AWS Security Hub Extended adds supply chain security as its 10th category
AWS Security Hub Extended now includes Supply Chain Security as its 10th category, adding Chainguard and Socket as curated partners to detect malicious open-source dependencies before deployment.
AWS Security Hub Extended has introduced Supply Chain Security as its tenth category, integrating Chainguard and Socket as curated partners. This addition addresses growing concerns over malicious open-source dependencies by enabling security teams to identify and block risks before they are embedded in applications. The feature operates under the same pay-as-you-go pricing model as other Extended categories, with no long-term commitments required. All solutions are billed through a single AWS invoice, streamlining procurement and management for enterprises.
Security Hub Extended consolidates endpoint, identity, email, network, data, browser, cloud, AI, security operations, and now supply chain security into a unified platform. Findings from all participating solutions, including the new partners, are automatically aggregated in AWS Security Hub using the Open Cybersecurity Schema Framework (OCSF). This integration allows security teams to correlate risks across multiple domains, improving visibility and response capabilities without requiring additional tools or integrations.
The two new curated partner solutions—Chainguard and Socket—are available immediately in all AWS commercial Regions where Security Hub is supported. Customers can activate these solutions through the AWS Security Hub console or product page, with pricing details accessible via the AWS Security Hub pricing page. The addition brings the total number of curated partner solutions in the Extended plan to 23, reflecting AWS’s ongoing effort to expand its security ecosystem based on customer demand.
AWS plans to continue expanding the Extended plan’s capabilities, incorporating additional curated partners and security categories in response to feedback. The Supply Chain Security category joins existing protections to provide a more comprehensive security posture for enterprises. Organizations can begin leveraging these features today, with no upfront costs or long-term obligations, aligning with AWS’s pay-as-you-go pricing model.