A quality variance appears during handover, but the records sit in separate plant applications. Supervisors wait for the right work instruction, managers cannot compare the same event across sites, and delivery decisions slow down while customers wait.
Cloud-based manufacturing systems connect production data, applications, and authorized users through centrally managed services. They give teams a common view of work, quality, and performance across plants, while placing each workload where it meets operational needs for response time, continuity, and accountability.
That shared view only works when the architecture fits the factory. Machine control and other time-sensitive functions often need to remain close to the line, especially where connectivity loss would interrupt production. Reporting, planning, quality analysis, and cross-site decisions may gain more from governed central services, provided teams define data ownership, recovery behavior, and access evidence before deployment expands.
This article compares cloud, on-premises, and hybrid manufacturing architectures through the decisions that matter in practice: which workloads need local execution, where centralized data creates value, and what leaders need to measure before migration. It also sets out a phased evaluation process, from a bounded first workload to tested continuity and integration ownership. The goal is a deployment decision that improves production visibility without forcing every factory process into one model.
How do cloud-based manufacturing systems change IT?
Cloud-based manufacturing systems change IT when they turn separate plant applications into a managed flow of production information and accountable decisions. The aim is shared visibility where it improves planning and support, while retaining local execution where the line needs it. That calls for architecture ownership, not a simple hosting change.
The integration gap shows why this work reaches beyond an MES replacement. Rockwell Automation’s Global MES Adoption Report found that 93% of surveyed manufacturers have MES in place, yet 28% have deployed it enterprise-wide and 23% report full integration across ERP, product lifecycle management, quality, and operational technology systems (2026). A local system may work well at one site while still leaving corporate teams unable to compare production performance reliably.
Consider a corporate operations leader reviewing downtime at three plants during shift handover. One plant counts a planned quality hold, another excludes it, and a third records only machine stoppages. The dashboard may look precise, but the comparison is not fit for a capital or scheduling decision. “Knowing that an MES is a business-critical application, we wanted to make the replacement as safe as possible,” Rahul Hege, Digital Manufacturing Leader at Schneider Electric, told Dürr Group: “Knowing that an MES is a business-critical application, we wanted to make the replacement as safe as possible.”
Which pressures make workload placement urgent?
The pressure comes from disconnected operating definitions, shared security duties, and finite infrastructure capacity. Leaders need to decide who owns each interface and who accepts its continuity obligations.
- Multi-site visibility: Define common measures for orders, quality events, downtime, and inventory before centralizing reports.
- Integration completeness: Assign an owner and exception path to every material exchange between ERP, MES, quality, and operational technology.
- Shared accountability: ISA/IEC 62443 defines industrial automation and control system cybersecurity as shared across asset owners, suppliers, integrators, and service providers (2024).
- Infrastructure burden: Decide which plant teams retain servers and local applications, and which services move under a provider operating model.
| Decision Dimension | Plant-Centric Legacy Model | Connected Manufacturing Model |
|---|---|---|
| Performance definitions | Each site interprets measures locally | Shared definitions govern enterprise reporting |
| Integration ownership | Interfaces sit with individual projects | Named owners manage data boundaries and exceptions |
| Infrastructure operations | Plant IT maintains local capacity | Central teams govern selected shared services |
| Security accountability | Responsibilities remain implicit | Asset-owner and supplier duties are documented |
Which workloads belong in a cloud manufacturing architecture?
A cloud manufacturing architecture places workloads according to what they do, how quickly they must respond, and what evidence they must retain. Control functions that need immediate plant response belong near machines or at the edge, while enterprise reporting and cross-site analysis often benefit from centralized services. Hybrid design is an intentional operating choice.
Use ISA-95 manufacturing standards as the boundary conversation between business planning and shop-floor execution. Think of workload placement like setting up a workshop: the tools needed at the bench stay within reach, while shared drawings and inventory records belong in a common store that every authorized team can consult. The framework below makes that distinction testable before a migration program expands.
- Control Criticality: Ask whether delayed execution could interrupt safe, time-sensitive production activity.
- Latency and Resilience: Determine whether the workload remains useful through degraded connectivity and how it reconciles afterward.
- Data Integration Value: Assess whether normalized data improves planning, quality analysis, or multi-site decisions.
- Assurance Requirements: Define the identity, change, traceability, retention, and regional-handling evidence the workload requires.
| Framework Dimension | Primary Question | Suitable Workloads | Placement Signal | Common Misread |
|---|---|---|---|---|
| Control Criticality | Does this function direct equipment activity? | Machine control, safety functions | Plant or edge execution | All MES functions require the same location |
| Latency and Resilience | What happens if connectivity degrades? | Local coordination, buffered collection | Edge with synchronization | Cloud access equals permanent connectivity |
| Data Integration Value | Who gains from common data? | ERP planning, enterprise analytics | Centralized data service | Centralization automatically improves data quality |
| Assurance Requirements | What proof must exist? | Quality records, approvals, reporting | Governed cloud or hybrid service | A provider assumes all lifecycle accountability |
How do control and latency shape placement?
Control criticality and latency set the first boundary. Machine control, safety-related functions, and fast production coordination often need local or edge execution because they cannot wait for a distant service to respond. Cloud services can still receive contextualized data for planning and analysis without taking over the control loop.
This is a measurable architectural question, not an assumption about every site. A 2024 IEEE Computer Society measurement study found edge clouds achieved an 84.1% latency reduction compared with centralized clouds. The result does not prescribe one design for every factory, but it supports testing latency-sensitive workloads individually. Resilience also requires a defined behavior during connectivity loss, including local continuity and later reconciliation.
Schneider Electric’s Batam site offers a context-specific example. Its iTAC case study reports nine hours less monthly patching downtime after MES servers moved to Linux-based cloud infrastructure, alongside an API response-time change from 90 milliseconds to 60 milliseconds. Site conditions and integration choices determine whether another plant sees similar results.
What creates integration and assurance value?
Central services earn their place when shared data improves a decision that no single plant can make alone. ERP planning, quality analysis, production scheduling, and enterprise reporting benefit when orders, confirmations, and master data use governed definitions. The value comes from disciplined integration, not from placing data in one location.
The asset owner must still govern the lifecycle. The ISA Global Cybersecurity Alliance’s ISA/IEC 62443 maturity model states that accountability remains with the asset owner even when activities are delegated to suppliers or service providers (2023). That means contracts and technical designs need clear evidence for access, change approval, data retention, and recovery responsibilities.
Centralized plant data can create material operational value when the scope is clear. Cognite’s account of Idemitsu Kosan reports that a Chiba Complex feasibility study identified more than 3,000 hours of operational-efficiency improvement and potential annual savings of tens of millions of yen (2024). Treat that as a feasibility result, not a universal business case. The next decision is whether your data model and operating owners can sustain the same discipline.
What should leaders measure before a cloud migration?
)
Leaders need a baseline that separates architecture outcomes from process redesign, equipment work, and workforce adoption. Measure the quality of integration and continuity before moving workloads, then track the same signals as deployment expands. A scorecard should inform portfolio decisions rather than rank plant managers.
The financial case depends on what changes in the operating system around the application. Deloitte’s 2025 implementation analysis reports surveyed manufacturers saw up to 20% improvement in production output, 20% in employee productivity, and 15% in available capacity from smart-manufacturing investments. Those are reported outcomes across investments, so teams must identify which gains came from data, process, or workforce changes.
- Integration completeness: Measure the share of priority ERP, MES, quality, maintenance, supervisory control and data acquisition (SCADA), and industrial internet of things (IIoT) exchanges with defined ownership and exception handling.
- Decision latency: Measure the time from a shop-floor event to an actionable, contextualized decision.
- Operational resilience: Track recovery objectives, offline continuity, synchronization backlog, and tested failure scenarios.
- Change throughput: Measure the time and governance effort required to alter workflows, reports, interfaces, or master data.
- Evidence coverage: Measure whether identity, approvals, access, data changes, and production records support internal and external audits.
| Metric | Leadership Signal | Decision Supported | Common Interpretation Error |
|---|---|---|---|
| Integration completeness | Known data boundaries and owners | Whether to extend deployment | Counting interfaces rather than usable exchanges |
| Decision latency | Speed from event to action | Cloud, edge, or plant placement | Treating dashboard refresh as operational response |
| Operational resilience | Continuity under degraded connectivity | Pilot readiness | Assuming backup records prove recovery works |
| Evidence coverage | Audit-ready access and change records | Control design and supplier review | Equating retained data with accountable evidence |
A case result can test the scorecard, but it cannot replace it. AWS reports that Weir Minerals achieved up to 30% lower manufacturing lead times, 10% higher on-time delivery, and 30% more bottleneck throughput after replacing legacy shop-floor systems with cloud MES on AWS (2026). Use such outcomes as a prompt to define your own baseline. Trend direction and service criticality matter more than a universal threshold.
How should manufacturers sequence cloud migration planning?
A credible migration begins with a bounded workflow whose value and failure conditions are visible. Reporting, data aggregation, quality evidence, and planning are often better first candidates than time-sensitive control functions. The first deployment must prove integration ownership and continuity behavior before it becomes an enterprise template.
Astec Industries provides an example of change that extends beyond a single application. Its OneAstec strategy moved enterprise operations across sales, supply chain, engineering, human resources, and finance to Oracle Cloud, as described in PwC’s Astec case study (2023). That scope reinforces a practical point: process ownership and workforce participation need the same attention as the target architecture.
- Choose a bounded first workload: Select reporting, data aggregation, quality evidence, or planning workflows before moving time-sensitive control functions.
- Define the system-of-record boundary: Establish ownership for master data, orders, confirmations, quality records, and machine data across ERP, MES, and historian environments.
- Test continuity before scale: Run connectivity-loss, restoration, data-reconciliation, and rollback scenarios at pilot plants.
- Preserve exit options: Assess exportability, integration standards, customization constraints, contractual data rights, and the cost of adding plants or modules.
| Migration Approach | Appropriate Context | Implication |
|---|---|---|
| Bounded pilot | Clear reporting or quality-evidence use case | Proves governance and adoption with contained scope |
| Domain rollout | Reusable interfaces and common process definitions | Extends standard work across selected plants |
| Broad replacement | Mature ownership, tested continuity, and stable data | Requires executive control of dependencies and change |
Standardization brings consistency, but local operating constraints still need a formal route into design decisions. As Rahul Hege, Digital Manufacturing Leader at Schneider Electric, told Dürr Group, “When all data is stored in the cloud, it remains secure from local disruptions and accessible.” Leaders should test that premise against their own connectivity, recovery, and data-handling requirements. A migration earns scale when operators, IT, and process owners agree on who changes what and how the result is validated.
Four controls teams skip in connected production
Connected production programs often fail at the handoffs between plant teams, corporate IT, and third parties. The service provider may run infrastructure, but the manufacturer retains responsibility for asset decisions, operational continuity, and access governance. Those duties must appear in named controls.
- Unclear asset ownership: Assign accountability for each integration, data domain, and recovery decision.
- Directly reachable plant assets: Segment operational technology environments and prohibit unmanaged public internet access paths.
- Untested continuity assumptions: Validate offline operation, restoration priorities, and reconciliation processes.
- Incomplete third-party evidence: Require time-bound access, activity records, and contractually defined responsibilities.
The need for disciplined controls has an operational basis. 56% of manufacturing and production respondents, per Sophos’s 2023 manufacturing-and-production report, experienced a ransomware attack in the prior year (2023); that figure does not establish that every incident affected operational technology. Waterfall Security’s 2025 OT Cyber Security Threat Report recorded cyber-related physical impairment incidents rising from 412 in 2023 to 1,015 in 2024. The control response is accountable system design: document decision rights, test continuity, and retain evidence of administrative activity.
RealVNC and the Manufacturing Access Problem
)
Plant-side control, cloud analytics, and multi-vendor integration create a practical access problem when specialists need to diagnose production-support systems from another location. A scheduled original equipment manufacturer troubleshooting session requires different permissions from standing administrator access. CISA advises organizations to reduce direct public access paths to operational technology and industrial control system devices (2024). Remote support therefore needs a governed route, with clear records for audit and incident review.
RealVNC Connect provides a controlled remote-access layer for those support workflows. Multi-factor authentication (MFA) and single sign-on (SSO) with Microsoft Entra ID or Okta align access with enterprise identity policies. Role-based access controls (RBAC) and granular action-based permissions let organizations separate viewing, keyboard and mouse control, and file-transfer rights by technician or vendor responsibility. Session monitoring, session recording, and detailed audit logs provide authorized administrators with a reviewable record of who connected, when, and with what permissions. Code Connect uses single-use nine-digit session codes for time-bound third-party access, avoiding a need to issue standing credentials for an ad hoc session.
This approach supports the shared-responsibility model described by ISA/IEC 62443 (2024) without replacing MES, ERP, operational technology segmentation, or cybersecurity governance. A connected production architecture needs controlled human access alongside data integration. RealVNC Connect makes support sessions attributable, bounded, and reviewable across plant and corporate boundaries.
Final Words
Choose workload placement before choosing a deployment label. Cloud-based manufacturing systems work when leaders assess whether each function directs equipment, must keep operating through connectivity loss, gains from shared data, or requires traceable evidence. That keeps machine control close to the line where needed, while reporting, planning, quality analysis, and cross-site decisions draw value from governed central services. A bounded pilot then tests integration ownership, reconciliation, and recovery before its design becomes the template for other plants.
The manufacturer remains accountable for lifecycle security decisions even when suppliers run parts of the service, as the ISA Global Cybersecurity Alliance’s ISA/IEC 62443 maturity model states (2023). That responsibility reaches remote support: CISA advises organizations to reduce direct public access paths to OT and ICS devices (2024). RealVNC Connect brings multi-factor authentication and single sign-on, role-based access controls, plus session recording and detailed audit logs into that operational boundary, so authorized support work remains attributable and reviewable. Start a free trial of RealVNC Connect to evaluate controlled, auditable remote access for manufacturing support workflows.
FAQs
What is the workload-placement framework?
Cloud-based manufacturing systems need a workload-placement framework that evaluates control criticality, latency and resilience, data integration value, and assurance requirements. This model helps leaders decide which functions belong in plant, edge, or centralized services, rather than applying one location to every MES, ERP, IIoT, and reporting workload. A large-scale measurement study found an 84.1% latency reduction in edge clouds compared with centralized clouds, supporting workload-specific testing (IEEE Computer Society, 2024).
What are examples of cloud manufacturing systems?
Examples include cloud MES, cloud MRP software, cloud-native ERP platforms, production-planning services, IIoT data platforms, and centralized quality reporting. A connected manufacturer might keep machine coordination at the plant while sending production records to shared services for planning and cross-site analysis. The right example depends on the decision the system supports and its response-time requirements.
What is the difference between cloud MES and hybrid MES?
Cloud MES hosts selected manufacturing-execution functions through provider-managed services, while hybrid MES keeps chosen control or resilience functions at the plant or edge and uses central services for reporting and analysis. Hybrid architecture suits operations where connectivity loss or delayed responses would affect production continuity. Teams must also reduce direct public access to operational technology and industrial control system devices, as CISA advises (CISA, 2024).
Which standards govern cloud-connected OT?
ISA/IEC 62443 is a central reference for industrial automation and control system cybersecurity, and it keeps lifecycle accountability with the asset owner even when work is delegated to suppliers. ISO/IEC 27001 may also guide information-security management, while sector obligations may apply to records, data handling, and electronic approvals. Standards guide control design; they do not transfer the manufacturer’s responsibility for its operating environment (ISA Global Cybersecurity Alliance, 2023).
Can an ERP be cloud-based?
Yes, an ERP can be cloud-based when its planning, finance, supply-chain, or master-data functions run through provider-managed services. Manufacturers still need to define the boundary between ERP records and plant systems such as MES, SCADA, historians, and quality applications. Before selecting a provider, assess integration ownership, data rights, continuity behavior, customization limits, and the evidence required for audit review.
How does RealVNC support manufacturing workflows?
RealVNC Connect supports manufacturing support workflows through session monitoring, session recording, detailed audit logs, role-based access controls, and granular action-based permissions. These controls let organizations review remote activity and limit technician or supplier actions according to assigned responsibility. Code Connect adds temporary third-party access through single-use nine-digit session codes, helping avoid standing credentials for scheduled OEM or integrator support.

