Dataset
Vendor jurisdiction exposure, by mechanism
The four legal mechanisms that follow a DDoS vendor’s home jurisdiction rather than the buyer’s: what each reaches, what sets it in motion, which document settles it, and which of them an architecture can remove. No vendor is named and no country is rated.
- Rows
- 4
- Last updated
- 2026-08-22
- Schema version
- 1.0
Rows are mechanisms, not countries, and the table deliberately does not rate jurisdictions. Every mechanism below reaches some supplier in every jurisdiction; what differs is the combination, and what a buyer controls is how much of one estate sits under a single one.
Vendor jurisdiction exposure, by mechanism
| Mechanism | What it reaches | What sets it in motion | Document that settles it | What removes it | Authority |
|---|---|---|---|---|---|
| Export licensing | Whether the product may be shipped, updated or supported across a border at all, including firmware and support delivered remotely. | The control list of the vendor’s home jurisdiction meeting the buyer’s country and, for some categories, the buyer’s sector. | The export classification of the exact model in writing, and a statement of whether a licence is required for the buyer’s country and how long one takes. | no purchase removes it; concentration is what a buyer controls | Wassenaar dual-use list; US Export Administration Regulations |
| Sanctions exposure | Payment, renewal, support and, where a designation names the counterparty, the legality of continuing to use what is already installed. | A designation naming the vendor, an entity in its ownership chain, or a jurisdiction the buyer’s own regulator applies a programme to. | The ownership structure in writing, screened against every programme that binds the buyer — not only the buyer’s own country’s list. | no purchase removes it; concentration is what a buyer controls | OFAC Specially Designated Nationals list; EU consolidated sanctions list |
| Extraterritorial data access | Data the vendor holds or is able to reach, wherever it is physically stored, including telemetry a device sends home for classification. | A lawful order served on the vendor in its home jurisdiction, which the vendor may be barred from disclosing to the buyer. | What telemetry leaves the buyer’s network, in which jurisdiction it is processed, how long it is retained and who may compel its production. | An architecture in which no telemetry leaves the network removes the mechanism, because there is nothing at the vendor to compel. | US CLOUD Act, 18 U.S.C. §2713; EU Regulation (EU) 2023/1543 |
| Vendor-operated cloud dependency | Whether the device still classifies traffic correctly on a day the vendor’s cloud is unreachable, for any reason including the three above. | An outage, a lapsed contract, a routing failure, or a legal event that stops the feed rather than the device. | The documented behaviour on feed loss, in writing: what still applies, what stops updating, and whether the device steps down to passing traffic. | Detection trained and executed on the customer’s own infrastructure removes the dependency; the device degrades gracefully because it was never being told what to think. | NIS2 Directive (EU) 2022/2555, Article 21(2)(d) on supply-chain security |
Sources
- Wassenaar Arrangement — Control Lists
The Wassenaar Arrangement Secretariat · accessed 2026-08-22
The dual-use list most national control regimes are derived from; national lists differ and the national one is what binds a given shipment.
- Export Administration Regulations (15 CFR 730–774)
US Bureau of Industry and Security · accessed 2026-08-22
- Specially Designated Nationals and Blocked Persons List
US Department of the Treasury, OFAC · accessed 2026-08-22
- EU Sanctions Map — consolidated list of restrictive measures
Council of the European Union · accessed 2026-08-22
- 18 U.S.C. §2713 — Required preservation and disclosure of communications and records
US Code, via Cornell Legal Information Institute · accessed 2026-08-22
The provision the CLOUD Act inserted; it is the operative text rather than the act’s title, which is why it is cited directly.
- Regulation (EU) 2023/1543 on European Production and Preservation Orders for electronic evidence
European Union · 2023-07-12 · accessed 2026-08-22
The ELI short form of this URL did not resolve from here; the CELEX form is the same instrument and does.
- Directive (EU) 2022/2555 (NIS2), Article 21(2)(d)
European Union · 2022-12-14 · accessed 2026-08-22
Supply-chain security, including the security of relationships between an entity and its direct suppliers.
What changed
- 2026-08-22Initial release: four mechanisms, with the document that settles each and the architectural property that removes it where one does.
Reuse: Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.