---
title: "Landing Zone"
description: "How to methodically design a cloud environment: decisions about structure, network, security boundaries, and operating standards — before the first workload moves in."
hero:
  tagline: "Building the Cloud Environment Correctly"
  illustration:
    name: product
    position: right
sidebar:
  order: 0
  label: "Overview"
hideLinkCard: true
source_url: "https://framework.stackit.cloud/adoption/landing-zone/"
source_file: "docs/adoption/landing-zone/index.mdx"
---

## Understanding Landing Zones

A landing zone is the structured cloud foundation that defines how your organization operates on
STACKIT from day 1. It combines governance, identity, security, network design, cost controls,
and automation into one coherent baseline.

Without this foundation, migration waves typically stall due to missing approvals, inconsistent
controls, and repeated platform decisions.

## Core components

The following visual summarizes the core components that should be addressed for a reliable
platform baseline. These six building blocks form a secure platform foundation:

- **Account Governance** — project structure, hierarchy, and ownership model
- **Identity & Access Management** — users, roles, and federated identity
- **Security & Compliance** — guardrails, policies, and compliance controls
- **Network Architecture** — segmentation, connectivity, and traffic control
- **Cost Management and Control** — tagging, budgets, and spend visibility
- **Automation (IaC)** — infrastructure as code, pipelines, and drift detection

<LinkCard
  title="For more information: Landing Zones Overview"
  description="Detailed guidance on platform and application landing zones, delivery model, and STACKIT acceleration assets."
  href="/migration/design-and-mobilize/landing-zones/overview/"
/>
