Back to the blog

AWS closed Audit Manager. Here's what replacing it with Config yourself actually costs.

Updated June 9, 2026 · by the BuriCloud team · 6 min read

TL;DR. Since April 30, 2026, AWS Audit Manager is closed to new accounts. AWS now points you at Config Conformance Packs. But read AWS's own documentation and you find Config has no SOC 2 or GDPR templates and no audit-report export. You can build those missing pieces yourself. The trap is that the Config charges (a few hundred dollars a month) are the cheap part. The real bill is weeks of engineering, and at the end of it you still have no signed, auditor-ready report. CloudProof hands you one in about ten minutes.

What changed

Audit Manager used to be the native way to turn your AWS posture into a report an auditor would accept. AWS is now retiring it, in plain language:

"Audit Manager is transitioning to maintenance mode and from April 30th 2026 customers will no longer be able to set up the service in new accounts... the service team will not build new features, nor add support for new frameworks or new versions of existing frameworks, nor add new region support." AWS Audit Manager availability-change documentation

Adopted AWS after that date? Spinning up a fresh account or a new region? Then you simply cannot switch Audit Manager on. The path AWS recommends instead is Config Conformance Packs. And AWS is refreshingly blunt about where that path falls short.

The gap, in AWS's own words

So you really have three honest choices. Build the missing rules and reporting on Config yourself. Buy a full GRC platform. Or use a focused AWS-evidence tool. Let's price the first one, since it's the option that looks free.

The real cost of building it on Config yourself

1. The Config bill is the small number

Config is usage-priced: $0.003 per configuration item recorded and $0.001 per conformance-pack rule evaluation (first 100k per region, cheaper after that). Take one account with a few hundred resources across four enabled regions, running the packs for frameworks that do ship a template (PCI DSS, NIST 800-53, HIPAA). You are usually looking at something like $150 to $400 a month. That number climbs with every extra account, region and resource you add.

Rough estimate. Your real figure depends on resource count, change rate, regions and how many accounts you run. Either way, the dollars are the easy part. This spend still buys you nothing for SOC 2, GDPR or ISO 27001.

2. The engineering time is the big number

For the frameworks AWS doesn't template (SOC 2, GDPR, ISO 27001) there is no pack to deploy at all. You write the control-to-rule mappings yourself, usually as custom, Lambda-backed Config Rules. Then, because there is no report, you build an evidence-export pipeline on top (Config Advanced Queries, Athena, get-resource-config-history). Realistically:

Put a loaded engineering rate on that and the first SOC 2 plus ISO pipeline lands somewhere around $10,000 to $25,000 of one-time work, maintenance on top. All to arrive roughly where a purpose-built tool already starts.

3. Side by side

 Build it yourself on AWS ConfigCloudProof
SOC 2 / GDPR / ISO 27001No. No conformance-pack template (AWS's own words), so you author every ruleYes. Mapped out of the box
Direct AWS cost$0.003 per config item plus $0.001 per rule eval. A few hundred dollars a month for one multi-region account, and it grows per account, region and resourceFlat subscription
Time to first evidenceDays for templated frameworks. Weeks to author custom rules and an export pipeline for SOC 2 or ISOAbout 10 minutes
Auditor-ready signed reportNo. Build it yourself (Athena and Config queries out to CSV or JSON)Yes. Signed and verifiable at /verify
All regionsDeploy and pay per regionYes. Every enabled region, included
Upkeep as frameworks changeYou own itYes. Managed

What CloudProof does

CloudProof connects to your AWS account read-only. No write access, ever. It runs 118 automated checks across 55 AWS services in every enabled region and produces a signed, timestamped evidence report mapped to CIS, AWS FSBP, PCI DSS, NIST, SOC 2, HIPAA, ISO 27001 and more. Whoever needs to check it (your auditor, a customer's security team) can confirm it's genuine and unedited at /verify.

It's EU-hosted. There is no sales call. You can run a free scan and pay by card today. It covers the AWS infrastructure controls auditors really look at (access, encryption, logging) and lets you attest the policy and process controls, without paying for or onboarding a full GRC suite you don't need yet.

It won't make you "SOC 2 certified" on its own. Nothing does. Audit Manager never did either. What you get is the auditor-ready AWS evidence Config can't produce, in minutes rather than weeks.

Run a free scan