Overview
WEI Landing Zone Accelerator
WEI Landing Zone Accelerator
WEI Landing Zone Accelerator helps organizations establish a secure, repeatable cloud foundation before they migrate, modernize, or build workloads on AWS. The engagement combines enterprise architecture, cloud governance, security engineering, networking, automation, and operational design to deliver a multi-account AWS environment aligned to your business objectives, risk posture, compliance obligations, and operating model.
What Is a Landing Zone?
A landing zone is more than a collection of AWS accounts. It is the standardized platform that enables teams to provision, govern, monitor, secure, and operate workloads consistently at scale. WEI designs the foundation around your specific requirements for account governance, identity, networking, centralized logging, security operations, policy controls, workload onboarding, and ongoing platform ownership.
Implementation Paths
WEI implements the landing zone using one of two primary paths, selected during discovery and design:
-
AWS Landing Zone Accelerator on AWS (LZA): An AWS solution built on AWS CDK and configuration files, designed to extend AWS Control Tower with additional governance, security, networking, compliance, and account-vending capabilities. WEI deploys or enhances AWS Control Tower as the foundational multi-account service and configures LZA on top of it, managing the environment as code.
-
Terraform: For customers with an established Terraform standard, existing modules, repositories, and CI/CD workflows, WEI designs and implements the landing zone using Terraform, preserving your existing DevOps and platform-engineering practices.
Security and Compliance
WEI configures AWS-native security services including AWS Security Hub, Amazon GuardDuty, AWS Config rules, Service Control Policies (SCPs), and centralized logging via AWS CloudTrail and Amazon CloudWatch. Encryption is managed through AWS KMS with customer-managed keys. These controls support organizations operating under compliance frameworks such as HIPAA, PCI DSS, SOC 2, and FedRAMP, with configurations tailored to your specific regulatory requirements.
Typical Engagement Flow
Engagements follow a structured methodology:
- Discovery and Design - Requirements gathering, architecture decisions, implementation-path selection, and scoping
- Build and Deploy - Account structure provisioning, networking, identity integration, security baseline deployment, and CI/CD pipeline configuration
- Validate and Handoff - Testing, documentation walkthroughs, operational runbooks, and knowledge transfer
Key Deliverables:
- Architecture decision document and account-structure diagram
- Deployed AWS Control Tower/LZA environment or Terraform-based foundation
- Security baseline with configured guardrails and detective controls
- Operational runbooks and platform evolution roadmap
- IaC repositories with CI/CD pipeline integration
Use Case Example
A regulated financial services organization preparing for its first production workload on AWS engaged WEI to design a multi-account foundation with centralized logging, network segmentation, and compliance-aligned security controls - enabling their application teams to begin deploying workloads on a governed platform rather than building ad hoc infrastructure.
Getting Started
To begin, schedule a discovery call with WEI. During this initial conversation, a named WEI engagement lead will assess your current environment, compliance requirements, and platform-engineering preferences to determine the right implementation path and scope for your organization.
The result is a documented, operationally sustainable cloud foundation that gives application and infrastructure teams a safer, faster path to deploy workloads on AWS while preserving your ability to manage and evolve the platform over time.
Highlights
- Deploy a secure, governed AWS multi-account foundation with AWS Security Hub, GuardDuty, Config rules, Service Control Policies, centralized logging, KMS encryption, and identity integration - configured to support compliance frameworks such as HIPAA, PCI DSS, SOC 2, and FedRAMP based on your regulatory requirements.
- Choose your implementation path: AWS Landing Zone Accelerator on AWS (CDK-based, extending Control Tower) or Terraform - selected during a structured discovery phase based on your existing platform standards, DevOps workflows, and operating model, so the foundation integrates with how your teams already work.
- Receive a complete set of engagement deliverables including architecture decision documents, account-structure diagrams, deployed environment, operational runbooks, IaC repositories with CI/CD integration, and a platform evolution roadmap - giving your teams a governed, repeatable path to onboard workloads at scale.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
Engagement Support
WEI provides support through email, scheduled working sessions, architecture reviews, and project-status meetings during standard business hours (Eastern Time, Monday through Friday). Each customer receives a named WEI engagement lead who serves as the primary point of contact and escalation path throughout the engagement.
Support Contact
Issues or questions can be raised through the designated WEI contact provided in the Statement of Work or via the WEI contact details on https://www.wei.com/aws/#awsContact . Ongoing operational or managed services support beyond the engagement can be scoped as a separate offering and transacted through AWS Marketplace private offers.
Engagement Phases
Discovery and Design: Requirements gathering, stakeholder interviews, architecture decisions, implementation-path selection, and statement of work finalization. Deliverables include architecture decision document and account-structure diagram.
Build and Deploy: Account provisioning, networking, identity integration, security baseline deployment, and CI/CD pipeline configuration. Deliverables include deployed environment and IaC repositories.
Validate and Handoff: Testing, documentation walkthroughs, operational runbook delivery, knowledge transfer sessions, and platform evolution roadmap.
Buyer Responsibilities
During the engagement, your organization should provide access to stakeholders for architecture decisions, an identity or security team representative for integration requirements, and a platform or DevOps engineer to participate in knowledge transfer.