---
title: Landing Zones
description: Landing Zones define the secure and governed cloud baseline and must start early to enable migration waves without delivery blockers.
hero:
  tagline: Landing Zones establish the cloud foundation for governance, security, networking, and automation before migration waves begin.
  illustration:
    name: product
    position: left
sidebar:
  label: Overview
  order: 0
source_url: "https://framework.stackit.cloud/migration/design-and-mobilize/landing-zones/overview/"
source_file: "docs/migration/design-and-mobilize/landing-zones/overview.mdx"
---

## Understanding Landing Zones

A landing zone is the structured cloud foundation that defines how your organization operates on
STACKIT from day 1. It combines governance, identity, security, network design, cost controls,
and automation into one coherent baseline.

Without this foundation, migration waves typically stall due to missing approvals, inconsistent
controls, and repeated platform decisions.

## Core components

The following visual summarizes the core components that should be addressed for a reliable
platform baseline.

<div
  style="max-width:1680px;overflow:hidden;border-radius:12px;"
  set:html={landingZoneCoreComponentsMapEn}
></div>

### Why you need a landing zone

- **Control and risk reduction**: Enforce security and compliance controls consistently across teams.
- **Scalable delivery baseline**: Enable repeatable provisioning patterns for multiple migration waves.
- **Clear responsibilities**: Define ownership boundaries for platform, security, and application teams.
- **Faster migration throughput**: Avoid redesigning core controls for each application move.

### When to start

Start the landing-zone stream as early as possible, in parallel with discovery.

- **Too late**: Productive migrations are blocked because mandatory controls are not yet available.
- **Too early without discovery feedback**: Application constraints are missed and later cause rework.

The practical model is a dual track: establish the platform baseline early, then refine
application landing zone templates as discovery insights mature.

### Two layers: Platform and Application Landing Zones

<CardGrid>
    <Card title="Platform Landing Zone">
        Company-wide foundation for governance, identity, security, networking, cost controls, and automation.

        <LinkChip href="/migration/design-and-mobilize/landing-zones/platform-landing-zone/">Open Platform Landing Zone</LinkChip>
    </Card>
    <Card title="Application Landing Zone">
        Workload-specific implementation patterns derived from the platform baseline and discovery findings.

        <LinkChip href="/migration/design-and-mobilize/landing-zones/application-landing-zone/">Open Application Landing Zone</LinkChip>
    </Card>

</CardGrid>

## Typical enterprise inputs

To design a landing zone effectively, enterprises usually provide:

- **Organization and ownership model**: Entities, project boundaries, and accountability model.
- **Compliance and policy requirements**: Regulatory obligations and internal control policies.
- **Security requirements**: IAM standards, network segmentation, encryption, and logging expectations.
- **Operations and support constraints**: Incident handling, escalation paths, and handover model.
- **Application portfolio insights**: Discovery findings about workload archetypes and dependencies.

## Delivery model

<Steps>

1. Define enterprise guardrails and target control model.
2. Build and validate the platform landing zone baseline as code.
3. Derive application landing zone templates from discovery and migration design.
4. Pilot with selected workloads, then scale through migration factory runbooks.

</Steps>

## STACKIT acceleration assets

To accelerate delivery, STACKIT provides concrete best practices and reusable templates:

<ScfAssetLoader
  showFilter={false}
  showSearch={false}
  frameworkSlug="migration"
  filterByTag="landing-zone"
/>
