What do you actually get from a VPN service, and how is a business VPN different?
Summary
A VPN wraps your traffic in an encrypted tunnel so it can cross a shared network like the internet without being read on the way. A VPN service sells you the servers at the far end of that tunnel and the app that connects to them. Consumer services send nearly everything your device does online through the provider's servers. Business services connect employees to company systems and let an administrator decide who gets in, which is why their pricing comes with minimum user counts and server charges that consumer plans don't have.
The tunnel and the product are two separate things
"VPN" names a family of techniques, not a product. NIST describes IPsec, one of the oldest of them, as "a framework of open standards for ensuring private communications over Internet Protocol (IP) networks." OpenVPN and WireGuard do the same basic job in different ways. One end wraps and encrypts each packet, the other end unwraps it.
A VPN company turns that into something you can buy. For a consumer, that means a network of servers in many countries and an app with a connect button. For a business it also means user accounts, multi-factor sign-in, connection logs, sometimes a dedicated IP address, and an admin console to manage all of it.
Consumer VPNs route everything. Business VPNs open a door
Switch on a consumer VPN and almost all of your phone's or laptop's internet traffic leaves through the provider's server. The websites you visit see that server's IP address, not your home connection.
Business VPNs usually start from the other direction. The goal is to let someone working from home reach a file server, an internal app or a private cloud network. Tailscale is a clear example. Out of the box, its documentation says, it "only routes traffic between devices running Tailscale, but doesn't touch your public internet traffic." Sending everything through the company network is an extra step, where you designate one machine as an exit node.
What you are paying for in a business product is control. Removing a departing employee's access on their last day, or letting only the finance team reach the accounting system, happens in the admin console.
Pricing terms you only see on business plans
Business VPNs are mostly advertised per user per month, and that figure alone rarely equals the bill. Proton VPN's business plans need at least two users for VPN Essentials and VPN Professional, and three for the plan that bundles its password manager. NordLayer sets a five-user minimum on all three of its plans, and Core also requires a server with a dedicated IP at $40 a month.
Some products don't count people at all. They bill per device or per server, and putting those next to per-user prices in one column compares two different things. Our article on billing units walks through the difference.
Why ZTNA keeps showing up
Search for a business VPN and you will run into ZTNA, short for zero trust network access. NIST's definition of zero trust is that nobody gets "implicit trust" just because of "their physical or network location" or because the company owns the device. Identity and device checks happen before each connection to a company resource.
If a VPN puts you on the company network, ZTNA gives you one application at a time. Most products sold today mix the two, and our tables list NordLayer and Tailscale as zero-trust products for that reason. Per-user ZTNA costs have a page of their own.
Sources
- https://csrc.nist.gov/pubs/sp/800/77/r1/final
- https://csrc.nist.gov/pubs/sp/800/207/final
- https://tailscale.com/docs/features/exit-nodes
- https://proton.me/business/vpn/pricing
- https://nordlayer.com/pricing/
- https://seatbill.com/vpn-pricing/
Related on this site
- Business VPN pricing: what teams actually pay per user
- Per user, per device, or per server — the unit is not the same everywhere
- ZTNA pricing: what zero-trust network access costs per user
- Which business VPN should a small team actually buy?
- What is a VPN tunnel, and does all of your traffic have to go through it?
- What's the difference between a VPN protocol, a cipher, and post-quantum encryption?
Written by Kaz (pen name). Published September 28, 2026. The facts above come from the vendor and standards pages listed under Sources. We have not used these products. Corrections: contact form.