Go live in AWS ESCIn 4 weeks.
The AWS European Sovereign Cloud (ESC) launched, a brand-new AWS partition where every organization starts from zero. With the NTC ESC Blueprint you skip 9 months of heavy lifting and go live in 4 weeks.
Build it yourself.
Ship it Monday.
The AWS ESC is a completely new AWS partition. No migration path. No existing accounts. Every organization starts at zero. We already finished the homework.
- Build everything from scratch
- Hire a cloud architecture team
- Trial-and-error security baselines
- Re-invent multi-account vending
- Compliance validation delays
- Pre-built, versioned, enterprise-grade modules
- Security & compliance baked in
- Multi-partition ready. Commercial, GovCloud, ESC.
- Account vending + security + connectivity out-of-the-box
- Start building applications on day one
What you actually get.
A multi-account landing zone, fully in your control. Every box below is a versioned Terraform / OpenTofu module you can tailor to your environment.

Organizations
Multi-account OU structure with SCPs and foundational guardrails.
View module docs →Account Factory
Automated account vending with customizable account baseline configuration.
View module docs →Identity Center
Centralized SSO via AWS IAM Identity Center. Federated access with permission sets and group-based assignments.
View module docs →Log Archive
Centralized CloudTrail, Config, GuardDuty, VPC Flow Logs. KMS-encrypted, audit-ready.
View module docs →Security Tooling
Security Hub, Config, GuardDuty, Inspector and IAM Access Analyzer, aggregated.
View module docs →Core Network
Transit Gateway, VPN, Direct Connect. Central VPCs with interface endpoints.
View module docs →Route53
Hosted zones and cross-account DNS resolvers. Centrally managed, delegated where needed.
View module docs →IPAM
Centralized IP plan with no CIDR overlaps. Hierarchical pools across partitions and accounts.
View module docs →VPC
Opinionated VPCs with subnets, route tables, and network configurations. Versioned.
View module docs →Compliant. Flexible. Proven.
Built by engineers who ship to regulated environments for a living. No magic. No vendor jail. The same modules running our customers' Swiss federal workloads run this page right now.
Up to 90% faster
9 months from scratch becomes 4 weeks with the Blueprint. Start building apps immediately.
Secure by default
SCPs, guardrails and AWS security best practices, pre-wired. Misconfigurations blocked before they ship.
Full control
Deployed in your environment. You own everything. We support; no lock-in.
Modular & flexible
Each module independently versioned. Use what you need; replace what you don't.
GitOps native
CI/CD from day one. Spacelift, Terraform Cloud, GitHub Actions, GitLab. Pick your poison.
Multi-partition ready
The easiest way to manage Commercial, GovCloud and ESC from one single codebase.
Built for teams that answer to regulators.
NTC powers production AWS landing zones across Swiss federal agencies and regulated enterprises. The kind of customers who don't ship without an audit trail.
on record.
NTC abstracts the complexity of infrastructure and allows us to focus on delivering business value.
MeteoSwiss






Three paths. One scales with you.
Control Tower and LZA are real options. They also have real limits: Control Tower is an abstracted AWS service that ceilings out fast on advanced requirements, and LZA is a monolithic CloudFormation solution with a wide blast radius. NTC is modular Terraform / OpenTofu, versioned per building block. Built to scale.
The honest answers.
Procurement, legal, and engineering arrive with the same questions.
01What is the license model?
02What does it cost?
03Do we get source code access?
04What happens if we stop the subscription?
05What support do you provide?
06How much can we customize?
07Does NTC support OpenTofu?
08Which AWS partitions does NTC support?
Need hands on deck?
Whether you need implementation support for NTC, application modernization, or workload migration to the AWS ESC, our certified system-integrator partners deliver.
tecRacer
AWS Premier Partner with deep expertise in cloud migrations, managed services, and infrastructure automation. Hands-on engineering teams that ship.
Partnership details →adesso SE
Certified AWS partner specializing in application modernization, cloud migration, and sovereign cloud implementations. Deep technical bench plus proven delivery methodologies.
Partnership details →Ship it.
Talk to the engineers who built the blueprint.
30-minute demo. We screen-share into a live ESC org and show you the modules we just talked about, running. No deck, no pitch, no pressure.