The question "cloud or on-premise?" seems technical. It isn't. It's a question about who carries the operational risk — and most Portuguese industrial companies answer it badly because they compare licence prices instead of comparing total control costs. According to the INE, in 2025 only 53.7% of Portuguese companies with ten or more employees used business management software. For half the industrial fabric, the architecture decision is premature: the prior problem is choosing the right product for the sector. But for those who already have an ERP and are evaluating migration or replacement, the choice of where the system runs defines who is left standing when something fails — and that question has a different answer in a footwear factory in Felgueiras and in a distributor with a warehouse in Lousada.
This article argues a simple and uncomfortable thesis: the cloud is the right choice for those without internal IT capacity, and the wrong choice for those who have it — unless connectivity is redundant across all locations and the service contracts cover what most people don't read. What follows is a decision matrix, a checklist of prerequisites and the mistakes we see repeated in real projects.
What to gather before opening any proposal
Without this data, any cloud vs. on-premise comparison is speculation. Gather it before speaking to any vendor — and attribute it to verifiable facts, not to estimates from the internal sales manager.
- Current IT infrastructure cost: server, operating system licences, UPS, maintenance, electricity.
- Number of concurrent users at peak — not the total of licences purchased, the actual measured peak.
- Bandwidth available at each location: main factory, secondary units, warehouse, stores.
- Downtime of the current ERP over the last 12 months, in hours — not the perception, the record.
- Classification of the data the ERP will process: personal data subject to GDPR, sensitive production data, financial data subject to SAF-T.
- Internal IT capacity: is there someone who runs backups, applies patches and responds to incidents at 11 p.m. on a Friday?
- Investment horizon: does the CEO want CAPEX or OPEX? Is there a PT2030/PRR application under way that conditions the cost structure?
- Integration requirements with machines, PLCs or third-party systems on the factory floor.
Cloud isn't cheaper. It's different — and the difference shows up in year three
The market narrative says cloud eliminates the server and therefore reduces costs. It's a half-truth that costs dearly to discover after signing.
On-premise has high CAPEX in year zero and low operating costs in years two to seven, assuming the server is amortised and the IT team already exists. Cloud has near-zero CAPEX in year zero and monthly costs that grow with users, activated modules and volume of data processed. In a typical Vale do Ave textile factory with sixty users and integration with production terminals, the total cost of ownership after five years may be equivalent — or higher in the cloud — if the internal IT team already exists and the hardware is already paid for.
What the cloud really sells is the transfer of operational responsibility: patches, backups, availability, infrastructure security. If you have no one internally to do this, that transfer has real, measurable value. If you do, you're paying for a service you already provide internally — and adding a high exit cost that rarely appears in the initial proposals.
The cloud vs. on-premise decision isn't about technology. It's about where you want responsibility to sit when the system goes down on a Monday morning, with forty operators waiting for manufacturing orders.
There's a detail the ERP manuals don't mention: in factories with multiple shifts, the critical moment isn't office hours — it's the early-morning shift, when there's no internal IT on duty and the cloud vendor's helpdesk is responding by ticket. A two-hour stoppage at 3 a.m. on a garment-making line subcontracting for a European parent company has a cost that appears on no TCO spreadsheet.
Decision matrix: ten weighted criteria
Fill in the "Weight" column according to your company's reality (1 = barely relevant, 3 = critical). Add up the points in each column. The option with the highest total is the one best suited to your context — not to the context of the vendor who sent you the proposal.
| Criterion | Weight (1-3) | Favours Cloud | Favours On-Premise |
|---|---|---|---|
| Internal IT capacity | No IT team or a very small one | Internal IT with infrastructure management capacity | |
| Connectivity on site | Redundant fibre across all locations | Unstable connections, rural areas, factories with poor coverage | |
| Data sensitivity | Standard data, no contractual location restrictions | Clients require data on national territory; defence or health data | |
| Integrations with machines and PLCs | Few integrations, via standard API | Many local integrations, critical latency, industrial protocols | |
| Preferred cost model | Predictable OPEX, no initial CAPEX | CAPEX acceptable; recurring OPEX undesirable over the long term | |
| Speed of launch | Need to go live in under twelve weeks | Flexible implementation timeline, phasing possible | |
| Deep customisation | Standard processes, little customisation | Highly specific processes, complex verticals (footwear, textiles) | |
| Regulatory compliance | Cloud vendor certified to ISO 27001, GDPR and SAF-T managed contractually | Full control of the environment for internal or client audits | |
| Expected user growth | Rapid and unpredictable growth — easy scaling | Stable number of users over the next five years | |
| PT2030/PRR funding | Application envisages SaaS subscription as eligible expenditure | Application envisages asset acquisition — eligible CAPEX |
How to use the matrix without making it useless
The most common mistake is filling in the weights after seeing the proposals. When that happens, the weights are unconsciously shaped by the price already seen — and the matrix stops being a decision tool and becomes a retroactive justification. Assign the weights before opening any quote.
Bring the decision trio — CEO, CFO and head of IT — into the same room. Without one of them, the matrix is incomplete: the CEO decides the investment horizon, the CFO decides the cost structure, IT decides what is technically feasible. Fill in the "Favours" column based on the facts gathered in the prerequisites, not on the opinion of the vendor's salesperson.
After adding up the weighted points — weight multiplied by a binary value, one if the column applies, zero if not — identify the weight-three criteria where there's a tie. Those are the negotiation points with the vendor. The weight-one criteria aren't worth the meeting time.
Always validate with a concrete failure scenario: "If the internet connection goes down for four hours, what happens to production?" The answer to this question is worth more than any aggregate score. In INFOS projects, we frequently see companies with unstable connectivity in secondary production units opting for hybrid architectures: MULTI ERP in the cloud with shop-floor modules — such as KORA Productivity — running locally with deferred synchronisation. It's not the most elegant solution on paper. It's the one that doesn't stop when the fibre goes down at two in the morning.
The regulatory factor that most people don't read until it's too late
Portaria 195/2020 requires monthly submission of the SAF-T file to the Tax Authority. DL 28/2019 requires invoicing software to be certified by the AT and to generate ATCUD. These obligations exist regardless of whether the ERP is in the cloud or on-premise — but the responsibility to fulfil them is distributed differently depending on the model.
In a cloud model, verify contractually who is responsible for updating the invoicing module when the AT changes the technical specifications. And it changes, frequently, with little advance notice. In an on-premise model, that responsibility is entirely yours — and if the update isn't applied in time, the company may end up with non-certified software and invalid invoicing. Neither model is immune. The difference is who takes the call when the deadline passes.
NIS2 — EU Directive 2022/2555, transposed by DL 65/2025 — adds another layer that most industrial SMEs have yet to incorporate into their analysis. Companies in sectors deemed critical or important now have obligations regarding incident notification and supply chain risk management. If the cloud ERP is hosted with a vendor that suffers a security incident, the company may have notification obligations that weren't in the original contract. Read the subcontracting clause before signing — not after.
The mistakes that keep recurring
Comparing licence price instead of five-year TCO is the most expensive mistake and the most common. Always calculate: licence plus implementation plus training plus integrations plus exit costs. Data migration to another vendor, when the relationship ends, rarely appears in the initial proposals and is rarely cheap.
Assuming that cloud equals automatic security is the second mistake. The cloud vendor protects the infrastructure. The configuration of access, profiles and Zero Trust policies is the company's responsibility. A user with excessive permissions is a risk regardless of where the server runs — and in factories where the same login serves three shifts because "it's more practical", the risk is structural.
Ignoring latency in industrial integrations is the mistake that shows up late. Production-logging terminals, scales, barcode readers in the warehouse — when they communicate with a cloud ERP via the internet, any latency spike affects response time on the shop floor. In a distribution warehouse with intensive picking, two seconds of latency per scan multiplied by a thousand scans per shift add up to real operating time lost. Test latency before signing, not after go-live.
Deciding without listening to the warehouse manager or the head of production is the mistake that guarantees resistance to adoption. They're the ones who live with the system eight hours a day. If connectivity fails on the night shift and there's no local support, they're the ones left idle — and who find creative ways to work around the system in the first week of use.
Confusing PT2030 funding with technical validation is the mistake we see in approved applications that then don't work in production. The fact that an application is approved doesn't mean the chosen architecture serves the operation. We see companies choosing cloud because "it's what the application consultant recommended for eligibility" — and then discovering that the factory doesn't have the network infrastructure to support it. The funding covers the investment; it doesn't cover the cost of redoing the architecture two years later.
Where Portugal stands — and what that changes in the decision
According to the INE, in 2025 only 53.7% of Portuguese companies with ten or more employees used business management software. Close to half the industrial fabric still operates without integration — spreadsheets, paper, systems isolated by department. For these companies, the cloud vs. on-premise decision is secondary. The primary decision is to adopt an ERP vertical suited to the sector. Choosing the hosting architecture before choosing the product is like deciding where to park before buying the car.
For those who already have an ERP and are evaluating migration or replacement, the guide to evaluating vertical fit before signing a contract is the step prior to this decision. The hosting architecture only makes sense after confirming that the product fits the processes — and that the vendor knows the sector deeply enough not to discover the specifics of footwear or textiles during implementation.
For additional context on how a centralised ERP changes the management of an industrial SME, the importance of a centralising ERP for SMEs and MULTI ERP as the foundation for scaling an industrial SME develop the argument with cases from the field.
The right question isn't "cloud or on-premise?". It's "who's responsible for what, when something goes wrong at three in the morning?" Answer that first — and with the weights assigned before seeing any proposal.
Sources
- INE — Survey on the Use of Information and Communication Technologies in Enterprises, 2025. Available at: ine.pt
- Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS2), transposed into Portuguese law by Decree-Law 65/2025.
- Decree-Law 28/2019, of 15 February — rules applicable to the processing of electronic invoicing and the retention of books and accounting records.
- Portaria 195/2020, of 13 August — monthly submission of the SAF-T file to the Tax Authority.
Frequently asked questions
What's the real cost difference between cloud and on-premise after five years?
There's no single answer. On-premise has high initial CAPEX but low operating costs afterwards. Cloud has predictable monthly OPEX but growing with users and modules. In a typical factory with sixty users and internal IT already in place, the total cost may be equivalent or higher in the cloud. The difference shows up in year three.
What should I measure before comparing cloud vs. on-premise proposals?
Gather: current infrastructure cost, actual number of concurrent users at peak, bandwidth available at each location, ERP downtime over the last twelve months, data classification (GDPR, financial), internal IT capacity, investment horizon and integration requirements with machines. Without this data, any comparison is speculation.
Is the cloud mandatory if I don't have an internal IT team?
Yes, practically. If you have no one to run backups, apply patches and respond to incidents at 11 p.m. on a Friday, transferring that responsibility to a cloud vendor has real, measurable value. Without internal IT, on-premise becomes a high operational risk.
What's the most common hidden cost in cloud projects?
The exit cost. The initial proposals show monthly OPEX, but they rarely include the price of data migration, reconfiguration of integrations or contractual penalties if you want to change vendor. Always ask for the total exit cost before signing.
Does a cloud outage at night have the same impact as an on-premise outage?
No. In factories with multiple shifts, a two-hour stoppage at 3 a.m. on a production line with subcontracting has a real but invisible cost in the TCO. If you have internal IT, you respond within minutes. If you're in the cloud, it depends on the vendor's helpdesk ticket.
Can I use the decision matrix to choose without talking to vendors?
Yes. Fill in the "Weight" column according to your company's reality (1 to 3 points). Add up the totals for cloud and on-premise. The option with the highest score is the one best suited to your context, not to the vendor's commercial context.
Is poor connectivity reason enough to choose on-premise?
Yes. If you have unstable connections, rural areas or factories with poor coverage, cloud is a high risk. It requires redundant fibre across all locations. Without that, on-premise with a local server is operationally safer, regardless of other factors.
