Buying verdict

Business VPN Cost per User

This verdict prices a business VPN per user across the three products sold under that name, then follows the gateways, dedicated IPs and engineer hours.

A person in a grey top seated at a light wooden desk with hands on a laptop keyboard, the screen showing a dark interface with a left sidebar and a grid of pale blue and violet card tiles, a small potted plant and a pale mug beside it, a curtained window behind
What's in this verdict
  1. What a business VPN actually costs
  2. Three different products share one name
  3. Model one, a consumer VPN with a team billing panel
  4. Model two, a business remote access VPN
  5. Model three, zero trust network access
  6. Illustrative per user pricing by model
  7. What actually unlocks as you move up the ladder
  8. Dedicated IP addresses and what they are really for
  9. Gateways and connectors are the second meter
  10. Bandwidth ceilings, data caps and speed tiers
  11. Devices per user and where that meter bites
  12. Single sign on and directory sync as a tier gate
  13. Logging, retention and the compliance rung
  14. External access for contractors and agencies
  15. Minimum seat counts and the small team floor
  16. Annual commitment discounts and the renewal that follows
  17. Self hosting an open source tunnel
  18. What deployment actually costs in hours
  19. Ongoing operation is the line with no invoice
  20. Migrating off a VPN you already have
  21. Support and the Monday morning problem
  22. A worked three year total at three team sizes
  23. Cost per protected resource, the number nobody calculates
  24. When the honest answer is not a VPN at all
  25. Signs your VPN bill has drifted
  26. How to trial a remote access product properly
  27. What to ask a vendor before you sign
  28. The bottom line

Ask what a business VPN costs and the first problem is that the question has three different answers, because three genuinely different products are sold under that name. One is a consumer VPN with a team billing panel bolted on. One is a business remote access VPN with cloud hosted gateways, dedicated IP addresses and site to site tunnels. One is zero trust network access, which is where most of the market has moved and which does not really work like a VPN at all. They are priced differently, they solve different problems, and a comparison table that puts all three in the same column is worse than useless.

This verdict prices each of the three the way it actually bills. It works through the per user bands for every model, follows the six meters that push the bill above the headline rate, puts an honest number on self hosting an open source tunnel where the true cost is engineer hours rather than licence fees, prices the annual commitment discount and the seat minimums, and carries three worked totals across three years at ten, forty and a hundred and fifty people. It sits next to our verdict on the true cost of business software, which takes per seat billing apart in general, and our verdict on business password manager cost, which shows the same identity premium in a neighbouring category. Put your own headcount through the true-cost calculator and the companion on this page before you shortlist anything.

Key takeaways

  • Illustrative per user bands: a consumer VPN with a team panel around $7 a month, a business remote access VPN around $12, zero trust network access around $18, an enterprise rung around $24. Self hosted open source software has no licence fee at all.
  • The seat rate is the smallest moving part. Gateways and connectors beyond the first are commonly metered around $25 each a month, and dedicated IP addresses around $5 each a month.
  • Operating time is the line with no invoice. On the illustrative forty person build here it is about $4,788 a year, roughly the same order as the entire subscription.
  • Self hosting is free to licence and expensive to run. The forty person example breaks even at about eight and a half engineer hours a month, and the ten person example cannot win at all.
  • Three year totals: about $5,252 for twelve people, about $35,763 for forty eight, about $140,893 for a hundred and seventy five. Cost per person rises with size, because gateways and operating time rise faster than headcount.

What a business VPN actually costs

A complete answer has five parts, and only the first one appears on a pricing page.

There is the per user subscription, which is the number every internal approval gets based on. There is the infrastructure meter, which is gateways or connectors, dedicated IP addresses, and in some plans a bandwidth or data ceiling that turns into throttling or overage. There is the rung premium, which is what you pay because one control you cannot go without, usually single sign on, directory sync or log retention, sits above the rung your other requirements would have justified. There is the one time deployment, which is design, gateway build, firewall or policy work and the per person time of getting everybody connected. And there is the standing operating line, which is certificate and key rotation, gateway patching, rule maintenance and the tickets that arrive whenever somebody changes network.

Those five scale on four different things. Seats scale with headcount including external people. The infrastructure meter scales with how many sites, cloud environments and regions you have, which is almost unrelated to headcount. The rung premium scales with your compliance and identity requirements. Deployment and operation scale with the number of gateways and with how tangled the network was before you started.

Everything below takes these apart with illustrative planning figures, and the companion on this page reprices the whole stack against your own numbers as you read.

Three different products share one name

The single most expensive mistake in this category is buying the wrong one of the three, and it happens because the marketing language is nearly identical across all of them.

The first product is a consumer VPN with a team billing panel. The engineering underneath it is the same consumer service sold to individuals: encrypted tunnels out to the provider’s servers, a choice of exit country, apps on every platform. The business version adds one invoice, an administrator who can add and remove people, and sometimes a shared dedicated IP address.

The second is a business remote access VPN. Here the provider hosts a gateway that sits logically inside your network, and your employees connect to that gateway rather than to the open internet. This is the product that lets somebody at home reach a file server, a database, an internal admin panel or a piece of factory equipment.

The third is zero trust network access, which grants a user a connection to one named resource at a time rather than putting their device on a network. It usually arrives bundled with identity checks and device posture rules, and it usually costs more per seat and less per hour of maintenance.

Establish which of the three you are actually buying before you look at a single price, because a cheap answer to the wrong question is not a saving.

Two hands at a whiteboard, one holding a black marker, beside a row of four pastel sticky notes in yellow, pink, lilac and blue joined by drawn black arrows
Map which resources each group of people actually needs to reach before you price anything. The count of protected resources, not the count of employees, is what decides whether a VPN or a per resource model is cheaper.

Model one, a consumer VPN with a team billing panel

This is the cheapest of the three and the most frequently mis-sold. Illustrative pricing lands around $7 per user per month, often with aggressive multi year discounting that can halve the effective first term rate.

What you get is real: encrypted outbound traffic so that a laptop on airport wifi is not readable by whoever else is on that wifi, an exit address in a country of your choosing, and one bill instead of fourteen personal subscriptions. For a distributed team of writers, salespeople or consultants who work entirely in browser based tools, this is often the correct and complete answer.

What you do not get is any path into your own systems. There is no gateway on your side, so there is nothing to reach. If your accounting system, your design file server or your internal dashboard lives on a machine you control, a consumer panel cannot connect anybody to it, and no amount of configuration will change that.

The administrative surface is also thin by design. Expect a seat list, an invoice, and possibly a shared dedicated IP address. Do not expect directory sync, per user access rules, device posture checks, meaningful audit logs or anything an auditor would accept as an access control.

The honest test is one question: are you trying to protect traffic on its way out, or reach something on its way in? A consumer panel answers only the first.

Model two, a business remote access VPN

This is the product most people picture when they say business VPN, and illustrative pricing lands around $12 per user per month with a gateway or connector included and extras metered.

The architecture is a hosted gateway that behaves as though it sits inside your network. Employees run a client, authenticate, and their device is then routed onto that network segment. Add a second gateway in another office or another cloud region and the provider can usually link the two, which is what site to site means: a permanent tunnel between two networks rather than between a person and a network.

The pricing consequence is that this model has two meters rather than one. Seats scale with people. Gateways scale with places. A twelve person company with four offices and three cloud environments can easily pay more for infrastructure than for seats, which is a shape that surprises buyers who budgeted per head.

The operational consequence is that once a device is on the network, what it can reach is decided by firewall and routing rules. Those rules are written by somebody, reviewed by somebody, and quietly rot when nobody does either. That maintenance is the hidden running cost of this model, and it is the specific cost that the third model claims to remove.

Model three, zero trust network access

Zero trust network access is where the market has moved, and it changes both the security model and the shape of the bill. Illustrative pricing lands around $18 per user per month at a business rung and around $24 at an enterprise rung.

Instead of joining a network, a user is brokered a connection to one named resource: this application, this database, this admin panel. Every request is checked against who the person is, what group they are in, and often what state their device is in. A compromised laptop reaches the three things that account was allowed to reach, rather than everything the network can see.

The cost argument runs in two directions and both are honest. Against it, the per seat rate is roughly half again the remote access VPN band, and the enterprise rung doubles the consumer panel. In its favour, the identity machinery that VPN vendors gate behind an upper rung is usually included, the firewall rule maintenance largely disappears, and offboarding becomes a directory action rather than a certificate revocation.

The thing to check before you assume the maintenance saving is real is how many resources you actually have. A company with six internal applications will feel this immediately. A company with one file server will pay more per seat to remove a maintenance burden it did not have.

Illustrative per user pricing by model

Start with the numbers people search for, framed as planning bands rather than quotes, because pricing here moves and varies by vendor, region, contract length, seat count and how much of the product is switched on.

Self hosted open source tunnel software costs nothing to licence. It is a real option, it is not a free one, and the section further down prices it properly.

Consumer VPN with a team billing panel commonly lands around $7 per user per month on a monthly term, with multi year terms discounted considerably harder.

Business remote access VPN commonly lands around $12 per user per month, usually with one gateway or connector included.

Zero trust network access commonly lands around $18 per user per month at a business rung, typically with identity integration included rather than gated.

Enterprise ZTNA or broader security service edge bundles commonly land around $24 per user per month and upward, adding web filtering, data controls, deeper reporting and contractual commitments.

Dedicated IP addresses are commonly billed around $5 per address per month across several of these models, and they are counted per address rather than per user.

Illustrative remote access list price per user per month

Product models and one commonly separated add-on, before gateway fees, bandwidth ceilings, retention add-ons, seat minimums or any internal time. Bar widths are drawn from each figure against the enterprise band.

Enterprise ZTNA or SSE rung~$24
Zero trust network access, business rung~$18
Business remote access VPN~$12
Consumer VPN with a team billing panel~$7
Dedicated IP address, per address~$5
Self hosted open source tunnel, licence only$0

The step from a consumer panel to a remote access VPN buys a gateway on your side of the tunnel, which is a different product rather than a better one. The step to zero trust buys per resource authorisation and usually the identity integration with it. The $0 bar is a licence fee, not a total.

Read that ladder against your own requirements rather than against a competitor’s stack. A team that works entirely in hosted tools and wants coffee shop wifi covered is shopping the bottom rung. A team with anything on its own infrastructure is shopping the middle. A team with an auditor asking who reached which system last quarter is shopping the top whether it wanted to or not.

What actually unlocks as you move up the ladder

Feature placement varies by product and shifts between releases, so treat this as a shape to verify rather than a specification. The pattern is consistent enough to plan against.

The consumer panel rung buys encrypted outbound tunnels, apps on the usual platforms, a country picker, a seat list and one invoice. Sometimes it buys a shared dedicated IP address. It does not buy an access control.

The remote access rung buys a hosted gateway, client software that routes your device onto a network segment, site to site tunnels between gateways, dedicated IP addresses as a metered add-on, and basic connection logs. Access rules are network shaped: subnets, ports and routes.

The zero trust rung buys per resource authorisation, identity integration against your directory, group based policy, device posture checks of some depth, and logs that record which person reached which resource rather than which address connected.

The enterprise rung buys the surrounding security service edge: outbound web filtering, data loss controls, custom administrator roles, log export or streaming into your own tooling, residency options and the contractual commitments a procurement process asks for.

The gate that catches most buyers is not a feature at all. It is that moving up a rung frequently means moving to a different architecture, and the migration between architectures costs more than the rate difference in year one. Establish where each product places single sign on, log retention and device posture before you build any comparison table, because those three answers move budgets more than the headline rate does.

Dedicated IP addresses and what they are really for

A dedicated IP address is one of the most commonly bought add-ons in this category and one of the most commonly misunderstood. Illustrative pricing lands around $5 per address per month.

The reason businesses buy one is allow listing. A supplier portal, a payment processor, a client’s system or your own database may be configured to accept connections only from a known address. If your people leave through a shared pool of provider addresses, that address changes, and the allow list breaks. A dedicated address gives you one stable value to hand over.

The reason the cost multiplies is geography and redundancy. One address covers one exit point. A business with people in three regions who all need to appear at an allow listed address is buying three, and a business that wants a failover path is buying more. At $5 each that is small money until somebody asks for one per office per region.

There is a quieter cost too. Every allow list containing your dedicated address is a dependency you now own. Change provider, change region, or let the address lapse at renewal, and each of those third party configurations has to be updated by somebody who may no longer work there. Keep a written register of every place your address is allow listed, because reconstructing that list under time pressure during a migration is genuinely unpleasant.

Gateways and connectors are the second meter

This is the line that most often breaks a headcount based budget. A gateway, sometimes called a connector or a network, is the thing that makes one of your environments reachable. Illustrative pricing includes one with a paid plan and meters extras around $25 per gateway per month.

Count yours honestly before you model anything. Each physical office with resources on its own network is one. Each cloud virtual network or account is one. Each data centre or colocation rack is one. A test environment that engineers need is one. A partner network you tunnel into is one. Redundant pairs, where the product needs them for failover, double the ones that matter.

A forty person company with a head office, one cloud environment and a staging environment is at three, so two are metered, which is about $600 a year before any discount. That is small. A company with six sites and four cloud accounts is at ten, so nine are metered, which is about $2,700 a year and now a real line.

The larger cost is not the fee. Each gateway is a piece of infrastructure that patches, expires, fails and gets logged into. The operating model further down prices roughly one hour a month per gateway of engineering time, which at $95 an hour is about $1,140 a year each, comfortably more than four times the metered fee. Gateways are cheap to buy and expensive to own.

Bandwidth ceilings, data caps and speed tiers

Not every product in this category meters traffic, but enough do that it belongs in any honest model, and the way it is expressed varies enough to be confusing.

Some plans apply a per user monthly data allowance, after which traffic is throttled rather than billed. Some apply a pooled account allowance, which is friendlier to a team with a few heavy users and harsher when the whole company has a busy month. Some apply no ceiling to the tunnel itself but cap the throughput of the gateway, which reads as a speed tier rather than a data cap. And some genuinely do not meter, which is worth confirming rather than assuming.

The exposure depends almost entirely on what travels through the tunnel. A team reaching a text based admin panel and a database will never notice a ceiling. A team pulling multi gigabyte design files, video assets or database dumps across the tunnel every day will notice within a fortnight, and will notice as slowness rather than as an invoice, which makes it harder to diagnose.

Two questions settle it. Ask what the ceiling is, per user or pooled, and ask precisely what happens when it is reached: throttling, overage billing or a hard stop. Then measure a typical week of your own traffic before you commit to a term, because guessing this number is how a fast product becomes a slow one three months after purchase.

Devices per user and where that meter bites

Most products in this category include several devices per user, and the included count is one of the few places where the small print can double an effective seat rate without changing the sticker.

The common shape is an allowance of somewhere between three and ten simultaneous connections per user, which suits an office laptop, a phone and a home machine. Above that, products differ sharply. Some simply disconnect the oldest session. Some require a second seat. Some meter additional devices separately.

The groups that break the allowance are predictable. Engineers carry a work laptop, a personal machine, a phone, a tablet and often a test device or two. Field staff carry a tablet plus a phone plus a rugged handheld. And any unattended machine that needs a permanent tunnel, such as a build server, a monitoring box or a piece of equipment in a workshop, consumes a device slot forever without a human attached to it.

That last case is worth pricing separately, because a business remote access VPN billed strictly per user gets awkward when the thing that needs the tunnel is not a user. Ask how the vendor handles service accounts and unattended devices before you assume your headcount is your seat count. Our note on the true cost of business software covers the same pattern in other per seat categories.

Single sign on and directory sync as a tier gate

Single sign on is the control most likely to be non negotiable and most likely to sit a rung above where the rest of your requirements landed. In this category the pattern varies by model, which is part of why comparison is so awkward.

Consumer team panels frequently do not offer it at all. Business remote access VPN products commonly place it on an upper rung, so a buyer who needs it pays the higher seat rate across every seat, not only the ones that use it. Zero trust products usually include it, because the entire product is built on identity and there is nothing to sell without it.

That difference is easy to miss and expensive to discover. Comparing a $12 remote access rung against an $18 zero trust rung looks like a fifty percent premium. If single sign on and directory sync push the remote access product to its own upper rung, the real comparison may be much closer, and the zero trust product may be cheaper once the rung premium is counted.

Directory sync deserves its own question. Single sign on decides how somebody proves who they are. Directory sync decides whether their account appears and disappears automatically when HR adds or removes them. The second is the one that closes the offboarding hole, and it is not always bundled with the first. Ask about both by name.

Four stacks of plain light wood cubes rising in a staircase from one cube to three, standing on a wooden surface against a soft violet grey wall
Rung ladders in this category do not compare cleanly, because moving up a rung often means moving to a different architecture rather than the same product with more switches turned on.

Logging, retention and the compliance rung

Every product in this category logs something. The three questions that decide cost are what it records, how long it keeps it, and whether you can get it out.

What it records varies more than buyers expect. A consumer panel may log only that a session existed. A remote access VPN typically logs connection events: which account, from which address, to which gateway, for how long. A zero trust product typically logs per resource authorisation, which is the level of detail that answers an auditor’s actual question, namely who reached which system and when.

Retention is where the money is. A short default window is common on lower rungs, and extending it to the period your sector or your customer contracts expect is frequently an add-on or a rung jump rather than a setting. As an illustrative shape, a retention add-on priced around $3 per user per month adds about $5,355 a year to the hundred and fifty person example in this verdict once annual prepay is applied, which is real money for a checkbox.

Export is the third question and the one most often skipped. Logs that live only in a vendor console are useful for troubleshooting and awkward for evidence. Ask whether the events can be exported on your rung, in what format, and whether they can be streamed into your own tooling. Nothing here states what any regulation, certification scheme or customer contract requires of you, because those obligations differ by sector and territory and change over time.

External access for contractors and agencies

Every business ends up needing to give somebody outside it a route in: a contract developer, an agency, a supplier’s support engineer, an accountant. How the product bills that person differs sharply and it is rarely on the pricing page.

Some products bill an external collaborator as a full seat, which is simple and the safest planning assumption. Some offer a limited role at a reduced rate or with a small free allowance. Some have no external concept at all, which in practice means somebody shares an account, which is the outcome you bought the product to avoid.

On the illustrative bands here, eight contractors on a $12 remote access rung with annual prepay is about $979 a year, and twenty five contractors on an $18 zero trust rung is about $4,590. Neither is enormous, and both are large enough to change a shortlist when two products treat them differently.

The structural question underneath the price is time limits. An external account that nobody expires is a standing route into your network held by a company you may have stopped working with. Ask whether access can be granted with an end date, whether that end date is enforced automatically, and what the account can reach after it passes. That answer matters more than the rate.

Four people gathered closely around an open silver laptop on a wooden table in a bright office with large windows behind them, one of them reaching toward the screen while the others watch
The price of an external seat matters less than whether the access it grants carries an end date. An account nobody expires is a standing route in, held by a company you may have stopped working with.

Minimum seat counts and the small team floor

Minimum billable seats put a floor under your bill that has nothing to do with your headcount, and they bite hardest on exactly the teams most attracted by a low per user rate.

Illustrative minimums in this category run around five billable seats on consumer team panels and on business remote access rungs, around ten on zero trust business rungs, and considerably more on enterprise agreements. A three person business on a $7 panel with a five seat minimum pays $420 a year rather than $252, which is an effective $11.67 per actual user per month against a $7 sticker, and $168 a year of pure structure.

The minimum matters most at the moment you choose a rung, because the jump to a rung with a higher minimum can cost more in enforced empty seats than in rate. A seven person team moving from a $12 rung with a five seat minimum to an $18 rung with a ten seat minimum is not paying a fifty percent premium, it is paying about $1,152 more a year on annual prepay, because it now also pays for three seats with nobody in them.

Ask two things: what the minimum is on the rung you want, and whether it changes at renewal. The second question catches the pattern where a promotional minimum resets upward when the initial term ends.

Annual commitment discounts and the renewal that follows

Annual prepay in this category commonly runs around fifteen percent below monthly billing, which on the illustrative forty eight seat example is about $1,127 a year. That is a real saving and an easy decision for a product you have already validated.

Consumer team panels behave differently and deserve caution. Multi year terms in that part of the market are frequently discounted far harder than fifteen percent, sometimes to a headline that looks like a different product entirely. The mechanism is that the discount applies to the initial term only, and the renewal returns to something much closer to list. A two year commitment at a steep discount is a genuine saving on the first two years and a genuine unknown on the third.

The way to handle it is not to refuse the discount. It is to get the renewal rate in writing at the point of signing, and to model your total across the full period you expect to use the product rather than across the discounted term. Our note on how to negotiate SaaS pricing covers the specific concessions vendors give away more readily than rate cuts, and a renewal cap is usually one of them.

The other reason to be careful with a long commitment here is architectural. This is a category in active movement, and a three year lock on a remote access VPN is a three year lock out of the model the market is heading toward. Buy the term that matches your confidence, not the term that matches the discount.

Self hosting an open source tunnel

Open source tunnel software is mature, widely deployed and genuinely free to licence. Every serious cost model in this category should include it as an option, and every honest one should be clear that the licence is the cheap part.

Price it as three lines. Infrastructure is a small cloud instance per gateway, illustratively around $180 a year each. The initial build is design, deployment, key management, client configuration and documentation, illustratively around forty engineer hours at $95, which is about $3,800. Ongoing operation is patching, key and certificate rotation, adding and removing people, and answering the connection problems, illustratively around four hours a month, which is about $4,560 a year.

For the forty person example in this verdict, with three gateways, that is about $20,108 across three years against about $35,763 for the hosted product. Self hosting wins, and it wins by a margin that would survive a fair amount of pessimism. The break even sits at about eight and a half engineer hours a month, so the question is not whether the software works but whether four hours is an honest estimate of your own upkeep.

For the ten person example it inverts completely. The same fixed build cost spread across twelve people lands near $18,272 across three years against about $5,252 hosted. Below a certain size, self hosting is more expensive than the product, and the reason is arithmetic rather than ideology.

What deployment actually costs in hours

Deployment is the line most buyers leave out entirely, and it lands in year one where it is least welcome.

The illustrative model used throughout this verdict prices design and build at ten hours plus one hour per gateway at $95 an hour, which covers the network design, the gateway deployment, the routing or policy work, the client packaging and enough documentation that a second person can operate it. It then prices per person onboarding at thirty minutes each at a loaded $42 an hour, which covers the account, the client install, the second factor enrolment and the first connection problem.

For the forty eight person example that is about $1,235 of design and build plus about $1,008 of onboarding, so about $2,243 in total, which is roughly six percent of the three year total. For the hundred and seventy five person example it is about $5,195, because onboarding scales with people while design scales with gateways.

Two things reliably inflate it. The first is discovering the resource list during the deployment rather than before it, which turns a build into an archaeology project. The second is a network that has grown by accretion, where nobody can say with confidence which subnets contain what. Both are fixed by the same cheap step: write down every resource people need to reach, and who needs to reach it, before anybody touches a gateway. Our walkthrough on migrating to new software covers the sequencing.

Three people in a bright office looking at an open laptop on a wooden table, one standing behind two seated colleagues, all smiling, with a potted plant and blue framed windows behind them
Per person onboarding is the half hour that turns a working gateway into a working company. It scales with headcount while the design work scales with gateways, which is why the two behave differently as you grow.

Ongoing operation is the line with no invoice

This is the largest cost in the category that never appears on a statement, and in the forty person example it is roughly the same order of magnitude as the entire subscription.

The illustrative operating model prices about one hour a month per gateway, covering patching, certificate and key rotation, capacity checks and whatever broke, plus about eighteen minutes a year per person, covering joiners, leavers, device changes and connection tickets. At $95 an hour, the forty person example with three gateways runs about $4,788 a year: about $3,420 of gateway work and about $1,368 of user support.

Against a subscription of about $6,385 a year, that means roughly two fifths of the running cost is time nobody invoices. Across three years, licences and gateway fees carry a little over half the total and internal time carries the rest.

The shape of that time differs by model. A remote access VPN concentrates it in firewall and routing rule maintenance, which is skilled work that only one or two people can do. A zero trust product concentrates it in policy and group management, which is closer to administration than engineering and can be delegated. Self hosting concentrates all of it in one person, which is the real risk of that route rather than the hours themselves. Price the concentration, not just the total, because a category whose upkeep depends on a single engineer becomes a business continuity question the moment that engineer takes a holiday.

Migrating off a VPN you already have

Most purchases in this category are replacements rather than first time buys, which means the migration is part of the price and is almost never quoted.

A migration here is not a switchover. It is a per resource cutover, and the unit of work is one application, file share, database, admin panel or piece of equipment at a time. Each one has to be made reachable through the new path, tested by somebody who actually uses it, and then removed from the old path. That last step is the one teams skip, and skipping it means paying for both products indefinitely while leaving the old route open.

Plan for an overlap period and put both subscriptions in the year one budget. Plan for a rule by rule audit of the existing firewall configuration, because a remote access VPN that has been running for years has accumulated rules whose purpose nobody remembers, and copying them across defeats the point of moving.

Plan also for the human part. People who have used one client for years will report the new one as broken when it is merely different, and the support load in the first month is meaningfully higher than steady state. The honest planning assumption for a company of any size is a quarter rather than a weekend. If you are also unwinding the old contract, our note on cancelling a SaaS subscription covers the notice periods that catch people out.

Support and the Monday morning problem

Support quality is worth pricing in this category more than in most, because the failure mode is specific and expensive: nobody can work.

When an accounting tool has a bad morning, work slows. When remote access has a bad morning, a distributed company stops entirely, and every minute is multiplied by headcount. That asymmetry is the reason support terms deserve more scrutiny here than the rate difference between two rungs.

Ask what the response commitment actually is on your rung, in hours, and whether it differs for an outage against a question. Ask whether support is available in your working hours or in the vendor’s. Ask what the escalation path is when a gateway is down rather than slow, and ask whether there is a status page with a history you can read rather than a dashboard that is always green.

Then ask the same questions of yourself. Who in your business is the first call when somebody cannot connect at eight in the morning? What do they have access to? What happens when that person is on leave? A product with excellent support and no internal owner still leaves forty people waiting for one person to wake up. The operating line in the model above assumes somebody owns this, and if nobody does, the cost does not disappear, it converts into downtime.

A worked three year total at three team sizes

Three illustrative builds, using the bands throughout, priced across three years. Deployment lands once in year one. All figures are planning illustrations rather than quotes.

Ten people, consumer team panel, billed monthly. Ten employees plus two contractors is twelve seats at $7, which is $1,008 a year, above the five seat minimum. No gateways, so no infrastructure meter. Operating time at eighteen minutes a person a year is about $342. Running cost is about $1,350 a year. Deployment is ten hours at $95 plus twelve onboardings at $21, so about $1,202. Year one is about $2,552 and three years is about $5,252, which is $12.16 per user per month against a $7 sticker, and about $135 per employee a year. Add one dedicated IP address at $5 a month and three years becomes about $5,432.

Forty people, business remote access VPN, annual prepay. Forty employees plus eight contractors is forty eight seats at $12, which is $6,912, plus two metered gateways beyond the included one at $25 each, which is $600. Annual prepay at fifteen percent brings that to about $6,385 a year. Operating time with three gateways is about $4,788. Running cost is about $11,173 a year. Deployment is thirteen hours plus forty eight onboardings, about $2,243. Year one is about $13,416 and three years is about $35,763, which is $20.70 per user per month and about $279 per employee a year. Add two dedicated IP addresses and three years becomes about $36,069.

A hundred and fifty people, zero trust business rung, annual prepay. A hundred and fifty employees plus twenty five contractors is a hundred and seventy five seats at $18, which is $37,800, plus five metered connectors beyond the included one, which is $1,500. Annual prepay brings that to about $33,405. Operating time with six connectors is about $11,828. Running cost is about $45,233 a year. Deployment is sixteen hours plus a hundred and seventy five onboardings, about $5,195. Year one is about $50,428 and three years is about $140,893, which is $22.36 per user per month and about $302 per employee a year. Add a log retention add-on at $3 a user and three years becomes about $156,958.

Where three years goes for the forty person remote access example

Shares computed from the worked example against a three year total near $35,763, with forty eight seats at $12, two metered gateways at $25, annual prepay at fifteen percent, gateway operation at one hour a month each and user support at eighteen minutes a person a year, both at $95, plus a $2,243 one time deployment. Shares rounded to whole numbers.

Seats 49% Gateway ops 29% Support 12% Build 6%

The unlabelled final segment is the metered gateway fee at about four percent, roughly $1,530 across three years. Note that it is dwarfed by the gateway operating time in the second segment, which is about $10,260 for the same three gateways. Gateways are cheap to rent and expensive to run.

Two patterns are worth reading off those three. Cost per user rises with size rather than falling, because gateways and operating time grow faster than headcount. And the subscription is never more than about half the total once internal time is counted honestly.

Cost per protected resource, the number nobody calculates

Everybody compares cost per user because that is the unit on the invoice. It is the wrong unit for judging whether the purchase makes sense, because a VPN does not protect users, it protects access to things.

Divide your annual running cost by the number of resources people actually reach through it. The forty person example above runs about $11,173 a year. If that tunnel exists to reach one legacy file server, the resource is costing eleven thousand a year to remain reachable, and the obvious question is whether moving that one thing to a hosted service costs less than that. If the same tunnel reaches fifteen internal systems, the number per resource is under a thousand and the purchase looks entirely different.

This calculation changes decisions more often than any rate comparison. It is the reason companies with one straggling on premise application often find that retiring the application is cheaper than keeping the network path to it. It is also the reason companies with a genuine internal estate stop worrying about a few dollars of seat rate.

Run it before you shortlist. Count the resources, count the people who need each one, and divide. If the answer embarrasses the tunnel, the right project is not a VPN procurement. Put both figures through the true-cost calculator and see which side the money is really on.

When the honest answer is not a VPN at all

For a meaningful share of teams asking this question, the correct outcome is no purchase in this category, and a verdict that never says so is not being straight with you.

If everything your team uses is a hosted application reached over the web, and the only concern is public wifi, then modern transport encryption already covers most of what a consumer VPN would add, and the remaining benefit is closer to a preference than a control. The money is better spent on the identity layer: enforced multi factor authentication, a directory that provisions and deprovisions properly, and a business password manager for the credentials that no directory covers.

If the driver is one internal application, price moving or replacing that application against three years of tunnel and operating time before you buy the tunnel.

If the driver is device management and estate visibility rather than access, the category you want is device management or remote monitoring and management, not remote access, and buying the wrong one leaves you paying for both.

And if the driver is an auditor’s question about who reached what, the honest answer is that logging and identity are what satisfy that, which points at zero trust rather than at a cheaper tunnel.

Signs your VPN bill has drifted

Bills in this category drift quietly, because the meters that grow are the ones nobody watches.

You are paying for seats that belong to people who left, because deprovisioning was manual and somebody was busy. You are paying for gateways pointing at cloud environments that were decommissioned two years ago. You are paying for dedicated IP addresses that were bought for one integration that has since moved. You are paying for a rung you climbed to get one feature that is no longer used. You are paying for a second product because the first one turned out to be the wrong one of the three models, and nobody cancelled it.

The check is an hour of work and worth doing twice a year. Export the seat list and compare it against your directory line by line. List every gateway and name the environment it serves out loud. List every dedicated address and name where it is allow listed. Then look at what rung you are on and write down the specific feature that justifies it.

Anything you cannot name has drifted. Cancel it before renewal rather than after, because in this category the removal of a gateway or an address often needs a term change rather than a toggle, and the window for that is narrower than people expect.

How to trial a remote access product properly

A trial in this category tests something different from a trial of an ordinary business tool, and the usual approach of clicking around the console tells you almost nothing.

Trial against your worst case, not your best. Connect from the slowest domestic connection somebody on the team has, not from the office. Connect from a phone on mobile data. Connect from a country somebody actually travels to. Reach the heaviest resource you have, not the lightest, and move a genuinely large file through the tunnel rather than loading a web page.

Then test the operations, because that is where the cost lives. Add a user through your directory and time how long it takes to work. Remove one and confirm the access actually stops rather than merely being marked inactive. Grant a contractor time limited access and let it expire. Deliberately break a gateway and see what the failure looks like from a user’s desk and what the console tells you about it.

Finally, test the exit. Ask how you would export the logs and the configuration if you left. Our walkthrough on running a software trial that tells you something covers the discipline in general, and it applies here with one addition: put at least one non technical colleague through the whole client install unsupervised, because their experience is the one that generates every support ticket.

What to ask a vendor before you sign

Take these to a call in this order and write the answers down. Most of them are absent from pricing pages by design.

Which of the three models is this product, and what specifically does it connect a person to?

What is the per user rate on the rung that contains everything on our requirement list, and what is the minimum billable seat count on that rung?

How many gateways or connectors are included, what does an additional one cost, and does a redundant pair count as one or two?

What does a dedicated IP address cost, is it per address or per region, and what happens to it if we change plan?

Is there a bandwidth or data ceiling, is it per user or pooled, and does exceeding it throttle, bill or stop?

How many simultaneous devices are included per user, and how are unattended machines and service accounts billed?

On which rung do single sign on and directory provisioning sit, and are they the same rung?

What is recorded in the access log, how long is it retained on our rung, and can it be exported or streamed?

How are contractors and external collaborators billed, can access carry an enforced end date, and what happens when it passes?

What is the renewal rate after any promotional term, and will you put a renewal cap in writing?

The bottom line

A business VPN is not one product with one price, and every budgeting mistake in this category starts by pretending otherwise. The bands are real and useful as a floor: around $7 for a consumer panel with a team invoice, around $12 for a hosted remote access gateway, around $18 for zero trust network access, around $24 at an enterprise rung. But the seat rate is the smallest moving part of the bill.

The lines that move are the gateway count, which tracks places rather than people, the dedicated addresses and retention add-ons that arrive one request at a time, and above all the operating hours, which on the forty person example here are roughly the same order as the entire subscription and which no invoice will ever show you. Self hosting removes the licence and keeps every one of those hours, which is why it wins comfortably at forty people and loses badly at ten.

So model it as infrastructure rather than as a subscription. Count your gateways before you count your seats, count the resources people actually reach and divide, get the renewal rate and the seat minimum in writing, and be willing to conclude that the right project is retiring one straggling internal application rather than buying a tunnel to it.

Run your own headcount and gateway count through the companion above and the true-cost calculator before you shortlist, and confirm the ceilings, the device allowance and the external access billing with each vendor in writing before you commit to a term.


VetLoft pays for the tools it writes about and takes no vendor money for a verdict, and this page is published on that footing: educational material only, and not security, network engineering, legal, procurement or compliance advice for your organisation. Every seat rate, gateway fee, dedicated address rate, retention add-on rate, prepay discount, seat minimum, hourly rate, deployment estimate and multi year total on this page is an illustrative planning figure chosen to show how the meters in this category behave, not a quotation from any vendor, and pricing here moves often enough that a band that was typical when this was written may read differently by the time you shop. Where features sit on each ladder varies by product, differs between the three models described here, and shifts between releases, so read those ladders as shapes to verify rather than specifications. No claim is made about the security, throughput, availability or suitability of any particular product, protocol or architecture, and nothing on this page states what any regulation, certification scheme, insurance policy or customer contract requires of you regarding remote access, encryption, access records or breach notification, because those obligations differ by sector and territory and change over time. Establish your own requirements with a qualified professional, and confirm rung contents, gateway allowances, data ceilings, device limits, external access billing, log retention, export rights and renewal terms directly with each vendor in writing before you commit.

Frequently asked questions

How much does a business VPN cost per user per month?

Illustrative planning bands, which move by vendor, region, contract length and how much of the product is switched on, put a consumer VPN with a team billing panel around $7 per user per month, a business remote access VPN around $12, a zero trust network access rung around $18, and an enterprise rung around $24. Those are list rungs before any of the meters that actually decide the bill: extra gateways or connectors, dedicated IP addresses, device counts, retention add-ons and external seats. On the illustrative forty person build in this verdict, a $12 sticker becomes about $20.70 per user per month once three years of operating time and the one time deployment are counted. The gap between sticker and effective cost is wider in this category than in almost any other line of business software.

What is the difference between a business VPN and zero trust network access?

A traditional business VPN puts a device on your network. Once the tunnel is up, the machine is inside, and what it can reach afterwards depends on firewall rules that somebody has to write and maintain. Zero trust network access inverts that: instead of joining a network, a user is granted a connection to one named application or resource at a time, checked against identity and device posture at each request. The practical consequences for cost are that ZTNA usually prices higher per user, usually includes the identity machinery that VPN products gate behind a rung, and usually removes the firewall rule maintenance that quietly consumes engineer hours. Whether it is cheaper in total depends entirely on how much of that maintenance you were actually doing.

Is a consumer VPN with a team plan good enough for a business?

It is good enough for exactly one job and misleading for every other. A consumer VPN with a team billing panel gives each employee an encrypted connection out to the internet through the provider, plus one invoice and one place to add and remove people. That covers public wifi and it covers geography. What it does not do is connect anybody to your own systems, because there is nothing on your side of the tunnel to connect to. Many small teams buy one, discover six months later that the finance system still needs a different tool to reach it, and end up paying for both. Decide first whether you are trying to protect outbound traffic or reach internal resources, because those are two products.

What makes the bill go above the advertised per user price?

Six things do most of the damage, and none of them appear in a comparison table. Dedicated IP addresses are billed per address per month and multiply if you want one per region. Gateways or connectors are usually included one per account with extras metered, so a business with several offices or cloud environments pays for each. Bandwidth or data ceilings sit on some plans and turn into throttling or overage. Device counts per user matter when engineers carry three machines. Single sign on and directory sync commonly gate an entire rung. And logging retention long enough for an auditor is frequently an add-on rather than a setting. Price all six before you compare any two products on seat rate.

Is self hosting an open source VPN actually cheaper?

The licence is free and the licence is not the cost. On the illustrative model in this verdict, self hosting is priced as about $3,800 of initial engineering at $95 an hour, around $180 a year per gateway instance for infrastructure, and roughly four hours a month of ongoing engineering, which is about $4,560 a year. For the forty person example that lands near $20,108 across three years against about $35,763 for the hosted product, so it wins if the four hour estimate holds. The break even is about eight and a half engineer hours a month. For the ten person example self hosting loses badly, because the fixed build cost is spread over almost nobody. Size decides this, not preference.

How do annual commitments and seat minimums change what a small team pays?

Annual prepay in this category commonly runs around fifteen percent below monthly billing, and consumer team panels discount multi year terms far harder than that, sometimes to a level that only applies to the first term and snaps back at renewal. Seat minimums do the opposite favour. Illustrative minimums run around five billable seats on team and business rungs and considerably more on enterprise agreements, so a three person business on a $7 panel with a five seat minimum pays $420 a year rather than $252, which is an effective $11.67 per actual user per month against a $7 sticker. Check the minimum before you check the rate, and get the post discount renewal price in writing.

What should we budget for migrating off a VPN we already run?

Budget for a period of running both, because that is what actually happens. A migration in this category is not a switchover, it is a per resource cutover: each application, file share, database and management interface has to be reachable through the new path, tested by somebody who uses it, and then removed from the old one. The illustrative deployment model here prices design and build at ten hours plus an hour per gateway at $95, and per person onboarding at thirty minutes each at a loaded $42, which for forty eight people is about $2,243 in total. A migration on top of that adds the overlap subscription and the rule by rule audit, and the honest planning assumption is a quarter rather than a weekend.

What does a business VPN cost across three years at different team sizes?

Three illustrative shapes from this verdict, using the bands throughout. A ten person team with two contractors on a $7 consumer panel billed monthly lands near $5,252 across three years, about $12.16 per user per month and about $135 per employee a year. A forty person company with eight contractors and three gateways on a $12 business remote access rung with annual prepay lands near $35,763, about $20.70 per user per month and about $279 per employee a year. A hundred and fifty person company with twenty five contractors and six connectors on an $18 zero trust rung lands near $140,893, about $22.36 per user per month and about $302 per employee a year. Cost per person climbs with size here, because the gateway count and the operating time climb faster than headcount.

Ivan Petrucci · Software reviewer

Ivan has migrated teams across dozens of SaaS tools and now tests them hands-on, scoring for real workflows instead of feature checklists.

Free, no obligation

Get software demos and quotes

Tell us what you are shopping for. We will match you with vendors who can send demos and pricing for your team.

We will connect you with software vendors. No spam.