On this page · 10 sections
Most AWS cost advice is a pile of tips. A checklist is more useful, because you can work down it, mark each item done or not applicable, and repeat it next quarter. This one has thirty checks in five groups, ordered roughly from low effort and low risk to higher effort. Pricing facts come from AWS's own pages and vary by region, so confirm yours.
Before You Start: Visibility
- Group spend by service, linked account and usage type in Cost Explorer for the last three months, and find the five biggest line items.
- Turn on detailed billing data (Data Exports) so you can query line items later.
- Activate cost allocation tags for team, environment and application. Tags are not retroactive, so do this first.
- Set budgets with alerts per account or team, and enable Cost Anomaly Detection.
Compute
- Find idle instances. Look for sustained near-zero CPU and network over several weeks, then stop or terminate with the owner's approval.
- Rightsize oversized instances. Use Compute Optimizer and your own monitoring; test downsizing in non-production first.
- Schedule non-production. Stop dev, test and staging outside working hours.
- Evaluate Graviton. AWS states Graviton-based instances cost up to 20% less than comparable x86 instances. Start with your biggest steady Linux workloads.
- Use Spot for interruptible work. Batch, CI runners and stateless workers tolerate interruption.
- Check Lambda memory and duration settings. Memory size drives both speed and cost, so tune it with real invocations.
- Review autoscaling policies. Minimum sizes set for a past peak keep paying for capacity.
Storage
- Convert gp2 to gp3. AWS lists gp3 at up to 20% lower price per GB ($0.08 versus $0.10 per GB-month in US East) with 3,000 IOPS and 125 MB/s baseline.
- Delete unattached volumes after owner sign-off.
- Expire orphaned snapshots and set lifecycle policies on the rest.
- Add S3 lifecycle rules or Intelligent-Tiering for rarely read data.
- Clean up incomplete multipart uploads and old object versions.
- Set retention on every CloudWatch log group. The default is to keep data forever.
Network and Data Transfer
- Audit NAT gateways. At $0.045 per hour plus $0.045 per GB (US East, Ohio), they add up. Consolidate where safe.
- Add gateway VPC endpoints for S3 and DynamoDB. AWS lists no hourly or data processing charge for gateway endpoints.
- Release idle public IPv4 addresses. AWS charges $0.005 per hour for every public IPv4 address, in use or idle.
- Find cross-AZ and cross-region traffic by usage type and decide whether the architecture needs it.
- Remove idle load balancers with no healthy targets or traffic.
Databases
- Rightsize RDS instances with sustained low CPU and memory.
- Review storage type and Provisioned IOPS. Many volumes carry IOPS they never use.
- Stop or snapshot-and-delete idle databases in non-production.
- Check backup retention and manual snapshots that outlive their purpose.
Commitments and Governance
- Commit last. Size Savings Plans or Reserved Instances to the steady baseline after cleanup. AWS lists up to 66% and up to 72% maximum savings for Compute and EC2 Instance Savings Plans, so expect less. See our commitment guide.
- Track commitment utilization and coverage monthly so unused commitments do not hide.
- Enforce tagging and ownership on new resources, with an expiry date for non-production.
- Review the support plan and Marketplace subscriptions against what you actually use.
How to Use the Checklist
- First pass (week one): checks 1 to 4, then the low-risk deletions and conversions (13, 14, 17, 20, 22).
- Second pass (weeks two to four): compute and database rightsizing, storage lifecycle and data transfer review.
- Quarterly: commitments, Graviton candidates and architecture-level changes.
Work with owners, not around them: every deletion should name a person who approved it. Our hidden AWS savings guide sizes the biggest leaks with worked examples, and why is my AWS bill so high covers diagnosing a sudden jump.
Five Mistakes That Undo the Savings
- Committing before cleaning up. A Savings Plan sized to a wasteful baseline locks the waste in for years.
- Deleting without an owner's sign-off. A "unused" volume is sometimes the only copy of something. Ask, then act, and keep a snapshot where it is cheap to do so.
- Optimizing one account. Waste concentrates in the accounts nobody reviews. Run the checklist across the whole organization.
- Treating it as a project. New resources arrive weekly. Without continuous detection the bill drifts back within a quarter.
- Reporting savings loosely. Keep realized savings, avoided cost and identified opportunities as separate numbers so finance trusts the total.
Automate the Repetition
A checklist run by hand decays, because new resources arrive every week. Varcio's AWS cost optimization runs 102 AWS detectors continuously and turns findings into ranked, costed actions with approval gates, dry runs and audit trails. Talk to our team for a baseline of your own account.
Frequently asked questions
What is the first thing to check when optimizing AWS costs?
Start with visibility: group last month's spend by service and by linked account in Cost Explorer so you know where the money goes. Then work the low-risk items first: unattached volumes, idle load balancers and IPs, gp2 to gp3 conversion, log retention and non-production schedules.
How often should I run an AWS cost optimization review?
Run a light review weekly (anomalies, new idle resources), a deeper review monthly (rightsizing, storage, data transfer) and a commitment review quarterly. Continuous detection is better than periodic reviews because waste returns as soon as teams ship new resources.
Should I buy Savings Plans before or after cleaning up waste?
After. Commitments lock in a baseline for one to three years, so remove waste and rightsize first, then commit to the steady usage that remains. AWS lists savings of up to 66% for Compute Savings Plans and up to 72% for EC2 Instance Savings Plans versus On-Demand, but those are maximums.
Can AWS cost optimization be automated?
Detection can be fully automated, and many fixes can be too, with approvals and audit trails for anything risky. Varcio runs 102 AWS detectors continuously and applies approved fixes with dry runs and before-and-after records.