At a glance
A global virtual healthcare technology company needed FedRAMP compliance to expand into the U.S. government sector. The company's AWS environment lacked the centralized security, networking, and logging controls required for FedRAMP Authorization. SoftServe built a FedRAMP-aligned AWS Landing Zone using AWS Control Tower across three delivery phases. SoftServe automated the client's CI/CD pipeline with Terraform, Terragrunt, and Jenkins. The result was a FedRAMP-compliant AWS environment that positioned the client for certification and expansion into government markets.
Client background
Our client is a global virtual healthcare technology company that provides cloud-based healthcare services and handles sensitive personal and health data. Cloud security is critical to any company operating in this space, and the bar rises further when a healthcare provider seeks to serve government agencies. To expand into the U.S. government sector, the client needed to raise its cloud security posture to meet FedRAMP requirements and obtain FedRAMP Authorization. The client approached SoftServe to build a FedRAMP-compliant cloud environment and CI/CD pipeline that would support this expansion.

Business challenges
The client needed to move from healthcare-grade cloud security to federal government-grade security to pursue FedRAMP Authorization. Before the engagement, the company had no standardized, repeatable AWS account structure and no centralized networking, security, or logging system across its multiple accounts and regions. These gaps stood between the client and both FedRAMP compliance and its planned expansion into government markets.
Specifically, the client lacked:
- A standardized, repeatable AWS account structure across multiple accounts and regions.
- Centralized networking, security, and logging services that met FedRAMP requirements.
- An automated CI/CD pipeline enforcing consistent, secure deployments.
- A unified identity and access management system across AWS accounts.
Activities & Solutions
SoftServe built a FedRAMP-aligned AWS Landing Zone, a well-architected, multi-account AWS environment and automated the client's CI/CD pipeline across three delivery phases. SoftServe migrated the client's infrastructure management to Infrastructure as Code (IaC), the practice of managing infrastructure through machine-readable configuration files instead of manual processes. This replaced inconsistent manual deployment steps with a repeatable, secure, multi-account environment and enforced security policy automatically across every new AWS account.
Phase 1: Built a FedRAMP-compliant Landing Zone
- SoftServe created a Landing Zone managed by AWS Control Tower, an AWS service that automates the setup of a secure, multi-account environment.
- Dedicated logging, security, and network accounts were structured through AWS Organizations, a service for centrally managing multiple AWS accounts.
- SoftServe configured AWS Transit Gateway (TGW), VPN connections, VPC endpoints, and edge routers for cross-region and on-premises connectivity.
- AWS Security Hub and AWS GuardDuty were integrated in an administrator-member relationship, giving one account centralized oversight of security across all others.
- SoftServe deployed Service Control Policies (SCPs), rules that govern the maximum permissions available to an AWS account to deny non-compliant regions, services, and configurations.
- A custom AWS Config Conformance Pack, combining FedRAMP and Control Tower rules, was deployed across the entire organization.
- SoftServe integrated AWS Single Sign-On (SSO) with the client's Okta identity provider and Active Directory, limiting console access to SSO users.
Phase 2: Automated CI/CD with Infrastructure as Code
- SoftServe used Terraform and Terragrunt to define application infrastructure as code, replacing manual provisioning steps.
- SoftServe redesigned the client's CI/CD pipeline using GitOps practices, managing infrastructure changes through version-controlled code and immutable infrastructure principles, orchestrated through Jenkins.
- The Jenkins pipeline builds Packer AMI images, encrypts them with AWS KMS keys, and distributes them across AWS accounts.
- Terraform deploys the client's containerized applications as Docker images into AWS EKS (Elastic Kubernetes Service) using Helm charts.
- SoftServe implemented the AWS IRSA model (IAM Roles for Service Accounts) to secure Kubernetes workloads running on EKS.
Phase 3: Extended the model organization-wide
- The client adopted the same Landing Zone and CI/CD model across its other AWS environments, turning the engagement into a standing capability rather than a one-time build.
SoftServe automated the client's CI/CD pipeline end to end, eliminating manual deployment steps across the organization.

Value delivered
SoftServe built a FedRAMP-aligned, multi-account AWS Landing Zone that gave the client the security foundation to pursue FedRAMP Authorization and enter the U.S. government market. The engagement replaced manual, inconsistent processes with a repeatable Landing Zone model, centralized security and logging, and a CI/CD pipeline automated through Infrastructure as Code. The result: a client positioned to pursue federal certification and scale into new markets.
SoftServe and AWS help regulated companies design secure, well-architected Landing Zones, automate CI/CD with Infrastructure as Code, and prepare for FedRAMP and other compliance milestones. Let's talk!


