A cloud SCADA lives on the internet, but the instruments in your field speak old industrial protocols over serial and local networks and were never meant to reach the cloud. The cloud gateway is the device that bridges the two - it sits at the site, talks to your equipment in its own language, and forwards the data securely to the cloud. This guide explains what a cloud gateway is, what it does, and where it fits.
What Is a Cloud Gateway? in one line: A cloud gateway is an edge device that connects local field equipment to a cloud platform. It reads data from devices over industrial protocols, translates and often buffers it, and forwards it securely to the cloud - typically over an encrypted outbound connection - so on-site instruments that cannot reach the internet directly can be monitored in the cloud.
A cloud gateway performs several jobs at the edge of the network. First, protocol translation: it polls or subscribes to local devices over Modbus, DNP3, OPC UA, EtherNet/IP, or Siemens S7, and republishes that data upstream in a cloud-friendly form, most often MQTT with Sparkplug B over TLS. This decouples the field's legacy protocols from the cloud's modern ones. Second, connectivity: it manages the cellular, satellite, or wired uplink to the internet.
Third, and critically, it provides store and forward: if the uplink to the cloud drops, the gateway buffers timestamped data locally and backfills the platform when connectivity returns, so a WAN outage causes a delay rather than a data gap. Many gateways also do edge processing - deadband filtering, unit scaling, basic calculations, even local logic - so only meaningful, cleaned data is sent, saving bandwidth on metered links.
The security model is a major reason cloud gateways exist. Rather than exposing PLCs and RTUs to inbound internet connections - a serious risk with unauthenticated legacy protocols - the gateway makes a single outbound, encrypted connection to the cloud. No inbound ports need to be opened at the site, so the field network stays behind the firewall and the attack surface shrinks dramatically. The gateway becomes the one controlled, hardened point of egress.
Architecturally, this keeps the boundary clean: local control keeps running on the PLCs and RTUs whether or not the cloud is reachable, while the gateway handles the entirely separate job of shipping data to the cloud for supervision, history, and remote access. If the cloud link fails, the process is unaffected and the gateway buffers until it recovers. This separation is what makes cloud SCADA safe for operational monitoring.
For distributed operators, a cloud gateway at each site or pad is often what makes cloud SCADA feasible: a solar-powered edge device reads the wellsite's flow computer, RTU, and PLC over their native protocols, buffers through cellular dropouts, and forwards to the cloud over an encrypted link. One gateway can front many devices at a site, aggregating them into a single secure uplink.
A gateway can be dedicated hardware, an industrial edge PC, or software running on an existing RTU or edge computer. The important capabilities are broad protocol support, store and forward, encryption, and reliable operation over marginal comms. Merobix connects to field devices over Modbus, DNP3, OPC UA, EtherNet/IP, S7, and MQTT and pairs with edge gateways that buffer and forward securely, so remote wells and pipeline sites reach the cloud without opening inbound ports or losing data through outages.
It is an edge device that bridges local field equipment to a cloud platform. It reads devices over industrial protocols, translates and buffers the data, and forwards it securely to the cloud over an encrypted outbound connection - letting on-site instruments that cannot reach the internet directly be monitored in the cloud.
An RTU is a field device that acquires data from local sensors and can run control logic. A cloud gateway's job is connectivity and translation - it reads from RTUs and PLCs, converts protocols, buffers, and ships data to the cloud securely. Some devices combine both roles, but the gateway function is specifically about bridging the field to the cloud.
Exposing PLCs to the internet is risky - many legacy protocols have no authentication or encryption and were never meant to face the public network. A cloud gateway makes one outbound, encrypted connection so no inbound ports are opened, keeps the field network behind the firewall, and adds store-and-forward buffering the PLC lacks.
This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.
Last reviewed: July 27, 2026. Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.