Posted on Mar 13, 2026 · Updated Mar 13, 2026 · 12 min read

AWS NAT Gateway Pricing: The Ultimate Cost Reduction Guide (2026)

NAT Gateway is quietly one of the most expensive line items on AWS bills. Organizations waste an estimated 27% of total cloud spend on idle or misallocated resources (Flexera 2025 State of the Cloud), and NAT Gateway charges are a consistent top offender. What looks like $0.045 per hour on the pricing page actually costs $0.135 per gigabyte when you add processing and egress fees together.

This guide breaks down exactly how AWS NAT Gateway pricing works, where the hidden charges stack up, and gives you seven concrete strategies to cut your NAT Gateway bill by 50–90%. If your monthly AWS bill has a "VPC" line item that keeps growing, this is where to start.

TL;DR

AWS NAT Gateway costs $0.045/hr + $0.045/GB processing + $0.09/GB egress — a true cost of $0.135/GB for internet-bound traffic. VPC Gateway Endpoints eliminate NAT charges for S3 and DynamoDB traffic entirely at $0 cost (AWS). Most teams can cut NAT costs 50–90% in a week.

Network infrastructure cables and connections in a modern data center rack

How does AWS NAT Gateway pricing actually work?

AWS charges for NAT Gateway across three separate dimensions, and most teams only notice the first one. The hourly charge is $0.045 per hour per gateway — roughly $32.40 per month just to have one running (AWS VPC Pricing). But the hourly fee is usually the smallest part of the bill. It's the per-GB charges that blindside teams.

On top of the hourly rate, AWS charges $0.045 per GB for data processing — every gigabyte that passes through the NAT Gateway. Then there's data transfer (egress) at $0.09 per GB for the first 10 TB per month. These charges stack. A single gigabyte that exits your VPC through a NAT Gateway and leaves AWS costs $0.045 (processing) + $0.09 (egress) = $0.135 total. That's three times what the "data processing" line item alone suggests.

The True Cost of 1 GB Through NAT GatewayPer-GB charges stack — most teams only see the first one$0.00$0.045$0.135Processing Only(what you expect)$0.045Processing + Egress(what you actually pay)$0.045$0.045$0.045Egress (internet)Cross-AZ transferNAT processing3xhigherSource: AWS VPC Pricing (us-east-1), March 2026
Most engineers see the $0.045/GB processing fee and miss the additional egress charges that triple the real cost per gigabyte.

AWS NAT Gateway charges $0.045 per hour ($32.40/month) plus $0.045 per GB of data processed. When egress charges are included, the true per-gigabyte cost reaches $0.135 for internet-bound traffic (AWS VPC Pricing, 2026 ). This triple-layer pricing structure makes NAT Gateway one of the most misunderstood cost drivers on AWS bills.

What catches teams off guard? Cross-AZ data transfer. If your NAT Gateway sits in us-east-1a and your EC2 instance runs in us-east-1b, AWS charges an additional $0.01/GB each way for the inter-AZ hop. That's on top of everything else. A three-AZ deployment with a single NAT Gateway means two-thirds of your traffic incurs this cross-AZ penalty. For a full picture of how these data transfer charges compound across your entire bill, see our complete guide to cloud egress costs.

Where do the hidden NAT Gateway costs come from?

The single biggest source of unnecessary NAT Gateway cost is AWS-to-AWS traffic that doesn't need to touch the internet at all. S3 API calls, DynamoDB reads, CloudWatch log pushes, ECR image pulls — all of these route through NAT Gateway by default in a private subnet. And every byte gets charged at the full processing rate.

Consider a typical data pipeline. It reads from S3, processes data on EC2, writes results to DynamoDB, and pushes metrics to CloudWatch. Every one of those API calls goes through NAT Gateway unless you've explicitly set up VPC endpoints. A team processing 10 TB per month through this pipeline pays $450 in NAT processing fees alone — for traffic that never leaves AWS.

Close-up of tangled server network cables illustrating complex cloud infrastructure routing
Where NAT Gateway Traffic Actually GoesTypical breakdown for a production AWS account0%25%50%S3 traffic35%free with endpointCloudWatch20%PrivateLink availableECR pulls15%PrivateLink availableExternal APIs12%requires NATDynamoDB10%free with endpointOther AWS8%~45% of NAT traffic can be eliminated with free VPC Gateway EndpointsSource: Aggregate patterns from AWS Well-Architected reviews, Vantage (2025)
Nearly half of all NAT Gateway traffic is to S3 and DynamoDB — services that offer free VPC Gateway Endpoints.

VPC Gateway Endpoints for S3 and DynamoDB cost $0 and eliminate NAT Gateway processing charges for traffic to those services (AWS, 2026 ). Since S3 and DynamoDB typically account for 35–45% of NAT Gateway traffic in production AWS accounts, this single change can cut NAT costs by nearly half with zero application changes.

Log shipping is the other silent killer. Every CloudWatch PutLogEvents call, every Kinesis stream write, every SQS message — they all transit NAT if you haven't configured Interface VPC Endpoints. A busy microservices deployment pushing 500 GB of logs per month pays $22.50 in unnecessary NAT processing for traffic that stays entirely within AWS.

What does a real NAT Gateway bill look like?

Let's build a realistic example. A mid-size SaaS company runs 20 EC2 instances across three availability zones in us-east-1. They use one NAT Gateway per AZ for high availability. Monthly traffic: 5 TB to S3, 2 TB to external APIs, 1 TB to DynamoDB, 500 GB to ECR, and 500 GB to CloudWatch. Here's what the bill looks like.

Monthly NAT Gateway Bill: Before vs. After OptimizationMid-size SaaS example (20 instances, 3 AZs, 9 TB/month)Before ($682/mo)After ($307/mo)$0$75$150$225Hourly$97$32S3$225$0DynamoDB$45$0Ext APIs$90$90ECR/Logs$45$5Egress55% savings ($375/mo → $4,500/year)Source: AWS VPC Pricing (us-east-1), calculated example
Gateway Endpoints alone cut S3 and DynamoDB processing to $0. Consolidating to one NAT Gateway in non-HA environments saves the hourly fee.

The "before" column totals $682 per month. After adding free VPC Gateway Endpoints for S3 and DynamoDB, PrivateLink for ECR and CloudWatch, and consolidating from three NAT Gateways to one (acceptable for this team's HA requirements), the bill drops to $307 per month. That's a 55% reduction. Annualized, it saves $4,500 — and the changes take an afternoon to implement. To see how NAT Gateway fits into the broader picture of AWS charges, read our AWS bill breakdown for startups.

For larger organizations, the numbers get serious fast. A company processing 100 TB per month through NAT Gateway pays $4,500 in processing fees alone. If 40% of that traffic is S3 and DynamoDB, adding free Gateway Endpoints saves $1,800 per month — $21,600 per year — with a Terraform change that takes 15 minutes.

How do VPC endpoints eliminate NAT Gateway charges?

AWS offers two types of VPC endpoints, and they have wildly different pricing. Gateway Endpoints are free. They work with S3 and DynamoDB only. Interface Endpoints (PrivateLink) cost $0.01/hour plus $0.01/GB processed. Knowing when to use each is the difference between eliminating costs and just moving them somewhere else.

Gateway Endpoints are the highest-ROI change you can make. They route S3 and DynamoDB traffic directly from your VPC to the service, bypassing NAT Gateway entirely. No hourly fee, no per-GB charge, no egress. The traffic stays on the AWS backbone. You add a route table entry, update your VPC configuration, and you're done. There's genuinely no reason not to have these in every VPC. For the DynamoDB side of the bill itself — On-Demand vs Provisioned capacity, Global Tables replication, DAX — see our DynamoDB pricing guide.

Glowing fiber optic cables in blue and red representing high-speed data routing and network traffic

AWS VPC Gateway Endpoints for S3 and DynamoDB cost $0 per hour and $0 per GB of data transferred, compared to NAT Gateway's $0.045/hr + $0.045/GB charges (AWS VPC Pricing, 2026 ). For a typical production account routing 5 TB/month to S3, switching to a Gateway Endpoint saves $225/month with zero application code changes.

Interface Endpoints are trickier. They create an elastic network interface in your subnet, and they cost $0.01/hour ($7.20/month) plus $0.01/GB. Whether they save money depends on volume. For services like ECR, CloudWatch Logs, SQS, and Secrets Manager, Interface Endpoints are cheaper than NAT Gateway when traffic exceeds roughly 160 GB per month per service. Below that threshold, the hourly cost of the endpoint outweighs the per-GB savings.

Here's the math: NAT Gateway charges $0.045/GB. An Interface Endpoint charges $7.20/month fixed + $0.01/GB. The breakeven point is $7.20 ÷ ($0.045 - $0.01) = ~206 GB/month. If a service handles more than 206 GB/month through the endpoint, PrivateLink saves money. Below that, NAT Gateway is cheaper per-service — but remember, NAT Gateway charges accumulate across all services.

Seven strategies to cut NAT Gateway costs by 50–90%

Not every strategy applies to every environment. This list is ordered by effort-to-impact ratio — start at the top and work down. For a broader checklist of cost reduction actions beyond networking, the cloud cost optimization checklist covers compute, storage, and commitment discounts as well. According to Flexera's 2025 State of the Cloud report, organizations waste 27% of cloud spend, with networking charges being a consistent top contributor (Flexera, 2025 ). NAT Gateway is often the single largest networking cost.

Where the NAT Gateway Savings Come FromPercentage of total NAT bill that each strategy typically eliminates78%addressableGateway Endpoints — 35-45%Architecture changes — 15-20%PrivateLink endpoints — 10-15%Monitoring & cleanup — 5-10%Unavoidable (true egress) — ~22%Source: SpendArk analysis of AWS customer optimization patterns
Free VPC Gateway Endpoints alone address the largest share. Combined with architecture changes and PrivateLink, up to 78% of NAT costs are addressable.

1. Add VPC Gateway Endpoints for S3 and DynamoDB

This is the single highest-impact, lowest-effort change. Gateway Endpoints are free. They take 5 minutes to create in the console or one Terraform resource. Every VPC in your organization should have them. If you do nothing else from this article, do this.

2. Audit your NAT Gateway traffic with VPC Flow Logs

Before optimizing further, you need to know where your traffic goes. Enable VPC Flow Logs on your NAT Gateway's elastic network interface. Filter for the NAT Gateway's private IP. You'll see exactly which instances generate the most traffic and which destinations receive it. Don't guess — measure.

3. Add Interface Endpoints for high-traffic AWS services

For CloudWatch Logs, ECR, SQS, SNS, Secrets Manager, and KMS: if any of these services handles more than 200 GB per month, an Interface Endpoint costs less than NAT Gateway. Prioritize ECR (container image pulls add up fast) and CloudWatch Logs (every service ships logs).

4. Consolidate NAT Gateways where HA isn't critical

Running three NAT Gateways (one per AZ) costs $97.20/month in hourly fees alone. If your workload can tolerate brief connectivity loss during an AZ failure, a single NAT Gateway cuts the hourly cost to $32.40. Dev and staging environments almost never need per-AZ NAT Gateways.

5. Move public-facing workloads to public subnets

Services that need internet access — load balancers, bastion hosts, CI runners — don't need NAT Gateway at all if they sit in a public subnet with an Internet Gateway. Every service you move out of private subnets reduces NAT traffic. This requires security group discipline, but the cost savings are immediate.

6. Implement egress-aware caching

If your application makes repeated calls to external APIs or downloads the same S3 objects frequently, add a caching layer. A small ElastiCache Redis instance costs $12/month and can eliminate hundreds of gigabytes of repeated NAT Gateway traffic. Container image layer caching for ECR is another quick win.

7. Set up cost anomaly alerts on NAT Gateway

NAT Gateway costs spike silently. A runaway log forwarder, a misconfigured health check, or an aggressive API polling loop can triple your NAT bill overnight. Set up AWS Cost Anomaly Detection specifically for the VPC service category. Catch surprises before they hit your monthly bill.

Digital shield representing cloud security monitoring and cost protection with data flowing in background

What's the right NAT architecture for your workload?

There's no single correct NAT architecture. The right choice depends on three factors: availability requirements, traffic volume, and budget constraints. The Kubernetes container market is projected to reach $10.4 billion by 2027 (Fortune Business Insights, 2025 ), which means NAT Gateway traffic will keep growing as more workloads move to private subnets.

For production workloads with strict uptime SLAs, one NAT Gateway per AZ is the standard recommendation. This ensures an AZ failure doesn't break internet connectivity for instances in other zones. But the hourly cost scales linearly — three AZs means 3x the base cost. Four AZs means 4x.

For dev, staging, and non-critical environments, a single NAT Gateway in one AZ is usually sufficient. If that AZ goes down, your dev environment loses internet connectivity — but it was probably going to be disrupted anyway. The savings are significant: $64.80 per month per environment for a three-AZ setup.

For batch processing and data pipelines, consider NAT instances instead of NAT Gateways. A t3.micro NAT instance costs roughly $7.50 per month compared to $32.40 for a NAT Gateway. It's less resilient and has lower throughput (up to 5 Gbps vs. 100 Gbps), but for batch jobs that run for a few hours per day, the cost difference is substantial.

Analytics dashboard with performance metrics and monitoring charts displayed on a laptop screen

Organizations waste 27% of cloud spend according to the Flexera 2025 State of the Cloud report, with networking charges being a persistent contributor (Flexera, 2025 ). NAT Gateway is a top networking cost driver because its triple-layer pricing model — hourly + processing + egress — compounds silently as traffic grows.

The bottom line: audit your NAT traffic first. You can't optimize what you can't see. Most teams find that 40–60% of their NAT Gateway traffic is to AWS services that offer free or cheaper endpoint alternatives. Start there, then evaluate architecture changes for the remaining traffic.

Frequently asked questions

How much does AWS NAT Gateway cost per month?

A single NAT Gateway costs $32.40/month in hourly fees ($0.045/hr × 720 hours). Add data processing at $0.045/GB and data transfer (egress) at $0.09/GB for the first 10 TB. A typical production setup with 3 AZs and 5 TB/month of traffic costs $322–$680/month depending on traffic destinations and endpoint configuration.

Are VPC Gateway Endpoints really free?

Yes. VPC Gateway Endpoints for S3 and DynamoDB have no hourly charge and no data processing fee (AWS VPC Pricing). They route traffic directly from your VPC to the service over the AWS backbone. Interface Endpoints (PrivateLink) for other services cost $0.01/hr + $0.01/GB — cheaper than NAT Gateway for high-traffic services.

Should I use a NAT instance instead of NAT Gateway?

NAT instances cost less ($7.50/month for t3.micro vs. $32.40 for NAT Gateway) but offer lower throughput (5 Gbps vs. 100 Gbps) and no built-in redundancy. They're suitable for dev environments, batch workloads, and low-traffic accounts. For production workloads requiring high availability and throughput, NAT Gateway is the standard choice.

How do I find out what's using my NAT Gateway?

Enable VPC Flow Logs on the NAT Gateway's elastic network interface. Filter logs by the NAT Gateway's private IP to see source instances and destination IPs. AWS Cost Explorer can show NAT Gateway charges by usage type. Third-party tools like Vantage and SpendArk can break down NAT costs by service destination.

How much can I save by optimizing NAT Gateway?

Most teams save 50–90% on NAT Gateway costs. Free VPC Gateway Endpoints typically eliminate 35–45% of NAT traffic (S3 + DynamoDB). Architecture changes like consolidating gateways save another 15–20%. Interface Endpoints for high-traffic services add 10–15%. Combined, these strategies reduce annual NAT costs by thousands to tens of thousands of dollars depending on traffic volume.

Estimate your cloud costs — for free

Compare AWS, Azure, and GCP pricing side by side with our free calculator, and dig into the guides to learn how to cut cloud waste. No sign-up required.