SassTurf
BlogGrowth
Growth

AWS WAF Pricing Explained (2026)

AWS WAF pricing decoded — the per-web-ACL, per-rule, and per-million-request charges — plus the free WAF a founder already gets from Cloudflare.

Shubham Soni
Shubham Soni
Jul 14, 2026 · 8 min read
Table of contents8 sections
  1. 01The Night a Bot Ate My Free Tier
  2. 02What a WAF Actually Does (in plain English)
  3. 03The Core AWS WAF Pricing, Piece by Piece
  4. 04The Managed Rules Trap
  5. 05Where It Gets Genuinely Pricey: Bot Control & Fraud Control
  6. 06When AWS WAF Is Actually the Right Call
  7. 07The Free WAF You Already Have
  8. 08The Bottom Line

The Night a Bot Ate My Free Tier

It was 2023. Clickly, my little URL shortener, had maybe eleven real users and one very determined stranger. Somewhere out there a script had decided my /api/create endpoint was a fun toy, and it was hammering it a few thousand times an hour. No malice, probably — just a scraper someone forgot to turn off. But I watched my request count climb and my brain did what a broke engineer’s brain always does: it panicked about the bill.

That night I did what everyone does. I typed “web application firewall” into a search bar, landed on AWS WAF, and started reading a pricing page written by people who have clearly never had $0 MRR. Web ACLs. Web Capacity Units. Per-million-request tiers. Managed rule groups with their own separate charges. I closed the tab feeling dumber than when I opened it.

So let me do for you what I wish someone had done for me. Here’s exactly what AWS WAF costs in 2026, what a WAF even does, and why — unless you’re already living inside AWS — you almost certainly shouldn’t pay for it.


What a WAF Actually Does (in plain English)

A WAF — Web Application Firewall — sits in front of your app and reads incoming HTTP requests before they hit your code. It’s a bouncer for the door of your API. Someone tries a SQL injection in a form field? Blocked. A cross-site-scripting payload in a URL? Blocked. A bot machine-gunning your login endpoint? Rate-limited or challenged with a CAPTCHA.

That’s the whole idea. It’s not a substitute for writing secure code — it’s a net that catches the obvious, high-volume garbage so your server never wastes a cycle on it. The classic checklist it defends against is the OWASP Top 10: injection, XSS, that whole family of well-known attacks that every automated scanner on Earth will throw at you the moment you go live.

You do want one. What you don’t want is to overpay for it before you’ve made a rupee. (This is the same trap I warned about with the whole cloud, honestly — what actually matters for AWS security as a founder is the longer version of this thought, and why managed platforms quietly remove most of it.)


The Core AWS WAF Pricing, Piece by Piece

AWS WAF has no flat plan. You assemble your bill out of parts, and there are three you can’t avoid. Prices are the same in every region, which is one of the few merciful things about it.

1. The web ACL — $5/month, just to exist

A web ACL (Web Access Control List) is the container that holds all your rules. You need at least one. It costs $5 per month, prorated hourly. That’s your entry fee before a single rule runs. Have three apps that each need their own? That’s $15/month before you’ve blocked anything.

2. Rules — $1/month each

Every rule you add to that ACL is $1 per month. A rule is one condition: “block requests from this IP range,” “rate-limit anyone over 100 requests in 5 minutes,” “reject anything with a SQL keyword in the query string.” A realistic starter setup has, what, five to ten rules? So tack on another $5–$10/month.

3. Requests — $0.60 per million

Then you pay for the traffic the WAF inspects: $0.60 per million requests. That part is genuinely cheap and scales fine. A million requests is a lot for an early SaaS; sixty cents to filter all of them is not the line item that’ll hurt you.

So the honest floor for a single small app with a handful of rules is roughly $5 + $8 + a few cents = ~$13/month. Not catastrophic. But keep reading, because AWS is very good at turning “$13” into “why is this $60.”


The Managed Rules Trap

Here’s where it creeps. Writing your own WAF rules is tedious and easy to get wrong, so AWS sells Managed Rule Groups — pre-built bundles maintained by AWS or third-party vendors that cover common threats, bad bots, known-bad IPs, and so on.

Each managed rule group you turn on is an extra $1/month (prorated hourly), on top of the per-rule and per-web-ACL charges. AWS’s own core rule set is free to add, but the vendor ones from the Marketplace carry their own subscription fees on top. It’s death by a dollar at a time — every toggle that looks like a freebie quietly adds a line.

None of this is expensive in isolation. That’s the whole psychology of AWS pricing: no single number scares you, so you keep saying yes, and then the invoice arrives looking like a phone bill from 2009.


Where It Gets Genuinely Pricey: Bot Control & Fraud Control

The base WAF is cheap-ish. The add-ons are where AWS makes its money.

Bot Control — the thing I actually wanted back in 2023 to stop my scraper — is a $10/month subscription per web ACL, and then you pay per request on top:

  • Common bot detection: first 10 million requests/month free, then $1 per million.
  • Targeted bot detection (the smarter, ML-driven tier that catches the sneaky ones): first 1 million requests/month free, then $10 per million.

Fraud Control — Account Takeover Prevention and Account Creation Fraud Prevention, which watch your login and signup flows — is another $10/month per web ACL, each, and its per-request pricing is genuinely eye-watering. It starts at $1,000 per million requests at the first tier and slides down with volume ($700, $400, $200, $50 per million as you scale), with 10,000 free requests to start. Read that again. A thousand dollars per million evaluated requests at the top tier. That’s a feature priced for a bank, not for you.

There’s also CAPTCHA at $0.40 per thousand challenges served, and little surprises like $0.30 per million for inspecting oversized request bodies. Individually trivial. Collectively, exactly why people rage-quit AWS.

Here’s the punchline: the founder who’s worried about bots is by definition the founder who can’t afford $10/month subscriptions stacked on per-million fees. The pricing is inverted against the person who needs it most.


When AWS WAF Is Actually the Right Call

I’m not going to tell you AWS WAF is bad. It isn’t. It’s a serious, powerful product. There’s exactly one situation where it’s the obvious answer:

You’re already all-in on AWS. Your app runs behind CloudFront, or an Application Load Balancer, or API Gateway. Your logs already flow into CloudWatch. Your team lives in the AWS console. In that world, WAF snaps in with two clicks and everything stays in one bill, one IAM policy, one dashboard. That integration is worth real money to a company with a DevOps team.

If that’s you — a funded startup with infra people — AWS WAF (often paired with AWS Shield for DDoS) is a completely reasonable choice. Turn it on and move on.

But you, reading a blog called “the broke solopreneur’s survival guide”? You are almost certainly not running a load balancer. You’re on Vercel, or Railway, or a $5 box somewhere. AWS WAF only protects things inside AWS. It can’t even sit in front of your Vercel app. So the entire question is moot — and that’s the good news.


The Free WAF You Already Have

This is the part I want you to actually remember. A solo founder gets a genuinely good WAF for free, and the two best options are ones I already use for other things.

Cloudflare’s free plan

Cloudflare — a company I respect but rarely reach for — includes a Free Managed Ruleset on its $0 plan. It’s a curated subset of their full WAF that automatically blocks the OWASP Top 10 core attacks (SQL injection, XSS) and high-risk, actively-exploited CVEs. It updates itself when a new severe vulnerability drops. You get basic DDoS protection and a CDN in the same free bundle. You can’t deeply customize rules without upgrading, but for stopping the automated internet garbage from reaching your app, it’s more than enough for a product with 11 users. Point your domain at Cloudflare, and you’re covered for zero dollars.

Bunny Shield

Regular readers know I’m a Bunny.net evangelist (the whole love letter is here). They now ship Bunny Shield, a security suite that rolls WAF, DDoS protection, bot mitigation, and rate limiting into one product — with a free tier at $0/month per site (preconfigured WAF rules plus a couple of rate limits), and paid plans from around $9.50/month when you need the full custom ruleset. If you’re already serving your assets through Bunny’s CDN — which, if you took my advice, you are — flipping on Shield is the natural move. One vendor, one dashboard, one tiny bill.

Between those two, most founders are protected for free, with better ergonomics than the AWS console, and zero risk of a per-million-request surprise. That’s not a compromise. That’s just the correct answer for our stage.


The Bottom Line

AWS WAF’s math, stripped of the jargon, is this: $5/month per web ACL + $1/month per rule + $0.60 per million requests, then optional add-ons — managed rule groups at $1/month each, Bot Control from $10/month plus per-request fees, and Fraud Control priced like it’s protecting Fort Knox. For a company already built on AWS, that’s fair and it integrates beautifully. For a broke solopreneur on Vercel or Railway, it’s a bill you don’t need to pay to solve a problem Cloudflare’s free plan already solves.

The tool isn’t the enemy. Paying for enterprise infrastructure while you have zero revenue is. I learned that the hard way, one panicked pricing page at a time — and if you’re still assembling the rest of your stack on a shoestring, start here and set a hard billing cap before anything else, because the bot that ate my free tier will eventually find you too.

My scraper, by the way? I blocked it with a ten-line rate limit and a free Cloudflare rule. Total cost: nothing. Total peace of mind: everything.

This is the Broken Engineer Guide — I over-engineer everything, fail at business, and hand you the shortcuts so you skip the scars. Go build something, and let the free tier fight your bots.

Shubham Soni
Written by
Shubham Soni

A decade building, launching, and occasionally breaking SaaS products. I write SassTurf to share what actually moved the needle — free, no fluff.

Keep reading

Building

LangChain Alternatives That Actually Earn Their Place (2026)

9 min read
Building

Kubernetes Deployment: A Founder's Guide to the One File You'd Actually Write (2026)

9 min read
Email Marketing

Out of Office Email Templates That Don't Sound Like a Robot (2026)

8 min read

Enjoyed this? Get the next one.

One useful SaaS essay in your inbox each week. No fluff, unsubscribe anytime.