A good fit if
- You are starting on Google Cloud, or moving onto it, and want the base right before workloads land.
- You already run on Google Cloud but projects were created by hand and nobody is sure what the policies are.
- You need an environment you can show an auditor or a security team.
Probably not a fit if
- You need a single project for a proof of concept. A landing zone is more than that needs.
Deliverables, not effort.
The base module covers the organisation, identity and policy layer. Networking and VPC Service Controls are separate modules, priced below.
Organisation hierarchy
Folders, projects and environments structured around how your teams and workloads are actually organised, with naming and labelling conventions.
Identity and access
Federation with your identity provider, groups mapped to roles, and break glass access documented and tested.
Organisation policy and guardrails
Organisation policies that stop the common misconfigurations before they happen, applied at the right level of the hierarchy.
Logging and audit
Central audit and log sinks, with retention set to what you need to keep.
Billing and cost visibility
Billing export, budgets and alerts, with costs attributable to the team or workload that incurs them.
Terraform and a pipeline
Every piece in Terraform in your repositories, with a deployment pipeline, so the next change goes through review rather than the console.
Pay for the modules you need.
Foundations
Always includedOrganisation hierarchy, identity, policy and guardrails, logging, billing and the Terraform pipeline.
A$45,000
Networking
OptionalShared VPC, subnets and firewall policy, Cloud NAT and private access, and connectivity to on premises or other clouds over VPN or Interconnect.
+ A$25,000
VPC Service Controls
OptionalService perimeters around sensitive data services, run in dry run mode first so nothing legitimate breaks when they are enforced.
+ A$20,000
Floors for scoping, not a quote. The price for your organisation is fixed in writing at scoping.
No surprises on the way.
The date is fixed at scoping, once we know the hierarchy and modules involved.
- Scoping
Decisions and a date
We work through the design decisions with you, confirm the modules, and fix the price and the delivery date in writing.
- Design
A written design
A short design record covering the hierarchy, identity, policy and any network choices, reviewed with your team before anything is built.
- Build
Built in your repositories
We build in Terraform in your repositories and your organisation, with your engineers able to review every change as it lands.
- Handover
Your team runs it
A walkthrough with the engineers who will own it, and documentation for adding the next project, team or environment.
Not included
- Migrating or deploying workloads into the landing zone. See the migration offer for that.
- Ongoing operation after handover.
- Google Cloud usage, Interconnect circuits and third party licences.
What we need from you
- An owner with authority over the Google Cloud organisation and billing account.
- Administrator access to your identity provider for federation.
- Time from security and networking contacts during design.
Questions we get asked
We already have projects on Google Cloud. Can you work with that?
Yes. Scoping covers what exists today and how it moves into the new hierarchy. Moving existing projects is planned so running workloads are not interrupted.
Why is the date set at scoping rather than published?
The date depends on the modules, the size of the hierarchy and how quickly identity and network decisions can be made on your side. We fix it in writing once we know those, and hold to it.
Do we need the networking module?
If your workloads need private networking, shared VPCs or connectivity back to an office, data centre or another cloud, yes. Serverless workloads with no private connectivity often do not.
Does it meet our compliance requirements?
Tell us at scoping which framework you report against, for example APRA CPS 234 or ISO 27001, and the design will reference the relevant controls. The landing zone supports compliance; it does not replace your own assessment.
Fixed price, fixed date, before you sign.
Rapid MVP
4 weeks
A$16,000
Agent MVP
2 weeks
A$25,000
AWS or Azure Migration
Set after assessment
Funded
Managed SRE and Agentic SOC
Ongoing
From A$5,000 / month
Prices are set in AUD; other currencies are fixed conversions as at 15 September 2026, shown for guidance, with the contracted currency confirmed before you sign.
Talk to an architect who has done this before.
Bring your current setup and the outcome you need. You will get a view on the approach, the risks and roughly what it costs.
Straight to a senior GCP architect. No SDR, no slide deck.
Not ready to talk? See how we migrated Hapana off AWS →
Or call +61 2 8359 9507 · Hello@aviato.consulting