Guide · Updated September 29, 2026
AWS cost monitoring for startups: a 15-minute weekly review
Turn on AWS Budgets and Cost Anomaly Detection once, then spend 15 minutes a week in Cost Explorer comparing cost by service with the previous week. After that, check the common leaks listed below.
On this page
Turn on the free alerts first
Two AWS tools email you when spend moves. Set up both before your first weekly review.
AWS Budgets
In Billing and Cost Management, create a monthly cost budget set to the spend you expect. Add three alerts: actual spend at 80% and 100% of the budget, and forecasted spend at 100%. Those thresholds are our suggestion.
Budget monitoring and alerts are free. Action-enabled budgets, which can apply an IAM policy or stop EC2 and RDS instances, are free for the first two, then $0.10 a day each (AWS Budgets pricing). Forecast alerts need about 5 weeks of usage history before they can fire (AWS Budgets best practices), so a new account depends on the actual-spend alerts at first.
Cost Anomaly Detection
For standalone and management accounts that enabled Cost Explorer on or after March 27, 2023, AWS sets it up by default: an AWS services monitor and a daily email summary. The default alert fires when actual spend is over $100 and more than 40% above expected spend. It costs nothing extra (AWS announcement).
If the Cost monitors tab in Cost Anomaly Detection is empty, create a monitor with Managed by AWS and the AWS services dimension. On a small bill, $100 may never trigger, so set an amount you want to hear about.
Daily and weekly summaries arrive by email only. To get each anomaly in Slack, add an alert subscription with Individual alerts. It publishes to an Amazon SNS topic. Map that topic to a Slack channel with Amazon Q Developer in chat applications, formerly AWS Chatbot (Cost Anomaly Detection guide). Budget alerts can also publish to an SNS topic, so both can share one channel.
Cost allocation tags
Tag resources with a few keys, such as env (prod, staging, dev) and project. Then activate the keys under Cost allocation tags in Billing and Cost Management. A new key can take up to 24 hours to appear there and up to 24 hours more to activate (AWS Billing guide). After activation, the management account can backfill up to 12 months, but only for months when the resource already had the tag.
The 15-minute weekly review
Pick a fixed day. Cost Explorer shows usage through the previous day, and some data can arrive later than 24 hours (Cost Explorer guide), so treat the latest day or two as provisional.
- Open Cost Explorer. Set the date range to the last 4 weeks, the granularity to Daily and Group by to Service.
- Compare the last 7 days with the 7 days before. Look for change, not size: a small service whose daily cost doubled matters more this week than a large line that stayed flat. For exact figures, download the CSV and subtract one week from the other for each service.
- For each service that moved, filter to it and group by Usage type. The usage type names the meter that grew, such as
NatGateway-Bytes(data processed by a NAT gateway),DataTransfer-Out-Bytes(data sent to the internet) orTimedStorage-ByteHrs(S3 storage). Most Regions add a prefix, such asUSE2-for US East (Ohio). - Open Cost Anomaly Detection and read the Detected anomalies tab for the week. It lists every anomaly AWS found, including those below your alert threshold, with the top root cause by service, account, Region and usage type.
- Open Cost Optimization Hub and note new recommendations. The savings are estimates (see below). The hub needs a one-time opt-in, and can take up to 24 hours to import recommendations after that (AWS).
- Write one line per change: the service, the amount, the likely cause and a label of expected, investigate or fix. Take the fix lines to your weekly operations review with an owner and a date.
Once a month, choose Compare in Cost Explorer's report parameters. It analyzes the change between two months and lists the largest cost drivers, at no additional cost (AWS).
Unblended or amortized cost
The default Cost Explorer graph shows unblended cost: charges on the day they are billed. An upfront Savings Plan or Reserved Instance payment then shows as one large spike. Amortized cost spreads upfront and recurring commitment fees across the period they cover (Cost Explorer guide), which keeps week-to-week comparisons fair. Switch to amortized once you hold any commitment. Without commitments, the two views are essentially the same.
Common leaks to check
These charges often keep running after the work that needed them is done. Go through the table once a month, or when the weekly review points at one of them (our suggestion).
| Leak | How to find it | Usual fix |
|---|---|---|
| NAT gateway data processing | Usage type NatGateway-Bytes | Gateway endpoints for S3 and DynamoDB |
| Unattached EBS volumes | EC2 Volumes list, state Available | Snapshot if needed, then delete |
| Old EBS snapshots | Snapshots list, sorted by start time | Delete unneeded ones; a Data Lifecycle Manager policy for new ones |
| gp2 volumes | Volume type column | Change to gp3 in place |
| Log groups that never expire | CloudWatch Logs retention column | Set retention, for example 30 days |
| Idle or oversized RDS | CPUUtilization and DatabaseConnections in CloudWatch | Downsize, or stop dev instances |
| Unused public IPv4 addresses | Elastic IPs list; Public IP Insights in VPC IPAM | Release the ones you don't use |
| x86 Lambda functions | Architecture setting on each function | Test on arm64, then switch |
| ECR images piling up | Image count and size per repository | A lifecycle policy that expires old images |
| Forgotten dev environments | Cost by env tag or by account | Delete, or stop outside working hours |
Prices and defaults behind the table
- NAT gateways bill per hour and per GB processed. In US East (Ohio), AWS lists $0.045 per hour and $0.045 per GB (VPC pricing), so one gateway costs about $33 a month in hours alone (730 hours). Traffic from private subnets to S3 or DynamoDB goes through it unless you add a gateway endpoint, and gateway endpoints have no additional charge.
- AWS lists gp3 at up to 20% lower price per GB than gp2, with a baseline of 3,000 IOPS and 125 MiB/s at any size. A gp2 volume above 1,000 GiB has a baseline above 3,000 IOPS, and one of 334 GiB or more delivers 250 MiB/s. If the workload uses that performance, provision the same on gp3 (EBS guide).
- CloudWatch Logs keeps log data indefinitely by default; the console shows this as Never Expire (CloudWatch Logs guide). Pick a retention period that meets any audit requirement you have.
- A stopped RDS instance stops instance-hour charges, but you still pay for storage, backups and any public IPv4 address. RDS starts it again after 7 consecutive days (RDS guide), so a stopped dev database needs a schedule or it comes back.
- Since February 1, 2024, AWS charges $0.005 per hour for every public IPv4 address, in use or idle (AWS News Blog). That is about $3.65 per address per month. Public IP Insights lists them at no cost.
- On arm64 (Graviton2), Lambda duration charges are 20% lower than on x86 (AWS launch post, 2021). Functions with native dependencies need arm64 builds, so test first.
How to read cost recommendations
Cost Optimization Hub lists rightsizing, idle resource, Savings Plans and Reserved Instance recommendations in one place, with estimated monthly savings that include your discounts (AWS). Read them with these points in mind:
- Estimates are not realized savings. Check the next month's bill to see what a change saved.
- Recommendations can overlap. Rightsizing an instance and covering it with a Savings Plan both count savings on the same usage. The hub deduplicates related items in its totals, so don't add up the individual figures yourself.
- Savings Plans commit you to an hourly spend for 1 or 3 years in return for lower rates; AWS says up to 72% (Savings Plans guide). Our suggestion: buy only after compute usage has been stable for a few months, and commit to no more than your steady baseline.
- EC2 rightsizing uses memory only if the CloudWatch agent runs on the instance (Compute Optimizer guide). Without it, a downsize suggestion is based on CPU, network and disk, so check memory before you act.
Who should own AWS cost at a small startup
One named person, usually the CTO or whoever runs the weekly operations review. That person receives the Budgets and anomaly emails, does the 15-minute review and brings fix items to the team. The engineer who owns a service fixes the items in it.
A COO or head of finance may track the monthly total, but keep the weekly review with engineering, because the fixes change infrastructure (our suggestion). What a startup COO does covers how company operations and engineering split the work.
If you use several AWS accounts under AWS Organizations, review from the management account so every account shows in one Cost Explorer view. The weekly operations review guide has an agenda and a decision log for the fix items.
Where Grant fits, and what he doesn't do

Liz, who covers costs on Grant's team, does part of this review on a schedule. She reads Cost Explorer daily amortized cost by service for the connected AWS account, compares the current period with the previous one of the same length, and reads existing Cost Optimization Hub recommendations. Check-ins run daily on Pro and every six hours on Studio. Grant answers in Slack, the dashboard and MCP, and can send an optional weekly digest.
- Costs stay account-wide unless AWS attributes them. She doesn't guess a project's share.
- Recommendation figures are estimates, not realized savings, and Cost Optimization Hub must already be enrolled.
- She doesn't read Budgets or Cost Anomaly Detection, so keep those alerts on.
- She never buys Savings Plans or changes resources.
- AWS charges $0.01 per paginated Cost Explorer API request (AWS), so her reads add small charges to your bill.
Grant and his team are AI agents. Their check-ins only read, except Vera's tests of your own agents, and nothing merges or deploys. Meet Grant and his team or read how the read-only AWS role and project scope work.
Questions
Is AWS Cost Anomaly Detection free?
Yes. AWS offers it at no additional cost, and sets up a default monitor for standalone and management accounts that enabled Cost Explorer on or after March 27, 2023. If you route individual alerts through Amazon SNS, SNS usage is billed at its normal rates.
How often does Cost Explorer update?
AWS says Cost Explorer refreshes cost data at least once every 24 hours, and some data can take longer. Costs reflect usage up to the previous day, so treat the most recent day as provisional.
Should I use unblended or amortized cost?
Use amortized cost once you have Savings Plans or Reserved Instances, so upfront and monthly commitment fees spread across the usage they cover. Without commitments, the two are essentially the same and the default unblended view is fine.
Does an AWS budget stop spending at its limit?
No. A standard budget only sends alerts. A budget action can apply an IAM policy or stop EC2 and RDS instances when a threshold is reached. The first two action-enabled budgets are free, and each one after that has a daily charge (see the Budgets section above).
Related guides
- Weekly operations review: a template for small software teamsA 30-minute weekly operations review for small software teams: the agenda, the checks for CI, AWS, security and dependencies, and a decision log to copy.
- DevOps for startups without a DevOps teamSet up four things once, then check five every week. A practical DevOps checklist for startups on GitHub and AWS that have no DevOps engineer yet.
- How to triage Dependabot, code scanning and Security Hub alertsA 20-minute weekly routine to triage Dependabot, code scanning and AWS Security Hub alerts: known exploitation first, then exposure, then severity.