Posted on Mar 22, 2026 · Updated Mar 22, 2026 · 11 min read
The $500/mo AWS Bill: Where Small Startups Actually Spend
You're a few months into your SaaS. A handful of paying users, maybe a small team. Your AWS bill just crossed $500 and you're staring at Cost Explorer wondering where it went. The line items are cryptic: "EC2-Other," "DataTransfer-Out-Bytes," "NatGateway-Hours." None of it maps to what you actually built.
This post translates a realistic $500/month AWS bill into plain language — every line item, what it is, why it costs that, and how much is waste you can cut today. We also show what happens at $1K, $2K, and $5K per month, because the composition changes in ways most founders don't expect. Industry data puts cloud waste at 27% of total spend on average (Flexera, 2025) — on a $500 bill, that's $135 running for no reason.
TL;DR
A typical $500/mo AWS bill for a small SaaS breaks down as: EC2 $180, RDS $120, Data Transfer $45, EBS $30, NAT Gateway $32, Load Balancer $25, S3 $25, CloudWatch $18, Other $25. Of that, $100-150 is likely waste — idle compute, oversized databases, and networking charges that VPC endpoints would eliminate. Costs don't scale linearly: the $1K bill is mostly the same shape, but $2K+ starts requiring architectural decisions.
Table of contents
The $500/mo bill, line by line
A typical $500/month AWS bill for a small SaaS breaks down as: EC2 $180, RDS $120, data transfer $45, EBS $30, NAT Gateway $32, load balancer $25, S3 $25, CloudWatch $18, other $25 — with $100–150 of that being removable waste (Flexera State of the Cloud, 2025). The workload below is a single production web app with a managed database, object storage, standard VPC networking, and basic observability. Not a toy. Not enterprise. The setup a 2–5 person startup runs after their first paying customers, before anyone has thought hard about infrastructure cost.
Compute and database together are $300 of the $500. Expected. But networking (NAT Gateway + data transfer) lands at $77 — more than most founders budget for. S3 at $25 and CloudWatch at $18 look minor, but both compound over time. "Other" is a catch-all that usually hides Secrets Manager entries, Route 53 hosted zones, and forgotten test resources.
EC2 — $180 (36%)
EC2 is the largest line item on virtually every startup AWS bill, and 30–40% of it is typically waste. At $500/month, $180 covers one or two production servers plus a dev or staging instance that never got shut down. In us-east-1, a t3.medium (2 vCPU, 4 GB RAM) costs $0.0416/hr on-demand — about $30/month. A t3.large is $59/month. Two of those plus a t3.small dev box ($15/month) puts you at $133. Add Elastic IPs ($3.65/month each after the first, charged since February 2024 per the AWS IPv4 pricing update) plus EC2-Other charges and $180 is easy to reach.
Why it costs that: EC2 bills whether your instances are busy or idle. That dev box left running "just in case" costs the same at 2% CPU as it does at 80%. Most startups at this tier have two or three instances averaging below 10% CPU — paying full price for headroom they never use.
How to reduce it: Pull average CPU utilization from CloudWatch for every running instance. Anything below 10% over two weeks is a rightsizing or shutdown candidate. Switching stable production servers from on-demand to 1-year Reserved Instances saves 30–40% immediately. A t3.large RI drops from $59/month to roughly $37/month. That one decision saves $40–50/month. For a full comparison of pricing models, see our reserved vs spot vs on-demand guide.
Quick win
Schedule your staging environment off nights and weekends using AWS Instance Scheduler or a Lambda cron. A t3.medium running 60 hours a week instead of 168 drops from $30/month to $15 — $180/year saved for zero architectural change.
RDS — $120 (24%)
RDS is the second-largest cost and the one founders most consistently overprovision. A db.t3.medium running Multi-AZ in us-east-1 costs about $96/month. Single-AZ is $48/month. Add 100 GB of gp2 storage ($11.50/month) and automated backups beyond the free tier, and $120 is reachable with room to spare.
Why it costs that: Multi-AZ doubles your instance cost. AWS runs a synchronous standby replica in a second availability zone. For most startups at $500/month, that's not a requirement — it's a default that nobody turned off. Your app probably doesn't have an SLA requiring sub-30-second automatic failover. A few minutes of manual recovery costs nothing. Multi-AZ costs $576/year.
How to reduce it: Disable Multi-AZ if you can tolerate brief manual failover. Switch gp2 storage to gp3 — same baseline performance, 20% cheaper. For a database that's genuinely idle most of the day (common in early-stage apps), Aurora Serverless v2 scales to near-zero when inactive. One caveat: Aurora has a minimum ACU charge, so it only pays off if your DB sits idle for long stretches.
The Multi-AZ question
At $500/mo total AWS spend, you almost certainly don't need Multi-AZ RDS. That's a $48/month decision — $576/year — for failover automation that only matters if customers would churn over a 5-minute outage. Most early startups are not in that position.
Data Transfer — $45 (9%)
Data transfer is the most misunderstood line item on any AWS bill. The $45 breaks into three buckets: outbound internet traffic ($0.09/GB after the first GB), cross-AZ traffic within your VPC ($0.01/GB each direction), and S3-to-EC2 traffic that many apps accidentally route through the internet instead of a free VPC endpoint. At $45/month, you're generating roughly 400 GB of outbound internet traffic, or a mix of 200 GB internet and substantial cross-AZ internal traffic.
One fact most guides skip: CloudFront egress to the internet costs $0.0085/GB at its cheapest tier, vs. EC2's $0.09/GB — a 10x gap on the same bytes. If you serve static assets directly from EC2, you're leaving that saving on the table.
How to reduce it: The biggest single lever is VPC Gateway Endpoints for S3 and DynamoDB. They route traffic through AWS's private network, eliminating both the data transfer charge and the NAT Gateway processing fee on that traffic. Takes 10 minutes. Costs nothing. For apps that read S3 heavily, this saves $15–30/month at this spend level.
EBS — $30 (6%)
EBS is persistent disk storage attached to EC2 instances. You pay for provisioned capacity, not used capacity. A 200 GB gp3 volume costs $16/month. Two volumes plus snapshot storage and an old 100 GB gp2 volume from a terminated instance that nobody deleted adds up to $30 quickly.
Why it costs that: EBS volumes persist after an instance is terminated. Root volumes are deleted by default, but secondary volumes attached manually are not. They continue billing indefinitely. A forgotten 200 GB volume costs $16/month until someone runs a cleanup. Most teams at this spend level have at least one or two of these.
How to reduce it: Go to EC2 > Volumes, filter for "available" state. Every unattached volume is a deletion candidate. Check snapshots too — at $0.05/GB, weekly snapshots of a 500 GB volume accumulate fast. Set a Data Lifecycle Manager policy to automatically expire old snapshots.
NAT Gateway — $32 (6.4%)
NAT Gateway is the charge that generates the most "wait, what is this?" reactions. It costs $0.045/hour just to exist — $32.40/month before a single byte flows through it. On top of that, you pay $0.045 per GB processed. NAT Gateways let private subnet resources reach the internet without being directly exposed to inbound connections. For a full breakdown of how AWS NAT Gateway pricing works, see our dedicated guide.
Why it costs that: Private subnets require a NAT Gateway for outbound internet access. The problem: many startups also route S3 and DynamoDB traffic through the NAT Gateway, paying $0.045/GB on traffic that could flow for free through VPC endpoints. That avoidable data processing fee often adds $10–20/month.
How to reduce it: You can't eliminate the hourly charge if you have private subnets that need internet access. But you can cut the data processing fee on AWS-internal traffic. Set up VPC Gateway Endpoints for S3 and DynamoDB — free, and they bypass the NAT Gateway entirely. For very small teams whose app doesn't strictly need private subnets, public subnets with tight security groups can eliminate the NAT Gateway altogether, saving $32/month on a $500 bill.
Load Balancer — $25 (5%)
An Application Load Balancer (ALB) costs $0.008/hour ($5.76/month) plus $0.008 per LCU processed. At low traffic, the fixed hourly charge dominates — you're mostly paying for the ALB to exist. At $25/month, you have one ALB running full-time with modest LCU charges.
Why it costs that: An ALB is essentially required once you run multiple EC2 instances or want HTTPS termination without managing certificates per server. For a simple app on a single EC2 instance, you may not need one at all — a free ACM certificate with a direct Elastic IP works, though it limits scaling options later. The real question: does your traffic volume actually justify the ALB yet?
How to reduce it: If multiple staging environments each have their own ALB, consolidate them behind one using host-based routing rules. One ALB can serve dozens of environments. Unused target groups and listeners don't cost extra, but they signal configuration drift that often comes packaged with orphaned resources that do cost money.
S3 — $25 (5%)
S3 pricing has three components: storage ($0.023/GB/month for standard tier), requests (PUT/GET/LIST), and data transfer out. At $25/month, you're likely storing around 500 GB with heavy GET traffic for user-facing assets, or less storage with significant outbound transfer.
How to reduce it: Enable S3 Intelligent-Tiering for buckets where objects are not accessed daily. Objects inactive for 30 days move automatically to infrequent access ($0.0125/GB vs. $0.023/GB — 46% savings on cold data). For user uploads older than 90 days, a lifecycle policy transitioning to Glacier Instant Retrieval drops storage to $0.004/GB. Put CloudFront in front of S3 for public assets — it cuts both GET request charges and data transfer at any meaningful traffic volume.
CloudWatch — $18 (3.6%)
CloudWatch charges for custom metrics ($0.30/metric/month after the first 10), log ingestion ($0.50/GB), log storage ($0.03/GB/month), and dashboard widgets ($3/dashboard/month). At $18/month you likely have a few dashboards, reasonable log volume, and some custom application metrics. It's one of the easiest costs to overpay without noticing — every service that logs to CloudWatch Logs adds to your ingestion bill.
How to reduce it: Set retention policies on every CloudWatch Logs group. Default retention is infinite. A 30-day policy on application logs and a 7-day policy on access logs cuts storage costs significantly. Also audit log verbosity — many frameworks default to DEBUG level in production, generating 10x the volume of INFO-only logging for zero operational benefit.
The log retention trap
New CloudWatch Logs groups are created with infinite retention. AWS services like Lambda, ECS, API Gateway, and VPC Flow Logs each create their own log groups automatically. At $0.03/GB/month, a year of high-volume logs can quietly grow into a real recurring charge. Audit your log groups and set explicit retention windows before the bill reflects it.
Where the waste hides ($100-150)
Of a typical $500/month AWS bill, $100–150 is waste — resources running that serve no meaningful purpose. Flexera's 2025 State of the Cloud Report puts average cloud waste at 27% of total spend (Flexera, 2025). Here's where those dollars typically hide.
Idle or oversized EC2 ($35–50/mo): The staging server running 24/7. The instance sized up "just in case" that never got downsized. The dev box for the engineer who left. Each is $15–30/month. Most teams at $500/month have at least two.
Multi-AZ RDS when it's not needed ($25–48/mo): The single most expensive unnecessary line item at this spend level. Disabling Multi-AZ on a db.t3.medium cuts your RDS bill roughly in half. If you enabled it because the AWS console suggested it and you've never tested what an actual RDS failover means for your app, revisit it today.
NAT Gateway processing on AWS-internal traffic ($10–20/mo): Every byte from EC2 to S3 through the NAT Gateway costs $0.045/GB. A VPC Gateway Endpoint routes that traffic for free. If your app reads S3 frequently — serving images, processing uploads, reading config — this is a zero-downtime win you can deploy in under 15 minutes.
Unattached EBS volumes and old snapshots ($10–25/mo): The graveyard of old test instances and resize experiments. Monthly audit: EC2 > Volumes, filter "available," delete what you don't recognize. Then EC2 > Snapshots, sort by date, remove anything older than your retention window.
Forgotten test resources ($5–15/mo): Elastic IPs not attached to a running instance ($3.65/mo each), unused Route 53 hosted zones ($0.50/mo plus query charges), old Lambda functions with their own CloudWatch Logs groups accumulating storage, Secrets Manager entries no one has accessed in months. Small individually. Together they add up.
Total: $100–150 of the $500 bill is legitimately removable without touching your application. That is the typical result of a first real cost audit on a small AWS account. For a line-by-line walkthrough before you start, our guide to reading your AWS bill covers every charge in plain language.
What happens at $1K, $2K, and $5K/mo
AWS costs do not scale linearly with users. A startup doubling from $1K to $2K/month may have grown only 30% in actual user load — the rest is architectural decisions compounding. The composition of your bill changes at each tier, and so do the relevant cost levers. Here is what typically shifts.
$1,000/month: Mostly the same bill, bigger numbers
A $1K bill is rarely a different architecture — it's the same setup scaled up. You've added another EC2 instance, upgraded to a db.t3.large, or traffic grew and data transfer doubled. Waste patterns are identical. The checklist above applies directly. At this level, a thorough cleanup can realistically save $200–250/month.
$2,000/month: Architecture decisions start mattering
At $2K, the bill shifts. You're likely running multiple AZs for real now — not just the Multi-AZ RDS checkbox — meaning cross-AZ data transfer charges become material. You may have added ElastiCache (~$25/month for a cache.t3.micro), message queues, and more CloudWatch custom metrics. RDS storage costs grow with your dataset: gp2 is $0.115/GB, gp3 is $0.10/GB.
This is where Reserved Instance decisions become financially significant. At $2K/month in compute, buying 1-year RIs for stable production instances saves $500–600/year. One hour of analysis. Recurring savings.
$5,000/month: New cost categories emerge
A $5K bill looks structurally different. You're likely running containers — ECS or EKS. EKS charges $0.10/hour per cluster ($73/month). Fargate adds compute on top. Data transfer at this scale runs $500–800/month. Multiple environments each with their own databases and NAT Gateways multiply fixed-cost overhead. Savings Plans, more flexible than RIs, become worth modeling carefully at this tier.
The key insight: bill growth is not purely a function of user growth. Architectural decisions — Multi-AZ, internal traffic routing, 24/7 environments — create step-function cost increases with no corresponding user increase. You can spend $5K/month on an app used by a few hundred people if the architecture is inefficient enough.
Get your own breakdown automatically
Reading a breakdown for a hypothetical $500 bill is useful. Seeing your actual bill broken down this way is far more useful. The problem is that AWS Cost Explorer groups charges in ways that require significant manual work to translate into "what is this and do I actually need it."
To put numbers behind that translation, SpendArk's free calculator lets you model this same setup across AWS, Azure, and GCP — so you can see what each pieceshould cost, test a rightsizing or VPC-endpoint change, and compare providers. No manual Cost Explorer archaeology, no spreadsheet.
It's free and needs no account. Pair it with the native tools (AWS Cost Explorer, AWS Compute Optimizer) to spot idle and oversized resources in what's already running. For a team at $500+/month, finding $100–150 in waste this way is common and costs nothing.
Fewer line items to decode in the first place
If cryptic entries like EC2-Other and NatGateway-Hours are the problem, these providers bundle compute, storage, and bandwidth into far fewer, easier-to-read charges.
- DigitalOcean — flat-priced droplets and managed databases with a bill you can read in under a minute.
- Hetzner — unbeatable price/performance for compute once you outgrow free tiers, with simple per-instance pricing.
- Vultr — global low-cost VPS sizes with predictable monthly costs instead of a dozen metered line items.
Some provider links above are affiliate links — we may earn a commission at no extra cost to you. It never affects our pricing data.
Frequently asked questions
What is a normal AWS bill for a startup?
Most early-stage startups (pre-revenue to first paying customers) spend $100-$500/month on AWS. Post-product-market-fit with a growing user base typically runs $500-$2,000/month. Series A companies often spend $2,000-$10,000/month depending on data volume and architecture choices. What matters more than the absolute number is whether your bill is growing proportionally to your user or revenue growth — if it's growing faster, something is misconfigured.
How much of my AWS bill is typically waste?
Industry estimates consistently put cloud waste at 25-32% of total spend. Flexera's 2025 State of the Cloud Report puts it at 27% on average. For startups specifically, waste tends to be higher in the $200-$1,000/month range because infrastructure was set up quickly without cost optimization in mind and rarely audited. Running a first audit on a $500/month account typically surfaces $100-150 in genuinely removable spend.
What is the biggest hidden cost on AWS for small teams?
NAT Gateway is consistently the most surprising charge. The $32/month fixed cost to have it exist is invisible until you look for it, and the data processing charge compounds on top. Data transfer in general — cross-AZ traffic, S3 egress, internet outbound — is the second biggest surprise. Most founders budget for compute and database but underestimate networking costs by 50-100%.
Should I use Reserved Instances at $500/month?
It depends on how stable your instance types are. A 1-year No Upfront Reserved Instance for a t3.large saves about 37% vs on-demand in us-east-1 — roughly $22/month per instance. If you're confident you'll run the same instance type for 12 months, yes. If you're still experimenting with sizing, wait. Convertible RIs offer more flexibility but smaller discounts. Savings Plans can be a better choice if your compute mix is likely to change.
Why is my AWS data transfer bill so high?
Three common reasons: (1) your EC2 instances are sending data to S3 via the internet instead of a VPC endpoint — fix by creating a free VPC Gateway Endpoint for S3; (2) your application architecture puts services in different availability zones without accounting for cross-AZ data transfer ($0.01/GB each direction); (3) you're serving large files directly from EC2 rather than CloudFront, paying $0.09/GB instead of $0.0085/GB on the same bytes.
Estimate your cloud costs — for free
Compare AWS, Azure, and GCP pricing side by side with our free calculator, and dig into the guides to learn how to cut cloud waste. No sign-up required.