CloudCompliance

AWS landing zone for compliance

A landing zone is the account structure, identity, logging and guardrails every new AWS account inherits. Build it before the audit window opens and most cloud controls exist before anyone asks.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

A compliant AWS landing zone is an AWS Organization with separate accounts for management, security tooling, log archive, production and non-production; IAM Identity Center federated to your identity provider; an organization CloudTrail trail and AWS Config in every account; and SCPs that stop anyone disabling those or working outside approved regions. Control Tower builds this in a day. A hand-built version takes longer and gives more control.

Control Tower or hand-built?

Landing zone approaches on AWS
ApproachGood forTrade-off
AWS Control TowerMost companies starting fresh or with a few accountsOpinionated; some customisation needs Customizations for Control Tower or Account Factory for Terraform
Hand-built with Organizations and TerraformTeams with strong IaC practice and specific needsYou maintain every guardrail and account template
Landing Zone Accelerator on AWSRegulated workloads needing a larger baselineHeavier than a small SaaS company needs

For a first SOC 2 at a company with fewer than ten accounts, Control Tower is the right default. It sets up the log archive and audit accounts, enables CloudTrail and Config, and applies preventive and detective controls you can point an auditor at.

Organizational units

Security
Log archive and security tooling accounts. Tightest access.
Infrastructure
Shared networking, DNS, CI/CD tooling if centralized.
Workloads, production
Customer-facing accounts. Strictest SCPs, smallest access group.
Workloads, non-production
Development and staging. Broader access, no customer data.
Sandbox
Optional experimentation, with a budget limit and no connectivity to production.

SCPs that matter for an audit

  • Deny stopping, deleting or modifying the organization CloudTrail trail.
  • Deny disabling AWS Config, GuardDuty or Security Hub.
  • Deny actions outside ca-central-1 and ca-west-1, with exceptions for global services, if you have committed to Canadian residency.
  • Deny creating IAM users and access keys, except for a named break-glass path.
  • Deny leaving the organization.
  • Deny making S3 buckets public at the account level through S3 Block Public Access settings.

SCPs are preventive controls, which auditors weigh above detective ones. Keep them in version control so changes carry an approval record.

When to build it

Before a Type 2 observation window opens. Moving production between accounts or changing identity during the window creates a period in which controls changed, which the auditor has to report or you have to explain. If the window is already open, add guardrails and logging now and schedule structural moves for after the period ends.

Is Control Tower required for SOC 2?

No. SOC 2 does not name any AWS service. Control Tower is a fast way to build the account separation, logging and guardrails that auditors expect to see.

Can we add Control Tower to an existing AWS Organization?

Yes. Control Tower can be set up in an existing organization and existing accounts enrolled. Check for conflicting SCPs, existing trails and Config recorders first, because enrolment will change them.

What does an AWS landing zone cost to set up?

Consulting help typically costs $8,000 to $30,000 CAD depending on how many accounts exist and whether production has to move. AWS charges for the underlying services, such as Config and CloudTrail, not for Control Tower itself.

Want a landing zone built before the audit?

Firms in the network build and document AWS landing zones for Canadian companies.

Get matched