Comparison
Control Plane vs VMware
9 min read
Summary
Control Plane runs your containers and full virtual machines across AWS, GCP, Azure, and your own servers as one platform, with platform-level compliance, unified identity and networking, scale-to-zero, and no hypervisor or per-core licensing to manage. VMware virtualizes servers: it turns the physical machines in your datacenter into virtual machines you manage centrally on your own hardware. Both virtualize, but they solve different problems. If you are modernizing toward the cloud and want to escape per-core licensing, Control Plane runs your VMs and containers directly under one model. VMware differs in one area: deployments anchored to bare-metal hardware features (vSphere, NSX, vSAN internals, device passthrough) or fully air-gapped datacenters may remain on it.
| At a glance | Control Plane | VMware |
|---|---|---|
| Runs across clouds | ●●●●● | ●●●●● |
| Infra to operate | No hosts | Hosts + vCenter |
| Scale-to-zero | ✓ Yes | ✗ No |
| Cost model | Consumption | Per-core license |
| Workload types | Containers + VMs | VMs first |
| Compliance built in | ✓ PCI L1, SOC 2, HIPAA | Self-managed |
What each one is
VMware and Control Plane both virtualize, but at different layers.
VMware is a software-defined datacenter stack. It rests on three pillars. vSphere is compute virtualization: the ESXi hypervisor runs many isolated virtual machines on one physical server, and vCenter manages them centrally, with live migration and automated resource balancing. NSX is software-defined networking: virtual switches, routing, and a distributed firewall that lets you micro-segment traffic between VMs without re-cabling anything. vSAN is software-defined storage: it pools the local disks across your servers into one shared datastore governed by policy. Together they turn a rack of hardware into a centrally managed pool of compute, network, and storage. Server virtualization has run the enterprise datacenter for two decades.
Control Plane is cloud virtualization. You point it at whatever substrates you have (an AWS account, a GCP project, a Kubernetes cluster, your own Linux servers) and it runs your workloads across all of them as one platform, with identity, networking, security, and scaling handled uniformly. You do not manage hosts or a hypervisor; you deploy applications and it places them.
Broadcom's acquisition of VMware and shift to per-core pricing is why many VMware teams are re-evaluating whether to stay on their own hardware or move to the cloud. Control Plane is a common destination when they move.
Control Plane vs VMware, side by side
| Dimension | Control Plane | VMware |
|---|---|---|
| What it virtualizes | The cloud: clouds, regions, clusters, servers into one virtual cloud | Physical servers into virtual machines |
| Where it runs | AWS, GCP, Azure, and on-prem, as one layer | Your datacenter hardware (cloud via VCF add-ons) |
| Workload types | Containers plus VMs (Linux and Windows), serverless, cron, stateful, plus Sandboxes for AI agents and untrusted code | Virtual machines (containers via Tanzu) |
| What you operate | No hypervisor hosts or vCenter; you run the platform and your apps (your own clusters too) | ESXi hosts, vCenter, upgrades, patching |
| Multi-cloud | Native, one network and identity model across clouds | Datacenter-first; cloud through add-ons |
| Pricing model | Consumption in your own cloud accounts | Per-core subscription bundles (Broadcom) |
| Cost controls | Scale-to-zero plus Capacity AI right-sizing | Provision hosts and VMs to peak |
| Compliance | PCI DSS Level 1, SOC 2 Type II, HIPAA, GDPR | Self-managed; you own the audits and controls |
What you operate. With VMware you run the infrastructure: ESXi hosts, vCenter, patching, upgrades, and capacity planning. Control Plane has no hypervisor hosts or vCenter to run; you operate the platform and your applications on it. Running Kubernetes is optional: bring your own clusters (Bring Your Own Kubernetes, BYOK) or use Managed Kubernetes (MK8s) when you want them.
Workload types. VMware is VM-first; containers arrive through Tanzu as a separate layer. Control Plane runs full Linux and Windows VMs and containers as first-class workload types on the same platform. This matters for the common real-world estate that is half containerized and half on VMs nobody wants to re-architect yet, because both run under one model instead of two parallel stacks.
Multi-cloud and cost. VMware is datacenter-first, with cloud reached through add-on products, and it bills per core whether or not a VM is busy. Control Plane is natively multi-cloud with one network and identity model, bills for consumption in your own accounts, and scales idle workloads to zero while Capacity AI right-sizes the rest.
Compliance. Control Plane ships with PCI DSS Level 1 and SOC 2 Type II, and supports HIPAA and GDPR, at the platform level. On VMware the platform is capable, but the certifications and controls are yours to build and maintain.
The case for moving to Control Plane
Leaving VMware is a chance to modernize, not just re-platform.
- Stop paying Broadcom per core. Control Plane bills for consumption in your own cloud accounts, scales idle workloads to zero, and right-sizes the rest automatically with Capacity AI. Teams typically cut cloud compute costs 30 to 50 percent after moving, and some far more: SAFE Health reports a 75 percent drop in AWS spend.
- Bring your VMs, and modernize on your own schedule. Control Plane runs full Linux and Windows VMs and containers as first-class workloads on one platform, so you lift VM-based apps as they are and containerize when it suits you, with no forced re-architecture.
- One platform across every cloud and on-prem. Run across AWS, GCP, Azure, and your own servers as a single layer with unified identity, networking, and scaling. Deploy active-active across regions for resilience and low latency, without rebuilding your stack in each provider.
- Nothing underneath you must operate. No ESXi hosts, no vCenter, and no cluster you are forced to patch or upgrade. Your team ships applications instead of maintaining infrastructure.
- Enterprise compliance and uptime built in. PCI DSS Level 1, SOC 2 Type II, HIPAA, and GDPR at the platform level, with a 99.999% uptime SLA.
Where VMware differs
VMware operates at the hardware layer, so a few capabilities are specific to it:
- Hardware-level datacenter features. NSX micro-segmentation, vSAN storage policies, vSphere DRS, and direct device passthrough and host tuning operate against physical hardware. Control Plane is not a bare-metal hypervisor and does not replace these; re-expressing an audit posture built directly on them is architecture work.
- Fully air-gapped deployments. Workloads that must run completely disconnected from the internet fit VMware's on-hardware model, since Control Plane's managed layer needs outbound connectivity. Data sovereignty alone is different: Control Plane can keep data in your own datacenter by running on your on-prem servers.
- Bare-metal hypervisor management. VMware manages ESXi hosts and vCenter directly on your servers. Control Plane places workloads onto your servers as managed locations but does not administer the hypervisor itself.
Control Plane does not require you to give up your own servers: you point it at your own on-prem Linux machines and they become managed locations, running alongside the public clouds. The deciding factor is whether a deployment depends on those hardware-level features, not whether you own hardware.
Which fits your scenario
Control Plane fits: a team modernizing to the cloud. A company running roughly forty containerized microservices plus a handful of Windows VMs for a legacy billing system. They want active-active across AWS and GCP for latency and resilience, and they just got a renewal quote several times their old VMware bill. Control Plane runs the containers and those VMs as one platform across both clouds in their own accounts, and scales the quiet services to zero overnight.
Where VMware still applies: a manufacturer anchored on-prem. A medical-device maker running latency-sensitive control software on specialized hardware inside an air-gapped datacenter, with NSX micro-segmentation mapped directly to their audit boundaries. Here the hardware and network dependencies have no cloud equivalent and the estate cannot leave the building, so it remains on VMware.
Why teams consolidate on Control Plane. The moment workloads move toward the cloud, span more than one provider, or mix containers with VMs, running everything under one platform beats maintaining a datacenter stack plus per-core licensing. Control Plane runs the containers and the VMs together across every cloud and your own servers, with platform-level compliance and unified identity, so a retailer can move spiky, customer-facing ecommerce and modernizing services onto it and retire the pieces of the VMware estate that no longer need dedicated hardware.
Modernizing off VMware?
Run your containers and VMs across AWS, GCP, Azure, and on-prem as one virtual cloud, in your own accounts, with no hypervisor or cluster to operate. Test it on one real workload.
99.999% uptime SLA · SOC 2 Type II · PCI DSS Level 1
"Control Plane positively impacted DIV Brands' daily operations by enabling us to host services in multiple regions with 99.999% availability and ultra-low latency."
Frequently asked questions
For workloads you are moving to the cloud, often yes. VMware virtualizes physical servers in your datacenter; Control Plane virtualizes the cloud, running your containers and virtual machines across AWS, GCP, Azure, and on-prem as one layer with no hypervisor to operate. It is not a like-for-like swap for a hardware-anchored VMware estate that depends on vSphere, NSX, or vSAN internals.
They are the three pillars of the VMware software-defined datacenter. vSphere is compute virtualization: the ESXi hypervisor that runs virtual machines on your servers, managed by vCenter. NSX is software-defined networking: virtual switches, routing, and a distributed firewall for micro-segmentation, without re-cabling hardware. vSAN is software-defined storage: it pools the local disks across your servers into one shared datastore with policy-based management.
Yes. Control Plane has a VM workload type that runs full Linux and Windows virtual machines alongside containers, cron jobs, and stateful services, plus Sandboxes for AI agents and untrusted code, all in your own cloud accounts. What it does not do is manage bare-metal hypervisor hosts in your datacenter the way VMware vSphere does.
The main driver is cost. After Broadcom acquired VMware and moved to per-core subscription bundles, many customers saw renewal costs jump sharply, with reported increases ranging from the low hundreds of percent to roughly tenfold in the largest court-documented cases. That, plus a broader push to modernize off datacenter hardware, is why teams are evaluating cloud-native alternatives.
No. Your own on-prem servers can be one of the substrates Control Plane runs on, alongside AWS, GCP, and Azure. Control Plane is not a bare-metal hypervisor: it does not replace ESXi, vCenter, or hardware-level features like NSX micro-segmentation and vSAN storage policies. The deciding factor is whether you depend on those hardware-level features, not whether you own servers.
