Skip to content

Dataset

Vendor jurisdiction exposure, by mechanism

The four legal mechanisms that follow a DDoS vendor’s home jurisdiction rather than the buyer’s: what each reaches, what sets it in motion, which document settles it, and which of them an architecture can remove. No vendor is named and no country is rated.

Rows
4
Last updated
2026-08-22
Schema version
1.0
Download
JSON·CSV

Rows are mechanisms, not countries, and the table deliberately does not rate jurisdictions. Every mechanism below reaches some supplier in every jurisdiction; what differs is the combination, and what a buyer controls is how much of one estate sits under a single one.

Vendor jurisdiction exposure, by mechanism

MechanismWhat it reachesWhat sets it in motionDocument that settles itWhat removes itAuthority
Export licensingWhether the product may be shipped, updated or supported across a border at all, including firmware and support delivered remotely.The control list of the vendor’s home jurisdiction meeting the buyer’s country and, for some categories, the buyer’s sector.The export classification of the exact model in writing, and a statement of whether a licence is required for the buyer’s country and how long one takes.no purchase removes it; concentration is what a buyer controlsWassenaar dual-use list; US Export Administration Regulations
Sanctions exposurePayment, renewal, support and, where a designation names the counterparty, the legality of continuing to use what is already installed.A designation naming the vendor, an entity in its ownership chain, or a jurisdiction the buyer’s own regulator applies a programme to.The ownership structure in writing, screened against every programme that binds the buyer — not only the buyer’s own country’s list.no purchase removes it; concentration is what a buyer controlsOFAC Specially Designated Nationals list; EU consolidated sanctions list
Extraterritorial data accessData the vendor holds or is able to reach, wherever it is physically stored, including telemetry a device sends home for classification.A lawful order served on the vendor in its home jurisdiction, which the vendor may be barred from disclosing to the buyer.What telemetry leaves the buyer’s network, in which jurisdiction it is processed, how long it is retained and who may compel its production.An architecture in which no telemetry leaves the network removes the mechanism, because there is nothing at the vendor to compel.US CLOUD Act, 18 U.S.C. §2713; EU Regulation (EU) 2023/1543
Vendor-operated cloud dependencyWhether the device still classifies traffic correctly on a day the vendor’s cloud is unreachable, for any reason including the three above.An outage, a lapsed contract, a routing failure, or a legal event that stops the feed rather than the device.The documented behaviour on feed loss, in writing: what still applies, what stops updating, and whether the device steps down to passing traffic.Detection trained and executed on the customer’s own infrastructure removes the dependency; the device degrades gracefully because it was never being told what to think.NIS2 Directive (EU) 2022/2555, Article 21(2)(d) on supply-chain security

Sources

  1. Wassenaar Arrangement — Control Lists

    The Wassenaar Arrangement Secretariat · accessed 2026-08-22

    The dual-use list most national control regimes are derived from; national lists differ and the national one is what binds a given shipment.

  2. Export Administration Regulations (15 CFR 730–774)

    US Bureau of Industry and Security · accessed 2026-08-22

  3. Specially Designated Nationals and Blocked Persons List

    US Department of the Treasury, OFAC · accessed 2026-08-22

  4. EU Sanctions Map — consolidated list of restrictive measures

    Council of the European Union · accessed 2026-08-22

  5. 18 U.S.C. §2713 — Required preservation and disclosure of communications and records

    US Code, via Cornell Legal Information Institute · accessed 2026-08-22

    The provision the CLOUD Act inserted; it is the operative text rather than the act’s title, which is why it is cited directly.

  6. Regulation (EU) 2023/1543 on European Production and Preservation Orders for electronic evidence

    European Union · 2023-07-12 · accessed 2026-08-22

    The ELI short form of this URL did not resolve from here; the CELEX form is the same instrument and does.

  7. Directive (EU) 2022/2555 (NIS2), Article 21(2)(d)

    European Union · 2022-12-14 · accessed 2026-08-22

    Supply-chain security, including the security of relationships between an entity and its direct suppliers.

What changed

  • 2026-08-22Initial release: four mechanisms, with the document that settles each and the architectural property that removes it where one does.

Reuse: Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.