Listing Thumbnail

    Adamass AWS Landing Zone Foundation

     Info
    Sold by: Adamass 
    Design and deploy a well-architected, multi-account AWS foundation using AWS Control Tower and the Landing Zone Accelerator on AWS. For greenfield builds or for teams already running in production without account separation, guardrails, or a security baseline. Includes migration of existing workloads and a prioritized remediation backlog.

    Overview

    Overview

    Many teams reach production on AWS before the foundation is in place. Workloads end up in a single account with no organizational boundaries, security findings are scattered or switched off, backup and recovery were never designed in, and nobody owns cost. This service puts the foundation underneath what you have already built — or builds it correctly from the start.

    We assess your current state (or design the target state for a greenfield build) against the AWS Cloud Adoption Framework and the AWS Well-Architected Framework, then deploy a multi-account foundation using AWS Control Tower, the Landing Zone Accelerator on AWS, or a combination of the two, depending on how complex or regulated your environment is.

    What the foundation includes

    • Multi-account structure with organizational units in AWS Organizations
    • Centralized logging — AWS CloudTrail and AWS Config aggregation
    • Organization-wide security baseline — Amazon GuardDuty and AWS Security Hub
    • Centralized backup strategy using AWS Backup
    • Preventive guardrails via Service Control Policies
    • Centralized identity through AWS IAM Identity Center

    How we deliver

    1. Assess / design — current-state review against CAF and Well-Architected, or target-state design for a new environment. Output: a written findings and design document.
    2. Deploy — the landing zone is built with AWS Control Tower (managed, console-based) and/or the Landing Zone Accelerator on AWS (infrastructure-as-code, for complex or regulated needs).
    3. Migrate — existing workloads are moved into the new account structure with a planned, low-downtime cutover. Skipped for greenfield engagements.
    4. Hand over — architecture documentation, runbooks, and a prioritized remediation backlog. Not just a deployed stack.

    Who this is for

    Organizations running production workloads on AWS without account separation or a governance baseline; teams starting a migration to AWS who want the foundation right the first time; and organizations preparing for an audit or a security review.

    Scope options

    • Greenfield / migrate-to-AWS — fixed-scope engagement, quoted from the standard scope.
    • Existing AWS environment (retrofit) — scoped and quoted after the assessment, since the work depends on what is already deployed.

    Recommended next step

    Most customers pair this engagement with a block of senior architecture time for the weeks immediately after go-live, when the remediation backlog is being worked through. See "Adamass AWS Architect as a Service" — 40 hours of hands-on support, usable within two months of handover. It can be included in the same private offer as this engagement.

    AWS charges

    This service does not include your AWS infrastructure costs. Any AWS resources deployed into your account as part of the engagement are billed to you by AWS separately from this AWS Marketplace transaction.

    Access and permissions

    Delivery requires access to your AWS accounts, granted through an IAM role that you create and control, scoped to the permissions listed in the statement of work. No long-lived access keys are used, and access is revoked at the end of the engagement. Full details of the provisioned AWS services and the IAM policy statements are provided before work begins.

    Highlights

    • Multi-account foundation deployed with AWS Control Tower and or our Landing Zone Accelerator on AWS, assessed against the AWS Cloud Adoption Framework and Well-Architected Framework
    • Built for brownfield as well as greenfield, existing production workloads are migrated into the new account structure with a planned, low-downtime cutover
    • Handover includes documentation and a prioritized remediation backlog, plus optional bi-weekly security posture reviews after go-live

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    "Adamass AWS Architect as a Service" — 40 hours of hands-on support, usable within two months of handover. It can be included in the same private offer as this engagement.

    Other inquiries: aws@adamass.se