AWS BillExplained
← Topics

Charges with no resource

  • Timenot billed
  • Bytesnot billed
  • Unitsnot billed

In one line

Some charges attach to an account, not a thing. Nothing to tag, and deleting infrastructure will not move them.

Why it works that way

Every other page here points at something you made: an instance, a bucket, a NAT gateway. The meter turns because the thing exists, and deleting the thing stops the meter. This page is about the charges that break that rule. They attach to an account or to an organisation, there is no resource behind them, and terminating infrastructure does not move them directly.

Two mechanics produce almost all of them.

The first is consolidated billing. AWS Organizations states it flatly: every organisation has a management account “that pays the charges of all the member accounts”, and the per-member bills are “for informational purpose only”. The account that spent the money and the account that pays it are different accounts by construction. So a line arriving in the payer that nobody in the payer created is not a bug.

The second is percentage-of-spend pricing. AWS Support has no unit. It is priced as a percentage of your monthly AWS charges, in graduated bands, with a floor. That one decision makes support cost a function of every other line on the bill, the only line item whose price is computed from the others.

Both still turn the time meter in the sense this site means it: charged per month because a subscription exists, whether or not anyone used it. What is unusual is not the meter. It is that the rate is not on a rate card.

A correction this site owes you. Trusted Advisor and the AWS Health Dashboard are listed here as free, and that is only true of the half you look at with your eyes. On Basic Support you get every check in the Service Limits category plus six selected checks in Security and Fault Tolerance: EBS public snapshots, RDS public snapshots, S3 bucket permissions, MFA on the root user, security groups with specific ports unrestricted, and STS global endpoint usage across Regions. Automatic check updates are not included; on Basic you refresh the security checks by hand. AWS’s own Trusted Advisor page counts the gap: 56 checks on any plan, 426 more unlocked by Business Support+ and above, 482 in total. The Trusted Advisor API is a paid-plan feature too. Health is stricter. Call the AWS Health API from an account without Business Support+, Enterprise Support or Unified Operations and you get SubscriptionRequiredException. The console is free, the automation is not, and the price of the automation is a percentage of everything else you spend.

Path through Your workload, The account, The payer account, hop by hop:

  • Your workload (EC2, S3, RDS: taggable) is billed on the Time meter for as long as it exists.
  • The account (AWS Support subscription) is billed on the Time meter for as long as it exists.
  • The payer account (Shield Advanced, Marketplace) is billed on the Time meter for as long as it exists.
  1. Your workload to The account: Gross charges, before discounts. Not billed.
  2. The account to The payer account: Consolidated onto one invoice. Not billed.
Where each charge attaches. The workload is taggable and deletable. The subscriptions above it are neither: they bill monthly for existing, and the account below them is only where the arithmetic starts. no charge

What it costs

The Support lineup changed, so working from memory means working from the old one. Developer Support, Business Support and Enterprise On-Ramp are all discontinued on 1 January 2027; Enterprise On-Ramp customers are being upgraded to Enterprise Support through 2026, and the Enterprise minimum fell from $15,000 to $5,000 in the process. All three remain available in the AWS GovCloud (US) Region. Three plans are on sale now, and Support pricing has no Region: the numbers are the same wherever you run.

Each charges whichever is greater, the minimum or the bands:

  • Business Support+: $29/month per account, or 9% of monthly AWS charges up to $10K, 7% from $10K to $80K, 5% from $80K to $250K, 3% over $250K. Calculated per account.
  • Enterprise Support: $5,000/month, or 10% up to $150K, 7% from $150K to $500K, 5% from $500K to $1M, 3% over $1M. Calculated on the aggregate gross charges of every subscribed account ID.
  • Unified Operations: $50,000/month, or 10% up to $1M, 6% from $1M to $5M, 5% over $5M. Also aggregate.

The base is gross charges “before any discounts or credits are applied”, which is worth reading twice: a negotiated discount does not shrink the support fee. A named list of services is excluded from the base, including AWS Support itself, AWS Marketplace, AWS Managed Services, AWS Professional Services, Amazon EKS Anywhere and VMware Cloud on AWS. Commitments count: Savings Plan and Reserved Instance upfront charges enter the base in the month you buy, recurring charges in the month they are incurred. Minimum commitment is 30 days, 90 days for Unified Operations. The add-ons are shaped the same way: AWS Countdown Premium at $10K per project per month, AWS Incident Detection and Response at a minimum of $7K or 2% of aggregated monthly charges in the enrolled accounts.

Exchange between Monthly gross charges, AWS Support, step by step:

  1. Monthly gross charges to AWS Support: First $10K at 9%. Billed on the Time meter, $900.
  2. Monthly gross charges to AWS Support: Next $10K at 7%. Billed on the Time meter, $700.
  3. AWS Support to Monthly gross charges: Invoiced to the account. Billed on the Time meter, $1,600 for the month. (reply)
AWS's own worked example: $20,000 of monthly AWS charges under Business Support+. Nothing was provisioned, nothing can be tagged, and the fee moves whenever any other line on the bill moves.

AWS Shield Advanced is the purest example on any bill: $3,000 per month, per organisation. AWS’s pricing note says the fee “is billed per payer account where that payer account, or at least one linked account, is subscribed”, and you pay it once as long as the payer owns the accounts. The API reference is blunter: for members of an organisation, subscriptions “are billed against the organization’s payer account, regardless of whether the payer account itself is subscribed”. It requires a 1-year subscription commitment and auto-renews annually, and a renewal can be cancelled only between 30 days and 5 days before the renewal date. Data transfer out of protected resources meters on top: AWS’s worked examples price regional data transfer out of an ALB at $0.050 per GB and CloudFront at $0.025 per GB. The subscription also covers up to 50 billion AWS WAF requests per calendar month per subscribed payer ID.

The same shape shows up elsewhere. AWS Billing Conductor uses tiered per-account pricing for accounts placed in a billing group, and AWS says the quiet part out loud: “The number of running resources in your account does not affect your ABC charges.” Across organisations, Billing Transfer is free on an AWS managed pricing plan and $50 per month per AWS organisation on a customer managed one. An Amazon EKS Anywhere Enterprise Subscription is $24,000 per cluster per year on a 1-year term, billed at $2,000 monthly, or $18,000 per cluster per year on a 3-year term, and the cluster runs in your data centre, so the only thing inside AWS is the subscription. AWS Marketplace software lands on the AWS invoice and is distinguishable only by bill/BillingEntity, which reads AWS Marketplace rather than AWS.

Traps

A cost-reduction project cuts its own support bill, and nobody models it. AWS’s Enterprise example puts $750K of monthly charges at a $52K fee. Take $100K out of the top of that and you also remove 7% of it ($7K a month) without touching a workload. It runs the other way for migrations that add spend. Two limits keep it honest: the saving stops at the minimum, so under Enterprise Support the $5,000 floor is what you pay however far you cut, and the base is gross, so a credit reduces the fee by nothing at all.

Naive showback under-reports every team by the same proportion. AWS is explicit that “subscription-based charges, such as AWS Support and AWS Marketplace monthly fees, can’t be allocated”. There is no resource ID to hang a cost allocation tag on, so the sum of your tagged costs will not reconcile to the invoice, and the gap is not random. It is roughly your support percentage plus your untaggable subscriptions. Allocate it deliberately instead. Cost Categories support split charge rules with three methods: proportional to each target’s weighted cost, a fixed percentage per target, or an even split, with an empty string as the source meaning uncategorised. On Enterprise Support the Billing API’s GetEnterpriseSupportChargeSummary returns supportChargePercentage, totalSupportEligibleSpend and a per-account supportCharge, so you can rebuild the allocation from AWS’s own arithmetic rather than estimating it.

Shield Advanced is not a lever you can pull this month. The 1-year commitment makes the answer to “can we switch it off to save money this quarter” no, and the cancellation window is five days wide at the far end of a year. It also has a failure mode that creates cost rather than removing it: an account that leaves the organisation stays subscribed, and because it is no longer in the consolidated billing family it starts incurring its own prorated Shield Advanced fee. An account migration done for governance reasons can quietly open a second $3,000 monthly line.

Support plans do not inherit. A plan on the management account does not cover members; each account subscribes on its own. When a member account that already has a plan joins an organisation, AWS cancels the plan, issues a prorated refund, reactivates it and bills it on the consolidated bill, so the joining month looks wrong in the report and is right on the invoice.

Sources