AWS WAF and Shield Pricing: Costs, Billing, and What’s Included
Published on · Updated on
Updated WAF, Shield, and CloudFront pricing guidance; removed unsupported cost examples.
AWS WAF and AWS Shield have separate billing models. Pay-as-you-go AWS WAF charges for web ACLs, rules, and inspected requests, with additional fees for some features and higher inspection capacity. Shield Standard is included at no extra charge. Shield Advanced has an annual commitment, a monthly subscription, and usage-based data-transfer fees; it covers only specified AWS WAF charges on resources you protect with Shield Advanced. CloudFront also offers flat-rate plans that bundle WAF and DDoS features with delivery services. Check the current AWS WAF pricing and AWS Shield pricing before budgeting, because rates and included features can change.
Key Takeaways
- Pay-as-you-go WAF cost depends on each web ACL, its rules, and requests processed. Bot Control, Fraud Control, CAPTCHA or Challenge actions, higher WCU usage, and deeper body inspection can add charges.
- Shield Standard is automatically enabled at no additional charge for common network- and transport-layer DDoS protection.
- Shield Advanced is currently $3,000 per month for the subscribed payer account, requires a one-year commitment, and can add data-transfer-out usage fees.
- Shield Advanced includes limited standard WAF usage only for resources protected by Shield Advanced. Optional WAF features and usage beyond stated limits can still be billed.
- For a CloudFront distribution, compare pay-as-you-go billing with CloudFront flat-rate plans, which package selected WAF and DDoS capabilities with plan-specific allowances.
AWS WAF and Shield at a Glance
| Service or model | What it does | How billing works |
|---|---|---|
| AWS WAF | Evaluates HTTP(S) requests against rules attached to a supported resource. | Pay-as-you-go charges for web ACLs, rules, and requests, plus optional feature and inspection charges. |
| Shield Standard | Provides automatic protection against common network- and transport-layer DDoS events. | No additional charge; automatically enabled on supported AWS services. |
| Shield Advanced | Adds DDoS protections for eligible resources, monitoring, and access to the Shield Response Team for eligible support plans. | $3,000 per month per subscribed payer account, a one-year subscription commitment, and data-transfer-out usage charges. |
| CloudFront flat-rate plan | Bundles CloudFront delivery with tier-specific WAF, DDoS, and other features. | Monthly plan price and published usage allowances; feature availability varies by tier. |
AWS WAF Pay-as-You-Go Pricing

With the standard pay-as-you-go model, AWS bills each web ACL (also called a protection pack), the rules and rule groups added to it, and the requests the ACL processes. The current AWS pricing page lists these unit rates:
| WAF charge | Current listed rate | How to read it |
|---|---|---|
| Web ACL | $5 per month | Charged for each web ACL. |
| Rule | $1 per month | Charged for each rule in the ACL. |
| Request inspection | $0.60 per million requests | Applies to requests processed by the ACL. |
| Rule group | $1 per month for each group added to an ACL | User-authored rules inside your own rule groups also count as rules. |
AWS states that prices can vary by Region and that monthly WAF fees are prorated hourly. These unit prices are not a complete estimate: they exclude optional features and your protected resource’s own charges. A managed rule group from an AWS Marketplace seller can add the seller’s subscription and request fees on top of AWS WAF charges. See the official AWS WAF pricing page for current regional rates and examples.
Extra WAF Charges for Capacity and Inspection
Web ACL capacity units (WCUs) measure the processing capacity of a web ACL. The base price includes up to 1,500 WCUs. Above that allocation, AWS lists an additional $0.20 per million requests for each extra 500 WCUs.
Body inspection limits depend on the protected resource. AWS WAF can inspect up to 8 KB for Application Load Balancers and AWS AppSync. For CloudFront, API Gateway, Amazon Cognito, App Runner, Verified Access, and Amazon Bedrock AgentCore Gateway, the default is 16 KB and can be raised in 16 KB increments to 64 KB. Requests inspected beyond the default limit incur an additional $0.30 per million requests for each additional 16 KB. Oversized body content beyond the configured limit is not sent to WAF for inspection, so choose oversize handling with care. See AWS’s guide to request body inspection limits.
Standard Allow, Block, and Count rule actions do not add a per-action fee. CAPTCHA attempts and Challenge responses are metered separately. If a web ACL uses these actions, include those event counts in the estimate.
Managed Rules, Bot Control, and Fraud Control
Do not assume every managed or advanced rule feature has the same price:
- AWS managed rule groups: AWS lists a monthly charge for each managed rule group added to a web ACL. Marketplace sellers set their own additional fees for third-party managed groups.
- Bot Control: AWS currently lists a $10 monthly fee per web ACL, plus analyzed-request charges. Common Bot Control includes the first 10 million requests per month; Targeted Bot Control includes the first 1 million. The listed per-million request rate differs by level: AWS’s examples use $1 for Common and $10 for Targeted after the included requests.
- Fraud Control: Account Takeover Prevention and Account Creation Fraud Prevention each add a $10 monthly fee per web ACL, plus tiered fees for requests they analyze. These request charges can be much higher than the base WAF charges, so estimate using the actual login or registration request volume.
These optional feature charges are separate from standard WAF inspection and generally remain chargeable when Shield Advanced protects the resource. The AWS WAF Anti-DDoS managed rule group is separately priced with pay-as-you-go WAF; Shield Advanced includes access to its Layer 7 Anti-DDoS group for protected resources, subject to the subscription terms and request allowance. Review the current Bot Control, Fraud Control, and DDoS pricing details before enabling them.
AWS Shield Standard vs. Shield Advanced Cost

Shield Standard
Shield Standard is automatically enabled at no additional charge. AWS describes it as protection against common, frequently occurring network- and transport-layer DDoS events. It is a baseline service protection, not a promise to block every attack or a replacement for application-layer controls such as WAF rules.
Shield Advanced
Shield Advanced currently costs $3,000 per month for the subscribed payer account and requires a one-year commitment. A single subscription can cover qualifying accounts in the same consolidated-billing family when the organization owns the accounts and their resources. Standard service charges still apply, and Shield Advanced adds usage fees based on data transferred out from protected CloudFront, Elastic Load Balancing, EC2, and Global Accelerator resources. These fees depend on resource type and Region; there is no general 2 TB transfer allowance.
Shield Advanced supports eligible internet-facing resources including CloudFront distributions, Elastic Load Balancers, EC2, Global Accelerator, and Route 53. Protection must be applied to the resources you want covered. To escalate a DDoS event to the AWS Shield Response Team (SRT), AWS currently lists Business Support+, Enterprise Support, or Unified Operations as qualifying support plans. If SRT access is part of the decision, budget for the support plan separately from Shield Advanced; see the current AWS Support plan pricing and DDoS response prerequisites. Existing customers on legacy Business Support should confirm their account’s SRT eligibility during the transition to the newer plans; AWS’s Support plan guide lists January 1, 2027 as the end date for legacy Business Support.
For resources protected by Shield Advanced, the subscription includes standard AWS WAF web ACL, rule, and base request-inspection fees up to 1,500 WCUs and the resource’s default body-inspection size, for up to 50 billion WAF requests per calendar month across the subscribed payer account. AWS also includes its Layer 7 Anti-DDoS managed rule group. Requests that Shield Advanced detects as DDoS do not count toward this allowance; requests above the limit can incur charges. WAF resources without Shield Advanced protection receive no such inclusion.
Shield Advanced does not cover every WAF charge. Bot Control, Fraud Control, CAPTCHA, WCU usage above 1,500, inspection beyond the default body limit, and Marketplace-managed rule fees can still cost extra. The subscription’s DDoS cost-protection benefits are subject to AWS terms and the one-year commitment; do not treat Shield Advanced as a general cap on all AWS charges. See AWS’s guidance on Shield Advanced and WAF costs and the Shield pricing page.
CloudFront Flat-Rate Plans That Include WAF
If the protected application is delivered through CloudFront, compare pay-as-you-go billing with CloudFront’s flat-rate plans. The plans combine CloudFront delivery with selected WAF and DDoS features, bot management, and other services for monthly prices currently starting at $0, $15, $200, and $1,000 for the Free, Pro, Business, and Premium tiers. Each tier has its own WAF features and usage allowances; Premium also offers higher configurable allowances. The plans have no overage charges, but sustained usage beyond an allowance can lead to traffic-delivery adjustments.
This is a CloudFront distribution pricing option, not a universal AWS WAF rate for ALBs, API Gateway, or other resources. Account Takeover Prevention, Account Creation Fraud Prevention, and partner-managed rule groups use pay-as-you-go pricing under a CloudFront plan. Compare required features and usage allowances against current CloudFront flat-rate pricing and the plan documentation before choosing a model.
Estimate and Manage Your WAF and Shield Bill
Build an estimate from your architecture and measured traffic, not a generic request-volume example. For each web ACL, record its Region, number of rules and groups, monthly request count, WCU total, and the volume of requests whose body inspection exceeds the default. Add analyzed-request counts for Bot Control and Fraud Control, CAPTCHA attempts, and Challenge responses. For Shield Advanced, include the protected resources, data transferred out, and any WAF traffic above the included allowance. Include the normal CloudFront, load balancer, or other service charges as well.
Use the AWS Pricing Calculator to compare the current pay-as-you-go and Shield Advanced components, then compare CloudFront plan features and allowances if the application uses CloudFront. After deployment, use Cost Explorer or cost and usage data to compare estimates with actual usage. Recheck prices when traffic patterns, rules, Regions, or service plans change.
To reduce avoidable charges, remove unused rules and groups, and enable premium rule features only on the traffic that needs them. A scope-down statement can reduce requests evaluated by a request-priced managed group such as Bot Control; it does not reduce the base WAF request charge for requests the ACL still processes. See AWS’s guidance on scope-down statements and metering. Rate-based rules can help limit abusive traffic reaching an application, but they do not by themselves reduce WAF request metering. Test rule changes to preserve the protection your application requires. For broader context on how WAF fits with API and serverless controls, see our serverless network security guide.
Summary
For pay-as-you-go AWS WAF, budget per web ACL, per rule or rule group, and per request, then add the fees for higher capacity, deeper body inspection, or optional managed features. Shield Standard is automatic and free; Shield Advanced is a one-year, $3,000-per-month subscription with additional data-transfer charges and limited standard WAF inclusions for protected resources. If CloudFront fronts the application, check whether a flat-rate plan meets its protection and traffic needs. Use current AWS pricing pages and your own traffic data for a defensible estimate.