How Much Does DDoS-Protected CDN Cost? Pricing & Protection Comparison

Sep 30, 2026105 mins read

How much does a DDoS-protected CDN cost in 2026? Compare CDN pricing, DDoS protection capacity, CC attack mitigation, traffic billing, and plan limits across leading providers to find the right protection for websites, games, APIs, and online services.

2323232
 

There is no single answer to the question, “How much does a DDoS-protected CDN cost per month?”

Some CDN providers offer free plans. Cloudflare is one well-known example. Other services may cost $10, $200, $500, or several thousand dollars per month. Enterprise-grade services often do not publish fixed pricing at all. Instead, quotes are based on traffic volume, attack history, deployment region, number of domains, and service requirements.

In other words, two services may both be marketed as DDoS-protected CDNs while having completely different pricing models and protection scopes.

This comparison is based on vendor websites, official pricing pages, and publicly available billing documentation. The prices below are intended to show the cost of entry and the structure of each service. We do not treat a provider’s total network mitigation capacity as the protection capacity guaranteed to an individual customer, nor do we present a standard CDN package as if it were a dedicated DDoS protection service.

The term “market-wide comparison” in this article refers to a representative selection of publicly available plans and enterprise services. It does not mean that every provider on the market is included.

The comparison focuses on five questions:

  • What is the fixed monthly cost?
  • How much protection does the plan explicitly include?
  • How much legitimate traffic can still be served during an attack?
  • What happens when the stated protection limit is exceeded?
  • Who is responsible for incident response when something goes wrong?

The first two points are usually easy to find on a pricing page. The remaining three are often what determine whether a DDoS-protected CDN is suitable for production use.

Public Pricing for Major DDoS-Protected CDN Services

Provider / PlanPublic PricePublished ProtectionBilling / Plan DetailsBest Suited For
CDN5 FreeFree50 Gbps DDoS protection, 20,000 QPS CC protection2 domains, 2 ports; no network acceleration, multi-line routing, or WebSocketLearning the platform, small test sites
CDN5 Standard$499/month150 Gbps DDoS protection, 30,000 QPS CC protection5 domains, 10 ports; global acceleration, BGP/CN2, WebSocketCross-border websites, APIs, frequently attacked sites
CDN5 Business$1,999/month400 Gbps DDoS protection, 50,000 QPS CC protection10 domains, 20 ports; global acceleration and multi-line networkingHigh-risk websites, game login services, larger web workloads
Cloudflare Free$0Unmetered DDoS protectionBasic CDN, DNS, SSL, and security features includedPersonal sites, small projects, basic origin shielding
Cloudflare Pro$20/month billed annually, $25 month-to-monthUnmetered DDoS protectionAdds performance and security features for professional websitesContent sites, blogs, small and midsize businesses
Cloudflare Business$200/month billed annually, $250 month-to-monthUnmetered DDoS protection; no fixed per-customer Gbps allocation published100% uptime SLA; advanced enterprise capabilities remain contract-basedSMB websites, e-commerce, SaaS front ends
Alibaba Cloud ESA Pro$15/monthSecurity and traffic allowances are emphasized; no fixed DDoS Gbps commitment published500 GB included, $0.03/GB overage, 10 Gbps peak bandwidthBudget-conscious international sites and development projects
Alibaba Cloud ESA Premium$249/monthAdds Bot Management and more security rules; enterprise DDoS options are customized1.5 TB included, $0.166/GB overage, 10 Gbps peak bandwidthCommercial sites needing WAF, Bot Management, and real-time logs
Tencent Cloud EdgeOneFree entry tier; paid services vary by console or quote25 Tbps of dedicated global DDoS mitigation capacity publishedCDN, security, Layer 4 access, and Asian network coverageAsian audiences, e-commerce, game updates, SaaS
Gcore CDN + DDoS ProtectionCDN starts free; enterprise protection is quote-basedMore than 200 Tbps of network/filtering capacity; L3-L7 protectionLarger deployments priced by bandwidth, service scope, and architectureGaming, media, APIs, global network services
AWS CloudFront + Shield StandardNo additional Shield Standard charge for eligible AWS resourcesBaseline network-layer DDoS protectionCloudFront, WAF, logs, and data transfer billed separatelyWebsites and applications already on AWS
AWS Shield Advanced$3,000/month plus related resource chargesAdvanced DDoS protection for critical AWS resourcesOne-year commitment; data transfer and some WAF usage billed separatelyCritical AWS workloads and large platforms
Akamai ProlexicCustom quoteEnterprise network scrubbing and response servicesPricing based on network size, clean traffic, access location, and SLAFinancial institutions, large platforms, critical infrastructure
Imperva DDoS ProtectionCustom quoteProtection for websites, applications, APIs, and network infrastructureOften bundled with WAF, Bot Management, and enterprise supportOrganizations with strong compliance and application-security requirements

This table should not be used to decide which provider is “the cheapest.”

Alibaba Cloud ESA Pro costs $15 per month, while CDN5 Standard costs $499 per month. Those numbers are not directly comparable because the product commitments are different.

ESA Pro publishes traffic allowances, an overage rate, and a 10 Gbps peak bandwidth limit. CDN5 Standard instead publishes 150 Gbps of DDoS protection and 30,000 QPS of CC protection.

Price only becomes meaningful when you understand exactly what the customer is buying.

Cloudflare uses another model altogether. DDoS protection is described as unmetered and is available from the free tier, but the standard plan pages do not assign an individual customer a fixed 100 Gbps or 400 Gbps protection quota.

CDN5 uses fixed plan-level protection figures, which are easier to understand at a glance. Both approaches are valid, but they are contractually different. “Unmetered” should not be interpreted as “unlimited dedicated capacity.”

Tencent Cloud EdgeOne publishes 25 Tbps of dedicated global DDoS mitigation bandwidth. Gcore publishes more than 200 Tbps of filtering capacity. Cloudflare publishes a global network capacity of 500 Tbps.

Those figures describe the scale of the provider’s network.

They do not automatically tell you how much protection an individual customer receives, how traffic is handled once an attack begins, or whether clean traffic is throttled. Those answers still have to come from the actual order form and service agreement.

What Are You Really Paying for With a DDoS-Protected CDN?

The price difference between an entry-level plan and a higher-tier plan is rarely just about scrubbing capacity.

Domains and ports

The number of protected domains and ports matters.

Protecting a single corporate website with two hostnames is very different from protecting a platform with a primary website, API, download service, payment endpoint, campaign pages, and multiple application subdomains.

Once TCP, UDP, or custom ports are involved, a standard website CDN may no longer be sufficient. You may need a protected IP service, Layer 4 proxy, or another dedicated network product.

Legitimate traffic

Clean traffic is another major cost component.

Some providers bill by GB. Others charge by Mbps or 95th-percentile bandwidth. Some include a traffic allowance in the monthly plan and charge separately for usage above that amount.

In Alibaba Cloud ESA Premium’s official example, 2.7 TB of monthly traffic exceeds the included 1.5 TB by 1,200 GB. At $0.166 per GB, the total monthly charge reaches $448.20.

That figure does not include optional services such as smart routing.

WAF and Bot Management

WAF and Bot Management are often assumed to be standard components of a DDoS-protected CDN. That assumption can be expensive.

Basic DDoS mitigation is primarily designed to handle volumetric and protocol-level attacks. HTTP Floods, malicious crawlers, API abuse, credential stuffing, and slow-request attacks are different problems.

A plan may advertise 100 Gbps of protection, but if it does not specify CC mitigation rules, WAF request limits, Bot detection, and false-positive handling, the application can still become unavailable long before the network pipe is saturated.

Support

Support can also account for a meaningful portion of the price.

Free tiers often rely on community support or tickets. Enterprise contracts may include phone escalation, emergency attack response, dedicated engineers, post-incident analysis, and service credits.

When you are under attack at 2 a.m., the ability to reach someone who can act is often more valuable than another feature in the dashboard.

These details are difficult to quantify from a pricing page, which is why they should be written into the SLA.

Where Does CDN5 Sit on Price?

CDN5 Standard costs $499 per month, while the Business plan costs $1,999 per month.

Compared with a conventional CDN, those prices are not low. Compared with packaged DDoS-protected CDN products that publish fixed protection levels, however, the positioning is fairly clear.

The Standard plan includes:

  • 150 Gbps DDoS protection
  • 30,000 QPS CC protection
  • 5 domains
  • 10 ports
  • WebSocket
  • Global acceleration
  • BGP/CN2 connectivity

For websites targeting Hong Kong, Southeast Asia, or other international markets while still needing better connectivity toward mainland China, that package is more specific than simply buying a low-cost traffic bundle.

The Business plan raises protection to 400 Gbps and CC mitigation to 50,000 QPS, while also increasing the number of domains and ports.

That makes it more relevant to continuously operated, higher-risk services.

For a site that depends on online transactions, or one that has already experienced attacks in the hundreds of Gbps, $1,999 per month is not necessarily more expensive than repeated emergency mitigation.

That only holds true if the plan actually covers the attack types you face and the rules for clean traffic, overages, and service limits are clearly documented.

One of CDN5’s advantages is pricing transparency. Monthly fees, protection levels, domain limits, port limits, and network options are listed publicly, making it easier for procurement teams to estimate the required budget.

There are still important questions to verify before signing:

  • How are the 150 Gbps and 400 Gbps limits measured?
  • Are they per-location peaks or network-wide figures?
  • What happens above the threshold: rate limiting, blackholing, or elastic mitigation?
  • How is legitimate traffic billed?

Those answers cannot be fully determined from the pricing page alone.

The free plan is useful for testing accounts, certificates, DNS switching, and the management console. It does not include network acceleration, multi-line networking, or WebSocket.

For that reason, its latency and routing behavior should not be treated as representative of the Standard or Business plans.

Before purchasing, ask for a temporary CNAME and test your own static assets, login endpoints, dynamic requests, and WebSocket traffic.

Can Cloudflare Replace a Fixed-Capacity DDoS-Protected CDN?

Cloudflare is an easy way to put a website behind a global Anycast network.

The free tier already includes CDN, DNS, SSL, and unmetered DDoS protection. Pro and Business pricing is also significantly lower than fixed-capacity protection plans costing several hundred dollars per month.

For personal websites, content sites, and typical SaaS front ends, it is often a practical first line of defense.

The important part is understanding the product boundary.

Cloudflare Free, Pro, and Business provide website protection on a shared global network. If an enterprise needs traffic prioritization, advanced support, sophisticated Bot Management, Magic Transit, Spectrum, or a custom SLA, pricing moves into a different tier and often becomes contract-based.

Game TCP/UDP traffic, self-hosted network blocks, and custom-port applications also cannot be evaluated using the standard website plans alone.

The benefit of unmetered DDoS protection is that attack traffic usually does not turn directly into a rapidly growing per-GB bill.

The benefit of fixed-Gbps plans is that procurement teams can more easily see a concrete number in the contract.

Which model is better depends on whether your priority is global website delivery or a clearly defined commitment for a specific region, route, protocol, or attack profile.

Is Alibaba Cloud ESA’s Low-Cost Pricing Worth Considering?

Alibaba Cloud ESA Pro costs $15 per month and includes 500 GB of traffic, with additional traffic billed at $0.03 per GB.

Premium costs $249 per month and includes 1.5 TB of traffic, with additional usage billed at $0.166 per GB.

Both public plans list a peak bandwidth of 10 Gbps. Enterprise plans are customized.

This model is attractive for budget-conscious websites because the traffic allowance and overage formula are easy to calculate. Malicious traffic blocked by WAF does not count toward traffic usage, and HTTPS and WAF requests are not billed separately.

For a standard corporate website, international utility site, or mid-sized e-commerce business, monthly costs can be estimated fairly accurately.

The public pricing model is more focused on edge acceleration and web security than on fixed-capacity DDoS mitigation.

If your procurement requirement is a clearly defined 100 Gbps, 300 Gbps, or higher attack-protection commitment, you will need to discuss an enterprise offering.

The 10 Gbps peak bandwidth figure should also be evaluated in the context of normal application traffic.

If your site normally uses only a few dozen Mbps, 10 Gbps leaves plenty of headroom. Large downloads, video delivery, and sudden campaign spikes require a different calculation.

Which Workloads Fit Tencent Cloud EdgeOne and Gcore?

Tencent Cloud EdgeOne combines CDN, WAF, Bot Management, Layer 4 access, and edge computing in one platform.

Its website lists more than 3,200 PoPs and 400 Tbps of global network bandwidth, including 25 Tbps dedicated to DDoS mitigation.

The platform is particularly broad for Asian network delivery, game updates, e-commerce, and cross-region SaaS.

A free entry option is publicly available, while higher-tier security capabilities and exact pricing depend on the selected plan or a sales quote.

When requesting pricing, website-layer protection and TCP/UDP Layer 4 protection should be discussed separately.

Support for both domain-based Layer 7 access and TCP/UDP connections does not mean every capability is included in the same low-cost plan.

Gcore offers a CDN that can be started for free. Its public materials state that plans include L3, L4, and L7 DDoS protection and WAF, and the company advertises more than 200 Tbps of network and filtering capacity.

Its strengths are particularly relevant to global media delivery, game assets, live streaming, and network-layer protection.

Larger deployments typically move to custom pricing, where customers should verify committed bandwidth, scrubbing-center locations, origin routing, and local support.

Both providers publish very large network-wide numbers.

In a procurement document, the more important figures are the limits that apply to one customer.

How much legitimate traffic remains available during an attack? How much latency does cross-region origin routing add? How close are the scrubbing centers to your main users?

Those numbers are usually more relevant to real-world service quality than a headline network capacity figure.

Why AWS, Akamai, and Imperva Rarely Publish Simple Monthly Plans

AWS is relatively easy to understand at the entry level.

Shield Standard provides baseline protection for eligible services such as CloudFront, ELB, and Route 53 without a separate Shield fee.

Customers still pay for cloud resources, bandwidth, WAF, and logging.

If the application already runs on AWS, using the native security stack may reduce the amount of migration and routing work required.

Shield Advanced costs $3,000 per month, in addition to related resource and data-transfer charges, and requires a one-year subscription commitment.

That price includes more advanced attack detection, cost protection, and expert support.

It is designed for critical workloads. It is not an economical reason to move a small website into AWS solely for DDoS protection.

Akamai Prolexic and Imperva are commonly purchased by larger organizations.

Their pricing has to account for network ranges, BGP integration, legitimate bandwidth, scrubbing-center requirements, compliance obligations, and incident-response services.

That makes a universal monthly price difficult to publish.

Custom pricing does not automatically mean expensive, but the sales cycle is usually longer and contract value depends more heavily on workload size.

The advantage of enterprise services is that responsibilities can be defined in detail.

Who decides when mitigation is activated? How quickly can scrubbing be engaged? How are false positives handled? Is a post-incident report included? What happens when the SLA is missed?

All of these points can become contractual obligations.

Public plans are easier to buy and easier to budget.

The two models are simply designed for different organizational requirements.

How Much Protection Do You Need: 100 Gbps, 300 Gbps, or 500 Gbps?

Protection capacity should be selected based on attack history.

If you do not have historical data, ask your cloud provider, data center, or previous security vendor for:

  • Peak attack bandwidth
  • PPS
  • Request rate
  • Attack protocol
  • Attack duration

Knowing only that “the site went offline” is not enough information to buy protection.

Plans below 100 Gbps may be sufficient for standard corporate websites and relatively low-risk applications.

If most attacks are HTTP-based, CC mitigation, WAF, and Bot rules may matter more than simply buying more network capacity.

The 150-400 Gbps range is more common for services that are repeatedly targeted, game login infrastructure, APIs, and cross-border applications.

In this range, pay close attention to the amount of clean traffic available after mitigation.

A provider may allow 300 Gbps of attack traffic to be scrubbed while giving the customer only 100 Mbps of legitimate outbound capacity.

The application can still become slow during peak usage.

Plans above 500 Gbps or in the Tbps range are more relevant to large platforms with a documented history of major attacks.

Do not buy a larger number simply because it looks safer.

Multi-vector attacks, UDP reflection, SYN Floods, and application-layer attacks all place different demands on mitigation infrastructure. The distance between the user and the nearest scrubbing center also affects latency.

Protection headroom should not be too small.

If your historical peak is 80 Gbps, a 100 Gbps plan leaves only 20 Gbps of margin. A change in amplification method or attack source can quickly exceed that limit.

A more defensible approach is to give the provider your historical attack peak, normal traffic growth, and business criticality, then ask them to recommend a protection level and explain the calculation.

Costs That Are Easy to Miss Beyond the Monthly Fee

1. Legitimate traffic

Attack traffic may be mitigated for free while normal user downloads, images, video, and dynamic responses are still billed.

Once monthly traffic reaches several TB, bandwidth charges can exceed the base subscription.

2. Origin and cloud egress

When the CDN fetches content from the origin, the cloud provider hosting that origin may charge for outbound traffic.

A low cache-hit ratio can increase both the CDN bill and the origin bill.

3. Security feature usage

WAF requests, Bot Management, log storage, real-time log delivery, custom rules, and premium certificates may all be billed separately.

A pricing page that says “WAF included” does not necessarily mean every WAF feature or unlimited rules are included.

4. Elastic mitigation during attacks

Some plans throttle traffic above the limit. Others activate elastic protection. Others may trigger blackholing.

A sales promise that “capacity can be expanded” is not enough to control costs.

The contract should state the maximum monthly charge under 100 Gbps, 300 Gbps, and 500 Gbps attack scenarios.

5. Migration

Changing DNS is easy.

Properly hiding the origin, updating firewalls, preserving the real client IP, reinstalling certificates, and validating application behavior takes time.

Applications using WebSocket, persistent connections, and custom ports require additional testing.

There is another cost that is often overlooked: the bill may continue changing after the attack ends.

Some services are billed on the highest monthly peak, 95th-percentile bandwidth, or attack duration.

A ten-minute attack can therefore affect an entire month’s bill.

Before signing, ask the provider to calculate a sample invoice based on a realistic attack scenario.

Do not ask only for the advertised starting price.

Third-Party Procurement Comparison

The table below reflects the transparency of public information and typical procurement scenarios. It is not a laboratory performance ranking.

Actual speed and stability should be tested with a customer-specific CNAME.

ServicePricing TransparencyProtection TransparencyMonthly Budget PredictabilityTypical Procurement Fit
CDN5HighHigh; fixed Gbps and QPS publishedRelatively high; overage rules still need confirmationSites needing explicit protection levels and Hong Kong/cross-border routing
CloudflareHighMedium; no fixed Gbps allocation on standard plansHigh for baseline website protectionGlobal websites, low-friction deployment, SMBs
Alibaba Cloud ESAHighMedium; traffic and bandwidth clear, high-capacity DDoS plans require inquiryHigh; overage pricing publishedBudget-sensitive projects needing WAF and Asian connectivity
Tencent Cloud EdgeOneMediumMedium; network capacity public, customer-level plan requires verificationMediumAsian businesses, gaming, e-commerce, Layer 4 access
GcoreMediumMedium; network-wide capacity public, enterprise commitments require confirmationMediumGaming, media, streaming, global network services
AWS ShieldHighHigh; service scope and billing documentation are detailedMedium; many related AWS chargesCritical workloads already deeply integrated with AWS
AkamaiLowDetailed inside enterprise contractsMedium; full quote requiredLarge enterprises, finance, critical infrastructure
ImpervaLowDetailed inside enterprise contractsMediumEnterprises focused on WAF, API security, and compliance

Cloudflare and Alibaba Cloud ESA have a lower barrier to entry.

If you specifically want a plan that publishes fixed protection levels in the hundreds of Gbps, CDN5 is more straightforward.

For predominantly Asian traffic, Tencent Cloud EdgeOne and CDN5 are worth testing in the same evaluation round.

If the application already runs on AWS, Shield Standard and Shield Advanced are easier to integrate into the existing architecture.

Large networks and mission-critical services will often end up discussing custom deployments with providers such as Gcore, Akamai, or Imperva.

There is no single overall winner in this comparison.

Change the user geography, attack profile, or existing infrastructure, and the right shortlist changes with it.

A content website serving mainly North America and Europe has very different requirements from a game login service that needs a Hong Kong entry point, WebSocket support, and stable connectivity toward mainland China.

How to Test Before You Buy

A provider should be able to offer a test hostname, temporary CNAME, or trial account.

Use your own application content and endpoints.

Pinging the provider’s corporate website does not test customer-node caching, origin fetch behavior, or mitigation performance.

For static testing, prepare 1 MB, 10 MB, and 100 MB files and measure:

  • Time to first byte
  • Full download speed
  • Cache hit rate

For dynamic testing, use login, query, and submission endpoints and record:

  • P95 response time
  • Error rate
  • Origin bandwidth

If your application uses WebSocket, maintain long-running connections and watch for disconnects and reconnections.

Security testing should always remain within the provider’s approved scope.

Do not launch a large-scale traffic attack without authorization.

Start by validating WAF rules, rate limiting, CAPTCHA, IP blocking, real-client-IP forwarding, and alerting.

Then ask the provider to arrange an authorized load test or mitigation exercise.

Testing should cover at least one weekday evening peak.

If users are located in mainland China, Hong Kong, Japan, and Singapore, place probes in each location.

Once access performance is stable, verify whether the origin can still be reached directly.

Historical DNS records, old servers, staging domains, email records, and error pages can all expose the origin IP.

Another often-overlooked test is failback.

If you disable the CDN, switch to a backup origin, replace a certificate, or roll DNS back, can the team restore service within the expected time?

A DDoS-protected CDN working normally under ideal conditions does not prove that your failover process will work.

Questions to Ask When Reviewing a Quote

A usable quote should clearly state:

  • Whether protection capacity is measured as a peak, average, or another metric
  • Which attack types are covered by network-layer DDoS protection and application-layer CC mitigation
  • What happens above the protection limit: throttling, blackholing, or elastic expansion
  • How much legitimate traffic remains available during an attack
  • How clean traffic, origin traffic, and logs are billed
  • Limits on domains, ports, certificates, WebSocket, TCP, and UDP
  • Locations of scrubbing centers, user-facing nodes, and origin routes
  • Alerting, false-positive handling, after-hours response, and incident-report timelines
  • Whether the provider assists with migration if the origin IP is exposed
  • What compensation applies if the SLA is not met

If a sales representative can repeatedly quote total network capacity but cannot explain customer-level bandwidth, overage rules, or response times, the proposal is not yet procurement-ready.

A smaller number with clear contractual boundaries is often more useful in production than a much larger marketing number.

FAQ

How much does a DDoS-protected CDN usually cost per month?

Small websites can start with free plans or edge-security services costing only a few dollars per month.

Plans that explicitly advertise protection in the hundreds of Gbps usually cost several hundred dollars per month, with higher tiers reaching $1,999 per month or more.

Large enterprise networks, dedicated lines, and Tbps-class protection are commonly quote-based.

Does Cloudflare Free count as a DDoS-protected CDN?

Cloudflare Free includes CDN and unmetered DDoS protection and can serve as a baseline website-security layer.

It does not assign every customer a fixed dedicated protection quota measured in hundreds of Gbps.

Advanced Bot Management, network products, and enterprise support also belong to different service tiers.

If a plan says 400 Gbps, does that guarantee it can absorb a 400 Gbps attack?

The 400 Gbps figure is a published vendor specification.

Before purchasing, confirm how the figure is measured, which attack types it applies to, whether it is per location or network-wide, when mitigation is triggered, how much clean bandwidth remains available, and what happens above the threshold.

The number only becomes operationally meaningful when those conditions are defined in the contract.

Should I buy a larger DDoS plan if my site is under a CC attack?

Not necessarily.

CC attacks mainly consume application and API resources.

Increasing network-layer bandwidth may have little effect.

Review WAF rules, rate limits, Bot Management, caching, and origin capacity.

The plan’s QPS mitigation capability and false-positive handling may be more relevant than its raw Gbps figure.

Do I still need to protect the origin after deploying a DDoS-protected CDN?

Yes.

If an attacker discovers the origin IP, they can bypass the CDN and attack the server directly.

After deployment, replace any exposed origin IP where possible, or configure the firewall to accept origin traffic only from the CDN’s egress addresses.

Also check historical DNS and other sources of IP leakage.

Can a game service use a standard website DDoS-protected CDN?

Login pages, download sites, and HTTP/HTTPS APIs can often use a website-focused protected CDN.

The main game connection may use UDP, dedicated TCP ports, long-lived sessions, or real-time voice.

Those workloads require comparison with protected IP services, Layer 4 proxies, or SDK-based protection.

A Gbps number shown on a website plan does not automatically represent protection for game protocols.

Does “unlimited” or “unmetered” protection mean attack traffic can never generate additional charges?

Read the service agreement.

“Unlimited” or “unmetered” usually means attack traffic is not billed like normal bandwidth.

It does not mean there are no fair-use policies, rate limits, service boundaries, or product restrictions.

Legitimate traffic, additional security features, and enterprise support may still be billed separately.

Final Procurement Takeaway

If your budget is limited and the site is relatively small, Cloudflare and Alibaba Cloud ESA are reasonable services to test first. Both have a low barrier to entry and relatively transparent public pricing.

If the site has a documented risk of attacks in the hundreds of Gbps and you want a plan with fixed DDoS and CC protection figures, CDN5 is worth testing. Its Standard and Business tiers have clear entry prices, although traffic billing, overage rules, clean bandwidth, and SLA terms should still be confirmed before signing.

For services with a large Asian user base, Tencent Cloud EdgeOne, CDN5, and Alibaba Cloud ESA can be tested in the same evaluation round.

Use your own domain and origin when comparing them. Do not use the latency of a provider’s corporate website as a substitute for customer-node performance.

If the application is already deeply integrated into AWS, evaluate Shield together with CloudFront before introducing another platform.

Large gaming, financial, and platform businesses generally need more detailed network commitments and should discuss enterprise agreements with providers such as Gcore, Akamai, and Imperva.

The market price of a DDoS-protected CDN can range from free to several thousand dollars per month.

The number only becomes meaningful after you document your attack history, legitimate traffic, application protocols, user locations, and incident-response requirements, then compare those needs against the exact boundaries of each plan.

Public Sources

Pricing, plans, and published specifications were reviewed on October 1, 2026.

Vendors may change pricing, PoP coverage, traffic allowances, and protection policies. Always confirm the latest pricing page, order form, and service agreement before purchasing.