Engagements

Eight engagements, each with a floor and a boundary

What is in scope is listed. What is out of scope is listed next to it, because a fixed price is only defensible when both are written down before the work starts.

Entry

Assessment and enablement

Cheaper, shorter, and useful on their own. Most engagements start here.

package/gcp-architecture-security-review

GCP Architecture & Security Review

Your existing estate assessed against the Google Cloud architecture framework. Findings ranked by severity, with Terraform for the fixes that matter most.

  • IAM and organization policy audit
  • Network topology and VPC Service Controls
  • KMS and secrets handling
  • Security Command Center findings triage
  • Workload Identity configuration
  • External exposure review
  • AI workload security: Model Armor policy review, Vertex AI endpoint exposure
  • remediation implementation
  • application-layer security
  • compliance certification

~$18,000

Starts with Discovery & Scoping

Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.

package/gcp-onboarding-workshops

GCP Onboarding Workshops

Two days, instructor-led, built around your architecture rather than a generic curriculum. Hands-on labs in a sandbox project provisioned for the cohort.

  • Track of your choice: foundations, GKE, networking, or security
  • Material written against your own architecture and naming
  • Hands-on labs in a sandbox project provisioned for the cohort
  • Sumech’s own slides, walkthroughs, and lab exercises
  • Skills Boost licensing
  • official Google certification training
  • ongoing enablement

~$8,000 per two-day cohort

Starts with Discovery & Scoping

Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.

Build

Delivery engagements

Longer programmes that change what you run. Automation leads the group because it is the deepest delivery evidence here and the capability the others depend on.

package/automation-iac-devsecops

Automation, IaC & DevSecOps

A versioned Terraform module library, pipelines with real gates, and security scanning that runs on every commit instead of before an audit.

  • Terraform module library: versioned, tested, published to a private registry
  • Remote state, workspace, and environment promotion model
  • CI/CD delivery pipelines with environment gates
  • Policy as code: Terraform plan validation, Policy Controller on GKE
  • SAST, dependency scanning, and secret detection in-pipeline
  • DAST against deployed pre-production environments
  • Supply chain: Artifact Registry, Binary Authorization, provenance attestation
  • Drift detection and a remediation workflow
  • application code changes and test authoring
  • remediation of findings the scanners raise
  • third-party scanner licensing
  • non-GCP CI/CD platforms beyond the agreed runner

~$28,000

Starts with Discovery & Scoping

Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.

package/gcp-landing-zone

GCP Landing Zone & Foundations

Organization hierarchy, identity model, Shared VPC, and hybrid connectivity, delivered as reusable Terraform modules with a handover runbook. Interconnect is priced inside, not renegotiated later.

  • Organization hierarchy and folder structure
  • IAM and least-privilege model
  • Shared VPC design
  • Hybrid connectivity: Cloud Interconnect or HA VPN, on-prem routing and DNS
  • Organization policy guardrails
  • Cloud KMS
  • Logging and monitoring baseline
  • CI/CD pipeline
  • workload migration
  • application refactoring
  • physical Interconnect procurement

~$40,000

Starts with Discovery & Scoping

Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.

package/vm-migration-to-gcp

Large-Scale VM Migration to GCP

VMware vSphere estates moved to Google Cloud with M2VM, snapshot-based cutover, and wave planning that survives contact with dependencies. 2,000+ VMs delivered.

  • Discovery and dependency mapping
  • Wave planning against real application dependencies
  • Migration factory setup
  • M2VM configuration and snapshot-based cutover design
  • VirtIO driver injection and OS licensing handling
  • Sole-tenant nodes where BYOL licensing requires them
  • Rollback strategy and cutover runbooks
  • Hypercare through the first waves
  • application remediation
  • database platform changes
  • non-GCP target environments

Program design ~$30,000–$45,000 fixed

Starts with Discovery & Scoping

Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.

package/gke-platform-engineering

GKE Platform & Scalability

Cluster architecture, autoscaling, and load testing against a defined latency SLO. Proving the platform holds at peak is the part most GKE work skips.

  • Cluster and node pool architecture
  • Horizontal and cluster autoscaling
  • Quota and limit design
  • Load and performance testing against defined latency SLOs
  • Observability: Prometheus and Grafana
  • Cost-aware node strategy
  • application containerization
  • service mesh
  • CI/CD pipeline authoring

~$26,000

Starts with Discovery & Scoping

Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.

package/governed-data-platform

Governed Data Platform

Self-serve ingestion with Dataplex governance and Sensitive Data Protection underneath it: classification, column-level security, and access that holds when the data multiplies.

  • Self-serve ingestion framework
  • Dataplex governance, cataloguing, and policy tag taxonomy
  • Sensitive Data Protection (Cloud DLP): classification, de-identification, redaction
  • Scheduled DLP inspection jobs with findings routed to Security Command Center
  • BigQuery column-level security and dynamic data masking
  • Conditional access: IAM Conditions and VPC Service Controls perimeters
  • Data quality gates
  • Dataflow and Pub/Sub pipelines, Cloud Composer orchestration
  • source system integration beyond agreed connectors
  • BI and dashboard development
  • data migration from legacy warehouses

~$34,000

Starts with Discovery & Scoping

Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.

package/gcp-cost-optimization

GCP Cost Optimization

A savings model with a prioritized implementation plan: commitment modelling, sole-tenant BYOL analysis, bin-packing, and the egress patterns nobody has looked at.

  • Committed and sustained use discount modelling
  • Sole-tenant BYOL licensing analysis
  • Idle and overprovisioned capacity
  • GKE bin-packing
  • Storage class and lifecycle policy
  • Egress patterns
  • implementation of recommendations
  • contract negotiation with Google
  • non-GCP spend

~$14,000 fixed

Starts with Discovery & Scoping

Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.

Sequence

How these follow each other

Engagements are bought one at a time, and some of them only make sense in an order. These are the sequences that come up most.

Start

Which one you need is a Discovery question

Build or remediate is not knowable from outside the estate. $4,500 fixed, 3–5 days, and you leave with a written scope and a fixed quote whether or not you proceed.

Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.

Book Discovery & Scoping