A single DDoS that knocks a small store offline for a weekend can erase weeks of profit. A two-hour outage often exceeds typical monthly mitigation fees.
Small e-commerce owners face opaque vendor pricing and surprise egress and IP charges. They also deal with mismatched capacity that wastes budget or leaves protection gaps. Use the short tables and examples below to decide.
For online businesses, expect a range of starting options: basic CDN/WAF tiers commonly cost $0–$30 per month. Low-tier managed mitigation handles modest volumes. It typically costs $30–$300 per month.
More robust managed or enterprise packages guarantee multi-Gbps headroom or include retainers. They generally start around $300 per month. They can rise to $1,500+ per month depending on SLA and included scrubbing capacity. Check provider examples and fees for real estimates.
Comparative snapshot
The table below shows practical SMB plans, what they protect, and typical hidden fees to watch. Read the first row to match plan types to real needs.
| Provider / Plan |
Typical monthly range |
Mitigation capacity |
Covers |
Common hidden fees |
Notes on integration |
| Cloudflare (Pro/Business) |
$20–$300 |
Up to several Gbps via CDN |
L7 WAF, bot mgmt, basic L3/L4 |
Extra IPs, Argo/Load balancing |
Easy for Shopify, WooCommerce via DNS |
| AWS Shield Advanced + CloudFront |
$300+ (plus egress) |
Carrier grade (depends on account) |
L3/L4 scrubbing, WAF via WAF |
Egress charges, CloudFront costs |
Best for AWS hosts; more setup work |
| Fastly / Imperva |
$100–$2,000+ |
1–10+ Gbps (tiered) |
CDN, WAF, scrubbing |
Per‑GB scrubbing, setup |
Good for higher traffic merchants |
| VPS/Host DDoS add‑on (DigitalOcean, Linode) |
$0–$200 |
Small to moderate (carrier limits) |
Network rate limit, basic scrubbing |
Overage egress, IP reserve fees |
Cheap but limited for big attacks |
Key criteria
Capacity is the first filter to apply. Decide what attack size would cause major loss.
Price ranges by real scenarios
Small static sites often use CDN/WAF plans under $30 per month. Stores with payment flows usually pick $100–$1,000 per month plans that include monitoring and some scrubbing. Businesses facing repeated volumetrics budget $1,500+ per month or negotiate carrier peering.
Example monthly invoice line for a 1 Gbps event: Base mitigation $500 + 5 TB scrubbed @ $0.05/GB = $256, plus DNS failover and logging $50 = $806 for the month.
For tiny stores and hobby sites it helps to see concrete package examples tied to traffic and attack capacity. That keeps decisions practical and not just theoretical.
- For a micro store (under $1k/month or occasional sales, about 100 RPS peak) a basic CDN + WAF plan typically runs $0–$30 per month and covers L7 attacks and bot management.
- Combine that with a VPS DDoS add‑on ($5–$50 per month) for basic network rate limiting.
- For an e-commerce business ($5k–$20k/month with moderate peaks) plan on managed DDoS protection or Business CDN plans in the $100–$800 per month range to cover about 1 Gbps with some per‑GB scrubbing.
For fast‑growing shops or marketplaces that need 5–10 Gbps headroom enterprise or carrier scrubbing commitments usually start at $2,000–$10,000+ per month. Alternatively negotiate a per‑attack blended rate with the vendor.
Stating these concrete bands alongside expected attack capacity helps small merchants map product tiers to realistic costs and risk appetite. This reduces buyer uncertainty.
Provider options and trade-offs
This section compares three practical choices for small merchants: managed CDN/WAF providers, cloud shielding, and host/VPS add‑ons. Each choice has predictable costs and clear blind spots.
Cloudflare and CDN providers
Cloudflare and similar CDNs offer easy setup and strong L7 protection. Many shops route DNS to them and gain WAF and bot controls with little engineering.
Cloudflare plans range from free to business tiers around $200–$300 per month. Watch for extra costs such as Argo, load balancing, or dedicated IPs.
A common error is assuming a free CDN protects against large volumetric attacks. Free or entry tiers usually stop small HTTP floods but not multi‑Gbps UDP floods.
AWS Shield + CloudFront
AWS Shield Advanced starts at a $300 per month subscription plus CloudFront egress charges. See AWS Shield pricing for details.
This option suits sites already hosted on AWS that accept the platform billing model. Setup and tuning require DevOps time.
It works well in theory; in practice the biggest surprise is egress billing during scrubbing, which often tops the mitigation fee.
VPS hosts and DDoS add‑ons
Many VPS hosts sell network DDoS protection as an add‑on or include basic network rate limiting. These plans cost $0–$200 per month and help with small to moderate attacks.
They rarely scale beyond moderate volumetrics. For anything above 1 Gbps a dedicated scrubber or CDN is necessary.
A common case: a WooCommerce shop added host DDoS for $20 per month, then a 1 Gbps event caused major egress charges because the host lacked scrubbing centers.
This guidance does not apply to personal blogs with negligible revenue or to hosting contracts that explicitly include unlimited carrier‑grade mitigation and an SLA. Confirm contract language before purchasing separate protection.
How to choose by situation
Choose protection based on expected attack size, revenue risk, and available technical resources. Match the plan model to cashflow: flat fee if predictability matters, pay‑as‑you‑go if attacks are rare.
Risk thresholds by sector
Retail stores with payment flows should plan for at least 1 Gbps mitigation when monthly revenue exceeds $10k. SaaS products often need always‑on protection when uptime affects SLAs.
For blogs or hobby sites a CDN/WAF under $30 per month usually suffices because downtime impact is low.
TCO and ROI check
Calculate hourly revenue at peak and multiply by expected outage hours. Then compare that number to protection cost plus expected overage.
- Break‑even formula: ProtectionCost/month >= (HourlyRevenue × ExpectedAttackHours × Probability) + ExpectedOverage
Example: a store at $20k per month earns roughly $27 per hour. An 8‑hour outage costs $216. A $300 per month protection pays off if probability or expected overage justifies it.
Each platform needs specific steps to work with mitigation providers. These checklists reduce friction and hidden effort.
Shopify checklist
Confirm platform DDoS and CDN coverage for the storefront. Keep checkout on Shopify and avoid headless routing unless needed.
Test payment flows after DNS changes. Shopify often absorbs large L7 loads but merchants have less visibility into mitigation details.
WooCommerce checklist
Route traffic through a CDN and enable WAF rules. Rate limit the REST API and protect admin paths with IP allowlists.
Ensure the host supports quick instance scaling. Backups and a tested DNS failover plan are crucial for recovery.
Magento checklist
Enable full page caching and place admin on a separate subdomain. Enforce strict WAF policies for checkout areas.
Document RTO and test traffic failover regularly.
A short practical TCO example helps pick between flat fee and pay‑as‑you‑go. Start with hourly peak revenue (MonthlyRevenue ÷ hoursPerMonth). Expected annual loss = HourlyRevenue × ExpectedOutageHoursPerYear × ProbabilityOfAttack.
Example templates: micro shop ($800/mo → ~$1.11/hr): if probability of a 4‑hour outage per year is 10% expected annual loss ≈ $0.44. A $20 per month CDN is sensible.
Small merchant ($8,000/mo → ~$11.11/hr): with a 10% chance of one 8‑hour outage expected annual loss ≈ $8.89. Add likely forensic and recovery costs (often $200–$2,000) to choose between $300 per month managed plan or pay‑as‑you‑go scrubbing.
Mid‑size merchant ($20k/mo → ~$27.78/hr): a single 8‑hour outage costs ~$222. A $500+ per month buffer may be justified. Add expected per‑GB scrubbing and egress (estimate using provider quotes) to get net ROI.
These worked examples give a repeatable calculator approach. Use it to evaluate Cloudflare, AWS Shield, managed DDoS, or VPS add‑ons against likely business impact.
What nobody tells you
Many guides list plan names but skip the real line items that create bill shock. Bandwidth egress and per‑GB scrubbing rates usually dominate incident charges.
The error most frequent at this point is buying the largest capacity plan "just in case" without mapping attack probability to revenue risk. That choice creates unnecessary recurring costs.
Data point: the Dyn/Mirai attacks peaked around 1.2 Tbps in a major attack. The large attack on Brian Krebs' site measured about 620 Gbps. Market per‑GB scrubbing rates commonly range $0.01–$0.50 per GB depending on provider and contract.
Hidden fees to audit in contracts
Look for these line items: egress/bandwidth, per‑GB scrubbing, extra IP addresses, setup and onboarding fees. Also watch incident retainer and forensic logging costs.
A practical tip: negotiate a capped egress rate or a blended monthly cap for predictable billing during seasonal peaks.
Vendor support and SLAs
Check response times and SLA credits. Some vendors offer rapid mitigation within minutes; others require manual routing via BGP which takes longer.
The difference in SLA language can cost thousands during a major event since credits rarely match business losses.
Opinion: For most small merchants a combined approach works best: a CDN/WAF for baseline L7 defense plus a low‑tier scrubbing retainer for rare volumetric events. This approach saves money except when attacks are frequent or sustained for many hours, in which case a higher always‑on tier pays off for reduced downtime and simpler incident handling. Choose the model that aligns with predictable revenue exposure.
Estimated per‑attack budgeting rule: plan base protection + reserve 2–5× monthly subscription as an incident buffer if using pay‑as‑you‑go scrubbing. That buffer covers typical medium attacks without disrupting operations.
If a short vendor shortlist would help, a tailored comparison can match exact traffic, revenue, and platform. Small merchants get billed on multiple axes. A clear sample invoice line helps avoid sticker shock.
- Example for a 1 Gbps, 4‑hour event (mixed L3/L4 + L7 traffic): Monthly subscription (managed DDoS + WAF): $500.
- BGP failover / DNS failover setup (one‑time amortized): $75.
- Per‑GB scrubbing 2 TB @ $0.05/GB = $102.40.
- Carrier egress surcharge 2 TB @ $0.02/GB = $40.96.
- Additional forensic logging & packet capture: $150.
- Emergency support / incident hours (4 hr @ $150/hr): $600.
Total incident month add = $1,468.36. Separate items to audit in any quote: per‑GB scrubbing rates, egress charges, extra IP address fees (often $2–$5 per IP per month or $25+ one‑time), setup and onboarding, logging and forensics, and incident retainer or emergency hourly rates. Ask providers to show a worked 1 Gbps / 4–8 hour example for your expected traffic.
Questions
What does always‑on mitigation actually do?
Always‑on routes traffic through a mitigation layer continuously, reducing reaction time. It blocks malicious traffic before it reaches the origin. It reduces the need for emergency DNS or BGP changes and avoids the slow turn‑up of on‑demand scrubbing.
Is pay‑as‑you‑go cheaper for rare attacks?
Yes — for rare, small attacks because monthly cost stays low. One large incident can create unexpectedly high bills. Estimate likely attack volume and compare expected per‑GB charges to a flat tier before choosing.
How big should mitigation be for a small site?
Aim for 1 Gbps protection when monthly revenue exceeds $10k or peak hours are critical. Lower revenue sites can start with CDN/WAF plans. Plan for extra IPs and DNS failover when checkout or API endpoints are involved.
What hidden fees typically surprise small merchants?
Egress and per‑GB scrubbing costs are the most common surprise. Setup fees, extra IPs, and forensic logging add further costs. Always request sample invoices or a worked example showing a 1 Gbps event for 4–8 hours.
Can a VPS DDoS add‑on replace a CDN for a store?
No for large volumetric attacks. VPS add‑ons help with small floods and rate limiting, but they lack scrubbing capacity. Use VPS protection as a low‑cost baseline, then add CDN or scrubber for higher threat levels.
How to estimate lost revenue during downtime?
Use average hourly revenue during peak traffic. Multiply by expected outage hours and attack probability to compute expected loss. Compare that expected loss to protection cost and expected overage to pick the least costly option over time.
Does PCI DSS require DDoS protection?
PCI DSS requires merchants to protect cardholder data and ensure availability when required by their model. It does not mandate a specific DDoS product, but mitigation helps meet availability controls. Keep logs and incident records to show control during audits.
Actionable recommendation and next steps
Pick a protection model in three steps:
- Calculate peak hourly revenue and acceptable outage hours.
- Choose flat tier versus pay‑as‑you‑go based on cashflow and attack probability.
- Require vendor sample invoices and an explicit egress cap in the SLA.
For most small stores the practical starting point is a CDN/WAF plan ($20–$300 per month) plus a modest retainer or pay‑as‑you‑go buffer for occasional volumetrics. Negotiate egress and test failover before peak season.
References and further reading: check the AWS Shield pricing page for platform specifics AWS Shield pricing and CISA guidance on incident response for additional best practices.