mission-finops --control-tower-fit
Should You Use AWS Control Tower?
Make the landing-zone and account-vending decisions separately.
Runs entirely in your browser. Your answers are not uploaded or stored.
Methodology and sources
Built from AWS's own Control Tower, Landing Zone, Account Factory for Terraform, and Landing Zone Accelerator documentation. Verified against:
- AWS multi-account landing zone overview
- Landing Zone 4.0 migration guide
- Extending governance in Control Tower
- Working with existing Config resources
- How Control Tower controls work
- Methods of account provisioning
- Account Factory for Terraform overview
- AFT pricing
- Account Factory Customization (AFC)
- Create a customized account from a blueprint (AFC)
- Single-Region Terraform support for Account Factory
- Automate account provisioning with Service Catalog APIs
- Service Catalog: ProvisionProduct API
- Service Catalog: UpdateProvisionedProduct API
- Control Tower pricing
- Control Tower in AWS GovCloud (US)
- Landing Zone Accelerator on AWS: solution overview
- LZA prerequisites (Control Tower or Organizations-only)
- LZA deployment options
- LZA cost estimate
- AWS account vending via ServiceNow and AFT
- terraform-aws-control_tower_account_factory releases
- Community-reported AFT caveat: opaque error on a failed Control Tower account creation
Last reviewed: August 28, 2026
Independent educational guidance from Mission FinOps. Not affiliated with or endorsed by Amazon Web Services. This is not a security, compliance or certification determination.