Yashveer Singh
Connect
<- All posts
DevOps, Deployment, Infrastructure11 min read

Egress Costs on AWS: The Bill Nobody Sees Coming

Egress costs on AWS are the fees charged when data leaves AWS for the public internet or moves across regions and availability zones. The rate is 0.09 USD per GB to the internet for most regions in 2026, after the first 100 GB free. Cross AZ transfer is 0.01 USD per GB each direction. At scale these add up. The teams that engineer for low egress save tens of thousands per month. The teams that do not pay the full rate.

Written by Yashveer Singh, founder of Yashveer Labs.

What you actually need to know

  • Egress to internet is 0.09 USD per GB after the free tier.
  • CloudFront cuts most of the bill for public traffic.
  • VPC endpoints eliminate NAT processing for AWS service calls.
  • Cross AZ is 0.01 USD per GB each direction. Adds up at scale.
  • Audit before optimizing. Cost Explorer plus VPC Flow Logs.
Egress type2026 rate
Internet (most regions)0.09 USD per GB after first 100 GB free
CloudFront0.085 USD per GB with volume discounts
NAT gateway processing0.045 USD per GB
Cross AZ0.01 USD per GB each direction
Cross region0.02 USD per GB
VPC endpoint to S3Free
VPC endpoint to other AWS servicesVariable

The core argument

Egress is the AWS cost that surprises founders most consistently. The compute and storage costs are visible because they show up in the same line items every month. The egress hides until the bill grows large enough to investigate. By then the team has been paying the full rate for months.

The fix is mostly architectural. CloudFront in front of any public traffic. VPC endpoints for any call to AWS services. AZ aware placement for services that talk to each other heavily. Each is a one time setup. Each cuts a meaningful percentage of the egress bill.

The pattern that catches most teams is talking to S3 over the public path. The application is in a VPC. The S3 bucket is in the same region. The call goes through the NAT gateway and back into AWS via the public endpoint. The team pays NAT processing plus a small internet egress for every call. The VPC endpoint for S3 makes the call direct and free.

The teams that audit their egress find these patterns and fix them. The teams that do not audit pay the full rate for years. The audit is hours of work. The savings can be tens of thousands per month at scale.

The biggest levers

LeverTypical savings
CloudFront in front of public traffic70 to 90 percent of public egress
VPC endpoint for S3All S3 NAT processing
VPC endpoint for other AWS servicesVariable but meaningful
AZ aware service placement50 to 90 percent of cross AZ
Compress responses30 to 70 percent of public egress
Use HTTP/2 or HTTP/3Modest, helps mobile
Image and video optimizationLarge for media heavy apps
Static asset versioning with long cacheLarge for asset heavy apps

How much does this cost

WorkloadMonthly egress before optimizationAfter
Small SaaS100 to 500 USD30 to 150 USD
Growth SaaS1000 to 5000 USD300 to 1500 USD
Media heavy10000 USD plus2000 USD or less
Multi regionHigherSignificant savings with right architecture

Features the egress optimization must have

  • CloudFront in front of public traffic.
  • VPC endpoints for AWS service calls.
  • AZ aware service placement.
  • Response compression.
  • Asset optimization for media.
  • Long cache headers on hashed static assets.
  • A monthly review of the egress bill.
  • An owner for the cost work.

Expert opinion

Egress costs are the most preventable line item on a typical AWS bill. The teams that audit and optimize cut the bill dramatically. The teams that do not audit pay the full rate forever. The cost of the audit is a day of engineering. The savings can be tens of thousands per month at scale. The math is consistently favorable.

>

Yashveer Singh, founder of Yashveer Labs

How this played out on a real project

A client SaaS was paying roughly 9000 USD per month in AWS data transfer costs. The investigation surfaced three issues. The application served images and videos directly from S3 to users on the public internet without CloudFront. The application made many S3 calls through the NAT gateway. The services talked across AZs heavily because the deployment was random.

We put CloudFront in front of the public traffic. We added a VPC endpoint for S3. We deployed services with AZ awareness so dependent services prefer the same AZ.

The data transfer bill dropped to roughly 1200 USD per month. The savings were 7800 USD per month against an investment of about a week of engineering. The payback was the first week of the new month.

For more on the related work, see cloud hosting costs at scale what founders underestimate and CDN strategy for a global SaaS in 2026.

Common mistakes teams make

  1. No CloudFront in front of public traffic.
  2. S3 calls through NAT gateway instead of VPC endpoint.
  3. AZ unaware service placement.
  4. No response compression.
  5. Uncompressed images and videos served directly.
  6. No long cache headers on hashed assets.
  7. No monthly review of the data transfer bill.
  8. Treating egress as fixed cost. It is not.

A 30 day egress audit and optimization

  1. Week one. Audit current data transfer line items in Cost Explorer.
  2. Week two. Add CloudFront. Add VPC endpoints for AWS services.
  3. Week three. AZ aware placement. Response compression.
  4. Week four. Asset optimization. Monthly review cadence.

For more on the related work, read cloud hosting costs at scale what founders underestimate and reserved instances and cost math when they pay off. On the broader CDN side, CDN strategy for a global SaaS in 2026 is the natural next read.

FAQ

Frequently asked

Author

About the author and why it matters

Yashveer Singh wrote this. I run Yashveer Labs out of New Delhi. The work I take on tends to come from founders who have been burned by an agency, a freelancer, or their own ambition. I do not promise miracles. I promise that the system will be online, the code will be readable, and the next engineer who touches it will not curse me. That is rarer than it should be.

Related reading