Why NAT shows up in audits so often
NAT Gateway is the AWS service teams budget least and overspend most. The hourly fee is small. The per-GB processing fee is what gets you. Every byte your private subnets push through NAT, regardless of destination, is metered.
The fix is rarely a single change. It is a route-table audit, a VPC endpoint rollout, and a small Terraform diff that nobody scheduled. We do it as part of the 14-day audit and hand the engineer a one-page playbook.