§ 01
AWS European Sovereign Cloud (ESC)
LIVE · eusc-de-east-1

Go live in AWS ESCIn 4 weeks.

The AWS European Sovereign Cloud (ESC) launched, a brand-new AWS partition where every organization starts from zero. With the NTC ESC Blueprint you skip 9 months of heavy lifting and go live in 4 weeks.

By NuvibitAWS ESC Launch PartnerISO 27001 certifiedSwiss made
§ 02
Without vs. With · 9 months to 4 weeks

Build it yourself.
Ship it Monday.

The AWS ESC is a completely new AWS partition. No migration path. No existing accounts. Every organization starts at zero. We already finished the homework.

A
Build from scratch
9 months · trial-and-error
  • Build everything from scratch
  • Hire a cloud architecture team
  • Trial-and-error security baselines
  • Re-invent multi-account vending
  • Compliance validation delays
B
NTC ESC Blueprint
4 weeks · production-ready
  • Pre-built, versioned, enterprise-grade modules
  • Security & compliance baked in
  • Multi-partition ready. Commercial, GovCloud, ESC.
  • Account vending + security + connectivity out-of-the-box
  • Start building applications on day one
§ 03
NTC ESC Blueprint · Multi-account landing zone

What you actually get.

A multi-account landing zone, fully in your control. Every box below is a versioned Terraform / OpenTofu module you can tailor to your environment.

NTC ESC Blueprint full architecture diagram

Use only what you need

The complete NTC library

Browse the full library →
§ 04
Why teams choose NTC

Compliant. Flexible. Proven.

Built by engineers who ship to regulated environments for a living. No magic. No vendor jail. The same modules running our customers' Swiss federal workloads run this page right now.

01

Up to 90% faster

9 months from scratch becomes 4 weeks with the Blueprint. Start building apps immediately.

02

Secure by default

SCPs, guardrails and AWS security best practices, pre-wired. Misconfigurations blocked before they ship.

03

Full control

Deployed in your environment. You own everything. We support; no lock-in.

04

Modular & flexible

Each module independently versioned. Use what you need; replace what you don't.

05

GitOps native

CI/CD from day one. Spacelift, Terraform Cloud, GitHub Actions, GitLab. Pick your poison.

06

Multi-partition ready

The easiest way to manage Commercial, GovCloud and ESC from one single codebase.

§ 05
In production at Swiss federal government & regulated enterprise

Built for teams that answer to regulators.

NTC powers production AWS landing zones across Swiss federal agencies and regulated enterprises. The kind of customers who don't ship without an audit trail.

on record.

NTC abstracts the complexity of infrastructure and allows us to focus on delivering business value.

MeteoSwiss

Federal Office for Customs and Border Security
Federal Office for the Environment
Federal Office for Meteorology and Climatology
Nuvibit is a trusted AWS partner of the Swiss federal government.
AWS Advanced Tier Services Partner
AWS Partner, Government Services Competency
ISO 27001, Information Security Management Certified
§ 06
NTC vs AWS Control Tower & Landing Zone Accelerator

Three paths. One scales with you.

Control Tower and LZA are real options. They also have real limits: Control Tower is an abstracted AWS service that ceilings out fast on advanced requirements, and LZA is a monolithic CloudFormation solution with a wide blast radius. NTC is modular Terraform / OpenTofu, versioned per building block. Built to scale.

Feature
AWS Control Tower
AWS LZA
NTC + ESC Blueprint
IaC engine
AWS-managed service. Logic is abstracted; you configure, not author.
CloudFormation YAML. Author and operate stacks.
Terraform / OpenTofu. Standard HCL modules.
Blast radius of changes
Opaque AWS rollouts. Failed landing-zone updates can be hard to unwind.
Monolithic CloudFormation pipeline. One bad change can cascade across accounts.
Per-module Terraform state. Plan and apply each module independently.
Customization depth
Lifecycle hooks and a narrow set of allowed extensions. Hard ceiling for advanced requirements.
Configurable via YAML schemas. Going beyond the schema requires forking the upstream repo.
Standard Terraform inputs, locals, and module composition. Replace any module without forking.
Source code access
Closed. AWS-managed service internals.
Open source on GitHub (Apache-2.0).
Customers get full read access to NTC modules.
Update model
AWS pushes landing-zone versions. Limited control over timing.
Monolithic releases. Major-version upgrades carry breaking changes across the whole solution.
Each module is versioned independently (SemVer). Upgrade one module at a time.
Account baselines
Pre-defined guardrails. Custom baselines via Account Factory Customizations (AFC), limited.
CloudFormation StackSets baked into the LZA config. Constrained by schema.
Customer-defined baselines (NTC Account Factory) fully defined in Terraform or OpenTofu.
Multi-partition portability
Available on Commercial, GovCloud, and ESC, but managed separately per partition.
Available across Commercial, GovCloud, and ESC, but not at parity: ESC uses a feature-reduced container deployment.
Same modules across Commercial, GovCloud, and ESC. Partition-aware behavior.
Support
AWS support tiers.
Community + AWS support.
Direct communication to NTC engineers.
§ 07
Frequently asked questions

The honest answers.

Procurement, legal, and engineering arrive with the same questions.

01What is the license model?
Commercial license per organization. Access to NTC modules is delivered under the terms agreed in the engagement contract. There is no open-core or freemium tier; access is granted to paying customers.
02What does it cost?
Pricing depends on organization size and support tier. NTC is sold as an annual subscription. Contact us for a quote tailored to your environment.
03Do we get source code access?
Yes. Customers get full read access to every NTC module. You can audit the code, vendor it internally, or even fork it if you ever need to.
04What happens if we stop the subscription?
Every NTC module is plain Terraform / OpenTofu. You own the state files, the AWS accounts, and the GitOps pipelines. There is no proprietary control plane to lose access to. If you end the subscription you keep what you deployed; you only stop receiving new updates and support.
05What support do you provide?
Direct access to the engineers who write the modules, via ticketing system. Response SLAs depend on tier. Production-impacting issues are prioritized over feature requests.
06How much can we customize?
Every module exposes Terraform inputs, locals, and outputs. You override defaults the same way you would with any community module. Larger deviations (custom IAM paths, additional guardrails, partition-specific behavior, compliance flags) are covered via templates.
07Does NTC support OpenTofu?
Yes. NTC modules are continuously tested against both Terraform and OpenTofu. You can pick either toolchain without changing module code.
08Which AWS partitions does NTC support?
AWS Commercial, AWS GovCloud (US), and the AWS European Sovereign Cloud (aws-esc). One codebase, partition-aware behavior. The same modules power production landing zones across all three.
§ 08
Implementation partners · certified delivery

Need hands on deck?

Whether you need implementation support for NTC, application modernization, or workload migration to the AWS ESC, our certified system-integrator partners deliver.

tecRacer

AWS Premier Partner with deep expertise in cloud migrations, managed services, and infrastructure automation. Hands-on engineering teams that ship.

Partnership details →

adesso SE

Certified AWS partner specializing in application modernization, cloud migration, and sovereign cloud implementations. Deep technical bench plus proven delivery methodologies.

Partnership details →
§ 09
Start your ESC journey · pick a route

Ship it.
Talk to the engineers who built the blueprint.

30-minute demo. We screen-share into a live ESC org and show you the modules we just talked about, running. No deck, no pitch, no pressure.

✉️ aws-esc@nuvibit.com
Built byNuvibit AG · Switzerland

Or drop us a line.

We reply within 1 business day.