The challenge behind the engagement.
Architecture design is for environments not yet built, where the account structure, network, and identity model can still be chosen. Workshops pin down data classification, regulatory boundaries, the workloads involved, how people and systems sign in, and how the cloud connects to anything on-premises. We then design the environment from a proven reference architecture: the account and environment hierarchy, the network and how traffic is segmented and inspected, federated sign-in for your workforce, and short-lived workload identities in place of static keys. Finally we fix where preventive, detective, and pipeline controls sit. You receive diagrams, a design decision record, a control placement map, a draft guardrail set, and a build plan with acceptance checks that tie back to the controls the environment must meet.
For engineering and security leaders standing up a first cloud environment or moving a regulated workload into the cloud. Also for teams replacing an account structure that grew without a plan. Typical trigger: a new product line, a FedRAMP or CMMC boundary to define, or an approved migration budget.
What we do.
What you can use.
Run requirements workshops
We meet with your security, platform, networking, identity, and compliance owners. Workshops capture data classification, regulatory boundaries, the workloads and environments, how people and systems sign in, on-premises links, and who owns the platform versus the workloads. Existing diagrams, data flows, and obligations come in as inputs. No production access is needed.
Draft the blueprint and control placement
We work from a proven reference architecture and draft the hierarchy, network, identity, logging, and key-management designs, placing each control where it belongs: across the whole organization, within an account, or in the delivery pipeline. The result is reviewed against the provider's security framework and against a zero trust model where that is a goal.
Hand over a buildable design
You receive target architecture diagrams and a design decision record that names the alternatives we rejected and why. The control placement map ties to the benchmark and to any regulatory control catalog you must satisfy. A draft guardrail set, a build backlog with acceptance checks, and a risk register complete the pack. The build accelerator is chosen and tailored with you.
Who it’s for.
When you need it.
- Engineering and security leaders standing up a first cloud environment from scratch
- Teams replacing an account or environment structure that grew without a plan
- Organizations moving regulated data, such as controlled or health information, into the cloud
- Product groups that need a repeatable environment template before workloads multiply
- A new product line or business unit needs its own cloud footprint
- A regulatory boundary, such as a FedRAMP or CMMC scope, must be defined
- A migration budget was approved and the target architecture is not yet chosen
- The current structure blocks segmentation, and rebuilding cleanly is now on the table
What the scope can include.
- 01
Requirements workshops on data classification, regulatory boundaries, workloads, sign-in, and platform versus workload ownership
- 02
Resource hierarchy design: how accounts and environments are separated so each workload sits in the right boundary
- 03
Network design: segmentation, egress inspection, name resolution, and private connectivity to provider services
- 04
Identity boundaries: federated workforce sign-in, break-glass accounts, and short-lived workload identity instead of static keys
- 05
Control placement: preventive across the organization, detective per account, pipeline enforcement, and a segregated log archive
- 06
Build accelerator selection and tailoring so the environment can be stood up repeatably and consistently
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
One new environment for a few applications in a single region
About 40–80 hoursMulti-account design with a link back to your office or data center
About 100–160 hoursRegulated or multi-region environment, such as a CMMC or FedRAMP boundary
About 180–300 hours- Number of workloads and environments to design for
- Whether a regulatory boundary must be defined and documented
- Connections to on-premises systems or other clouds
- Number of requirements workshops and stakeholder groups
2–4 weeks for a small design; 6–12 weeks when a regulatory boundary or hybrid connectivity is involved
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Target architecture diagrams covering hierarchy, network, identity, logging, and key management
- Design decision record with the rejected alternatives and the reason each was set aside
- Control placement map tied to the chosen benchmark and to any regulatory control catalog you must satisfy
- Build plan with acceptance checks tied to controls, a draft guardrail set, and a risk register
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Should we start from a provider accelerator or build the environment ourselves?
Start from the provider's accelerator unless you have a reason not to. The accelerators encode the reference architecture, ship with guardrails already written, and are what the providers test against. We tailor rather than replace: adding the boundaries your regulatory scope needs, tightening the default guardrails, and wiring in how your people sign in. Building from scratch makes sense only when an accelerator conflicts with an existing environment you cannot rebuild, and the design decision record will say so.
Will this design hold up for FedRAMP or CMMC?
We design the boundary, hierarchy, logging, and key management with those programs in view, and the control placement map ties each control to the catalog your documentation will cite. What we cannot do is decide the outcome. Authorization belongs to the sponsoring agency and its independent assessor, and a CMMC assessment belongs to an independent assessor who did not help build the environment. A design engagement usually runs a few weeks of workshops and drafting, longer where regulated data or several providers are in scope.
- CIS Critical Security Controls Version 8.1
- CIS Amazon Web Services Benchmarks
- Security Pillar - AWS Well-Architected Framework
- The AWS Security Reference Architecture
- Overview of the Microsoft cloud security benchmark v2 (preview)
- What is an Azure landing zone? - Cloud Adoption Framework
- Enterprise foundations blueprint | Cloud Architecture Center
