Walk into almost any chain store, clinic, bank branch, or distribution center in America and start counting the things quietly talking to the internet over a cellular signal. The backup modem in the back office. The LTE camera over the register. The card reader at the counter. The digital sign in the window. The sensor watching the walk-in freezer. The handheld the stock crew carries around. Now ask whoever runs that company's security which of those devices their firewall can actually see, and most of the time the honest answer is none of them.
That single fact is quietly rewriting what fixed wireless access means for the enterprise, and it is the reason a slice of the market everyone used to file under "backup internet" has suddenly landed at the intersection of connectivity, compliance, and cyber risk. I have spent the last few weeks in rooms full of MSPs, MSSPs, and TSD partners across the US and Canada arguing about exactly this, and I want to lay out honestly where the shift is real, where it is overhyped, and whether the combined MergeWiFi and Aeris solution people keep asking me about is the genuine article or just another box with a nicer brochure.
THE MARKET IS NOT MOVING SUBTLY
Fixed wireless used to be the thing you deployed when fiber had not shown up yet, and that framing is dead. Analyst forecasts put the global fixed wireless access market at roughly $43 billion in 2026, up from about $37 billion the year before, growing at a mid-teens compound rate that carries it past $84 billion early next decade. The Ericsson Mobility Report has global connections climbing from roughly 185 million to around 350 million by 2031, most of it now running on 5G.
And while analyst house slices the numbers differently, so treat them as directional, but the direction is not in dispute. What is driving it is not the technology; it is the math of opening and running distributed sites. A fiber install still runs 6 to 8 weeks in a lot of markets, sometimes longer, and construction does not wait, so every day a finished store sits dark is rent and payroll burning with no revenue coming in. Fixed wireless flips that. You ship a device, plug it in, power it on, and you are live in a day or two with no trench, no permit, and no truck roll. So, the first honest finding is simple. This is not hype. The center of gravity for distributed connectivity really is sliding toward cellular.
DOES FIXED WIRELESS REPLACE SD-WAN? YES AND NO
This is where the puff pieces overreach, so let me be straight about it. Fixed wireless is not about to rip out SD-WAN at a bandwidth-hungry headquarters or a big campus, and for high-throughput, latency-sensitive, data-dense environments the wired stack still wins and will for a long time. But at the distributed edge, meaning the 50 or 500 or 5,000 small sites where most of the device sprawl actually lives, the story flips. Broadband fragments across local providers with no real service guarantee. MPLS is expensive and slow to change. SD-WAN was built to make public broadband good enough, and it still needs a firewall bolted on beside it, and here is the part everyone glosses over, it cannot see cellular traffic at all.
Your SD-WAN box, your SIEM, your entire enterprise security stack, all of it watches the LAN. Every device that reaches the internet over a SIM instead of the router simply is not in the picture. It is out of band and invisible. So, the accurate verdict is that fixed wireless is not a wholesale SD-WAN killer, it is becoming the primary or co-primary link for the distributed edge, and in the process it drags a security problem into the light that the legacy stack was never built to solve.
THE ROUTER AT LEAST SHOWED UP ON THE MAP
It is tempting to wave that off as low value. Who is really coming after a freezer sensor. Plenty of people, as it turns out, because the device was never the prize, the foothold is.
Consider what happened on July 13, when 19 government agencies across 13 countries, led by the NSA, CISA, and the FBI, issued a joint advisory on Russia's FSB Center 16, the crew tracked for more than a decade as Berserk Bear, Energetic Bear, and Dragonfly. The method is the part that should stop you. They did not drop a brilliant zero-day. They scanned the internet for routers still answering SNMP with default or weak community strings, pulled the device configurations straight off the boxes over TFTP, and walked away with network maps, credentials, and VPN details. They did not break in. They logged in, to a device nobody was watching.
And here is the uncomfortable follow-on for this conversation. That router, as neglected as it was, at least lives in your world. It has an IP address. It shows up in a scan eventually. The cellular version of that same device shows up nowhere, because its traffic never touches your network, so there is no scan, no proxy, and no log that ever sees it. Layer on top of that the commodity threat that is already industrialized, with botnets built on compromised routers and cameras throwing denial-of-service attacks measured in tens of terabits per second, and the picture is clear. When something does slip in through the cellular side, nobody notices for a long time, with dwell times for cellular-connected breaches clustering around 200 days, for the simple reason that there is no tool in the traditional stack watching that path. You cannot alert on traffic you cannot see. That is the cellular blind spot in one sentence. Your perimeter security stops at the LAN, and a growing share of your devices do not live on the LAN anymore.
THE COMPLIANCE CLOCK IS ALREADY RUNNING
If the risk argument does not move a buyer, the compliance calendar will, and that is the strongest reason to act now.
In the US, PCI DSS 4.0 became fully mandatory on March 31, 2025, and it landed harder than anything before it, with something like 80 to 90% of the requirements new, segmentation that now has to be tested every six months rather than assumed, and penetration tests that have to actively try to defeat it. Cleanly separating cellular point-of-sale and IoT off the payment environment has become one of the cheapest ways to shrink audit scope, and most operators cannot answer on the spot how their cellular devices are segmented today. That silence is the opening.
In Europe the Cyber Resilience Act is already law, and it phases in on two dates. The one everyone quotes is December 11, 2027, when the full rulebook applies, meaning secure by default, security updates across the whole support life of the product, a software bill of materials, and CE marking. The date that actually matters more is September 11, 2026, when the reporting obligation goes live, because from that day, if a connected product you make or ship into Europe has a vulnerability that is being actively exploited, you have 24 hours to file an early warning with EU authorities, 72 hours for a fuller report, and 14 days for the final one. 24 hours. You cannot cram for that date, because you cannot report an incident you never detected. The CRA does not treat every device the same either, it pushes higher-risk gear like routers, modems, cameras, and alarms into tougher important and critical tiers, and the manufacturer stays on the hook for the entire support life of the product. It reaches well past Europe too, since a manufacturer in California or Toronto is bound the moment its product hits EU customers through normal commercial channels. Miss the essential requirements and the penalty runs to €15 million or 2.5% of global revenue, whichever is higher, and regulators can pull the product from the EU market entirely, which for a lot of vendors stings worse than the fine. Compliance deadlines are the one thing that reliably turns a security nice-to-have into a funded purchase, and there are two hard ones sitting right in front of us.
THE OLD WAY KEEPS GETTING MORE EXPENSIVE
Here is the kicker that is pushing partners to look for something new. The incumbent hardware path is not just leaving the security gap open; it is getting more expensive while doing it. Distributor notices this summer put Cradlepoint's price increases at roughly 10 to 15%, effective July 1, 2026, across its enterprise router lines, which is worth confirming against your own quotes but points clearly in one direction. And that is before you have solved a single thing, because with the traditional approach you are still typically buying a single or dual-carrier device, then licensing a firewall or security layer separately, then standing up management on top of both. 3 line items, 3 vendors, 3 renewals, and your cellular devices still sit outside whatever security you bolted on. Call it the stack tax. You pay more every year for an architecture that structurally cannot see the fastest growing part of your fleet.
WHAT THE MERGEWIFI AND AERIS BUNDLE ACTUALLY IS
Strip away the marketing and it is two layers sold as one motion. The connectivity layer is the MergeWiFi hardware, with the 5G MAX as the enterprise workhorse, an IQMC-class gateway running 5G alongside LTE-Advanced and carrier-aggregating up to multi-gigabit peaks. What matters operationally is not the spec sheet, it is the behavior. All 3 major US carriers live inside a single device, it ships preconfigured and truly plug and play no matter where it lands, it constantly hunts for the strongest available signal, and it fails over to a second or third carrier within seconds when the first one drops. That is real multi-carrier resilience, a genuinely different network and not just a different tower on the same one that just failed, and for a site where an outage costs real money by the minute that distinction is the whole point. The security layer is Aeris IoT Watchtower, and this is the part competitors genuinely cannot quote. Watchtower is agentless, meaning nothing gets installed on the device, which is the only approach that works for headless gear like cameras, terminals, and sensors that cannot run software. It sits in the connectivity layer and runs in line with the normal cellular data path at the SIM level, in two halves, with Watchtower Awareness giving you real-time visibility into every device and where its traffic is going, and Watchtower Enforcement applying zero-trust policy, anomaly detection, and blocking of malicious destinations right there in the mobile core, and it generates the audit-ready reporting that a 24-hour obligation makes survivable instead of theoretical. Put the two together and you get one device, one bill, and one pane of glass at a bundle price of $299 per site each month, all 3 carriers, the gateway, and the security platform included. The claim worth sitting with is that this often lands below what companies already pay for a single or dual-carrier solution that comes with no security at all.
THE PART THAT REFRAMES THE CATEGORY
Here is where I think it crosses from nice bundle into something that reframes the category. Most solutions solve one slice. A Cradlepoint solves connectivity and leaves you to bolt on security. A firewall vendor secures the LAN and never touches cellular. An SD-WAN box optimizes wired transport and stays blind to the SIM. Every one of them hands you a piece. This combines the pieces and closes the one gap none of them can reach, because it connects and protects what is inside the perimeter and then pulls every SIM-enabled device that used to live outside the perimeter, the cameras, the terminals, the sensors, the backup modems, onto the same monitored, policy-controlled network. For the first time you can see and secure all of it across 3 carrier networks from a single platform. The devices that were invisible become the devices you are watching, and that is not a feature, that is the blind spot disappearing.
THE HONEST SCORECARD
Because this should not read like a sales sheet, here is what a buyer ought to press on. Cellular data economics still deserve scrutiny at very high-bandwidth sites, since unlimited always has fine print. Multi-carrier failover is resilience, not link bonding, so latency-critical or throughput-heavy workloads still need a hard look. And any agentless, network-layer security model should be tested against your own threat model rather than taken on faith. No product hands you a compliance certificate either, the CRA obligations sit with manufacturers, importers, and distributors, and you still own your program. Ask the hard questions. But weigh all of that against what it replaces, which is 3 vendors, a widening security gap, a rising hardware bill, and a compliance clock that is already ticking, and for distributed, device-heavy, multi-site operations like retail, quick service, healthcare, banking, logistics, and the public sector, the convergence story holds up under scrutiny in a way most revolutionary pitches never do. For MSPs, MSSPs, and TSDs the takeaway is even simpler. This is a faster sales cycle wrapped around a differentiator your competitors literally cannot put on a quote, cellular-layer security, with recurring and sticky economics underneath it.
THE BOTTOM LINE
The FSB did not need a masterpiece, they needed one device nobody was watching, and most enterprises have hundreds of those humming along on cellular right now. The market is moving to the cellular edge whether the industry is ready or not, and the only real question left is who is watching that edge when it does. So, it is worth asking out loud, what is living on your cellular network right now that your firewall has never seen, because that is the conversation worth having this quarter.
If your cellular fleet is a blind spot, that is exactly the gap MergeWiFi and Aeris IoT Watchtower were built to close. Happy to compare notes. See how it works: https://www.aeris.com/partner-ecosystem/