CloudCompliance

AWS Config, Security Hub and Audit Manager

AWS Config records what your resources look like over time. Security Hub scores them against standards and collects findings. Audit Manager maps evidence to frameworks. For a first audit, the first two do most of the work.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Turn on AWS Config and Security Hub in every account and region you use, aggregated to a delegated security account. They give you configuration history and a scored, deduplicated list of findings, which covers most of the AWS evidence a SOC 2 or ISO 27001 auditor asks for. Audit Manager is optional: useful if you want AWS evidence mapped to a framework without a separate tool, and redundant if you already use a compliance platform.

The three AWS compliance services compared
ServiceWhat it doesEvidence it producesNeeded for a first audit?
AWS ConfigRecords resource configuration and changes; evaluates rules and conformance packsConfiguration timeline, rule compliance historyYes
Security HubRuns security standards checks, aggregates findings from GuardDuty, Inspector, Macie and othersStandard scores, findings with workflow statusYes
Audit ManagerCollects evidence from Config, Security Hub and CloudTrail and maps it to frameworksAssessment reports organized by controlOptional

AWS Config

Config is the foundation. Once the recorder is on, every change to a recorded resource is kept with a timestamp, which answers the auditor's question "was this true across the whole period?" Managed rules check common settings such as encryption, public access and logging. Conformance packs bundle rules; AWS publishes packs aligned with frameworks including NIST SP 800-53 and CIS, which are useful starting points.

  • Record all resource types, or at least all types in your production accounts.
  • Use an aggregator in the security account for an organization-wide view.
  • Watch cost: Config charges per configuration item recorded, which grows with churn in large container or autoscaling estates. Periodic recording for noisy resource types reduces it.

Security Hub

Security Hub turns Config and other services into a findings list with a score per standard. The AWS Foundational Security Best Practices standard is the most useful for SOC 2; the CIS AWS Foundations Benchmark is common for customers that name CIS.

Its value as evidence depends on workflow. An auditor sampling CC7 will look at findings from the period and ask what happened to them. Use the workflow status (new, notified, suppressed, resolved), suppress controls that genuinely do not apply with a reason, and route high severity findings to tickets.

Audit Manager

Audit Manager has prebuilt frameworks, including one for SOC 2, that pull evidence automatically from AWS sources and let you add manual evidence. It produces an assessment report you can share. Two limits: it only sees AWS, so controls about your identity provider, code repository or people need manual uploads, and auditors still decide what they accept. It suits AWS-heavy companies without a compliance platform.

Other AWS services an auditor will ask about

CloudTrail
The audit log. See audit logging.
GuardDuty
Threat detection across accounts. Evidence for CC7.2.
Inspector
Vulnerability scanning for EC2, ECR and Lambda. See vulnerability management.
IAM Access Analyzer
Finds resources shared outside your organization and unused access. Useful for access reviews.
Macie
Finds sensitive data in S3. Useful for data classification evidence, optional for most audits.
Is AWS Audit Manager free?

No. Audit Manager charges per resource assessment, and Config and Security Hub have their own usage charges. For a small estate the combined cost is modest; check current AWS pricing against your resource count before enabling everything organization-wide.

Does Security Hub have a SOC 2 standard?

Security Hub's standards are technical benchmarks such as AWS Foundational Security Best Practices and CIS, not SOC 2 itself. Audit Manager has a SOC 2 framework that uses Security Hub and Config results as evidence.

Do we need AWS Config if we use a compliance platform?

Usually yes. Platforms read your current configuration through the API, but Config keeps history, which is what proves a control held across the audit period. Many platforms read Config and Security Hub data themselves.

Want the AWS tooling set up properly?

Firms in the network configure Config, Security Hub and the triage routine.

Get matched