AWS security and IAM pricing, negotiated.
GuardDuty, Security Hub, Macie, KMS, WAF, Shield Advanced, and Inspector commercial terms — benchmarked across 500+ AWS engagements and $2.4B+ in reviewed spend.
Security spend is the line nobody questions
until it's eight figures.
AWS security and identity services are the easiest line items on an AWS bill to ignore — until they aren't. GuardDuty, Security Hub, Macie, Detective, Inspector, KMS, WAF, Shield Advanced, Network Firewall, and Verified Permissions each carry their own usage-based pricing models, their own scaling characteristics, and their own optimization levers. Most enterprise customers turn them on for compliance, then discover two years later that security tooling represents 8% to 14% of their total AWS spend and is growing faster than the rest of the bill.
This page documents how each of AWS's security and identity services is priced, where the most common cost overruns occur, and what commercial levers are available inside an Enterprise Discount Programme (EDP), Private Pricing Addendum (PPA), or annual Shield Advanced subscription. We have benchmarked AWS security pricing across financial services, healthcare, public sector, SaaS, and retail customers — a representative sample of every regulatory profile that drives security tooling adoption at scale.
For customers spending more than $300K per year on AWS security services, the commercial conversation is meaningfully different. Volume-based service discounts, multi-account aggregation, finding ingestion caps, and Shield Advanced PPA pricing all become negotiable. For customers under that threshold, the optimization conversation is almost entirely about architecture and configuration. This page covers both.
How each AWS security service is priced.
What is actually negotiable.
Volume tier pricing
GuardDuty CloudTrail and S3 data event volumes, Macie GB scanned, and Detective ingest all carry published volume tiers. At enterprise scale we routinely negotiate tier breakpoints lower than the public defaults inside the EDP.
Shield Advanced PPA
Shield Advanced is a flat subscription at list, but Private Pricing Addendums for multi-year commits and organization-wide coverage are common at $1M+ AWS spend tiers, with attack-traffic credit pools negotiable on top.
Multi-account aggregation
Security Hub, GuardDuty, and Macie all support delegated administrator accounts. Aggregating evaluation and ingest into a single account before billing materially changes the EDP-eligible spend profile and can simplify the negotiation.
Where the quick wins are.
Architecture-level
- Sample, scope, or exclude non-sensitive S3 buckets from GuardDuty S3 protection and Macie scans.
- Disable overlapping Security Hub standards (CIS vs. AWS Foundational) where controls duplicate.
- Enable data key caching for chatty KMS workloads — typical 70%+ request reduction.
- Consolidate AWS Private CA instances and use short-lived certificate mode where possible.
- Aggregate findings to a single delegated administrator account to reduce per-region replication.
Commercial
- Roll all security services into EDP-eligible commitment to deepen the effective discount.
- Negotiate Shield Advanced subscription terms and attack-traffic credit pool at renewal.
- Push GuardDuty and Macie volume tier breakpoints into the PPA at $300K+ annual category spend.
- Bundle Inspector and Detective into a single commercial conversation rather than negotiating each separately.
Often combined with security pricing.
AWS security spend
is negotiable.
500+ engagements. $2.4B+ AWS spend reviewed. We benchmark your security tooling commercials in 5 business days.