As the cellular IoT market matures, enterprises are transitioning from experimental projects to business-critical programs. This shift has exposed significant shortcomings in traditional “home-routed” roaming architecture, which often fails to meet modern security, performance, and data sovereignty requirements.
Central to solving these challenges is the deployment of packet gateways (PGW or UPF).
For connectivity providers this path usually leads to a choice between two distinct deployment strategies: in-house hardware or a virtualised managed service approach.
The choice isn’t just about technical architecture; it’s a decision that impacts financial flexibility, security posture, and long-term scalability. Here’s a breakdown of the two primary deployment strategies.
Dedicated In-House Hardware Deployment
Historically, packet gateway infrastructure was based on dedicated hardware deployed within an operator’s own data centre. While this model was standard for years, it faces several modern hurdles.
- High Capital Investment (Capex): In-house efforts require significant upfront capital, which can be difficult to align with internal budgets, especially since high traffic volumes rarely occur immediately.
The “Over-Specced” Risk: There is a constant danger that if traffic doesn’t meet expectations, the expensive data centre assets become underutilised sunk costs.
Maintenance & Resource Burden: Beyond the hardware itself, in-house deployment requires ongoing investment in integration, configuration, and maintenance, which can be difficult to scale under budget or resource constraints.
Performance Ceilings: Dedicated hardware is inherently constrained. What is cutting-edge at deployment can quickly become legacy, as the tight coupling between hardware and software limits how much the solution can evolve with market needs.
Virtualised Packet-Gateways via a Managed Service Model
The alternative is a cloud-native, software-defined managed service approach, designed to overcome the limitations of the hardware-centric model.
Opex-Based Scalability: Managed services shift costs from Capex to Opex. Capacity can scale up or down according to actual demand, eliminating the financial risk of wasted outlay. In addition, as your customer base grows in specific geographic regions, a managed service approach such as that provided by Stacituy allows you to scale capacity in those set locations instantly. Once you are integrated with Stacuity’s globally distributed network, you gain access to all edge sites, with no additional integration required.
Continuous Innovation: Because these solutions are software-driven and decoupled from underlying hardware, they are far easier to keep current. Instead of hosting, deploying and managing your own hardware in every global territory, you gain immediate access to an established global network.
Operational Agility and Global Reach: A managed service eliminates the internal burden of configuring and running the network yourself. Instead of hosting, deploying and managing your own hardware in every global territory, you gain immediate access to an established global network.
- Follow-the-Sun Reliability: Managing global IoT means dealing with 24/7/365 operational demands. With a managed service, the burden of “follow-the-sun” support for locations outside your primary time zone rests with the provider, not your internal team.
Enhanced Resilience: Managed services provide the ability to move devices from one geography to another in real-time for routing purposes or to bypass local network issues. This adds a layer of global resilience within the same cost structure that hardware-based models simply cannot match.
Fine-Grained Control: Unlike traditional hardware that often lacks the ability to handle complex requirements, advanced virtualised solutions offer “fine-grained” control. This includes the ability to apply policy and security on a per-device basis through a single APN.
Why the Deployment Style Matters for IoT
The choice between in-house and managed services isn’t just about cost, it’s about meeting the strict requirements of today’s IoT verticals.
Security: 51% of enterprises cite end-to-end security as a top concern. Virtualised gateways allow for real-time network event visibility and continuous monitoring, which is far more effective than traditional Call Data Records (CDRs).
Data Sovereignty: 72% of adopters value the ability to route traffic to comply with national regulations. A flexible managed service makes it much easier to process data in-country to meet mandates in regions like the EU, UAE, or Saudi Arabia.
Latency: For use cases like automotive or robotics, low latency is critical. Virtualised gateways can be distributed to the “edge,” shortening the transport path and reducing latency by avoiding the “tromboning” effect of traditional roaming.
While in-house deployment offers a traditional sense of oversight, it often leads to technological stagnation and high financial risk. For organisations looking to scale internationally with modern security and performance, a virtualised managed service provides the flexibility and operational agility required to succeed in the evolving IoT landscape.

Secure, Sovereign and Performant Connectivity with Edge Network Infrastructure
FAQ
A Packet Gateway is a critical network element that acts as the interface between the mobile network and external IP networks, such as the internet or a private corporate cloud.
In 4G networks, this is known as the PGW (Packet Data Network Gateway), while in 5G, it is referred to as the UPF (User Plane Function). It is responsible for routing data, enforcing security policies, and managing device IP addresses.

