Four-Phase CCoE Rollout
Last updated on
The CCoE develops — in four phases
Section titled “The CCoE develops — in four phases”A CCoE does not become fully operational on day 1. It goes through four maturity phases, each with different priorities and different success signals.
Phase 1: Foundation (Months 1–3)
Section titled “Phase 1: Foundation (Months 1–3)”Focus: Build the team, establish the mandate, set first standards
What happens:
- CCoE core team recruited and released from other duties (minimum 4 FTE)
- Charter adopted and communicated
- First technical decisions made: IaC toolchain (Terraform + STACKIT Provider), Git workflow, CI/CD principles
- STACKIT accounts and organisational structure created
- First guardrails implemented as policy-as-code (geo-restriction, mandatory tags, encryption)
- Track A training started for all IT staff
What good progress looks like:
- Charter is signed ✓
- STACKIT organisational structure in place ✓
- 3 core guardrails implemented and tested ✓
- CCoE team at full strength ✓
- Track A running for all IT staff ✓
Warning signs:
- Charter signing delayed by >6 weeks → mandate problem, not a technology problem
- Team cannot be staffed → rethink recruitment strategy, bring in a partner
- Guardrails are blocking every deployment → too restrictive, calibration needed
Phase 2: Foundations (Months 4–8)
Section titled “Phase 2: Foundations (Months 4–8)”Focus: Build the landing zone, onboard first workloads, activate FinOps
What happens:
- Landing zone fully deployed as Terraform code (hub-and-spoke network, IAM structure, centralised logging)
- First pilot team onboarded — 2–3 workloads migrated as lighthouse projects
- IaC module library starts (5–10 standard modules for common resource types)
- FinOps basics: tagging standard implemented, showback reports for first business units
- Cloud Champions nominated in first teams
- Track C/D training started for Platform Engineers and Architects
What good progress looks like:
- Landing zone fully deployed, all guardrails active ✓
- First workload team independently (with support) in the cloud ✓
- Tagging compliance >80 % for new resources ✓
- First showback reports delivered to business unit ✓
-
5 Terraform modules in the library ✓
Warning signs:
- Landing zone still not finished after 6 months → reduce scope, MVP first, then iterate
- Pilot team has been waiting weeks for CCoE approvals → decision processes too slow, build self-service
- FinOps tagging being ignored → escalate, harden the guardrail
Phase 3: Scale (Months 9–18)
Section titled “Phase 3: Scale (Months 9–18)”Focus: Migration waves, expand self-service, decentralise the CCoE
What happens:
- Migration waves 1–N: structured workload migration process
- Self-service catalogue: teams can deploy standard resources without CCoE tickets
- CCoE transitions from “operational support” to “enablement and governance”
- FinOps maturity increases: from showback to chargeback
- Communities of Practice (Cloud Guilds) are active and self-organised
- STACKIT advanced features are being used: Managed Kubernetes, Managed Databases
What good progress looks like:
- Teams deploy independently without CCoE tickets ✓
-
50 % of target workloads migrated ✓
- Guardrail compliance >99 % ✓
- Cloud costs within budget (±10 %) ✓
- CCoE spends <30 % of time on operational support ✓
Warning signs:
- CCoE is still an operational bottleneck → self-service not developed far enough
- Migration speed declining → resource bottleneck or technical hurdles — run a retrospective
- Costs rising uncontrolled → FinOps escalation, activate budget alerts
Phase 4: Institutionalisation (Month 18+)
Section titled “Phase 4: Institutionalisation (Month 18+)”Focus: Cloud is the norm, CCoE is an innovation driver
What happens:
- All target workloads migrated or consciously excluded
- CCoE focus shifts from migration to innovation: cloud-native modernisation, evaluating new STACKIT services
- FinOps fully operational: chargeback active, budget accuracy ±5 %
- Cloud competency embedded in breadth — no single point of failure in the CCoE
- Regular platform upgrades, Kubernetes version management, service evaluations
Signals that Phase 4 has been reached:
- New projects start automatically in the cloud — nobody asks whether on-premises is possible
- CCoE conducts proactive platform reviews without teams having to wait
- External audits confirm compliance without remediation work
- Business units ask the CCoE for new cloud capabilities, not just for help with problems
What is realistic after 12 months?
Section titled “What is realistic after 12 months?”A well-performing CCoE after 12 months:
- 60–80 % of target workloads migrated
- Landing zone stable, no unplanned guardrail exceptions
- 15–25 % cloud cost savings through FinOps optimisation realised
- 4–6 Cloud Guilds active, all technical teams have Cloud Champions
- CCoE spends >50 % of time on enablement and innovation
A dysfunctional CCoE after 12 months:
- CCoE is a migration bottleneck, teams are waiting for approvals
- Guardrails are being bypassed because they are too restrictive or too slow
- FinOps exists on paper but nobody looks at the costs
- Cloud knowledge is concentrated in 2–3 CCoE people
Practical steps
Section titled “Practical steps”- Define phase timeline with date targets for your transformation
- Agree phase-gate criteria for each phase transition with the CIO
- Monthly retrospective in the CCoE team: where are we in the phase, what is blocking, what should we accelerate?