AWS Control Tower pricing
Overview
There is no additional charge to use AWS Control Tower. However, when you set up AWS Control Tower, you will begin to incur costs for AWS services configured to set up your landing zone and mandatory controls. While some AWS services, such as AWS Organizations and AWS IAM Identity Center, come at no additional charge, you will pay for services, such as AWS Service Catalog, AWS CloudTrail, AWS Config, Amazon CloudWatch, Amazon Simple Notification Service (Amazon SNS), Amazon Simple Storage Service (Amazon S3), and Amazon Virtual Private Cloud (Amazon VPC), based on your usage of these services. You only pay for what you use, as you use it.
For example, if you edit the AWS Control Tower account factory configuration to enable public subnets when provisioning a new account, then account factory will configure Amazon VPC to create a NAT Gateway, and you will be billed for your usage by Amazon VPC. The following examples show how AWS Control Tower can influence the cost you incur by enabling other services.
If you are running ephemeral workloads from accounts in AWS Control Tower, you may see an increase in costs from AWS Config as it records configuration changes associated with creating and deleting these temporary resources. An ephemeral workload is a temporary use of computing resources that are loaded and run when needed. Examples include Amazon Elastic Compute Cloud (Amazon EC2) Spot Instances, Amazon EMR jobs, and AWS Auto Scaling.
Please see AWS Config pricing for details. Contact your AWS account representative for more specific information about managing these costs.
Pricing example 1: Setting up AWS Control Tower
Pricing example 2: Customer with a smaller usage profile on AWS
Pricing example 3: Customer with a larger usage profile on AWS
Pricing example 4: Customer with ephemeral workloads on AWS