Enterprise VPN in 2026: What to Buy When the Appliance Is the Risk
Enterprise VPN buyer's guide 2026: ZTNA vs legacy appliances, real per-user pricing for NordLayer, Twingate and Tailscale, seat minimums, audit logs and annual cost at 10, 50 and 500 users.
How the VPN box became the way in
For twenty years the remote-access design was the same everywhere. A concentrator sits at the network edge with a public IP, staff authenticate to it, and the tunnel drops them onto the corporate LAN. It worked because the office was where the applications were.
Two things ended it. The applications moved to SaaS and three clouds, so the LAN stopped being the destination. And the box itself turned into the most consistently exploited class of device in enterprise IT:
- Ivanti Connect Secure, January 2024: CVE-2023-46805 and CVE-2024-21887 chained for unauthenticated remote code execution, exploited in the wild before patches shipped.
- Palo Alto GlobalProtect, April 2024: CVE-2024-3400, a CVSS 10.0 command injection, exploited as a zero-day.
- Ivanti again, January 2025: CVE-2025-0282 exploited before a patch existed, with post-exploitation implants that reportedly survived factory resets and firmware updates.
- Cisco ASA and FTD, 2025: CVE-2025-20333 and CVE-2025-20362, zero-days used by a state-linked actor over a period of months, serious enough for CISA emergency directive 25-03.
- FortiOS, February 2026: CISA ordered federal agencies to patch or disconnect an actively exploited zero-day within 72 hours.
The pattern is the problem, not any single vendor. An appliance that must be reachable from the entire internet to do its job, running a proprietary stack that only its vendor can audit, and which grants network-level access once you are through it, is a poor bet however diligent your patching is. When one of these is exploited the attacker does not land on a web server. They land inside, holding the credentials of everyone who ever connected.
Why a consumer VPN is not a business VPN
Companies under about twenty people often try to solve this with five seats of a consumer service, and it fails for reasons that have nothing to do with encryption quality. A consumer VPN sends your traffic to a provider's exit node so a website sees their IP instead of yours. A business needs the opposite direction: bringing a named employee, on an approved device, to one internal application and nothing else.
What you do not get from NordVPN, ExpressVPN or Surfshark, regardless of price:
- A central console showing who is connected to what, right now.
- Per-user or per-group rules that scope access to individual resources.
- Audit logs, which is precisely the thing consumer providers advertise not keeping.
- SSO and SCIM, so access appears and disappears with the identity provider record.
- A static egress IP your systems can allowlist. Consumer IPs are shared and rotate, and half of them are already on somebody's blocklist.
- Device posture, so an unpatched personal laptop cannot connect at all.
A consumer VPN protects an employee on hotel wi-fi. That is a real use, and it is not remote access.
What you can actually buy, and what it costs
All prices below were checked on the vendors' own pricing pages on 26 July 2026, at annual billing rates. Monthly billing runs roughly 15% to 25% higher everywhere.
NordLayer
The closest thing to a drop-in replacement for a traditional business VPN, from the company behind NordVPN. Lite is $8 per user per month, Core $11, Premium $14, all with a five-user minimum. Enterprise starts at $6 per user but requires 200 seats. SSO is included on every tier, which is unusual and genuinely to their credit; charging extra for SAML is a widespread practice worth refusing to pay. Device posture is an add-on on Lite and Core and included on Premium. Site-to-site connectors start at Premium. A dedicated IP, which most buyers need, is a further $40 per month per gateway and is easy to miss when comparing headline seat prices.
Twingate
The cheapest credible ZTNA product. Teams is $4.25 per user per month, Business $8.50, and the free Starter tier covers 5 users, 10 remote networks and 50 resources, which is enough to run a genuine pilot rather than a demo. The tier boundary that matters is not price: Teams only supports Google Workspace SSO, and audit logs do not exist below Business, where retention is 30 days. Enterprise takes it to 12 months. Teams also caps at 100 users, Business at 500.
Tailscale
A WireGuard mesh rather than a gateway product, and the one engineers choose for themselves. Personal is free for up to 6 users with unlimited devices. Standard is $8 per user per month and includes SCIM provisioning and device posture integrations with MDM and EDR tooling. Premium is $18 and adds network flow logs, log streaming and just-in-time access. There is no seat minimum. The catch to price in: network flow logs, the thing a security team will ask for, sit on the $18 tier, not the $8 one.
The enterprise end
Zscaler Private Access, Palo Alto Prisma Access and Check Point's Harmony SASE (formerly Perimeter 81) are quote-only. Expect procurement cycles, annual commitments and a floor that makes them irrelevant below a few hundred seats. Cloudflare's Zero Trust offering has a free tier worth pricing directly if you already run Cloudflare, though the seat allowance was not published on the page checked here.
The things that decide it
Access scope. The single question that separates ZTNA from a VPN with better marketing: after a user connects, can they scan the internal subnet? On Twingate and Tailscale, access is granted per resource, so a compromised laptop reaches only what that person was entitled to. A traditional tunnel puts them on the network and relies on internal segmentation you probably have not finished.
The SSO line. Check which tier carries SAML with your specific identity provider. Twingate's Teams plan supports Google Workspace but not Okta or Entra ID, which quietly pushes most companies to Business and doubles the seat price.
Log retention in months, not features. "Audit logs: yes" is not an answer. Thirty days on a mid tier will not satisfy an auditor asking for a year, and log streaming to your own SIEM is usually the highest tier.
Connectors and legacy apps. Every ZTNA product needs an agent inside each network holding a private resource. Budget for where those run, how they are updated, and what happens when one dies. This is the migration work that surprises people, not the client rollout.
Egress IP. The moment a bank, a supplier or a legacy system asks you to allowlist an address, you need a static IP. Confirm the cost per gateway per region before signing.
Exit path. Ask how you leave. Tailscale's clients are open source under BSD-3, except the Windows, macOS and iOS graphical wrappers, which lowers the cost of changing your mind.
The arithmetic at 10, 50 and 500 people
Seat prices are easy to compare and easy to misjudge. These are annual list totals at the July 2026 rates above, assuming annual billing and one seat per employee.
- 10 people: Twingate Teams $510 a year. Tailscale Standard $960. NordLayer Lite $960, Premium $1,680 before the $480 a year dedicated IP. At this size Twingate's free tier already covers half your staff, and the honest advice is to run the pilot before paying anything.
- 50 people: Tailscale Standard $4,800. Twingate Business $5,100, which is the first tier with audit logs and Okta or Entra SSO. NordLayer Premium $8,400, or $8,880 with one dedicated IP. Tailscale Premium, if you need flow logs, is $10,800 and changes the ranking completely.
- 500 people: NordLayer Enterprise at $6 per seat is $36,000. Tailscale Standard list is $48,000, Twingate Business $51,000 at the top of its user cap. Nobody pays list at this size; the number that matters is the discount you negotiate and the length of commitment attached to it.
Two costs sit outside these totals in every case: the engineering time to map resources and deploy connectors, and the higher support tier you will want in year one.
The self-hosted route, and where it stops
Teams that dislike putting a control plane in someone else's cloud usually find Headscale, an open-source reimplementation of Tailscale's coordination server under a BSD-3 licence. It is more capable than its reputation suggests: ACLs, Tailscale SSH, MagicDNS, exit nodes, subnet routers, OIDC login and Taildrop all work, and release v0.29.2 landed on 1 July 2026 with active weekly commits.
Read the maintainers' own words before you plan around it. The project documentation states that Headscale is not enterprise software, that its audience is homelabbers and self-hosters, and that it can likely handle hundreds of devices provided the network changes little. It supports a single tailnet with no multi-tenancy, ships no official admin interface, and cannot use identity-provider groups in access policies, so role-based access has to be maintained by hand. The README also says running it behind a reverse proxy or in a container is neither supported nor encouraged, which rules out most standard deployment patterns.
Tailscale's own position is worth stating precisely, because both common summaries are wrong. It does not support Headscale and it is not hostile to it: it employs one of the maintainers, documents pointing official clients at a custom control server, and sells you nothing for it. Self-hosting DERP relays is separately possible, but it moves relay traffic only. The coordination server stays Tailscale's.
The reasonable compromise for a company that wants less trust in a SaaS control plane, without operating one, is Tailnet Lock: node keys are signed by your own trusted nodes, so the coordination server cannot silently add a device to your network.
What to buy
Under 20 people, engineering-heavy: Tailscale. The free tier covers 6 users, the mesh needs no gateway sizing, and it is the only option here your developers will set up without being asked twice. Move to Standard at $8 when you need SCIM and posture checks.
20 to 200 people, mixed workforce: Twingate Business at $8.50. It is the cheapest tier that includes Okta or Entra SSO plus audit logs, and per-resource access is a genuine security improvement rather than a repackaged tunnel. Pilot it free first, because the connector work is where your estimate will be wrong.
Compliance-driven, or you still need site-to-site: NordLayer Premium at $14 plus $40 a month for the dedicated IP. It costs more, and it is the one that behaves like the VPN your auditors and your legacy systems already understand, with SSO included at every level.
Who should not buy any of these: if your entire stack is SaaS behind an identity provider with conditional access and device compliance already enforced, you may not need a remote-access product at all. Buying one to "have a VPN" adds a dependency, a bill and an agent on every laptop to protect a network you no longer use. Spend the money on the identity provider instead.
Whatever you choose, the decision that pays for itself is retiring the internet-facing appliance. Everything above removes that box from the public internet, and that box is what the last three years of incident reports have been about.
Ready to try NordLayer?
Visit the official website to see the latest plans, pricing, and special offers.
Get Started — NordLayer* Affiliate link — we may earn a commission at no extra cost to you.