The NordVPN two-year plan list price is $3.39 per month, billed as $81.36 up front. The ExpressVPN equivalent is $4.99, billed as $99.95 plus three free months. The Surfshark Starter two-year is $2.19. ProtonVPN's two-year Plus is $3.59. Pull those four numbers into a column and the spread looks tractable — call it a $2.80 monthly band across the headline tier. That is the receipt. Every provider above has been the subject of a public assurance engagement; none of those engagements, in their published scope, included fee-structure verification. That is the gap this desk is interested in.

The article title nods at five providers because that is the number affiliate sites lead with. We will analyse four, because those are the four whose published audit history makes the cross-check meaningful. The fifth slot in most "best VPN" listicles is rotated for affiliate inventory reasons we are not interested in subsidising.

What the Fee Numbers Actually Say

Stack the headline rates in the order a consumer would encounter them on a comparison page. Surfshark Starter, two-year commitment, $2.19/month. NordVPN Basic, two-year, $3.39/month. ProtonVPN Plus, two-year, $3.59/month. ExpressVPN, two-year-plus-three-free, $4.99/month. The arithmetic mean is $3.54. The standard deviation across the four is roughly $1.04. On a per-month basis, the band reads narrow.

The billing receipt reads differently. Surfshark takes $52.56 up front for 24 months. NordVPN takes $81.36. ProtonVPN takes $86.16. ExpressVPN takes $99.95 for the equivalent term, structured as 27 months for the price of 24. Now the spread is $47.39 in dollars actually moved at sign-up — a 90% gap between the highest and lowest stated cash outlay. That is the first place the per-month framing distorts the comparison.

A second layer: the "from" rate is not what the user pays in year three. Auto-renewal is the default state across all four providers. NordVPN's standard one-month renewal rate post-term is $12.99. ExpressVPN's is $12.95. ProtonVPN Plus monthly is $9.99. Surfshark monthly is $15.95. If the user fails to cancel before the renewal date, the effective rate in year three jumps by a factor of between 2.8x (ProtonVPN) and 7.3x (Surfshark, Starter → monthly).

A third layer: the displayed rate often excludes add-ons that the checkout flow pre-selects. NordVPN's Plus tier (which includes the password manager) is $4.39/month on the two-year, not $3.39. ExpressVPN's identity defender add-on is $3.49/month on top of base. Surfshark's One tier (the bundle including antivirus and alert tooling) is $2.69/month. The default-selected upsell tier is, in three of four cases, what the checkout button actually commits the user to.

So the spread the consumer sees ($3.39 vs $4.99, NordVPN vs ExpressVPN, a 47% gap) is one of at least three numbers in play. The renewal spread compresses the gap. The pre-selected add-on spread inverts the ranking. The cash-at-sign-up spread is twice the per-month spread.

What the Audit Scope Did Not Cover

Each of the four providers has commissioned at least one third-party assurance engagement. The published reports cover specific things and explicitly exclude others. The exclusions are where the fee-structure question lives.

NordVPN's no-logs claim was assessed by PricewaterhouseCoopers AG Zurich in 2018, and re-assessed by Deloitte in 2022 and again in 2023, with subsequent re-attestation cycles. The Deloitte engagement scope, per the public summary, covered server configuration and data-handling practices for the no-logs claim — verifying that infrastructure was configured consistent with the stated policy at the point of inspection. Pricing, billing, renewal mechanics, refund processing, and add-on default selection were not in scope. That is not Deloitte failing to do the work. That is the engagement letter limiting the work.

ExpressVPN's no-logs claim has been the subject of PwC assessments and a Cure53 penetration test, the latter published 2022-09 with full-scope coverage of the Lightway protocol stack and no critical findings on protocol implementation. Cure53's report is one of the more substantive in the consumer-VPN space. It is also, explicitly, a protocol and codebase engagement — not a commercial-terms or pricing-disclosure engagement.

ProtonVPN, headquartered in Switzerland, publishes the apps as open source and has had Securitum review the Linux, Windows, macOS, iOS, and Android clients (the most recent rounds published in 2022 and 2023). The audits address client-side behaviour. They do not address billing pages, renewal-cancellation flows, or the question of whether the displayed two-year rate matches the rate actually charged after the introductory term expires.

Surfshark's audit history includes Deloitte attestation on the no-logs claim from 2023 onward, plus prior server-infrastructure assessments by Cure53. Again — server configuration, claim consistency, infrastructure posture. Not fee disclosure, not auto-renewal practice, not the default add-on tier.

This is not a complaint about Deloitte or PwC or Cure53. Their engagement scope is what the client commissions. The point is structural. "Audited" in VPN marketing copy means audited against the no-logs claim or the codebase, not against the commercial relationship the user enters. No major consumer VPN, at the time of writing, publishes a third-party attestation report covering fee-structure accuracy, renewal-rate transparency, or default-tier-selection compliance with consumer-protection standards.

That is a verifiable gap. It is the gap this cross-check is centred on.

The Real Cost When You Work It Through

Convert the four pricing layers into a 36-month total-cost-of-ownership figure and the comparison shifts.

A NordVPN Basic subscriber who buys the two-year at $3.39/month and lets it renew at the standard monthly rate of $12.99 for the remaining 12 months pays $81.36 + ($12.99 × 12) = $237.24 over 36 months. That is an effective rate of $6.59/month, not $3.39. If the same user is auto-upgraded into Plus at $4.39/month at sign-up (a documented default-selection pattern), the year-one figure starts at $105.36 and the 36-month figure crosses $260.

An ExpressVPN buyer at the two-year-plus-three-free promo pays $99.95 for 27 months, then renews monthly at $12.95 for nine months to fill the 36-month window: $99.95 + ($12.95 × 9) = $216.50. The effective rate is $6.01/month. ExpressVPN's headline rate is the highest on the list. ExpressVPN's 36-month effective cost is the lowest of the four, because the promo window is longer and the renewal multiple is the smallest.

A ProtonVPN Plus buyer at $3.59/month pays $86.16 for 24 months, then $9.99/month for 12 months: $206.04 over 36 months. That is the lowest unsubsidised 36-month figure. ProtonVPN's headline is the second-highest of the four. ProtonVPN's three-year all-in is the lowest.

A Surfshark Starter buyer at $2.19/month pays $52.56 for 24 months, then $15.95/month for 12 months: $243.96. Surfshark's headline is the lowest. Surfshark's 36-month all-in is the highest, by margin. The 7.3x renewal-rate multiple is what drives that inversion. A user who cancels and re-signs at the introductory rate each cycle gets a different number — but Surfshark's renewal flow does not automatically present that option, and consumer-protection bodies in several EU jurisdictions have logged complaints on this specific pattern (the EU Consumer Protection Cooperation network's 2022 sweep of subscription-trap practices flagged subscription auto-renewal disclosure as an ongoing enforcement priority, though it did not name individual VPN providers).

So the actual ranking, on a three-year total-cost basis, inverts the headline ranking. ProtonVPN cheapest. ExpressVPN second. NordVPN third. Surfshark most expensive. The displayed monthly rate was a poor predictor.

That is the cost the audit scope did not cover. The user paid a different number than the marketing page said. The auditor verified the no-logs claim. Both statements are simultaneously true.

The Threat Model the Fee Page Hides

There is a class of threat model that the fee analysis above maps to, and it is worth naming. The adversary in this model is not a nation-state. It is not an MLAT-empowered law-enforcement subpoena. It is not a DPI-capable ISP fingerprinting WireGuard handshakes. The adversary is the provider's own billing system, and the capability is the auto-renewal cycle.

Capability assessment: the provider has the technical ability to charge a stored payment method at any time during the renewal window. The provider has the contractual right, granted at checkout, to apply the renewal rate disclosed in the terms of service. The user's exposure is the cash held on the linked card or PayPal account, multiplied by the number of renewal cycles before the user notices.

Likelihood assessment: the EU CPC sweep cited above found subscription-cancellation friction rates above 60% in the sample of online services audited. That is across all categories, not VPN-specific. VPN-specific evidence is thinner but the renewal-rate multiples (2.8x to 7.3x) create the economic incentive the adversary model assumes. A provider with no incentive to retain users at the renewal rate would price renewal at the new-customer rate. None of the four does.

User mitigation: cancel the subscription immediately after purchase. This sounds counter-intuitive but it works mechanically across all four providers. The two-year service period is honoured; the auto-renewal trigger is removed. The user pays $52.56 (or whatever) once, gets 24 months of service, and exits without the second cycle's full-rate charge. That is the actual cost-minimisation move. It is not in any of the providers' onboarding documentation.

This is what threat-model analysis applied to fee structure looks like. The auditor's report says the servers do not log. The auditor's report does not say the billing system will not charge a rate three to seven times higher than the rate that closed the sale. Both facts coexist. The reader's job is to know which one they are buying protection against.

What Colombia's SIC handles through consumer-protection ruling 5111/2017 on automatic-renewal contracts is what the United Kingdom's Competition and Markets Authority handles through its 2023 guidance on subscription contract transparency under the Digital Markets, Competition and Consumers framework. The substantive standard converges. The enforcement posture diverges by jurisdiction. A VPN provider operating globally is subject, in theory, to whichever framework the cardholder's bank applies — in practice, dispute-resolution friction means the framework rarely matters until the user files a chargeback. That is the jurisdictional shape of the problem.

If You Only Remember One Thing

The audit scope is the audit. Read the engagement letter. If the auditor was retained to attest to server configuration consistent with the no-logs claim, the auditor attested to server configuration consistent with the no-logs claim. The auditor did not attest to the fee page. The auditor did not attest to the renewal flow. The auditor did not attest to the default-tier selection. Treating the audit badge as a general endorsement of the provider's commercial behaviour is the structural error this desk is built to refuse.

Pull the renewal rate from the terms of service before you commit to the headline rate. Calculate the 36-month total. Compare that number against the headline. The gap between the two is the real cost. Across the four providers cross-checked here, that gap ranged from $117 to $191 per user over three years — and the ranking inverted. The headline cheapest was the all-in most expensive. The receipt is in section three.

FAQ

Has Deloitte actually audited VPN fee structures?

No. Deloitte's published assurance engagements for NordVPN and Surfshark are scoped to the no-logs claim — verifying that server configuration and data-handling practices were consistent with the stated policy at the point of inspection. Fee structure, renewal-rate disclosure, default add-on selection, and refund mechanics are not in scope. This is standard for the engagement type. The audit is doing what the engagement letter commissioned, which is narrower than the marketing copy implies.

Why do most VPN comparison sites quote only the introductory rate?

Because the introductory rate is the affiliate-attribution number. Most VPN comparison sites are funded by affiliate commission paid on first-purchase conversion. The renewal rate, the add-on default, and the 36-month total cost are not relevant to the first-purchase attribution event, so they rarely appear in the comparison. That is a structural incentive of the affiliate economics, not a reader-service decision.

What is the actual cheapest VPN over three years among the four covered?

On the figures used in this analysis, ProtonVPN Plus comes out lowest at $206.04 across 36 months, assuming the standard two-year introductory rate followed by 12 months at the monthly renewal rate. ExpressVPN is second at $216.50. NordVPN Basic is $237.24. Surfshark Starter is $243.96. The headline ranking — Surfshark, NordVPN, ProtonVPN, ExpressVPN — inverts almost completely once the renewal multiplier is applied.

Can I avoid the renewal rate increase by cancelling immediately after purchase?

Yes, mechanically, across all four providers covered. Cancelling the recurring subscription after the initial charge does not terminate the paid service period — the 24 months you bought are honoured. What it removes is the auto-renewal trigger at the end of that period. The user has to actively repurchase at the next sign-up rate. This is the simplest cost-control mechanism available and it is not surfaced in any of the four providers' onboarding flows.

How is the audit scope worded in the published assurance reports?

The published summaries use language of the form "we examined the design and operating effectiveness of controls relevant to the no-logs claim as of [date]" or similar. The scope is point-in-time, claim-specific, and infrastructure-focused. Phrases like "fee accuracy", "renewal-rate disclosure", or "subscription transparency" do not appear in the four providers' public assurance summaries reviewed for this piece. Readers who want full scope can request the underlying engagement letter — most providers do not publish it.

Does jurisdiction change which fee-disclosure rules apply?

In theory, the consumer-protection regime of the cardholder's jurisdiction applies — EU subscription-transparency rules, UK CMA guidance on subscription contracts, US state-level automatic-renewal statutes like California's ARL. In practice, dispute resolution against a VPN provider headquartered in Panama, Switzerland, or the British Virgin Islands runs through chargeback friction first, and chargeback success depends more on the card network's posture than on which consumer-protection framework theoretically applies.

Are the add-on default selections at checkout something the audits cover?

No, in every case reviewed. The pre-selected upsell tier at checkout — NordVPN Plus over Basic, Surfshark One over Starter, ExpressVPN's identity defender add-on — is a commercial design choice. The published audits cover infrastructure and codebase. They do not cover whether the default-checked tier complies with dark-pattern enforcement frameworks like the EU's Digital Services Act guidance on online interface design or the FTC's 2023 proposed Click-to-Cancel rule. That gap is structurally identical to the fee-disclosure gap.

Why focus on four providers when the title mentions five?

Affiliate listicles default to five because the structure performs in search. This desk analyses four because those four have published assurance engagements that make a cross-check meaningful. Adding a fifth name with no audit history to round the number would be adding marketing surface, not analysis. The structural compromise of writing "five" in the title to match query patterns is acknowledged. The analytical work is on the four providers with verifiable audit documentation.