GeoBusinessIQGeoBusinessIQ

Hosted by a vendor or running in the plant: where factory software lives

Deployment location looks like an IT preference and behaves like a production decision. Software that lives with a vendor arrives maintained, updated and reachable from anywhere, and depends on a connection the plant does not own. Software running on site keeps working when the outside world does not, and hands you every task the vendor would otherwise have performed. What decides it is what your operation does during an outage and how tightly the software is coupled to machines.

Comparison criteria

Criteria are stated explicitly and neither option is declared a winner: which one fits depends on the constraint that binds hardest in your operation.

CriterionCloud: vendor-hosted software delivered as a serviceOn-premise: software running on servers inside the plant
Behaviour when the external link failsDepends entirely on what was designed for it. Some products cache locally and reconcile later; others stop being usable until connectivity returns.Unaffected by the outside world. Production continues as long as the plant network and the local servers are running.
Shape of the spendA recurring charge covering hosting, maintenance and updates, which scales with users or sites and continues for as long as you use it.An upfront licence and infrastructure purchase, followed by maintenance, and a hardware refresh that arrives whether or not it was budgeted.
Who decides when the software changesThe vendor, within whatever notice its terms allow. Improvements arrive without a project, and so do changes you did not ask for.You do. Upgrades happen when the plant can absorb them, which matters where a change requires requalification before production may continue.
Coupling to equipment on the floorSuited to functions that tolerate variable response, with a local gateway usually required for anything talking to controllers directly.Sits on the same network as the equipment, which suits deterministic interaction with controllers and high-frequency data collection.
How security responsibility is dividedSplit: the vendor secures the platform, you secure identities, access rights, integrations and every device that connects to it.Yours in full, including patching, backup, physical security and the segregation between office systems and production networks.
Where production data sitsIn the vendor's infrastructure, in locations set by their architecture, which has to be checked against customer contracts and applicable law.Inside your own facility, which simplifies residency questions and places the whole burden of protecting and backing it up on you.
Skills the plant must retainApplication administration, integration and vendor management, without needing server, database and backup expertise on the payroll.Infrastructure competence available when something fails at an inconvenient hour, either employed or contracted with a response commitment.
Persistence of tailoringConfiguration inside supported boundaries usually survives updates; anything beyond those boundaries may not, and the vendor sets where the line falls.Modifications persist because nothing changes without your action, and each one then has to be revalidated whenever you do upgrade.

Choose Cloud: vendor-hosted software delivered as a service when

  • Site connectivity is dependable and the function can tolerate a short interruption
  • There is no server room and no intention of employing infrastructure staff on site
  • Several plants need the same system and a shared instance suits how the business is run
  • The vendor's release cadence delivers capability you would otherwise have to fund yourself

Choose On-premise: software running on servers inside the plant when

  • Production must continue at full function while the external connection is down
  • The software interacts with controllers at a cadence that cannot tolerate variable latency
  • A qualified or regulated environment requires you to control the timing of software changes
  • Contractual or legal restrictions apply to where certain production data may be held

Start by asking what the line does when the link drops

This one question separates the functions that can be hosted remotely from the ones that cannot, faster than any architecture discussion. Planning, reporting, document control and analytics generally survive an interruption because nobody is waiting on them minute by minute. Recording an operation, releasing a batch, printing a label, confirming a torque result or authorising a material move are different: if the system is unreachable, the line either stops or starts working on paper, and paper reconciliation afterwards is where traceability breaks. Look at the specific function, establish the tolerable outage, then check whether the offered product actually degrades gracefully. Vendors differ enormously on this and the answer is rarely in the brochure.

Update timing is a governance matter in a qualified plant

Software delivered as a service improves continuously, and continuous improvement is exactly what a validated environment is designed to control. Where a plant must demonstrate that the system used to release product is the version that was qualified, an update applied by a vendor on their schedule creates a genuine problem: either the qualification evidence trails the software, or every release triggers assessment work nobody planned. Serious vendors in regulated sectors address this with staged environments, advance notice and documentation supporting the change. Establish before signing what notice you receive, whether releases can be deferred, and what evidence the vendor supplies. Where those answers are unsatisfactory, local control of the environment is a legitimate requirement rather than conservatism.

Security responsibility moves, it does not disappear

Hosting shifts platform patching, physical security and infrastructure hardening to a supplier whose specialist teams do that work full time. What stays yours is substantial: who has an account, what those accounts can do, how integrations authenticate, which devices reach the service, and how remote access into the production network is controlled. Industrial incidents frequently arrive through remote access and through the bridge between office and production networks, and neither is fixed by where an application is hosted. On-site hosting keeps everything under your control and thereby keeps every one of those duties as well, including the patching that small teams routinely defer. Both routes need segmentation, access discipline and tested recovery.

Frequently asked questions

Can a hosted system control equipment on the shop floor?
Not directly, and reputable architectures do not attempt it. Real-time control stays with programmable controllers and local systems, while a hosted application supervises, records and instructs at a slower cadence through a local gateway or edge component. That gateway is what allows production to continue during an interruption, buffering data until the connection returns. When evaluating a product, ask specifically what runs locally, how much it can buffer, and what happens to the buffer if the outage outlasts it.
Which option costs less over the life of the system?
It depends on assumptions that are rarely stated in a comparison. Hosted costs continue indefinitely and scale with users and sites; local costs front-load and then reappear as hardware refreshes, database licences, infrastructure staff time and the periodic upgrade project. Compare them across a full replacement cycle including a hardware renewal and at least one major version upgrade, and include the internal effort each option consumes. The result often turns on staffing rather than licensing.
How hard is it to move away from a hosted manufacturing system?
Harder than the sales process implies, so establish the exit terms while you still have negotiating leverage. Confirm what export format your data is returned in, whether it includes historical transactions and audit trails rather than only current records, how long the vendor retains it after termination, and what assistance is provided. Production history frequently has to be retained for years under customer or regulatory obligations, so a route to reading it after the relationship ends is a practical requirement rather than a formality.

Data limitations

  • Manufacturing figures are operator-supplied inputs, not market data. GeoBusinessIQ holds no factory costs, production volumes, yields, cycle times, tooling prices or capacity data and does not estimate them — every result reflects only the figures you enter.
  • No manufacturer, supplier, vendor or factory is recommended, rated or ranked anywhere in this cluster, and no directory of them is published. Selection material describes how to run your own assessment; the assessment itself remains yours.

Explore the graph

Sources

  • National Institute of Standards and Technology NIST (accessed )
    Covers: Measurement science, manufacturing technology research, cybersecurity frameworks, and industrial standards support.
    Does not cover: Certification of products, endorsement of vendors, or costs for any specific implementation.
    Why it matters: A United States federal research institute whose public material covers measurement, manufacturing technology and control-system security.
    Review cadence: annual
  • International Electrotechnical Commission IEC (accessed )
    Covers: International standards for electrical, electronic and related technologies, including industrial automation and machinery safety.
    Does not cover: Standard text, conformity decisions, or product approval.
    Why it matters: Cited for the origin of electrotechnical and automation standards referenced on automation and machinery pages.
    Review cadence: annual
  • Cybersecurity and Infrastructure Security Agency CISA (accessed )
    Covers: Guidance and advisories on industrial control system and operational technology security.
    Does not cover: Vendor product assessments, or the security posture of any specific installation.
    Why it matters: Cited on industrial cybersecurity pages as the public authority for control-system security practice.
    Review cadence: annual

Educational and operational information only — not legal, engineering, safety, customs, tax, or financial advice. Requirements vary by jurisdiction, product, process, and contract; confirm with the relevant authority or a qualified professional before acting.

Last updated: