The short version
Siemens gets the architecture right and charges you in hardware. SINEMA Remote Connect is a server you run yourself, so there is no vendor cloud in the access path and no third-party rendezvous to document under NIS2. On the question that trips up Talk2M and IXON Cloud, Siemens is already on the correct side.
Segmentation is the separate purchase. To divide the plant you deploy Scalance firewalls at the boundaries you want enforced, which means hardware per boundary, configuration per boundary, and in most retrofits, cabling. The architecture is sound. The bill and the change window scale with how many zones you actually want.
Where Siemens is strong
Self-hosted by default. SINEMA RC runs on your infrastructure. When procurement asks who operates the path into your plant, the answer is you. That removes an entire category of supply-chain paperwork, and it is the reason Siemens and Secomea both survive conversations that cloud-brokered gateways do not.
Integrated with the automation stack. If the plant is already Siemens end to end, the remote-access product speaks the same language as the PLCs, the engineering tooling and the support contract. That coherence is worth real money and should not be dismissed.
Scalance is a proper firewall. This is not a criticism of the hardware. It does what industrial firewalls do, and it does it from a vendor that understands industrial environments.
Where the cost actually lands
The gap is not capability, it is the unit of deployment.
Zone-based segmentation with firewalls means one device per boundary. Ten zones is ten devices to buy, rack, cable, configure and keep patched. In a greenfield build that is a line item. In a running plant it is a project: you are inserting hardware into paths that currently carry production traffic, which means planning, a change window, and a rollback story for each one.
That is the reason so many IEC 62443 zone-and-conduit designs exist as a document rather than as a configuration. The design is agreed, the hardware is quoted, and the retrofit never finds a window.
The same arithmetic applies to the remote-access side. A gateway per machine plus a firewall per boundary is an estate: a site with fifteen machines and six zones is twenty-one devices, each with a firmware version, a certificate and a configuration that drifts from its neighbours. The operational cost is not the purchase, it is that no single place answers who can reach what.
The overlay alternative
The other way to enforce a boundary is to stop treating it as a physical location. An overlay puts each asset in an enclave defined in software, with the enforcement point in the path but the topology untouched. Assets keep their IP address, gateway and VLAN. There is no per-boundary hardware, because the boundary is policy rather than a box, and adding a zone is a configuration change rather than a purchase order.
Practically, that collapses the two purchases into one appliance: the remote-access broker and the segmentation enforcement point are the same device, so the technician's session and the enclave policy are decided in the same place and logged in the same record.
The comparison in one table
| SINEMA RC + Scalance | Trout Access Gate | |
|---|---|---|
| Broker location | Your server | Your appliance |
| Vendor cloud in path | No | No |
| Segmentation method | Firewall per boundary | Overlay enclaves in software |
| Cost of an extra zone | Another appliance | A policy change |
| Re-cabling to segment | Usually, in a retrofit | None |
| Asset inventory | Not part of the product | Automatic discovery |
| Detection and alerting | Not part of the remote-access product | Snort rules, curated alert library, SIEM forwarding |
Deploy both, not one instead of the other
Keep SINEMA RC. It is self-hosted, it is integrated with the automation stack, and on the sovereignty question it is already on the right side. Nothing here argues for removing it.
The risk is remote access without a control point behind it. A gateway per machine gives you doors into the plant, and unless something governs what passes through them at protocol level, your only enforcement is whatever Scalance boundaries you have managed to fund and install.
The solid architecture is both. Keep SINEMA RC for connectivity, put Access Gate behind it for the enforcement and visibility layer, and you get the IEC 62443 zone model as software policy rather than as a hardware bill that never finds its retrofit window.
Related reading
- Industrial remote access compared, including SINEMA RC, Secomea, Ewon and IXON
- IEC 62443 zones and conduits explained
- Overlay networking versus VLANs