Cloud computing is the delivery of computing resources over the internet on an on-demand, pay-as-you-use basis. The most widely referenced formal definition comes from the U.S. National Institute of Standards and Technology, which describes it as “a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.”1National Institute of Standards and Technology. The NIST Definition of Cloud Computing That technical language boils down to a straightforward idea: instead of buying and maintaining your own computers, you rent someone else’s and access them through the internet. But the definition has more layers than that summary suggests, and those layers matter for understanding how cloud computing shapes everything from your phone apps to corporate IT budgets.
What Makes Something “Cloud Computing” and Not Just Hosting
People sometimes confuse cloud computing with ordinary web hosting or renting a dedicated server at a data center. The NIST framework draws a clear line by identifying five characteristics that must be present for something to qualify as cloud computing.2National Institute of Standards and Technology. The NIST Definition of Cloud Computing These are worth knowing because they explain why “the cloud” behaves differently from older approaches to IT.
- On-demand self-service: You can spin up new servers, storage, or applications whenever you need them, without calling someone at the provider to set things up manually. A few clicks or a line of code, and the resource exists.
- Broad network access: You reach these resources over standard internet connections from laptops, phones, tablets, or other devices. There is no special proprietary network required.
- Resource pooling: The provider serves many customers from the same physical hardware, dynamically assigning and reassigning resources as demand shifts. You generally do not know or care which specific server in which specific building is handling your workload.
- Rapid elasticity: Resources can scale up or down quickly, sometimes automatically, to match what you actually need. To you, the available capacity can feel essentially unlimited.
- Measured service: Usage is tracked and billed like a utility. You pay for what you consume, and both you and the provider can monitor that consumption transparently.
If a service checks all five boxes, it is cloud computing. If it is missing one or two, it is something else, perhaps traditional hosting or a managed service that borrows cloud vocabulary for marketing purposes. The self-service and elasticity characteristics are the ones that trip people up most often. A dedicated server you lease monthly from a hosting company is not cloud computing if you cannot resize it on the fly or provision a second one without human intervention.
The Three Service Models
Cloud computing comes in three flavors, each handing you a different amount of control and responsibility. Think of them as a spectrum: at one end, you manage almost everything yourself using raw computing power; at the other end, you just use a finished application and the provider handles the rest.
Infrastructure as a Service
IaaS gives you the fundamental building blocks: virtual machines, storage, networking, and firewalls. You get access to shared resources on a need basis, with full control over the server infrastructure, including operating systems and installed software, but you do not have to worry about the physical hardware underneath.3Journal of Network and Computer Applications. Resource management for Infrastructure as a Service (IaaS) in cloud computing: A survey Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform all offer IaaS products. If your company previously ran its own data center full of servers, IaaS is the closest cloud equivalent: same level of control, but you are renting the hardware instead of owning it.
Platform as a Service
PaaS sits in the middle. It provides a ready-made environment for developers to build, test, and deploy applications without having to manage the underlying servers or operating systems. You write your code, push it to the platform, and the platform handles the rest, including load balancing, scaling, and patching. PaaS currently holds a smaller share of the cloud market than SaaS or IaaS, though it is expected to grow as organizations look for faster ways to ship software.4arXiv. Platform-as-a-Service (PaaS): The Next Hype of Cloud Computing Google App Engine and Heroku are well-known PaaS offerings.
Software as a Service
SaaS is what most people interact with daily without thinking of it as “cloud computing.” When you use Gmail, Slack, Salesforce, or Microsoft 365, you are using SaaS. The application runs entirely on the provider’s infrastructure, you access it through a browser or an app, and you have no visibility into or control over the servers behind it. SaaS is by far the most consumer-facing model and represents the largest slice of the cloud market.
Public, Private, Hybrid, and Multi-Cloud
Beyond what level of the technology stack you are renting, there is also the question of where it lives and who shares it. These are the deployment models.
A public cloud is owned and operated by a third-party provider and shared among many customers. It is well suited to organizations with limited upfront capital, workloads that fluctuate in demand, development environments, and applications built for global reach.5World Journal of Advanced Engineering Technology and Sciences. Cloud computing showdown: Public vs. private cloud explained A private cloud, by contrast, is dedicated to a single organization, either on its own premises or hosted by a provider but isolated from other customers. Private clouds better serve regulated industries, workloads with consistently high utilization, specialized computing needs, and environments dealing with sensitive data.6World Journal of Advanced Engineering Technology and Sciences. Cloud computing showdown: Public vs. private cloud explained
The performance difference is real, not just theoretical. Experiments comparing public internet connections (with encryption) to private direct-connect links found that private connections maintained jitter below 5 milliseconds, while public internet jitter spiked as high as 35 milliseconds during peak congestion. Private links also achieved about 22 percent higher sustained throughput for large-scale database transfers.7International Journal of Science, Strategic Management and Technology. An Experimental Comparison of Public Internet vs. Private Direct Connect for Enterprise Cloud Performance For many applications this gap is irrelevant, but for latency-sensitive workloads like financial trading or real-time analytics, it matters.
Hybrid cloud blends both: an organization runs some workloads on a private cloud and others on a public cloud, with the two environments linked. Multi-cloud goes further, spreading workloads across two or more public cloud providers. Both approaches aim to give organizations flexibility and resilience, but they come with real complexity. Different providers use different programming interfaces, data formats, and management structures, which makes seamless integration between them difficult.8International Journal of Global Innovations and Solutions. Navigating the Multi-Cloud Maze: Benefits, Challenges, and Future Trends Providers also have a financial incentive to make their platforms sticky, which compounds the problem.9International Journal of Computer Technology and Electronics Communication. A Survey on Hybrid and Multi-Cloud Environments: Integration Strategies, Challenges, and Future Directions
How It Works Under the Hood
Two technologies make cloud computing practical: virtualization and containerization. Both solve the same basic problem, which is how to let many customers share the same physical server without stepping on each other’s toes.
Virtualization creates virtual machines, essentially software-based computers that each run their own full operating system on top of a shared physical host. Containers take a lighter approach: they isolate individual applications while sharing the host’s operating system kernel. Published research consistently finds that containers start faster, use less disk space, and pack more workloads onto the same hardware. Virtual machines, meanwhile, offer stronger isolation and the ability to run entirely different operating systems side by side.10arXiv. Docker Containers vs. Virtual Machines: A Comparative Study of Architecture, Performance, Configuration, and Security In practice, most cloud providers use both. The efficiency-versus-isolation trade-off is a design decision, not a competition with a winner.
On top of virtualization sits auto-scaling, the mechanism that delivers the “rapid elasticity” characteristic. Auto-scaling systems monitor incoming demand and automatically add or remove computing resources to match. Strategies range from simple threshold rules (add a server when CPU usage crosses 80 percent) to machine-learning models that predict traffic spikes before they happen.11PubMed Central. Auto-Scaling Techniques in Cloud Computing: Issues and Research Directions Auto-scaling is what allows a small e-commerce site to handle a sudden surge on a holiday sale without crashing, then scale back down overnight to avoid paying for idle servers.
Why Companies Switched From Buying to Renting
The financial model is as much a part of cloud computing’s definition as the technology. Before the cloud, building IT capacity meant large upfront purchases: servers, storage arrays, networking gear, data center space, cooling systems, and the staff to maintain it all. Those costs were capital expenditures, assets that depreciated on a balance sheet over years. Cloud computing converts that entire cost structure into a variable operating expense tied directly to usage.12IIP Series. On-Premises vs. Cloud Infrastructure: Decoupling Capital Expenditures (CapEx) from Operational Expenditures (OpEx)
The appeal is obvious: a startup does not need millions of dollars in hardware to launch a product, and an established company does not need to guess years in advance how much capacity it will need. You pay for what you use, much like an electricity bill. But the metaphor is not perfect. Cloud bills can grow unpredictably if workloads are not managed carefully, and some organizations with very stable, high-utilization workloads find that owning hardware is actually cheaper in the long run. The shift from buying to renting is not universally advantageous; it depends on how variable your needs are and how much financial flexibility you require.
Security Is Shared, Not Delegated
A common misconception is that moving to the cloud means the provider handles all your security. In reality, cloud security operates on a shared responsibility model. The provider secures the physical infrastructure, the network, and the base platform. You are responsible for everything you build on top of that: your data, your access controls, your application code, your encryption choices.
Research on cloud security dynamics highlights that this shared model creates something resembling a collective-action problem. Each customer’s security decisions affect the broader environment, because vulnerabilities in one customer’s configuration can sometimes create exposure for others sharing the same platform. Users also have to weigh the need for strong security against the risk of becoming too dependent on a single provider’s security tools, which deepens vendor lock-in.13Information Systems Research. Dynamics of Shared Security in the Cloud The practical takeaway is that migrating to the cloud does not eliminate security work. It changes the nature of that work from maintaining physical infrastructure to managing configurations, permissions, and data governance.
Vendor Lock-in and Portability
The more deeply you build on a specific provider’s tools and services, the harder and costlier it becomes to leave. This is vendor lock-in, and it is one of the most persistent concerns in cloud computing. Cloud providers develop proprietary features, specialized databases, and unique programming interfaces that do not transfer cleanly to a competitor’s platform. When organizations interact with providers in the current marketplace, they often encounter significant barriers to migrating or interconnecting their cloud environments.14Computer and Information Science. A Holistic Decision Framework to Avoid Vendor Lock-in for Cloud SaaS Migration
Multi-cloud strategies are sometimes pitched as the antidote, but as noted in the deployment models discussion, they bring their own complexity. The interoperability gaps between providers can be substantial enough that large organizations struggle to realize multi-cloud benefits in practice.15International Journal of Global Innovations and Solutions. Navigating the Multi-Cloud Maze: Benefits, Challenges, and Future Trends Open-source tools and container orchestration platforms have helped somewhat by creating portable abstractions that work across providers, but full portability remains more aspiration than reality for most enterprise workloads.
Data Sovereignty and Where Your Data Lives
When your data sits on someone else’s servers, “where” is not a trivial question. Different countries have different laws about what data can leave their borders, who can access it, and what rights individuals have over their personal information. The European Union’s General Data Protection Regulation, for example, imposes strict rules on transferring personal data outside the EU. Other countries have enacted similar data localization laws.
Cloud providers respond by operating data centers in many regions and allowing customers to choose where their data is stored. But this gets complicated with multi-cloud or hybrid setups, where data may move between environments in ways that are not always transparent. For organizations in regulated industries like healthcare, finance, or government, understanding the physical location and legal jurisdiction of their cloud-hosted data is not optional. It is a compliance requirement that shapes which providers and configurations are viable.
Edge Computing and the Expanding Definition
The traditional cloud model routes everything through massive centralized data centers, sometimes located thousands of miles from the end user. Edge computing pushes processing closer to where the data originates, onto servers at the network’s edge, in a nearby cell tower facility, or even on the device itself. This is not a replacement for cloud computing but an extension of it.
The reduced latency of edge servers brings measurable benefits. Research comparing edge-based and centralized cloud servers found that edge processing significantly lowered the energy consumption of client devices communicating over mobile networks, with the savings varying based on whether the workload was upload-heavy or download-heavy and on the time of day.16Computer Communications. Edge computing vs centralized cloud: Impact of communication latency on the energy consumption of LTE terminal nodes For applications like autonomous vehicles, industrial robotics, or augmented reality, where waiting even a few hundred milliseconds for a round trip to a distant data center is not acceptable, edge computing is what makes cloud-based intelligence practical.
Edge computing blurs the boundary of what counts as “the cloud.” Strictly speaking, a tiny server in a cell tower is not a shared pool of configurable resources in the NIST sense. But in practice, major cloud providers now offer edge services as a seamless extension of their platforms, with the same management tools and billing models. The definition of cloud computing is quietly stretching to encompass a distributed continuum of processing locations, from your pocket to a server rack across the world, all stitched together by software and billed by the second.

