Cloud Computing Web Directory


What cloud computing means and how it took shape

Cloud computing is a way of delivering computing power, storage, and software over a network instead of from hardware that an organisation owns and runs on its own premises.

NIST's foundational framework

The reference definition that most of the industry returns to comes from the United States National Institute of Standards and Technology, which framed it as a model for enabling on-demand network access to a shared pool of configurable computing resources that can be provisioned and released quickly and with little management effort (Mell and Grance, 2011).

That phrasing matters because it shifts attention away from any single product and towards a set of behaviours: capacity that appears when asked for and billing tied to actual use, with infrastructure that the customer never has to physically touch.

The same NIST document set out five characteristics that separate a genuine cloud service from older forms of hosting. These are on-demand self-service, broad network access, resource pooling under a multi-tenant arrangement, rapid elasticity, and measured service where consumption is metered.

A web hosting plan from twenty years ago might have offered some of these traits, but rarely all five together, and almost never with the automation that lets a customer add a hundred servers at two in the morning without a phone call.

Characteristics establishing categories

The companies and services collected in a cloud computing business directory usually match one or more of these characteristics, which is part of why the category is wide enough to hold both global platform operators and small specialist consultancies.

Measured service deserves a closer look because it is the trait that distinguishes cloud from a fixed monthly hosting fee. Resources are metered, reported, and billed according to what was actually used, whether that is gigabytes stored, hours of processor time, or requests served.

This is what makes elasticity meaningful: there is little point in being able to scale up and down quickly if the bill stays the same either way.

The metering also produces a stream of data that customers can use to understand their own consumption. And it is the foundation on which cost-management tools and chargeback schemes inside large organisations are built. The downside is that a usage-based bill can be unpredictable, which is a recurring theme for anyone who has watched a test environment quietly run up charges over a weekend.

The idea did not arrive fully formed. Time-sharing systems in the 1960s let multiple users draw on one expensive mainframe. And the language of computing as a public utility, comparable to electricity or water, circulated among researchers for decades before the technology caught up.

Economics enabling projects

Commercial momentum built in the mid-2000s when large online retailers and search firms found themselves running enormous server estates and began renting spare capacity to outside customers.

A widely cited academic survey from the University of California, Berkeley argued that the economics had finally tipped: the illusion of infinite resources available on demand, with no up-front commitment and payment for short-term use, removed barriers that had constrained smaller firms (Armbrust et al., 2010).

A few enabling technologies had to mature before any of this became practical at scale. Cheap commodity servers made it cheaper to add capacity by buying more ordinary machines than by buying ever larger ones. Virtualisation let a single physical machine present itself as many independent ones, which is what makes resource pooling and multi-tenancy possible in the first place.

Fast and affordable wide-area networking meant a customer no longer paid a heavy penalty for keeping their data somewhere far from their desk. Automation software, able to create and destroy thousands of machines from a script, turned what had been a manual provisioning task into something a program could do in seconds. None of these on its own produced cloud computing; together they removed the obstacles one by one.

Standards bodies followed the market rather than leading it. The joint technical committee of the International Organization for Standardization and the International Electrotechnical Commission published a vocabulary standard, ISO/IEC 17788, to settle the meaning of terms that vendors had been using loosely, working in collaboration with the International Telecommunication Union (ISO/IEC, 2014).

Multiple paths to scale

This kind of groundwork sounds dry, but it underpins contracts, audits, and procurement rules in which a phrase like "cloud service" has to mean the same thing to a buyer in one country and a supplier in another. Anyone browsing cloud computing web directories will encounter providers who advertise conformance to these standards as a mark of credibility.

It helps to separate cloud computing from a few neighbours that often share a page with it. Virtualisation is a technique that cloud relies on, not a synonym for it. Hosting is older and usually narrower. Edge computing pushes processing closer to where data is generated, which can complement cloud rather than replace it.

Keeping these distinctions clear is one reason curated business directories that list cloud computing companies remain useful, since a search engine alone rarely sorts a true platform operator from a reseller or a marketing site that merely borrows the vocabulary.

Service models, deployment patterns, and the supporting market

Three service models structure most discussions of what a cloud provider actually sells. Infrastructure as a Service, usually shortened to IaaS, rents raw building blocks such as virtual machines, block storage, and networking, leaving the customer responsible for operating systems and everything above them. Platform as a Service, or PaaS, adds a managed layer for building and running applications without the customer maintaining the underlying servers.

Software as a Service, SaaS, delivers a finished application through a browser or a thin client, with the provider handling everything beneath it. The same NIST work that defined the five characteristics also fixed these three models, and they have proved durable enough to survive a decade of marketing terms layered on top (Mell and Grance, 2011).

Deployment patterns and access

Deployment patterns answer a different question: who can use a given cloud and where it sits. NIST identified four. A public cloud is open to the general market and run by a provider for many unrelated customers.

A private cloud is dedicated to a single organisation, whether hosted internally or by a third party. A community cloud is shared by several organisations with common concerns, such as a group of agencies bound by the same compliance rules.

A hybrid cloud stitches two or more of these together so that workloads can move between them. The reference architecture that accompanied the definition described the actors involved, including the cloud consumer, the cloud provider, the cloud broker, the cloud carrier, and the cloud auditor, giving procurement teams a shared map of responsibilities (Liu et al., 2011).

Naming has become a source of confusion as vendors coined a string of further "as a Service" labels. Function as a Service, sometimes called serverless, lets a developer run small pieces of code in response to events without managing any server at all, with billing measured down to fractions of a second.

Database as a Service, container platforms, and managed machine learning offerings all sit somewhere on the spectrum between the three classic models rather than replacing them.

A useful habit when reading a provider's marketing is to ask which of the original three layers a service really occupies and how much operational responsibility it leaves with the customer, since that question settles most of the invented vocabulary. Sorting entries this way is also how a cloud computing business directory keeps an IaaS host and a SaaS application from being filed under the same heading.

Around these models sits a supply chain that the public rarely sees. Data centres, undersea and terrestrial fibre, power contracts, cooling systems. And the silicon supply for processors and accelerators all feed into whether a cloud service is fast, available, and affordable. Much of this physical layer is concentrated among a small number of operators.

Synergy Research Group reported that the number of large data centres run by hyperscale companies passed well over a thousand sites, with the United States accounting for a large share of total capacity, and projected that hyperscale operators would hold the majority of all data centre capacity within a few years (Synergy Research Group, 2025).

Geography shapes the experience of using these services in ways that are easy to overlook. Providers organise their capacity into regions, each a cluster of data centres in a part of the world, and within those into availability zones that are isolated enough to fail independently.

A customer chooses regions for latency, since data travels no faster than physics allows, and for legal reasons, since some data must remain within a particular country. The same choice affects price, because electricity, land, and connectivity cost different amounts in different places. This is why two customers running an identical workload can pay different rates and see different response times depending only on where they placed it.

Geography shaping infrastructure

The money involved has grown to a scale that reshapes whole economies. Gartner forecast that worldwide end-user spending on public cloud services would reach roughly 850 billion United States dollars in 2026, a sharp rise on the prior year, driven in large part by demand for capacity to train and run artificial intelligence models (Gartner, 2025).

For people using a cloud computing business directory to shortlist suppliers, those headline numbers translate into a crowded field where it can be hard to tell a venture-funded newcomer from an established operator. This is one of the practical jobs a directory does: it gathers listings and resources relevant to cloud computing in one place so that buyers can compare without starting every search from scratch.

The category also stretches well beyond the handful of names that dominate the news. Managed service providers configure and run cloud estates for clients who lack in-house expertise. Independent software vendors build their products on top of the major platforms and sell access as SaaS. Consultancies advise on migration, cost control, and security. Training organisations certify engineers.

Backup and disaster-recovery specialists, cloud cost-management tools, and compliance auditors all occupy their own niches. A web directory covering cloud computing that records these smaller players gives a fuller picture of the market than the league tables of platform revenue ever could, because most real projects depend on this surrounding ecosystem as much as on the platforms themselves.

Security, privacy, and the shared responsibility model

Moving data and applications off your own premises does not remove the duty to protect them. The most useful concept for understanding cloud security is the shared responsibility model, an idea that providers and standards bodies have settled on over time.

Provider versus customer roles

In broad terms the provider secures the cloud itself, meaning the physical sites, the host infrastructure, and the virtualisation layer, while the customer secures what they put in the cloud, meaning their data, their access controls, and their application configuration.

The split moves depending on the service model: a customer running raw infrastructure carries far more responsibility than one consuming a finished software product. Misunderstanding where the line falls is behind a large share of publicised breaches, where a storage bucket was left open not because the platform failed but because a customer misconfigured it.

Formal guidance exists to keep these arrangements honest. ISO/IEC 27017 extends the general information security controls of ISO/IEC 27002 to the cloud setting, adding cloud-specific guidance on matters such as the allocation of responsibilities between provider and customer, the removal and return of assets when a contract ends, the protection and isolation of virtual machines, and the monitoring of customer activity (ISO/IEC, 2015).

A provider that holds certification against this standard gives a buyer something more concrete than a marketing claim. Several listings in a cloud computing directory will reference such certifications, and treating them as a filter rather than a footnote is sound practice when the stakes include regulated or personal data.

Privacy law beyond technology

Privacy law adds a second layer of obligation that no technical control can satisfy on its own. Where personal data is processed, regimes such as the European Union General Data Protection Regulation impose duties on both the organisation that decides why data is used and the cloud provider that processes it on instruction.

Questions of where data physically rests, who can compel its disclosure, and how it crosses borders have become central to procurement, and they explain why some buyers insist on data centres within a particular jurisdiction. The community deployment model described earlier exists partly to serve groups, such as public sector bodies, that share a strict legal baseline and want assurances written into the contract rather than implied.

The vocabulary standard from the joint ISO and IEC committee matters here for an unglamorous reason: contracts and audits need agreed terms. When a data protection agreement refers to a cloud service provider, a cloud service customer. And the processing activities between them, both sides need those words to carry the same meaning regardless of which country's lawyers drafted the clause (ISO/IEC, 2014).

Certification schemes build on that shared language, letting an independent body assess a provider once and issue a result that many customers can rely on, rather than every buyer running its own audit. This is part of why standards conformance shows up so often in supplier marketing. It is a shortcut through what would otherwise be a slow trust-building process.

Threats specific to multi-tenant environments deserve attention because they differ from those facing a single isolated server. When many customers share pooled hardware, the isolation between tenants becomes a security boundary in its own right, and weaknesses in that boundary can in principle let one tenant observe or affect another.

Defending multi-tenant boundaries

Account hijacking, exposed application programming interface keys, and insecure interfaces appear repeatedly in industry threat reports. Identity and access management, encryption of data both in transit and at rest, careful key handling, and continuous monitoring form the working defences. Many specialist firms listed across cloud computing web directories exist precisely to supply these capabilities to organisations that cannot build them in-house.

Resilience is the quieter side of security and is often what fails first in practice. A region-wide outage at a single provider can take down thousands of dependent services at once, which is why serious operators design for failure across availability zones and, increasingly, across more than one provider.

The reference architecture's inclusion of a cloud auditor as a distinct role reflects an understanding that independent verification matters; trusting a supplier's own dashboard is not the same as having someone check it (Liu et al., 2011).

Buyers using a curated cloud computing directory to assemble a shortlist do well to treat documented audit history and transparent incident reporting as selection criteria in their own right, alongside clear exit provisions, rather than as fine print.

The service level agreement is the document where security and resilience meet commerce. It states what availability the provider commits to, often as a percentage of uptime over a month, and what compensation, usually a service credit, follows if the commitment is missed.

Clauses revealing true capability

Read carefully, these agreements reveal as much by what they exclude as by what they promise. Scheduled maintenance windows, force majeure clauses, and the narrow definition of what counts as downtime can leave a customer with little recourse after a painful outage.

The credit on offer rarely matches the business loss from an interruption, which is the real reason mature buyers treat the agreement as a floor for expectations rather than a guarantee, and build their own redundancy on top of it.

A cloud computing business directory will not parse these clauses for a reader. But it does narrow the field of suppliers whose agreements are worth reading in the first place.

Economics, energy, and where the field is heading

The financial appeal of cloud computing rests on turning large up-front capital costs into ongoing operating costs that scale with use. A startup no longer needs to buy a room full of servers to test an idea, and a retailer can rent enough capacity to survive a seasonal peak without owning it for the rest of the year.

Shifting capital into consumption

The Berkeley survey captured this early, noting that the ability to pay for resources by the hour and to treat capacity as effectively unlimited changed which projects were even worth attempting (Armbrust et al., 2010).

That said, the pay-as-you-go model cuts both ways. Costs that are easy to start are easy to lose track of. And an entire sub-industry of cloud cost management has grown up to help organisations avoid bills that climb faster than the value delivered.

Lock-in is the economic risk that buyers underestimate most often. Once an application is built around one provider's particular databases, queueing systems, and machine learning tools, moving it elsewhere can cost more than the savings that prompted the move. This is why portability standards, open formats, and container technologies attract attention, and why some organisations deliberately design for more than one provider despite the added complexity.

When consulting business directories that list cloud computing companies, buyers often look specifically for migration specialists and tooling vendors whose whole purpose is to reduce this dependence, which is a reminder that the category covers escape routes as much as on-ramps.

Data transfer shaping behavior

Data transfer charges deserve a mention because they shape behaviour in ways that surprise newcomers. Moving data into a provider's network is usually free, while moving it out again often costs money, a pattern sometimes described informally as data gravity.

Over time this pulls more and more of an organisation's data and the applications that act on it into one provider, which compounds the lock-in problem rather than easing it.

Careful buyers model these egress costs before they commit and treat them as a recurring line item rather than an afterthought, especially in any plan that involves keeping a second provider on standby. The cheapest place to store data is not always the cheapest place to use it.

Energy now constrains where and how fast the sector can grow. The International Energy Agency estimated that data centres consumed on the order of 415 terawatt hours of electricity in 2024, roughly one and a half per cent of global demand, and projected that figure to climb steeply through the rest of the decade as artificial intelligence workloads expand (IEA, 2025).

The siting of new facilities, the price and carbon intensity of local power, and the availability of water for cooling now shape where capacity gets built, and they feed directly into the sustainability claims that providers make. Several jurisdictions have begun to scrutinise the energy footprint of large data centres, which adds a regulatory dimension to what used to be a purely commercial decision.

Artificial intelligence driving expansion

Artificial intelligence is changing the field faster than anything else at present, and it does so from both directions. AI workloads consume cloud capacity at a rate that has driven much of the recent surge in provider spending, with hyperscaler capital expenditure rising sharply year on year to fund specialised hardware (Synergy Research Group, 2025).

At the same time, cloud platforms have become the main channel through which most organisations reach AI capabilities at all, since few can afford to buy and operate the accelerator hardware themselves.

The result is a tightening loop in which AI demand expands the cloud and cloud access broadens AI adoption. Many of the newer entries appearing in a cloud computing business directory reflect this shift, and they offer managed access to models and the infrastructure that runs them.

A few patterns already seem settled rather than speculative. Hybrid and multi-cloud arrangements continue to spread as organisations balance cost, resilience, and regulatory pressure, while edge computing grows where low latency or data residency rules make a distant data centre impractical.

Jurisdictional design constraints

Sovereign cloud offerings, designed to keep data and operations within a single legal jurisdiction, attract public sector and regulated buyers, and sustainability reporting is turning from a marketing flourish into a procurement requirement.

For anyone tracking the sector, a web directory covering cloud computing offers a way to watch these trends settle into the supplier market, since new categories of provider tend to appear in such listings before they reach the mainstream press.

Using this category and reading further

This category page collects organisations, services, and resources connected to cloud computing in one curated place. The aim is practical: rather than wading through search results that mix genuine platform operators with resellers and marketing pages, a visitor can scan a focused set of listings and resources relevant to cloud computing and follow the ones that fit a specific need.

Because the field spans everything from global infrastructure providers to single-discipline consultancies, the listings here are best read as a starting map rather than an endorsement of any one supplier.

Framework for vendor selection

When evaluating an entry, it helps to read it against the framework set out in the earlier sections. Identify which service model the provider works in, since an IaaS specialist and a SaaS vendor solve different problems. Check the deployment patterns they support, especially if data residency or a community arrangement matters to you.

Look for references to recognised standards and independent audits rather than self-description alone. Business directories that list cloud computing companies can point you towards candidates, but the selection work, comparing security posture, exit terms, and total cost, still belongs to the buyer.

Different visitors will use the same category differently. A small business owner may be looking for a managed provider to take operational burden off their hands. A developer may want a platform with particular tooling. A compliance officer may be screening suppliers against a regulatory checklist.

A student or researcher may simply be building an understanding of how the parts fit together. Curated business and web directories covering cloud computing accommodate all of these by gathering breadth in one place, while leaving the detailed judgement to the reader, who knows their own constraints best.

Visitors seeking different outcomes

A small glossary may help readers who arrive without the background. A region is a geographic cluster of facilities. An availability zone is an isolated part of a region designed to fail on its own. Multi-tenancy means many customers share the same underlying hardware, kept apart by software. Egress is data leaving a provider's network, usually the part that costs money.

Elasticity is the ability to add and remove capacity quickly. And a hyperscaler is one of the very large operators whose data centre estates account for much of global capacity. These few terms recur across almost every listing, and knowing them turns most provider descriptions from marketing into something a reader can actually compare.

They are also the words to scan for when working through any web directory covering cloud computing, since a provider that uses them precisely usually understands the part of the market it claims to serve.

One caution is worth stating plainly. The cloud sector moves quickly, headline figures change from year to year, and a provider that looks dominant today can be displaced or acquired. Treat any specific statistic as a snapshot and check a supplier's current standing directly before committing, preferring documented evidence over claims.

Sector dynamics requiring verification

Used in that spirit, the cloud computing listings in this directory are a useful filter on a noisy market rather than a substitute for due diligence. The references below point to the primary sources behind the explanations in this description, so that interested readers can check the originals.

References

  1. Mell, P. and Grance, T. (2011). The NIST Definition of Cloud Computing (Special Publication 800-145). National Institute of Standards and Technology, United States Department of Commerce
  2. Liu, F., Tong, J., Mao, J., Bohn, R., Messina, J., Badger, L. and Leaf, D. (2011). NIST Cloud Computing Reference Architecture (Special Publication 500-292). National Institute of Standards and Technology, United States Department of Commerce
  3. Armbrust, M., Fox, A., Griffith, R., Joseph, A. D., Katz, R., Konwinski, A., Lee, G., Patterson, D., Rabkin, A., Stoica, I. and Zaharia, M. (2010). A View of Cloud Computing. Communications of the ACM, Volume 53, pages 50 to 58
  4. International Organization for Standardization and International Electrotechnical Commission. (2014). ISO/IEC 17788:2014 Information technology, Cloud computing, Overview and vocabulary. ISO, Geneva
  5. International Organization for Standardization and International Electrotechnical Commission. (2015). ISO/IEC 27017:2015 Information technology, Security techniques, Code of practice for information security controls based on ISO/IEC 27002 for cloud services. ISO, Geneva
  6. International Energy Agency. (2025). Energy and AI. IEA, Paris
  7. Synergy Research Group. (2025). Hyperscale Data Center Market Tracker. Synergy Research Group, Reno, Nevada
  8. Gartner. (2025). Forecast: Public Cloud Services, Worldwide. Gartner, Stamford, Connecticut

  • Amazon Web Services (AWS) V
    Amazon's comprehensive cloud computing platform offering over 200 services including compute, storage, databases, AI/ML, and analytics with global infrastructure and pay-as-you-go pricing.
    https://aws.amazon.com/
  • NIST Cloud Computing Standards V
    National Institute of Standards and Technology's authoritative definition and framework for cloud computing, establishing industry standards for characteristics, service models, and deployment models.
    https://www.nist.gov/
  • Microsoft Azure
    Microsoft's cloud platform providing IaaS, PaaS, and SaaS solutions with strong enterprise integration, hybrid cloud capabilities, and AI services across global data centers.
    https://azure.microsoft.com/

FAQ

The cloud computing category, briefly

Straight answers about what sits here and how the listings get in.

Which cloud sites end up on this page?

Expect large platform providers and the standards bodies behind them. The current entries include Amazon Web Services, Microsoft Azure, and the NIST cloud computing standards. So it is infrastructure vendors alongside the reference material that defines the terms.

Where does Cloud Computing fall in this web directory?

It sits under Computers & Technology. That parent holds the wider set of technical categories. This is a topical branch, not a regional one, so nothing here is filed by country or state.

How is this different from Data Storage or Databases?

Those are separate sibling categories with a narrower focus. Data Storage and Databases cover specific parts of the stack, while this page is for the broader platform and its standards. A provider that covers both areas may appear under each. Each placement is judged on its own.

What are the editorial picks I see at the top?

They are entries the editors chose to feature within this category. It is a curation call, not a paid slot. The pick still passes the same review as any other listing.

Does a human actually look at every submission?

Yes. Every submission passes under a human eye first, and anything that misses the guidelines is declined with the one-time review fee refunded. About ninety percent of the directory was added by hand this way. It has run on that basis since 2009.

Why should a description read plainly rather than like a pitch?

A listing is a URL and a short factual line about what the site does. If the wording sells instead of describing, it gets trimmed or sent back. Higher plans can add deep links to inner pages, and editors look at those during review too.

What happens if a listed site disappears?

Every URL gets retested over time. An entry that stops resolving or lands on a parked domain is flagged and pulled. Owners may also request edits to a live listing; those changes face the same review.