• Cohort starts Jan 16, 2027
Reserve seat
All posts
AWS

AWS Security Hub vs Security Hub CSPM: 2026 Guide

PrimeSec Academy·9/15/2026
AWS Security Hub vs Security Hub CSPM: 2026 Guide

AWS Security Hub and Security Hub CSPM are two different services. Learn what each does, how to enable them, and which standards to turn on first.

AWS now ships two products with almost the same name: AWS Security Hub, a unified risk analytics service that went generally available on December 2, 2025, and AWS Security Hub CSPM, which is the original Security Hub renamed. Security Hub CSPM runs configuration checks against standards like FSBP and CIS, while the new Security Hub correlates and prioritizes signals from GuardDuty, Inspector, and Security Hub CSPM into ranked risks and attack paths.

If that sounds confusing, you are not alone. AWS took a well known product name, applied it to a brand new service, and appended "CSPM" to the old one. This guide clears up which service does what, how to configure each one properly, and what a cloud security engineer is actually expected to know about them in an interview or on the job.

The naming change, explained simply

Before late 2025, "AWS Security Hub" meant one thing: a posture management service that ran automated configuration checks and aggregated findings from other security services into a single console.

That service still exists, unchanged in function, but it is now called AWS Security Hub CSPM (Cloud Security Posture Management). Your existing configurations, standards, automation rules, and integrations continue to work.

The name "AWS Security Hub" was reassigned to a new unified security service. It sits one layer above CSPM and consumes its findings, along with signals from Amazon GuardDuty and Amazon Inspector, to produce correlated and prioritized risk analytics.

One practical detail worth remembering: organizations that enabled the public preview of the new Security Hub had to take migration action by January 15, 2026 to keep it running. Disabling the preview did not affect Security Hub CSPM, which kept operating normally.

Security Hub vs Security Hub CSPM at a glance

DimensionSecurity Hub CSPMSecurity Hub (new)
Primary jobDetect misconfigurations against standardsCorrelate and prioritize risks across services
Core outputControl findings with pass/fail statusRanked exposures and attack paths
Data sourcesAWS Config, AWS services, partner productsGuardDuty, Inspector, Security Hub CSPM
Key artifactSecurity score per standardNear real-time risk analytics and trends
Hard dependencyAWS Config must be enabledUnderlying detection services
Best forCompliance evidence, baseline hygieneTriage, incident prioritization, response

The short version: CSPM answers "are my resources configured correctly?" The new Security Hub answers "what should my team work on right now, and why?"

You do not choose one over the other. In a mature account structure, CSPM feeds Security Hub, and both are enabled across the organization.

What Security Hub CSPM actually checks

Security Hub CSPM evaluates your environment against security standards. Each standard contains controls, and each control represents one best practice that is checked continuously.

AWS currently supports these standards:

  • AWS Foundational Security Best Practices (FSBP): the AWS-authored baseline covering a broad set of services. This is the standard most teams enable first.
  • AI Security Best Practices: a newer standard covering deployed AI resources, including network isolation, encryption, VPC placement, and AWS KMS key usage.
  • AWS Resource Tagging: checks whether resources carry tags, which matters more than it sounds for ownership and incident routing.
  • CIS AWS Foundations Benchmark: the industry benchmark from the Center for Internet Security, supported across multiple versions including v1.2.0, v1.4.0, v3.0.0, and v5.0.0. Version 5.0.0 was published by CIS in March 2025 and became available in Security Hub CSPM in October 2025.
  • NIST SP 800-53 Revision 5 and NIST SP 800-171 Revision 2: for federal alignment and Controlled Unclassified Information respectively.
  • PCI DSS: for organizations that store, process, or transmit cardholder data.
  • Service-managed standard, AWS Control Tower: for detective controls governed from Control Tower.

AWS is explicit that enabling a standard does not make you compliant with the underlying framework. Standards give you a continuous, measurable view of configuration state. Auditors still want evidence, scope definitions, and compensating controls.

The AWS Config dependency people miss

Security Hub CSPM uses service-linked AWS Config rules to run most of its checks. If AWS Config is not enabled and recording resources in a Region, most controls will not generate findings at all, and your security score will look deceptively clean.

Two more constraints matter operationally:

  1. Security Hub CSPM only processes findings generated after you enable it. It does not retroactively analyze history.
  2. Findings are processed in the Region where the service is enabled. For full CIS AWS Foundations Benchmark coverage, AWS requires enabling it in all supported Regions, then using cross-Region aggregation to centralize the view.

This is exactly the kind of detail that separates someone who has read a blog post from someone who has built the control. We cover multi-account, multi-Region enablement as hands-on lab work in the PrimeSec curriculum.

A practical enablement sequence

If you are standing this up from scratch in an AWS Organization, work in this order:

  1. Designate a delegated administrator account for security services. Do not run this from the management account.
  2. Enable AWS Config with resource recording in every Region you operate in, plus a recorder in Regions you do not use, so that unexpected resources are still caught.
  3. Enable Security Hub CSPM organization-wide with auto-enable for new accounts. Each account gets a 30-day free trial when first enabled.
  4. Turn on consolidated control findings. Without it, a control that belongs to three enabled standards generates three separate findings for the same issue, which inflates noise and finding volume.
  5. Enable FSBP first, then add CIS and any regulatory standards you actually need. Enabling every standard on day one produces a wall of findings nobody triages.
  6. Set an aggregation Region so one console shows findings across all linked Regions.
  7. Enable GuardDuty and Inspector, then enable the new Security Hub so correlation has something to correlate.
  8. Write automation rules to suppress known-accepted findings and elevate severity for production-tagged resources.

Tuning the noise

The most common failure mode is a team that enables everything, sees thousands of failed checks, and quietly stops looking at the console.

Practical countermeasures:

  • Suppress rather than disable where possible, so the finding history stays intact for audit purposes.
  • Use automation rules keyed on resource tags. A failed encryption check on a sandbox bucket is not the same priority as one on a production data store.
  • Route findings to Amazon EventBridge and into your ticketing system so remediation has an owner and a deadline rather than living in a dashboard.
  • Track the security score trend rather than the absolute number. Direction matters more than the starting point.

Finding data flows in the AWS Security Finding Format (ASFF), a normalized schema. If you build any custom automation, learn ASFF field names early, because every downstream rule depends on them.

How this fits the rest of your AWS security stack

Security Hub CSPM does not detect threats. It detects misconfigurations. Threat detection is GuardDuty's job, and vulnerability assessment belongs to Inspector. The new Security Hub is the layer that ties those signals together.

A useful mental model:

  • Identity misconfiguration: Security Hub CSPM flags it. See our guide to AWS IAM security best practices for the underlying controls.
  • Active threat behavior: GuardDuty flags it. See AWS GuardDuty threat detection.
  • Exposed data store: CSPM flags the configuration, and Security Hub correlates it with reachability into an attack path.

That correlation is the real value of the new service. A public S3 bucket is a medium finding. A public S3 bucket holding sensitive data, reachable from an instance with an over-permissioned role, is an incident. Correlation is what turns the first into the second.

What this means for your career

Posture management is one of the most commonly assigned tasks for junior and mid-level cloud security engineers, because it is measurable and it produces visible wins fast. Hiring managers ask about it constantly.

Interviewers tend to probe three things:

  • Do you understand the AWS Config dependency, or did you just click Enable?
  • Can you explain how you reduced finding noise without hiding real risk?
  • Can you describe a remediation workflow end to end, from finding to ticket to verified fix?

Answering those well requires having actually built it. Reading documentation is not enough, which is why hands-on labs and portfolio projects matter more than another certificate. If you are working toward the AWS specialty exam, posture management appears throughout the blueprint. Our AWS Security Specialty SCS-C03 exam guide maps the domains in detail.

Frequently asked questions

Is AWS Security Hub CSPM being deprecated?

No. AWS has announced no deprecation timeline for Security Hub CSPM. It continues to receive updates, including new standards and control versions. It is now positioned as the posture management layer that feeds the newer unified Security Hub service.

Do I need both Security Hub and Security Hub CSPM?

For most organizations, yes. Security Hub CSPM produces the configuration findings and compliance evidence. The newer Security Hub correlates those findings with GuardDuty and Inspector signals to prioritize what to fix first. Running only the correlation layer leaves you without posture checks.

Does Security Hub CSPM work without AWS Config?

Not meaningfully. Most controls rely on service-linked AWS Config rules, so without Config enabled and recording resources, the majority of checks will not generate findings and your security score will be misleading.

Which security standard should I enable first?

Start with AWS Foundational Security Best Practices. It is the broadest AWS-authored baseline and covers a wide range of services. Add the CIS AWS Foundations Benchmark next, then layer on PCI DSS or NIST only if your industry or contracts require them.

Does enabling a standard make my organization compliant?

No. AWS states directly that standards and controls do not guarantee compliance with any regulatory framework or audit. They provide a way to evaluate and monitor your configuration state. Formal compliance still requires scoping, evidence collection, and assessor review.

Is Security Hub CSPM free?

Each account gets a 30-day free trial when Security Hub CSPM is first enabled. After that, charges are based on security checks and ingested findings. You also pay for AWS Config configuration items, though not for Config rules activated only by Security Hub CSPM standards.

Build this, do not just read about it

Posture management is a skill you prove by shipping a working configuration, not by memorizing service names. At PrimeSec Academy, our 20-week Cloud and AI Platform Security Engineer program puts you inside real AWS, Azure, and GCP environments with 36 hands-on projects and a defended capstone.

Explore the curriculum or enroll now to start building the portfolio that gets you hired.

Stay ahead in cybersecurity

Get the Latest Security Insights

Subscribe to our newsletter and get updates on new courses, labs, events, and career tips.

We respect your privacy. Unsubscribe at any time.