Cloud Service Models Explained: SaaS, PaaS, DaaS, IaaS, and More
Learn how SaaS, PaaS, IaaS, Desktop as a Service, and FaaS differ—and how to choose a model based on control, effort, and responsibility.

Cloud service models describe what a provider supplies and which parts of the technology stack you manage. The canonical NIST models are Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS). Desktop as a Service (DaaS) is a specialized category for remotely delivered desktops, while Function as a Service (FaaS) is an additional pattern for running event-triggered code. The practical question is: What’s the difference between SaaS, PaaS, and IaaS? In short, SaaS lets you use a finished application, PaaS lets you deploy your application on a managed platform, and IaaS gives you computing building blocks to configure and operate.
1. What is a cloud service model?
A service model describes the capability a cloud provider makes available and the boundary between provider and customer responsibilities. NIST defines cloud computing around network access to a shared pool of configurable resources that can be provisioned and released with limited management effort. Its model has five essential characteristics, three service models, and four deployment models. The service-model taxonomy and deployment-model taxonomy answer different questions.
The five characteristics are on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. The three service models are SaaS, PaaS, and IaaS. The deployment models are private, community, public, and hybrid cloud. In other words, “public cloud” is not another service-model option beside SaaS or IaaS: it describes how infrastructure is made available. NIST’s summary is: “This cloud model is composed of five essential characteristics, three service models, and four deployment models.” NIST SP 800-145 (Peter Mell and Timothy Grance, 2011) is the source for that taxonomy.
2. SaaS, PaaS, and IaaS compared
| Model | What you receive | What you mainly manage | Shorthand |
|---|---|---|---|
| SaaS Software as a Service |
Use of an application running on cloud infrastructure, commonly through a browser or client. | Your users, access settings, service configuration, and the data you put in it. The provider operates the application implementation and underlying infrastructure. | Use a finished application. |
| PaaS Platform as a Service |
A provider-supported platform and tools on which you deploy an application you created or acquired. | Your application and, depending on the service, its hosting configuration. The provider operates the underlying network, servers, operating systems, and storage. | Deploy your application on a managed platform. |
| IaaS Infrastructure as a Service |
Fundamental computing resources such as processing, storage, and networks. | Operating systems, storage configuration, deployed software and applications, and possibly selected network components. The provider operates the underlying cloud infrastructure. | Rent computing building blocks. |
These are management boundaries, not a ranking from “old” to “modern” or “bad” to “good.” Real services may combine capabilities. Classify the capability you are using instead of relying only on a vendor’s label. NIST SP 500-322 provides guidance for evaluating whether a capability fits the cloud definition and which of SaaS, PaaS, or IaaS best describes it.

A practical example
Suppose a team needs a customer-support system. With SaaS, the team configures accounts and workflows in a ready-to-use service. With PaaS, the team deploys its own support application to a managed runtime. With IaaS, it provisions compute, storage, and networking, then installs and maintains the operating system and application stack. Each step downward in this example gives the team more direct control and more operational work; exact duties depend on the service.
3. How to choose a model
Start with the work you need done, then decide how much of the environment your team wants to operate. There is no universally best model. The right fit depends on workload, customization requirements, available skills, and desired operational control.
- Choose SaaS when the capability is the application itself. It suits a need to use a finished product with service-specific configuration, rather than build and operate the application.
- Choose PaaS when you need to deploy software but want a managed platform. It can reduce the infrastructure and operating-system work your team must perform while leaving your application under your control.
- Choose IaaS when you need control over the software environment. It supplies core resources, while your team takes on more configuration and maintenance.
- Evaluate the actual service boundary. Ask who patches each layer, configures networking, controls identities, handles backups, and responds to failures. A product can provide more than one kind of capability.
- Check the operational fit. Compare the skills and on-call capacity you have with the work the service leaves to you. More control also means more things to configure and maintain.
If a product’s marketing category is unclear, map what the customer receives and manages to the NIST definitions. NIST SP 500-322 addresses service evaluation and categorization.
4. What does DaaS mean?
In this article, DaaS means Desktop as a Service: a cloud category that remotely delivers desktop functions from a provider. Users access hosted desktops from their devices, while the environment can be managed centrally. It is a specialized end-user-computing service, not one of the three service models named in NIST SP 800-145.

DaaS can be considered for remote work, contact centers, training environments, back-office work, knowledge workers, or on-demand developer workstations. These are examples described in provider documentation, not proof that DaaS is always cheaper or more secure. Keeping sensitive data within a hosted desktop rather than on an endpoint can be an architectural choice, but it does not by itself guarantee security. Evaluate identity controls, data flows, endpoint access, availability, and the service’s responsibility documentation. ITU-T Y.3503 describes the DaaS category; AWS documents hosted desktop examples and use cases.
The acronym is ambiguous: DaaS can also mean Data as a Service in other contexts. Spell out the intended expansion the first time, and use the surrounding product or architecture context to interpret it. The DaaS discussed here is Desktop as a Service.
5. What about FaaS and serverless?
Function as a Service (FaaS) is a useful additional cloud pattern. A developer supplies small, modular functions, and a provider runs them in response to specified events. The provider-managed runtime handles the infrastructure underneath. “Serverless” does not mean there are no servers; it means the user does not directly manage that server infrastructure in the same way as in a traditional deployment.
FaaS is not a fourth model in NIST SP 800-145’s original SaaS/PaaS/IaaS list. It describes a way to deliver and execute code, and provider terminology may group serverless offerings differently. For a particular service, check the runtime, scaling behavior, event triggers, execution limits, and responsibilities in its own documentation. See Google Cloud’s FaaS overview.
6. Service models are not deployment models
Service models tell you what capability is supplied and what the consumer controls. Deployment models describe how the cloud infrastructure is arranged or made available. NIST names four deployment models:
- Private cloud: cloud infrastructure provisioned for exclusive use by one organization.
- Community cloud: infrastructure provisioned for exclusive use by a community of organizations with shared concerns.
- Public cloud: infrastructure provisioned for open use by the general public.
- Hybrid cloud: a composition of distinct cloud infrastructures connected to enable data or application portability.
A service may therefore be described along both dimensions. For example, SaaS identifies the service capability; public or private describes a deployment arrangement. Do not add “public cloud” to a list of SaaS, PaaS, and IaaS as though the labels were interchangeable categories.
7. Security and the shared-responsibility boundary
Using a managed service does not remove customer security duties. The provider generally remains responsible for its underlying network and infrastructure, while customers retain duties such as managing access policies and protecting their data. The detailed split varies by service and configuration. A SaaS customer may not manage the application operating system, for example, but still needs to control who can sign in and what data users can access.
Use the service’s security documentation, contract, and responsibility matrix to make the actual assignment. Check identity and access controls, data classification and retention, encryption responsibilities, logging, backup and recovery, patching, network exposure, and incident processes. These are prompts for checking the boundary, not claims that every provider assigns each task the same way. NIST SP 800-210 discusses access-control guidance across cloud models, while Google Cloud’s shared-responsibility guidance describes the provider/customer split. See NIST SP 800-210 and Google Cloud’s shared-responsibility guidance.
8. Applying cloud services to a developer workflow
Screenshot capture illustrates how a developer can consume a finished online capability rather than run a browser stack. A do-it-yourself setup typically means launching a browser, navigating to a URL, waiting for the page, and saving an image; this can be useful when you need direct control over the browser environment. For a service-based workflow, ScreenshotNeo is a website screenshot API and MCP server from Yorker Media. A single GET request can return a PNG, JPEG, WebP, or PDF. See the ScreenshotNeo site and API documentation.
Do it yourself with a browser
For example, with Playwright in Node.js, install the package and browser, then save this as shot.mjs. Replace the target URL if needed. This is a minimal full-page screenshot script; add your own waits or browser configuration for pages that need them.
import { chromium } from 'playwright';
const browser = await chromium.launch({ headless: true });
try {
const page = await browser.newPage({ viewport: { width: 1440, height: 900 } });
await page.goto('https://example.com', { waitUntil: 'networkidle', timeout: 60000 });
await page.screenshot({ path: 'shot.png', fullPage: true });
} finally {
await browser.close();
}
Install with npm install playwright and install its browser with npx playwright install chromium. For highly active pages, networkidle may never occur; choose a more suitable wait condition or wait for a specific selector. In production, use bounded timeouts, close the browser in a finally block, and account for browser binaries and runtime resources.
9. Or skip the browser setup
Use ScreenshotNeo’s one-call API when you want a hosted capture. The API base is https://api.screenshotneo.com/v1/shot. Create an API key through the service, then pass it with the destination URL. The examples save the returned bytes as a WebP file; consult the ScreenshotNeo documentation for request options and response details.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" \
-d access_key=YOUR_API_KEY \
--data-urlencode url=https://stripe.com \
-o shot.webp
Python
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({
access_key: 'YOUR_API_KEY',
url: 'https://stripe.com',
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
const bytes = new Uint8Array(await res.arrayBuffer());
await import('node:fs/promises').then(fs => fs.writeFile('shot.webp', bytes));
Cookie banners, newsletter popups, and chat widgets are removed before the shot; each cleanup step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers report the page verdict and billing status. The MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Sign up for free ScreenshotNeo access.
10. Troubleshooting and edge cases
| Symptom | Likely cause | What to check |
|---|---|---|
| The screenshot is blank or mostly empty | The destination returned an empty page, content had not rendered, or a bot check blocked access. | Open the URL normally, check the page verdict or response, and for DIY captures wait for a meaningful selector or app-ready signal. |
| Navigation times out | The page is slow, keeps network connections open, or waits never resolve. | Use a finite timeout and a page-specific readiness condition. Do not assume network idle suits every application. |
| Images are missing | Lazy-loaded content may not have entered the viewport or loaded before capture. | Scroll or trigger the page’s loading behavior in a DIY script; use a capture option that loads lazy images when available. |
| A consent banner or overlay covers content | The site presents a cookie dialog, popup, or chat widget. | For DIY, handle the relevant selector or consent flow. ScreenshotNeo accepts consent and removes known consent platforms and common overlays before capture; these steps are configurable. |
| The output file is not an image | The request returned an error or another response body, which the client wrote without checking. | Check the HTTP status and response headers before saving bytes; inspect the API response details in the documentation. |
| Capture behavior differs between runs | Dynamic content, animations, personalized pages, or changing network conditions affect rendering. | Use a stable viewport, an explicit wait condition, and appropriate page state. For repeatable captures, review cache settings and request configuration. |
11. Performance, reliability, and cost
With a self-managed browser, capture time includes browser startup, navigation, page rendering, and image encoding. Reusing a browser process can avoid repeated startup overhead, but long-lived browser workers need resource limits, cleanup, and isolation between jobs. Parallel captures increase throughput only while CPU, memory, network capacity, and target-site behavior allow it. Use bounded concurrency, timeouts, and retries with backoff for transient failures; avoid retrying deterministic invalid URLs indefinitely.
A hosted API removes the need to provision browser binaries and capture workers yourself, but makes the workflow dependent on network access and the service’s documented behavior. For reliability, check status and response metadata, set client timeouts, distinguish failed captures from valid image bytes, and retain enough request context to reproduce issues. ScreenshotNeo reports page verdict and billing status in response headers; failed loads and cache hits are not billed under the stated product behavior.
For cost planning, estimate the number of requested captures and confirm how the service treats retries, cache hits, and unsuccessful pages. ScreenshotNeo’s listed monthly plans are Free: 1,000 shots with no card; Starter: $5 for 3,000; Growth: $15 for 15,000; Pro: $39 for 60,000; Scale: $99 for 250,000; and Business: $249 for 1,000,000. Yearly billing gives two months free, and every feature is available on every plan. Compare those limits with your volume and any operational cost of running your own browser workers.
12. FAQ
Is SaaS always easier than IaaS?
It usually shifts more operation to the provider, but whether it is easier depends on the application, configuration, and team’s needs.
Is DaaS part of NIST’s three-model list?
No. Desktop as a Service is a specialized remote-desktop category; NIST SP 800-145 names SaaS, PaaS, and IaaS.
Does serverless mean a provider has no servers?
No. The provider still runs infrastructure; the term describes the customer’s level of direct server management.
Is a private cloud automatically more secure?
The deployment label alone does not establish security. Security depends on architecture, configuration, controls, and operations.
Can a product fit more than one model?
Yes. Products can combine capabilities, so evaluate the specific capability and responsibility boundary in question.
Sources
- NIST SP 800-145: The NIST Definition of Cloud Computing.
- NIST SP 500-322: Evaluation of Cloud Computing Services.
- NIST SP 800-210: General Access Control Guidance for Cloud Systems.
- ITU-T Y.3503: Requirements for Desktop as a Service.
- Google Cloud: Cloud Functions concepts and shared responsibility.
- AWS WorkSpaces, an example of hosted desktop documentation.


