Skip to content
Article

What Is Cloud Computing? Cloud Models and Types

Cloud computing means getting computing resources over a network and paying for what you use. Service and deployment models, costs and risks explained.

Oğuzhan Gerçek··7 min read
What Is Cloud Computing? Cloud Models and Types

Short answer: Cloud computing means getting computing resources such as servers, storage, networking and software from a provider over a network, on demand and paid for by use, instead of buying them. The provider runs the hardware and the data center, and resources can be started and stopped in minutes. There are three service models (IaaS, PaaS, SaaS), depending on how much the provider takes on, and four deployment models (public, private, community, hybrid), depending on who the infrastructure is for. The cloud does not remove cost; it changes its shape, replacing up-front investment with a regular bill.

What is cloud computing?

The definition still in use today comes from SP 800-145, published by the US National Institute of Standards and Technology (NIST) in September 2011. NIST defines cloud computing as "a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources" (networks, servers, storage, applications and services) "that can be rapidly provisioned and released with minimal management effort or service provider interaction."

In everyday speech, "the cloud" means infrastructure that works this way: your data and applications run not on your own computer but on servers in the provider's data center.

Five characteristics that make a service cloud

NIST describes the model through five essential characteristics, three service models and four deployment models. The characteristics are:

  • On-demand self-service: Users provision resources such as server time and storage themselves, without talking to anyone at the provider.
  • Broad network access: Resources are reached over the network through standard mechanisms, from a phone just as well as from a workstation.
  • Resource pooling: Resources serve many customers through a multi-tenant model. Customers generally do not know exactly where the hardware is, but may be able to choose the country or the data center.
  • Rapid elasticity: Capacity grows and shrinks with demand and often appears unlimited to the user.
  • Measured service: Usage is metered and reported, and is typically billed per use.

The list also shows what is not cloud: a virtual machine that takes a request form and several days to appear, or a physical server rented on an annual contract, lacks most of these characteristics. As Red Hat explains, until virtualized resources are gathered into shared pools and offered through self-service and automation, what you have is not cloud but just virtualization.

Service models: IaaS, PaaS and SaaS

Service models differ in how much of the stack the provider takes on:

  • IaaS: The provider supplies compute, storage and networking; the operating system and everything above it is yours. Examples: a cloud server running as a virtual machine, and object storage.
  • PaaS: The operating system and the runtime platform also pass to the provider; you bring your application. Example: managed databases.
  • SaaS: The application itself is delivered as a service. Examples: email, office suites, CRM.

We go into detail in our IaaS and SaaS articles. One thing never changes: according to Microsoft's shared responsibility table, data, endpoints, accounts and access management stay with the customer in every model.

Deployment models: public, private, community and hybrid cloud

NIST defines four deployment models:

  • Public cloud: Infrastructure open to the general public. It runs on the provider's premises, and many customers share the hardware.
  • Private cloud: Infrastructure dedicated to a single organization. It can sit in the organization's own building or in a provider's data center (our private cloud article).
  • Community cloud: Infrastructure reserved for organizations that share concerns such as mission, security, policy or compliance.
  • Hybrid cloud: Two or more distinct cloud infrastructures bound together so that data and applications can move between them (our hybrid cloud article).

Multi-cloud, often confused with hybrid, is not one of these models; it means using more than one public cloud provider together.

What does the cloud deliver?

Of the six advantages AWS lists, four matter most to organizations:

  • Variable instead of fixed expense: Instead of investing in servers up front, you pay for what you use. We explain what that means for the books in our CAPEX and OPEX article.
  • No more capacity guessing: A capacity decision made before deployment often ends in either expensive idle resources or too little capacity; in the cloud, capacity changes within minutes.
  • Speed: Making a new resource available to developers takes minutes rather than weeks.
  • Global reach: An application can be deployed in other regions with a few clicks.

Racking and powering servers becomes the provider's job as well.

The cost and risk side of the cloud

Paying as you go cuts both ways: forgotten resources end up on the bill too. According to Flexera's research released on March 18, 2026, the share of wasted cloud spend rose to 29%, its first increase in five years. We explain how to make that spend visible in our FinOps article. Three more risks are easy to miss:

  • Egress fees: Uploading data from the internet to Amazon S3 is free, but data going out to the internet is billed after the first 100 GB a month. In architectures that move data constantly, this line adds up.
  • Configuration: A storage bucket left open to the public or an overly broad permission is a gap in your layer, not the provider's.
  • Outages: According to AWS's summary, the disruption in the us-east-1 Region, triggered by a defect in DynamoDB's automated DNS management, lasted about 14.5 hours on October 19–20, 2025. An architecture tied to a single region inherits that region's outages; we explain availability targets in our uptime article.

Cloud in Türkiye: data residency and data protection

The cloud does not settle where data lives; it ties the answer to the provider and region you choose. Processing personal data in a region abroad counts as a cross-border transfer, and the conditions in Article 9 of the KVKK (Türkiye's personal data protection law), amended as of June 1, 2024, apply. We cover the details in our KVKK article; for your own situation, consult your legal counsel.

Production data is not the only thing to check: backups, logs and support access can also reach another country. For banks, see our BDDK article; for why data residency alone is not enough, see our sovereign cloud article.

How big is the cloud market?

According to IDC's forecast of March 4, 2026, worldwide public cloud spending will grow more than 21% in 2026, pass $1 trillion and double by 2029. More than half of that spending goes to SaaS; the fastest-growing model is PaaS, up more than 37% year over year.

Before moving to the cloud

Three questions need answers before a migration: which workloads get cheaper in the cloud, how much responsibility you will hand over, and who will run the cloud. With IaaS you get the resources, but monitoring, patching and backup stay with you; one way to hand that work over is managed cloud services. You can find the migration steps on our cloud migration page and how the model works in our managed services article.

Frequently asked questions

What does cloud computing mean? Getting servers, storage, networking and software over a network, on demand and paid for by use, instead of buying them.

What is "the cloud"? Infrastructure or services that work on the cloud computing model: data and applications run on servers in a provider's data center and are reached over the internet.

What are examples of cloud computing? Microsoft 365 is SaaS, virtual server services such as Amazon EC2 are IaaS, and managed databases are PaaS.

Is the cloud the same as virtualization? No. Virtualization is the technology that divides hardware into virtual machines; cloud is the model in which those resources are offered as a self-service, metered and elastic service.

Is the cloud secure? The security of the infrastructure is the provider's; data, accounts and access management are yours in every model. So security depends as much on how your layer is run as on the provider.

Is the cloud always cheaper? No. It is often cheaper for variable workloads; for workloads running steadily 24/7, your own hardware or committed-use pricing can cost less.

Sources