Public vs private LoRaWAN — independent comparison of which fits.
Public vs private LoRaWAN is a coverage, cost and control decision — not a religion. Match the network model to asset density and data residency.
Reviewed September 2026. No universal winner.
The right choice is highly use-case-dependent, and most mature enterprises end up with a mix. This is the operator-level comparison that helps procurement decide.
The architecture difference
Public LoRaWAN: you connect devices to a carrier's network (Orange / Bouygues / Objenious in France, KPN in Netherlands, Swisscom in Switzerland, Senet and Everynet in North America, Helium globally on a peer-operated model).
You pay per-device subscription; the carrier operates gateways and network server.
Private LoRaWAN: you operate your own gateways and network server (ChirpStack open source, The Things Industries, Actility ThingPark Enterprise) on your site. Devices connect only to your network. Capex up-front, no subscription, full control.
Coverage — the deciding factor
Public LoRaWAN coverage is excellent across most of Europe (carrier-run networks cover major countries comprehensively), patchy in North America (Senet, Everynet, Helium fill in but coverage is uneven), and limited in much of Asia, Latin America and Africa.
For deployments concentrated within carrier coverage, public is the fastest path to scale. For deployments spread across patchy or uncovered regions, private (or hybrid) is the only practical option.
Cost economics — which wins?
Public: per-device subscription, typically 1–5 Euros per device per year for low-payload sensors, more for trackers. No upfront infrastructure capex.
Private: gateway capex (1,000–3,000 Euros each, you need 1–5 per site depending on size), network-server capex or licence (ChirpStack free, TTI / Actility commercial), operations overhead.
Breakeven happens around 500–2,000 devices per site, depending on density and gateway choice. Above that, private is usually cheaper TCO.
Security and control
Both use AES-128 encryption end-to-end. The security difference is operational. Public: traffic transits the carrier's network server; key management is shared. Private: you control the entire path, including device provisioning, network keys and routing.
For defence, critical infrastructure, regulated industries (pharma, financial-services field equipment, oil & gas) and sensitive corporate use cases, private is usually required for governance reasons even when public coverage exists.
Vendor and platform landscape
Public carriers: Orange Business / Objenious, Bouygues Telecom, KPN, Swisscom, Telekom Austria, Senet, Everynet, Helium (peer-operated).
Private network servers: ChirpStack (open source, dominant for self-managed), The Things Stack (TTI commercial + community), Actility ThingPark Enterprise (carrier-grade for large private deployments), AWS IoT Core (with LoRaWAN integration), Azure IoT Central.
Gateways: Kerlink, Multitech, Tektelic, Cisco, MikroTik — most work with both public and private. Devices: thousands of LoRaWAN-conformant sensors and trackers.
Hybrid is increasingly common
Many enterprises run both. Public LoRaWAN for assets that move across regions (returnable containers, livestock, mobile equipment) where carrier coverage exists. Private LoRaWAN for sensitive in-site applications (factory sensors, hospital staff, military / defence equipment).
Hybrid stacks use roaming standards to hand devices between networks. We design the network architecture in stage 1 — see /insights/lorawan-explained for the deeper technology treatment.
Decision criteria
Public LoRaWAN buys coverage from a carrier or community network — often powered nationally by platforms such as Actility ThingPark. Private LoRaWAN deploys your gateways and a network server (Actility, The Things Stack, ChirpStack and others). Decide on coverage footprint, data residency, uplink density, roaming needs and operations maturity before comparing logos.
When public wins
- Assets move across cities or regions where you will not build gateway density.
- Operations wants network-as-a-service with operator-style SLAs.
- Device counts are modest and public coverage maps already meet the use case.
- Speed to first devices matters more than indoor engineering control.
When private wins
- Campus or plant density, latency or RF control exceeds public capacity.
- Security policy requires on-prem or VPC-held network server and keys.
- You need predictable indoor coverage engineering, not best-effort outdoor maps.
- Chattery sensors would explode public subscription economics.
TCO traps
Trap: public subscriptions that scale poorly with chatty sensors. Trap: private gateway CapEx without backhaul, NMS and RF planning. Trap: ignoring roaming and join behaviour at site edges. Trap: choosing carrier-grade Actility when The Things Stack or ChirpStack would meet mid-market needs — or the reverse at national operator scale. Trap: forgetting regional channel plans and certification.
Architecture checklist
Before choosing public or private, document: device count and uplink profile (bytes and interval), indoor versus outdoor mix, roaming between campuses, key custody requirements, gateway backhaul (Ethernet, cellular), and who operates the network server. Public networks excel when coverage already exists and devices are sparse. Private networks excel when you must engineer indoor reliability or keep payloads inside your VPC.
Actility ThingPark frequently underpins carrier public networks and also sells enterprise private. The Things Stack suits mid-market private with a smoother developer path. ChirpStack remains the open-source control option when you have ops capacity. Semtech LoRa silicon is common across devices regardless of NNS choice — do not confuse chipset with network architecture.
Hybrid designs are increasingly normal: private gateways on the plant, public roaming for over-the-road assets, with clear join and roaming policies so devices do not flap. TRACIO models coverage, duty cycle and five-year subscription versus CapEx without preferring a carrier logo.
Operational ownership
Private LoRaWAN fails when nobody owns RF planning, gateway monitoring and firmware hygiene. Public LoRaWAN fails when indoor dead zones are discovered after tags ship. Assign an ops owner, write an acceptance walk-test, and put battery and uplink budgets in the same workbook as gateway quotes. That discipline matters more than which slide deck looks more “enterprise.”
Decision summary
Choose public LoRaWAN for wide-area sparse assets on existing coverage; choose private for engineered campus density, residency and uplink control; choose hybrid when plants and over-the-road assets share a device fleet. Pick NNS altitude (Actility, TTI, ChirpStack) after the architecture decision, not before. TRACIO models both without carrier preference.
Decision criteria
Public LoRaWAN buys coverage from a carrier or community network — often powered nationally by platforms such as Actility ThingPark. Private LoRaWAN deploys your gateways and a network server (Actility, The Things Stack, ChirpStack and others). Decide on coverage footprint, data residency, uplink density, roaming needs and operations maturity before comparing logos.
When public wins
- Assets move across cities or regions where you will not build gateway density.
- Operations wants network-as-a-service with operator-style SLAs.
- Device counts are modest and public coverage maps already meet the use case.
- Speed to first devices matters more than indoor engineering control.
When private wins
- Campus or plant density, latency or RF control exceeds public capacity.
- Security policy requires on-prem or VPC-held network server and keys.
- You need predictable indoor coverage engineering, not best-effort outdoor maps.
- Chattery sensors would explode public subscription economics.
TCO traps
Trap: public subscriptions that scale poorly with chatty sensors. Trap: private gateway CapEx without backhaul, NMS and RF planning. Trap: ignoring roaming and join behaviour at site edges. Trap: choosing carrier-grade Actility when The Things Stack or ChirpStack would meet mid-market needs — or the reverse at national operator scale. Trap: forgetting regional channel plans and certification.
Architecture checklist
Before choosing public or private, document: device count and uplink profile (bytes and interval), indoor versus outdoor mix, roaming between campuses, key custody requirements, gateway backhaul (Ethernet, cellular), and who operates the network server. Public networks excel when coverage already exists and devices are sparse. Private networks excel when you must engineer indoor reliability or keep payloads inside your VPC.
Actility ThingPark frequently underpins carrier public networks and also sells enterprise private. The Things Stack suits mid-market private with a smoother developer path. ChirpStack remains the open-source control option when you have ops capacity. Semtech LoRa silicon is common across devices regardless of NNS choice — do not confuse chipset with network architecture.
Hybrid designs are increasingly normal: private gateways on the plant, public roaming for over-the-road assets, with clear join and roaming policies so devices do not flap. TRACIO models coverage, duty cycle and five-year subscription versus CapEx without preferring a carrier logo.
Operational ownership
Private LoRaWAN fails when nobody owns RF planning, gateway monitoring and firmware hygiene. Public LoRaWAN fails when indoor dead zones are discovered after tags ship. Assign an ops owner, write an acceptance walk-test, and put battery and uplink budgets in the same workbook as gateway quotes. That discipline matters more than which slide deck looks more “enterprise.”
Decision summary
Choose public LoRaWAN for wide-area sparse assets on existing coverage; choose private for engineered campus density, residency and uplink control; choose hybrid when plants and over-the-road assets share a device fleet. Pick NNS altitude (Actility, TTI, ChirpStack) after the architecture decision, not before. TRACIO models both without carrier preference.
Frequently asked questions
Which is cheaper — public or private LoRaWAN?
Depends on device count and site geography. Public wins at low device counts in carrier coverage. Private wins above ~500–2,000 devices per site, or for deployments outside carrier coverage. We model both in stage 1.
Can a device roam between public and private networks?
Yes, in principle — the LoRa Alliance has standardised roaming. In practice, public-private roaming is not yet plug-and-play and requires careful key management. Most hybrid deployments segment devices by network rather than roaming them dynamically.
How reliable is Helium for enterprise use?
Helium's peer-operated model has uneven coverage and quality. It's improved since the Solana migration but isn't yet a stable enterprise-grade carrier in most regions. We treat it as a supplementary network, not primary.
Do private LoRaWAN networks require ongoing maintenance?
Yes — gateway firmware updates, network server patching, key management, monitoring. Typically a few engineer-days per year for a stable deployment. Managed-services arrangements with TTI or Actility handle this for enterprises that don't want in-house ownership.
Where do cellular IoT (LTE-M / NB-IoT) fit in this comparison?
Cellular IoT is the other LPWAN option. NB-IoT and LTE-M are carrier-managed, globally available where cellular exists, and integrate naturally with mobile devices.
LoRaWAN wins on cost-per-device at scale and on private-network capability; cellular wins on global mobility and standardised interoperability. Most enterprises run both for different use cases.
Last updated: