Home  /  Journal  /  What an OCI Migration Really Costs  /  What a Production Landing Zone Costs
Migration Cost and Assessment

What a Production Landing Zone Costs to Build

The landing zone is the first real line on any honest OCI migration budget and the one most often shrunk to make a quote look good. Skimp on it and every workload that follows pays interest: rework, security findings, network redesigns under pressure. Gold plate it and you spend six months building governance for workloads that have not arrived. Here is what the build actually involves, what it costs at three levels of ambition, and how to scope it.

Published Jun 6, 2026 · By Fredrik Filipsson · 11 min read · Independent OCI advisory
Construction site with tower cranes against the sky

Every OCI migration quote contains a line near the top that says something like foundation build or platform setup, and the number next to it varies by a factor of ten between bidders. The variance is not dishonesty, it is scope: one bidder means a compartment tree and a VCN, another means a full enterprise foundation with federated identity, hub and spoke networking, a security baseline mapped to a compliance framework, and everything expressed as Terraform under version control. Both call it a landing zone. Until you know which one you are buying, the quotes cannot be compared, and until you know which one you need, neither bidder can be right.

This article is part of our series on what an OCI migration really costs, and it unpacks the foundation line: what a production landing zone contains, where the effort actually goes, what the realistic ranges look like at three tiers of ambition, and how to scope the build so you pay for the governance your estate needs rather than the governance someone enjoys building.

What a landing zone actually is

A landing zone is the set of decisions and infrastructure that exist before the first workload arrives: who can do what, where things go, how traffic flows, what gets logged, and how all of it is created and changed. In OCI terms that means the tenancy structure and compartment hierarchy, identity federation and IAM policy, the virtual cloud network design with its gateways and routing, the security baseline including Cloud Guard and logging, the tagging and budget scaffolding that makes spend attributable, and the infrastructure as code that builds all of the above repeatably. It is not a data center replica and it is not a single VCN with an open security list. It is the difference between an estate and a pile of resources.

The reason it belongs early in the budget conversation is that every workload inherits it. A weak foundation taxes every migration wave with rework and every operations year with incidents. A sound one is invisible, which is why it is chronically undervalued by people who have not yet lived without it.

Where the effort actually goes

Identity and compartments

Federating OCI identity with the corporate directory, designing groups and policy statements, and shaping the compartment tree around how the organization budgets and operates. The technical work is days; the decisions are weeks, because compartment design encodes questions about team boundaries and cost ownership that organizations have usually never answered explicitly. Getting this wrong is expensive precisely because compartments are hard to restructure once workloads live in them.

Network

The largest single block of effort in most builds. Hub and spoke design with a DRG at the center, IP address planning that respects the existing corporate scheme, FastConnect or VPN back to on premises, DNS strategy across environments, and the routing and security rules that govern every flow. Network mistakes are the ones migrations discover at cutover, which is why this block deserves senior hands and a design review, not a template applied at speed.

Security baseline

Cloud Guard configuration, security zones where they fit, vault and key management strategy, logging turned on everywhere it matters and shipped somewhere it can be searched, and the IAM policy review that closes the gap between what was granted to make things work and what should survive an audit. For regulated estates, add the mapping of all of this to the control framework the auditors will bring.

Infrastructure as code

Expressing the whole foundation as Terraform, wiring it into a pipeline, and establishing the discipline that changes go through code rather than the console. This is the block most often cut when budgets squeeze, and the cut is invisible for six months until the estate has drifted into a state nobody can reproduce. Oracle publishes open source landing zone templates that give this block a real head start, which is part of why accelerators matter to the economics, covered below.

Observability and operations scaffolding

Monitoring defaults, alarm topics and notification plumbing, budgets and cost alerts, tagging defaults enforced at compartment level, and the runbook skeletons the operations team will fill in. Thin but essential: an estate that goes live without it operates blind for its first quarter.

Three tiers, three budgets

Most builds land in one of three tiers, and naming the tier is the fastest way to make competing quotes comparable.

TierScopeTypical effortElapsed time
FoundationCompartment tree, federated identity, single region hub and spoke VCN, Cloud Guard defaults, core logging, Terraform for all of it15 to 30 consulting days3 to 5 weeks
EnterpriseFoundation tier plus FastConnect, multi environment network segmentation, vault and key strategy, tagging and budget governance, CI pipeline for the IaC, operations runbooks40 to 70 consulting days6 to 10 weeks
RegulatedEnterprise tier plus control framework mapping, security zones, dual region design for disaster recovery, evidence automation, formal design authority review cycles80 to 130 consulting days10 to 16 weeks

Two notes on reading the table honestly. First, the OCI consumption cost of a landing zone is minor, gateways, logging storage, a bastion, monitoring, typically a few hundred to a couple of thousand per month before workloads arrive; the build cost is almost entirely people. Second, elapsed time is rarely gated by engineering. It is gated by decisions: address space sign off, security review queues, change boards. A four week build inside a twelve week approval cycle is a twelve week project, and the budget should say so.

The landing zone is almost entirely a people cost. The cloud bill for an empty foundation is pocket change; the decisions are what you are paying for.

Accelerators change the slope, not the destination

Oracle maintains open source landing zone frameworks, including CIS benchmarked Terraform modules, and the temptation is to read them as the build for free. They are better understood as a discount on the typing. The modules deploy a sound generic structure in days, but they do not know your address plan, your identity provider quirks, your compartment politics, or your auditors. In practice accelerators reliably remove a third to a half of the engineering effort at Foundation and Enterprise tier, and rather less at Regulated tier where the effort lives in mapping and evidence, not deployment. What they remove entirely is the blank page, which is worth having. What they cannot remove is the decision load, which is where a partner who has made these decisions across 500+ engagements earns the fee: not by typing Terraform faster but by collapsing weeks of deliberation into days of recommendation.

The costs people forget

Three lines belong in the landing zone budget and rarely appear in it. The first is decision facilitation: the workshops, written options papers, and review cycles that get network and compartment designs signed. The second is the first wave shakeout: however good the build, the first production workloads will find gaps, a missing route, a policy too tight, an alarm threshold that pages at 3am for nothing, and a sensible budget reserves ten to fifteen percent of build effort for the weeks either side of first landing. This is also why the first migration wave should be small and forgiving, a point we develop in wave planning economics. The third is documentation and handover: the foundation outlives the project team, and an undocumented landing zone becomes archaeology within a year.

It is also worth scoping what the landing zone deliberately excludes. Workload architecture, database platform selection, and application level security belong to the waves that bring those workloads, and the inventory that drives all of it should already exist from the assessment, where our 40 point assessment checklist does the heavy lifting. A landing zone build that drifts into workload design has lost its scope discipline and its budget will follow.

Where the landing zone meets the migration schedule

The foundation build sits on the critical path of the entire program, and its scheduling interaction with the waves is worth money in both directions. Built too late, it stalls the first wave and burns migration team availability waiting for an environment to land in. Built too early in full Regulated splendor, it consumes budget governing an empty tenancy while the workload inventory was still being argued. The pattern that works is deliberate overlap: start the landing zone build alongside the late stages of assessment, target readiness two to three weeks before wave one's entry gate, and let the long lead items, FastConnect circuits, identity federation approvals, address space sign off, start earliest of all because their calendars belong to other people. Teams that sequence this way buy their foundation with time that would otherwise have been spent waiting, which is the cheapest funding any build will ever get.

The foundation also needs a review rhythm written into its budget from day one. Landing zones are built against the estate as imagined during assessment, and the estate as it actually grows always diverges: new workload classes arrive, a compliance scope expands, a team structure changes and takes the compartment logic with it. A lightweight quarterly review, an afternoon of drift checks, policy tidying, and a look at whether the tagging and budget scaffolding still matches how money is actually being spent, costs a few days a year and prevents the slow decay that turns a clean foundation into next year's remediation project. Estates that skip the rhythm do not save the money; they defer it at interest, and the interest compounds in the least visible part of the bill.

A framework for scoping the build

Run this sequence before asking anyone for a foundation quote, and the quotes that come back will finally be comparable.

  1. Name the tier. Foundation, Enterprise, or Regulated, based on what the first year of workloads actually requires, not on ambition. You can grow a Foundation into an Enterprise later; you cannot refund gold plating.
  2. Inventory the decisions, not just the tasks. List what must be decided: address space, identity source, compartment shape, environment count, connectivity model, compliance scope. Assign each a decider and a date, because these gate the calendar.
  3. Fix the address plan first. IP space conflicts with on premises networks are the single most common source of landing zone rework. Get network architecture sign off before any VCN is created.
  4. Decide the accelerator posture. Adopt the open source modules as a base and budget for adaptation, or build bespoke and budget for the full slope. Either is defensible; pretending the modules are free is not.
  5. Insist on infrastructure as code as a deliverable. The contract should hand over a repository and a pipeline, not a tenancy full of console clicks. Verify this in acceptance criteria.
  6. Reserve the shakeout budget. Ten to fifteen percent of build effort, held for the first workload wave, spent on fixing what contact with reality reveals.
  7. Define done in operational terms. The landing zone is finished when a workload team can request an environment and receive it through the pipeline with policy, network, logging, and budget attribution already in place. Anything less is a partial build wearing a finished label.

Buying the build

The landing zone is the most quotable piece of an OCI program: scope is definable, deliverables are concrete, and done can be written down, which makes it natural fixed fee territory. That is how we price it inside an OCI implementation engagement, a fixed project fee against a named tier with the decision load carried by people who have shaped these foundations across 500+ engagements and 20+ years of combined Oracle experience. After first landing, the foundation needs tending rather than building, drift watched, policies evolved, costs attributed, which is where a managed monthly retainer takes over, backed by 24/7/365 monitoring. And for estates whose foundation was built thin and is now taxing every workload on it, an optimization engagement on a percentage of verified savings basis frequently starts by paying down exactly this debt; teams routinely find that the foundation fixes are where the first tranche of the 40% average spend reduction comes from.

The landing zone line on a quote deserves more scrutiny than any number twice its size elsewhere on the page, because every other number stands on it. Name the tier, gate the decisions, demand the code, reserve the shakeout, and the foundation becomes what it should be: the cheapest insurance the migration will ever buy.

Free white paper

Go deeper on this topic with The OCI Landing Zone and Architecture Guide, a reference architecture for security, networking, and governance on OCI. An independent analyst style report with comparison tables and recommendations, free with a work email. Prefer a monthly summary instead? The OCI Brief delivers one practical OCI briefing a month.

Part of a series
This guide is part of OCI Cost & Licensing — our complete pillar guide on the topic.

About the author

Fredrik Filipsson, Co-founder of OCI Specialists — 20 years of enterprise IT experience in Oracle Database, OCI cost optimization, licensing, and data platforms. Full profile · LinkedIn

Moving Oracle workloads to OCI, or already running on OCI and not sure the architecture or the spend is right? Most teams bring in a specialist before they commit to a region, a shape, or a Universal Credits number. OCISpecialists.com plans the landing zone, runs the migration, and manages the estate after go live, on a fixed project fee, a managed monthly retainer, or a cost optimization fee paid only on verified savings.