Private vs Public 5G: A Technical Decision Guide for Enterprise IoT

You are planning a 5G rollout for a fleet of connected sensors, autonomous vehicles, or industrial machines. Somewhere in the architecture review, someone asks the question that will shape the next three years of capex and operations. Do we build our own 5G network, or run on the public one?

Cellular IoT Connectivity / 5G Standalone / Private 5G |
5G cell tower illustrating public vs private 5G network deployment
The answer is rarely absolute, and getting it wrong is expensive in both directions. The private 5G market is projected to pass USD 56 billion by 2033, driven by enterprise IoT workloads where Wi-Fi 6/6E cannot meet SLA targets and public MNO offerings cannot guarantee spectrum priority. Public 5G, meanwhile, is already covering the geography your distributed assets live in, at a per-connection cost private cannot touch. This guide walks the private vs public 5G networks decision on the seven technical criteria that actually decide it.

Definitions, precisely

Public 5G is a mobile network operator (MNO) service delivered over licensed spectrum, typically in 3GPP bands n78 (3.5 GHz mid-band), n1/n3/n28 (sub-1 GHz coverage layer), or n258/n260 (mmWave) where deployed. Access is provisioned by SIM, eSIM, or iSIM, authenticated via 5G-AKA against the operator's AUSF/UDM, with your traffic sharing the carrier's RAN, transport, and 5G core.

Private 5G is a non-public network (NPN) in 3GPP terminology, deployed in one of two architectural patterns. A Standalone Non-Public Network (SNPN) runs a complete 5G core (AMF, SMF, UPF, plus the data-plane functions) on-premises, typically over local licensed spectrum such as CBRS (3.55 to 3.7 GHz) in the US, the German 3.7 to 3.8 GHz industrial band, the UK Shared Access Licence at 3.8 to 4.2 GHz, or the Norwegian local 3.8 to 4.2 GHz allocation. A Public Network Integrated NPN (PNI-NPN) uses an MNO's public infrastructure with a dedicated network slice, dedicated DNN, or a local UPF breakout at the edge, so signalling and control still traverse the operator core but user-plane traffic can be pinned on-site.

Between them sits hybrid 5G network deployment, where a local UPF and MEC host handle latency-sensitive workloads on-premises while a public network extends coverage to everything that leaves the site.

Seven criteria for choosing between private and public 5G

1. Security and data path

SNPN keeps the entire user plane on-premises. Packets from a PLC or an AGV terminate at a local UPF and never touch a shared operator core, which materially reduces attack surface and simplifies compliance with data-residency regimes (GDPR, NIS2, sectoral rules for healthcare and critical national infrastructure). 5G improves subscriber-privacy defaults over LTE (SUCI protects the SUPI on the air interface, replacing the LTE IMSI exposure), and private APNs with strong device authentication cover most enterprise threat models on public 5G. The structural argument for private is when your compliance posture cannot accept a shared control plane, not when it cannot accept encryption over a shared radio.

2. Coverage and mobility

Public 5G wins on reach by definition. Enterprise IoT deployments with distributed assets, meaning vehicles, meters, digital signage, remote monitoring, benefit from operator RAN density and cross-border roaming under GSMA agreements. Com4 aggregates 950+ operator networks across 190+ countries via multi-IMSI and eSIM SM-SR/SM-DP+ profile switching, which is the practical alternative to negotiating individual roaming deals per market.

Private 5G covers only the RF footprint you engineer. For a plant, a port, or a hospital campus this is a design choice, not a limit. Site surveys, link-budget modelling, and small-cell density planning replace carrier coverage maps.

3. Latency and reliability

This is where 5G's Ultra-Reliable Low-Latency Communication (URLLC) profile matters. 3GPP Release 16 and Release 17 target one-way user-plane latency of 1 ms with 99.999 percent reliability for URLLC bearers. In practice, achievable end-to-end latency depends on RAN scheduling numerology (30 kHz or 60 kHz SCS), the location of the UPF, and whether workloads run at a co-located MEC host. On SNPN with an on-premises UPF and MEC, 5 to 10 ms end-to-end for closed-loop control is realistic; on public 5G, guarantees depend on the operator's slice availability and MEC footprint, which vary by market.

For eMBB (enhanced mobile broadband) and mMTC (massive machine-type communications), public 5G is normally sufficient. mMTC targets one million devices per square kilometre and is designed for battery-powered sensors using PSM and eDRX for multi-year field life.

4. Control, slicing, and QoS

On SNPN you own the PCF and can define QoS Flow Identifiers, 5QI mappings, and per-application prioritisation policies without operator involvement. On public 5G, comparable control is possible via network slicing (a dedicated S-NSSAI) or a private APN with QoS policies, but the granularity and commercial terms differ per MNO and generally require an enterprise-tier agreement.

5. Scalability and lifecycle

Public 5G scales as a subscription. You provision additional SIM or eSIM profiles through a connectivity management platform (Com4 Polaris, for example) and lifecycle them via SGP.32 (IoT eSIM remote provisioning) or SGP.22 (consumer eSIM). Private 5G scales as infrastructure. Additional coverage means additional gNodeBs, transport capacity, and core-function scaling, plus in-house or partner-managed operations for the RAN and core over a typical 5 to 7 year hardware refresh cycle.

6. Spectrum and regulation

SNPN economics depend on spectrum access. Where local licences exist (CBRS PAL/GAA in the US, German 3.7 to 3.8 GHz, UK Shared Access, Nordic local licences at 3.8 to 4.2 GHz), private is viable. Where they do not, PNI-NPN over an operator's licensed spectrum is often the only path, which brings you back into a commercial relationship with an MNO.

7. Total cost of ownership

A public 5G rollout is opex-dominant: per-SIM data plans, platform fees, and integration effort. Days-to-weeks to first packet. An SNPN is a capex project: spectrum access, gNodeBs (indoor small cells or outdoor macro), 5G core software, transport, integration, and a multi-year operations model. Payback comes from what the network enables (automation, cable replacement, closed-loop control), not from the network itself. If you cannot name a workload that only SNPN unlocks, PNI-NPN or public with a private APN is the cheaper answer.

Use case patterns

Public 5G use cases: telematics and asset tracking across borders, remote patient monitoring, smart-meter fleets, digital signage estates, micromobility, connected construction equipment across job sites. Anything that has to work reliably where you do not own the ground and where sub-20 ms deterministic latency is not a hard requirement.

Private 5G use cases: deterministic Industry 4.0 workloads (AGV fleet control, robotic cells, machine vision on the factory floor), port and terminal automation, automated mining, hospital campuses with wireless-first clinical workflows, secure defence and CNI sites. High device density, sub-10 ms closed-loop control, and traffic that cannot leave the site.

Construction workers in orange safety gear walking through an active tunnel construction site, with icons representing CO₂ monitoring, worker safety, and IoT connectivity overlaid on the left.

The pragmatic architecture: hybrid

Most enterprise deployments end up hybrid. SNPN or PNI-NPN inside the facility for deterministic control-plane workloads, public 5G with a private APN for anything that leaves the perimeter, unified by a single connectivity management platform, a common IPSec or SD-WAN overlay to the enterprise WAN, and consistent identity and policy across both. That is one network fabric, two access models, one operations team.

Where Com4 fits

At Com4 we design and operate the public and hybrid side of enterprise 5G deployments: global SIM, eSIM (SGP.22 and SGP.32), and iSIM connectivity across 190+ countries, private APN, IoT security services, and the Polaris connectivity management platform for provisioning, monitoring, and lifecycle. Where SNPN or PNI-NPN is the right answer, we work with our customers on the integration between on-premises 5G and the wide-area connectivity that surrounds it.

If you are architecting a specific deployment and want a second opinion on where the private vs public 5G line should fall, that is exactly the conversation we are set up to have. It is what a true partner for IoT connectivity is for.

 

Northern-light-sky
START YOUR JOURNEY TODAY

Stay up to date with the latest news and developments in Com4 and IoT industry