๐Ÿ—๏ธ Enterprise Cloud Assessment

Cloud Landing Zone Assessment

AI-powered review of your Azure, AWS or GCP environment against Cloud Adoption Framework, Well-Architected Framework and Control Tower. Get a scored report with architecture recommendations.

Request Access โ†’ See Sample Report
3
Clouds Supported
7
Assessment Domains
CAF
Framework Based
Free
Request Access

7 Domains Assessed

Every landing zone assessment covers these critical architecture domains.

๐Ÿข

Subscription / Account Structure

Management group hierarchy, account vending, subscription design, resource organisation and naming conventions.

๐ŸŒ

Network Architecture

Hub-spoke topology, VNet/VPC peering, ExpressRoute/Direct Connect, firewall placement, DNS and connectivity design.

๐Ÿ”‘

Identity & Access

Entra ID / IAM / Cloud Identity configuration, conditional access, PIM, MFA coverage and RBAC design.

๐Ÿ›ก๏ธ

Security & Governance

Azure Policy / SCPs / Org Policies, Defender/Security Hub/SCC, CSPM posture and compliance framework alignment.

๐Ÿ“Š

Operations & Monitoring

Log Analytics / CloudWatch / Cloud Logging, alerting, tagging strategy, cost management and BCDR posture.

๐Ÿค–

AI Landing Zone

Microsoft Fabric readiness, AI service governance, data platform architecture and responsible AI controls.

๐Ÿ“‹

Maturity Scoring

Overall landing zone maturity score (0-100) across all domains with P1/P2/P3 prioritised recommendations.

Framework Coverage

Assessment mapped to official cloud provider frameworks.

โ˜๏ธ Microsoft Azure

Azure Landing Zone (ALZ)

Cloud Adoption Framework (CAF), Well-Architected Framework (WAF), Azure Policy, Microsoft Entra ID, Defender for Cloud, Microsoft Fabric AI Landing Zone.

โ˜๏ธ Amazon AWS

AWS Control Tower

Landing Zone Accelerator, AWS Well-Architected Framework, AWS Organizations, Service Control Policies (SCPs), AWS Config, Security Hub, Transit Gateway.

โ˜๏ธ Google Cloud

GCP Cloud Foundation

Google Cloud CAF, Resource Hierarchy, VPC Service Controls, Cloud Identity, Shared VPC, Security Command Center, Landing Zone Blueprint.

Sample Maturity Score

Your assessment produces a score across 7 domains โ€” here's what a typical result looks like.

Overall Maturity Score
42 / 100
Developing โ€” Landing Zone Needed
๐Ÿ—๏ธ

Identity

35

Network

28

Security

50

Governance

20

Operations

45

AI Readiness

15

What You Get

A comprehensive report covering your full landing zone architecture.

MATURITY SCORE

Overall + per-domain scores (0-100) with maturity label and color coding

GAP ANALYSIS

Current state vs target state across all 7 domains with specific gaps identified

P1/P2/P3 RECOMMENDATIONS

Prioritised recommendations with effort, impact and CAF/WAF framework reference

ARCHITECTURE DIAGRAM

Proposed target landing zone architecture diagram (hub-spoke, management groups, security)

3-PHASE ROADMAP

Foundation โ†’ Security & Governance โ†’ Optimisation with timeline and deliverables

AI LZ ASSESSMENT

Microsoft Fabric / SageMaker / Vertex AI landing zone readiness and governance gaps

Request Access

This tool is currently in early access. Submit a request and our team will review within 24 hours.

๐Ÿ—๏ธ Request Landing Zone Access

Tell us about your environment and we'll get you access within 24 hours.

Frequently Asked Questions

What is a cloud landing zone?

A cloud landing zone is a pre-configured, secure and scalable cloud environment that serves as the foundation for all workloads. It includes subscription/account structure, identity management, network topology (hub-spoke), security controls, governance policies and monitoring. Azure calls this Azure Landing Zone (ALZ), AWS calls it Landing Zone Accelerator via Control Tower, and GCP calls it Cloud Foundation.

What does the assessment require from me?

You answer 15 questions about your current environment and optionally upload architecture diagrams, billing exports or network topology documents. The more context you provide, the more detailed the assessment. No sensitive credentials or access required.

How is this different from cloud provider native tools?

AWS Trusted Advisor, Azure Advisor and GCP Recommender focus on their own cloud. TCOIQ's assessment is cloud-agnostic, covers all 3 major clouds, and assesses holistically across identity, network, security, governance, operations and AI readiness โ€” not just cost or specific service recommendations.

Do I need an enterprise landing zone?

If you have more than 2-3 cloud accounts/subscriptions, multiple teams, compliance requirements, or production workloads โ€” yes. Without a landing zone, organisations typically face security gaps, inconsistent governance, network complexity and difficulty scaling.

Is the AI Landing Zone assessment included?

Yes. For Azure, we assess Microsoft Fabric readiness, Copilot/Azure OpenAI governance and AI landing zone design. For AWS, we assess SageMaker domains and AI service governance. For GCP, we assess Vertex AI and data platform architecture.