Posted on Mar 13, 2026 · Updated Mar 13, 2026 · 12 min read
AWS NAT Gateway Pricing: The Ultimate Cost Reduction Guide (2026)
NAT Gateway is quietly one of the most expensive line items on AWS bills. Organizations waste an estimated 27% of total cloud spend on idle or misallocated resources (Flexera 2025 State of the Cloud), and NAT Gateway charges are a consistent top offender. What looks like $0.045 per hour on the pricing page actually costs $0.135 per gigabyte when you add processing and egress fees together.
This guide breaks down exactly how AWS NAT Gateway pricing works, where the hidden charges stack up, and gives you seven concrete strategies to cut your NAT Gateway bill by 50–90%. If your monthly AWS bill has a "VPC" line item that keeps growing, this is where to start.
TL;DR
AWS NAT Gateway costs $0.045/hr + $0.045/GB processing + $0.09/GB egress — a true cost of $0.135/GB for internet-bound traffic. VPC Gateway Endpoints eliminate NAT charges for S3 and DynamoDB traffic entirely at $0 cost (AWS). Most teams can cut NAT costs 50–90% in a week.
Table of contents

How does AWS NAT Gateway pricing actually work?
AWS charges for NAT Gateway across three separate dimensions, and most teams only notice the first one. The hourly charge is $0.045 per hour per gateway — roughly $32.40 per month just to have one running (AWS VPC Pricing). But the hourly fee is usually the smallest part of the bill. It's the per-GB charges that blindside teams.
On top of the hourly rate, AWS charges $0.045 per GB for data processing — every gigabyte that passes through the NAT Gateway. Then there's data transfer (egress) at $0.09 per GB for the first 10 TB per month. These charges stack. A single gigabyte that exits your VPC through a NAT Gateway and leaves AWS costs $0.045 (processing) + $0.09 (egress) = $0.135 total. That's three times what the "data processing" line item alone suggests.
AWS NAT Gateway charges $0.045 per hour ($32.40/month) plus $0.045 per GB of data processed. When egress charges are included, the true per-gigabyte cost reaches $0.135 for internet-bound traffic (AWS VPC Pricing, 2026 ). This triple-layer pricing structure makes NAT Gateway one of the most misunderstood cost drivers on AWS bills.
What catches teams off guard? Cross-AZ data transfer. If your NAT Gateway sits in us-east-1a and your EC2 instance runs in us-east-1b, AWS charges an additional $0.01/GB each way for the inter-AZ hop. That's on top of everything else. A three-AZ deployment with a single NAT Gateway means two-thirds of your traffic incurs this cross-AZ penalty. For a full picture of how these data transfer charges compound across your entire bill, see our complete guide to cloud egress costs.
What does a real NAT Gateway bill look like?
Let's build a realistic example. A mid-size SaaS company runs 20 EC2 instances across three availability zones in us-east-1. They use one NAT Gateway per AZ for high availability. Monthly traffic: 5 TB to S3, 2 TB to external APIs, 1 TB to DynamoDB, 500 GB to ECR, and 500 GB to CloudWatch. Here's what the bill looks like.
The "before" column totals $682 per month. After adding free VPC Gateway Endpoints for S3 and DynamoDB, PrivateLink for ECR and CloudWatch, and consolidating from three NAT Gateways to one (acceptable for this team's HA requirements), the bill drops to $307 per month. That's a 55% reduction. Annualized, it saves $4,500 — and the changes take an afternoon to implement. To see how NAT Gateway fits into the broader picture of AWS charges, read our AWS bill breakdown for startups.
For larger organizations, the numbers get serious fast. A company processing 100 TB per month through NAT Gateway pays $4,500 in processing fees alone. If 40% of that traffic is S3 and DynamoDB, adding free Gateway Endpoints saves $1,800 per month — $21,600 per year — with a Terraform change that takes 15 minutes.
How do VPC endpoints eliminate NAT Gateway charges?
AWS offers two types of VPC endpoints, and they have wildly different pricing. Gateway Endpoints are free. They work with S3 and DynamoDB only. Interface Endpoints (PrivateLink) cost $0.01/hour plus $0.01/GB processed. Knowing when to use each is the difference between eliminating costs and just moving them somewhere else.
Gateway Endpoints are the highest-ROI change you can make. They route S3 and DynamoDB traffic directly from your VPC to the service, bypassing NAT Gateway entirely. No hourly fee, no per-GB charge, no egress. The traffic stays on the AWS backbone. You add a route table entry, update your VPC configuration, and you're done. There's genuinely no reason not to have these in every VPC. For the DynamoDB side of the bill itself — On-Demand vs Provisioned capacity, Global Tables replication, DAX — see our DynamoDB pricing guide.

AWS VPC Gateway Endpoints for S3 and DynamoDB cost $0 per hour and $0 per GB of data transferred, compared to NAT Gateway's $0.045/hr + $0.045/GB charges (AWS VPC Pricing, 2026 ). For a typical production account routing 5 TB/month to S3, switching to a Gateway Endpoint saves $225/month with zero application code changes.
Interface Endpoints are trickier. They create an elastic network interface in your subnet, and they cost $0.01/hour ($7.20/month) plus $0.01/GB. Whether they save money depends on volume. For services like ECR, CloudWatch Logs, SQS, and Secrets Manager, Interface Endpoints are cheaper than NAT Gateway when traffic exceeds roughly 160 GB per month per service. Below that threshold, the hourly cost of the endpoint outweighs the per-GB savings.
Here's the math: NAT Gateway charges $0.045/GB. An Interface Endpoint charges $7.20/month fixed + $0.01/GB. The breakeven point is $7.20 ÷ ($0.045 - $0.01) = ~206 GB/month. If a service handles more than 206 GB/month through the endpoint, PrivateLink saves money. Below that, NAT Gateway is cheaper per-service — but remember, NAT Gateway charges accumulate across all services.
Seven strategies to cut NAT Gateway costs by 50–90%
Not every strategy applies to every environment. This list is ordered by effort-to-impact ratio — start at the top and work down. For a broader checklist of cost reduction actions beyond networking, the cloud cost optimization checklist covers compute, storage, and commitment discounts as well. According to Flexera's 2025 State of the Cloud report, organizations waste 27% of cloud spend, with networking charges being a consistent top contributor (Flexera, 2025 ). NAT Gateway is often the single largest networking cost.
1. Add VPC Gateway Endpoints for S3 and DynamoDB
This is the single highest-impact, lowest-effort change. Gateway Endpoints are free. They take 5 minutes to create in the console or one Terraform resource. Every VPC in your organization should have them. If you do nothing else from this article, do this.
2. Audit your NAT Gateway traffic with VPC Flow Logs
Before optimizing further, you need to know where your traffic goes. Enable VPC Flow Logs on your NAT Gateway's elastic network interface. Filter for the NAT Gateway's private IP. You'll see exactly which instances generate the most traffic and which destinations receive it. Don't guess — measure.
3. Add Interface Endpoints for high-traffic AWS services
For CloudWatch Logs, ECR, SQS, SNS, Secrets Manager, and KMS: if any of these services handles more than 200 GB per month, an Interface Endpoint costs less than NAT Gateway. Prioritize ECR (container image pulls add up fast) and CloudWatch Logs (every service ships logs).
4. Consolidate NAT Gateways where HA isn't critical
Running three NAT Gateways (one per AZ) costs $97.20/month in hourly fees alone. If your workload can tolerate brief connectivity loss during an AZ failure, a single NAT Gateway cuts the hourly cost to $32.40. Dev and staging environments almost never need per-AZ NAT Gateways.
5. Move public-facing workloads to public subnets
Services that need internet access — load balancers, bastion hosts, CI runners — don't need NAT Gateway at all if they sit in a public subnet with an Internet Gateway. Every service you move out of private subnets reduces NAT traffic. This requires security group discipline, but the cost savings are immediate.
6. Implement egress-aware caching
If your application makes repeated calls to external APIs or downloads the same S3 objects frequently, add a caching layer. A small ElastiCache Redis instance costs $12/month and can eliminate hundreds of gigabytes of repeated NAT Gateway traffic. Container image layer caching for ECR is another quick win.
7. Set up cost anomaly alerts on NAT Gateway
NAT Gateway costs spike silently. A runaway log forwarder, a misconfigured health check, or an aggressive API polling loop can triple your NAT bill overnight. Set up AWS Cost Anomaly Detection specifically for the VPC service category. Catch surprises before they hit your monthly bill.

What's the right NAT architecture for your workload?
There's no single correct NAT architecture. The right choice depends on three factors: availability requirements, traffic volume, and budget constraints. The Kubernetes container market is projected to reach $10.4 billion by 2027 (Fortune Business Insights, 2025 ), which means NAT Gateway traffic will keep growing as more workloads move to private subnets.
For production workloads with strict uptime SLAs, one NAT Gateway per AZ is the standard recommendation. This ensures an AZ failure doesn't break internet connectivity for instances in other zones. But the hourly cost scales linearly — three AZs means 3x the base cost. Four AZs means 4x.
For dev, staging, and non-critical environments, a single NAT Gateway in one AZ is usually sufficient. If that AZ goes down, your dev environment loses internet connectivity — but it was probably going to be disrupted anyway. The savings are significant: $64.80 per month per environment for a three-AZ setup.
For batch processing and data pipelines, consider NAT instances instead of NAT Gateways. A t3.micro NAT instance costs roughly $7.50 per month compared to $32.40 for a NAT Gateway. It's less resilient and has lower throughput (up to 5 Gbps vs. 100 Gbps), but for batch jobs that run for a few hours per day, the cost difference is substantial.
Organizations waste 27% of cloud spend according to the Flexera 2025 State of the Cloud report, with networking charges being a persistent contributor (Flexera, 2025 ). NAT Gateway is a top networking cost driver because its triple-layer pricing model — hourly + processing + egress — compounds silently as traffic grows.
The bottom line: audit your NAT traffic first. You can't optimize what you can't see. Most teams find that 40–60% of their NAT Gateway traffic is to AWS services that offer free or cheaper endpoint alternatives. Start there, then evaluate architecture changes for the remaining traffic.
Frequently asked questions
How much does AWS NAT Gateway cost per month?
A single NAT Gateway costs $32.40/month in hourly fees ($0.045/hr × 720 hours). Add data processing at $0.045/GB and data transfer (egress) at $0.09/GB for the first 10 TB. A typical production setup with 3 AZs and 5 TB/month of traffic costs $322–$680/month depending on traffic destinations and endpoint configuration.
Are VPC Gateway Endpoints really free?
Yes. VPC Gateway Endpoints for S3 and DynamoDB have no hourly charge and no data processing fee (AWS VPC Pricing). They route traffic directly from your VPC to the service over the AWS backbone. Interface Endpoints (PrivateLink) for other services cost $0.01/hr + $0.01/GB — cheaper than NAT Gateway for high-traffic services.
Should I use a NAT instance instead of NAT Gateway?
NAT instances cost less ($7.50/month for t3.micro vs. $32.40 for NAT Gateway) but offer lower throughput (5 Gbps vs. 100 Gbps) and no built-in redundancy. They're suitable for dev environments, batch workloads, and low-traffic accounts. For production workloads requiring high availability and throughput, NAT Gateway is the standard choice.
How do I find out what's using my NAT Gateway?
Enable VPC Flow Logs on the NAT Gateway's elastic network interface. Filter logs by the NAT Gateway's private IP to see source instances and destination IPs. AWS Cost Explorer can show NAT Gateway charges by usage type. Third-party tools like Vantage and SpendArk can break down NAT costs by service destination.
How much can I save by optimizing NAT Gateway?
Most teams save 50–90% on NAT Gateway costs. Free VPC Gateway Endpoints typically eliminate 35–45% of NAT traffic (S3 + DynamoDB). Architecture changes like consolidating gateways save another 15–20%. Interface Endpoints for high-traffic services add 10–15%. Combined, these strategies reduce annual NAT costs by thousands to tens of thousands of dollars depending on traffic volume.
Estimate your cloud costs — for free
Compare AWS, Azure, and GCP pricing side by side with our free calculator, and dig into the guides to learn how to cut cloud waste. No sign-up required.
