. There is no sales call. You can run a free scan and pay by card today. It covers the AWS infrastructure controls auditors really look at (access, encryption, logging) and lets you attest the policy and process controls, without paying for or onboarding a full GRC suite you don't need yet.
It won't make you "SOC 2 certified" on its own. Nothing does. Audit Manager never did either. What you get is the auditor-ready AWS evidence Config can't produce, in minutes rather than weeks.