What Does Bot Protection Cost a Small Business in 2026?

Short answer: For almost any small business site, the tool that stops the bots you have is free. Cloudflare Turnstile costs nothing at any volume. Google's reCAPTCHA is free up to 10,000 checks a month. hCaptcha has a free tier, and Friendly Captcha has one for non-commercial sites. If you pay for anything, Cloudflare Pro at $25 a month or Business at $250 buys bot filtering across the whole site rather than one form. The tier to be wary of is the metered one: Google's paid reCAPTCHA tiers and Fingerprint both charge per check once you cross a free ceiling, which is fine until a bot flood or a viral post pushes your bill up with it. The enterprise vendors, DataDome and Kasada, only make sense once you handle millions of requests and lose real money to bots: DataDome's cheapest published contract is $45,960 a year, and Kasada's one published contract is $99,000. Below is every number, read off the vendor's own page on 2026-09-23, and a table to match a tier to your site.
What Cloudflare charges
Cloudflare splits bot protection into a widget you add to one form and a filter that runs on everything.
Turnstile, the CAPTCHA replacement widget, is free at any volume on the Free plan: up to 20 widgets per account, 7 days of analytics, 10 hostnames per widget. The only paid tier is Enterprise, priced by quote, which raises those caps, removes Cloudflare branding and adds Ephemeral IDs. Cloudflare pitches it at organizations that need device fingerprinting. For a contact form, a signup form, or a booking form, the free plan is the whole product.
Site-wide bot filtering is a plan feature, not a separate purchase. Cloudflare's own plan comparison, read on 2026-09-23, lists Free, Pro at $20 a month billed annually (or $25 month to month), Business at $200 a month billed annually (or $250 month to month), and a custom-priced Contract tier, usually called Enterprise. The same page's feature table names what each tier actually catches, under "Bot Mitigation": Free stops "Simple bots," Pro adds "Easy-to-detect bots," Business adds "Sophisticated bots + basic bot analytics," and the Contract tier adds "All bots, anomaly detection, custom CAPTCHAs, advanced bot analytics." Those are Cloudflare's words. A site on the Free plan is defended against the crude end of the traffic only.
The practical read: a blog or a five-page marketing site needs Turnstile on its one form and nothing else. A site that takes bookings, logins, or payments, where a bot flood means real cost, gets real protection starting at Pro, and the floor for "sophisticated bots" is Business at $250 a month.
What Google charges once the free quota runs out
Older guides say reCAPTCHA is free up to a million checks a month. That no longer holds. Google has moved reCAPTCHA into Google Cloud, and its migration guide says you "will be charged when you exceed the free monthly allowance of reCAPTCHA, which is 10,000 assessments per month." The million-call line still sits in Google's older reCAPTCHA FAQ, which is where the confusion comes from.
Google's pricing page, read on 2026-09-23, lists three tiers. Essentials is free up to 10,000 assessments a month. Premium is free for the first 10,000, then an $8 flat fee from 10,001 to 100,000, then $1.00 per 1,000 above that. Enterprise is a fixed monthly commitment at $1 per 1,000, with a 12-month minimum. The free 10,000 is counted per Google Cloud organization across all your sites, and without billing enabled, requests past it return an error. A small business contact form rarely gets near 10,000 checks a month. A busy signup form under attack can, and the bill rises in step with the attack, which is the opposite of what you want from a security tool.
The rest of the CAPTCHA and proof-of-work field
hCaptcha's pricing page, read on 2026-09-23, lists a free Basic tier, then Pro at $139 a month billed monthly or $99 a month billed annually, including 100,000 evaluations a month with overages at $0.99 per 1,000, then a custom-quoted Enterprise tier with risk scores, a passive "No-CAPTCHA" mode and SAML SSO. The passive mode that spares visitors a puzzle starts at Pro.
Friendly Captcha, a proof-of-work widget that never shows the visitor a puzzle, lists these plans on its own site: free for one domain and 1,000 requests a month, for non-commercial websites only; Starter at €9 a month for one domain and 1,000 requests; Growth at €39 a month for up to five domains and 5,000 requests, and Advanced at €200 a month for up to 50 domains and 50,000 requests, with Enterprise on custom quote above that.
Two more options cost nothing because nobody sells them: ALTCHA and Anubis are open-source, self-hosted proof-of-work checks. There is no vendor bill, but there is no support line either, and you carry the hosting and the update burden yourself.
Device fingerprinting: Fingerprint's published number
Fingerprint's pricing page, read on 2026-09-23, lists a free tier at up to 1,000 API calls a month, then Pro Plus at $99 a month for 20,000 calls with $4 per additional 1,000, then a custom Enterprise tier with a 99.9% uptime SLA. This is different from a CAPTCHA: it identifies a returning device rather than challenging a visitor, which matters more for fraud and account-takeover defense than for stopping a spam form. For a small business, pay for it only after you've found bots creating fake accounts or false leads under different identities, not as a first line of defense.
Where the enterprise tier starts
DataDome and Kasada do not publish a price list on their own marketing pages, but their AWS Marketplace listings show one. DataDome Bot Protect's AWS listing, read on 2026-09-23, shows a 12-month Essentials contract at $45,960, about $3,830 a month, covering up to 100 million requests a month. The tiers above it run to $104,040, $121,920 and $159,240 a year as the included volume rises to 500 million requests a month. Kasada's AWS listing, read the same day, shows one contract: $99,000 for 12 months, covering up to 20 million requests a year across web, mobile and API traffic combined.
These contracts are sized for sites that count requests in the millions and lose real money to credential stuffing or scraping. At that scale, a $4,000-a-month bill can be small next to the loss it prevents. For a business running a handful of forms and a checkout page, this tier is not a discount away from making sense. It is the wrong shelf.

What doing nothing costs
Most small sites do not need the enterprise tier, but doing nothing has a cost too. Elon Musk said on a Twitter Spaces call in December 2022, as reported by Commsrisk in January 2023, that "Twitter was being scammed to the tune of 60 million dollars a year for SMS texts, not counting North America," from telecom operators running bot accounts through two-factor SMS over and over to collect the per-message fee, 390 telcos in total once the team went looking. That is an extreme case at platform scale, but the mechanism is the same one a small signup form with SMS verification is exposed to: every one-time code a script requests is a text you pay for, and it costs the person requesting it nothing. Imperva's 2026 Bad Bot Report puts automated traffic at more than 53% of all web traffic in 2025, up from 51% the year before, with human traffic at 47%. That is a web-wide figure, and your own site's split may be very different, but some share of your hosting bill is almost certainly serving bots. The pillar post in this series has the fuller picture of what that traffic split means and where it is heading. How bots spam contact and signup forms, a sibling post, covers the sales-time cost of fake leads and how the OTP-fraud pattern above plays out on a small form, in more detail than belongs in a pricing post.
A decision table by site type
| Site type | Start here | Add if the problem persists |
|---|---|---|
| Blog, portfolio, five-page marketing site | Turnstile (free) on the contact form | Nothing, usually |
| Local-service site with a booking or quote form | Turnstile or hCaptcha free tier, plus a honeypot field and a per-identity rate limit | Cloudflare Pro ($25/mo) if the whole site, not just the form, is getting hit |
| SaaS or membership signup with SMS/email verification | reCAPTCHA (free to 10,000 checks/mo) at signup, verification cost capped at the valuable step, not the front door | Paid reCAPTCHA or Fingerprint once volume or account fraud crosses what the free tier can absorb |
| E-commerce checkout | Cloudflare Business ($250/mo) for site-wide "sophisticated bot" filtering | Fingerprint ($99/mo) if fraud is coming through repeat devices under different identities |
| High-value target: ticketing, government portal, anything scalpers or credential-stuffers actively target | Cloudflare Business as the floor, not the ceiling | DataDome or Kasada, once volume and loss both justify a five-figure annual contract |

What Ready Bytes would and would not build here
The disclosure first: Ready Bytes has not built a bot-protection product, and this is not a sales pitch dressed as a buyer's guide. We build web apps, back-office automation, and integrations for owner-led businesses, the pattern behind AI back office for small business. Nothing in this post is a case study.
Most of what is above is configuration, not development: turning on Turnstile, adding a honeypot field, setting a rate limit on the right endpoint. Paying anyone to build that would be a waste of money, and we would say so.
Where it becomes real work is wiring the check to the value at risk, not the front door: verify identity before an OTP goes out, rate-limit per account or phone number instead of per IP so the SMS-pumping pattern above actually stops, and route a suspicious signup to manual review rather than blocking it outright or waving it through. If that is a gap on your site, here is the ladder:
- A free AI opportunity audit at /ai-audit: about five minutes, no cost. Shyam reviews it and emails a written audit within two business days.
- A $500 full audit if the free one surfaces something specific: your top 3 opportunities ranked by ROI, a 90-day roadmap, and a fixed pilot quote, credited against the pilot if you proceed.
- A fixed-quote pilot, typically $3,000 to $8,000 over 2 to 6 weeks, scoped to one piece: here, usually moving the check from the front door to the form submit, OTP send, or checkout step where a bot actually costs you money.
- Ongoing work once a pilot has proved itself.
Sometimes the most useful outcome is a recommendation to spend nothing, because the free tier already covers it.
Start here
Before any tool, spend twenty minutes finding out what you are actually paying for bots today.
Pull last month's SMS or OTP bill if you send either, and count how many verification texts went to numbers that never became a customer. Pull your contact-form or signup inbox and count submissions that were obviously automated, gibberish text, spam links, the same message worded three different ways within a minute of each other. Check whether your hosting or CDN dashboard shows a request-volume spike that does not match your traffic in Google Analytics; that gap is bot load you are paying server costs for.
Match what you find against the table above. If the count is a handful a month, the free tier fixes it this afternoon. If it is hundreds, or if it is costing you real SMS spend, that is worth a proper look before you buy anything.
Shyam Verma founded Ready Bytes in 2009 and has been building software since 2005. He writes about back-office automation, legacy modernization and applied AI at readybytes.in/blog.

Shyam Verma
Full Stack Developer & Founder
Shyam Verma is a seasoned full stack developer and the founder of Ready Bytes Software Labs. With over 13 years of experience in software development, he specializes in building scalable web applications using modern technologies like React, Next.js, Node.js, and cloud platforms. His passion for technology extends beyond coding—he's committed to sharing knowledge through blog posts, mentoring junior developers, and contributing to open-source projects.


