Security, GRC, and regulated teams
The audit asks what your posture was in March, and the console only knows what it is today.
Continuous posture data against CIS, NIST 800-53 r5, FedRAMP Moderate, FedRAMP High, CMMC L2, PCI DSS 4 — with a rule engine pure enough that a new rule replays over historical snapshots.
AWS Foundational Security Best Practices is the floor and is never replaced. CIS, NIST 800-53 r5, FedRAMP Moderate, FedRAMP High, CMMC L2, PCI DSS 4 layer on top of it. A framework gets a CSPM standard or a Config conformance pack — never both, because both bill separately for the same evaluations.
The two share an evidence layer and deliberately share nothing else. Letting a compliance pack move an architecture score would make both numbers mean less.
The rule engine is pure — snapshot in, findings out, no AWS calls and no clock. That is what lets a rule written today replay over the snapshot archive and report how long a condition has existed, rather than only seeing it from its deploy date forward.