Skip to content

Dataset

Regulatory instruments with a DDoS dimension

Instruments bearing on availability, incident reporting or data location in a way that changes DDoS architecture. Rows exist only where the instrument could be reached and read.

Rows
6
Last updated
2026-08-15
Schema version
1.0
Download
JSON·CSV

This is technical implementation reference, not legal advice, and it is deliberately incomplete. Several jurisdictions this site covers editorially — Qatar, the UAE, Kazakhstan, and the Turkish instruments above — have no verified link here because their official portals could not be reached from the environment this dataset was built in. An unverified citation would be worse than the gap.

Regulatory instruments with a DDoS dimension

JurisdictionInstrumentRegulatorSectorDDoS relevanceIncident reportingBinding textOfficial source
European UnionDirective (EU) 2022/2555 (NIS2)National competent authorities per member stateEssential and important entities across listed sectorsAvailability risk on an all-hazards basis; supply-chain security applied to the mitigation supplier.Staged: early warning, fuller notification, final reportYour member state’s transposing act, not the directive itselfeur-lex.europa.eu/eli/dir/2022/2555/oj
European UnionRegulation (EU) 2022/2554 (DORA)European Supervisory Authorities and national financial regulatorsFinancial entities and their ICT third-party providersICT risk management, resilience testing including an advanced regime, and third-party concentration.Major ICT-related incident reporting under the regulationThe regulation applies directly; technical standards carry the detaileur-lex.europa.eu/eli/reg/2022/2554/oj
Saudi ArabiaPersonal Data Protection LawSDAIAAny controller processing personal dataWhere mitigation processes personal data — source addresses, headers, session data — cross-border processing becomes a compliance question rather than an implementation detail.not verified from a primary source for this datasetThe Arabic text; the linked English version is published for referencesdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf
Saudi ArabiaTelecommunications and IT licensing frameworkCommunications, Space & Technology Commission (CST)Licensed operatorsLicence conditions bearing on service continuity and network security for licensed operators.not verified from a primary source for this datasetThe licence instrument issued by the Commissioncst.gov.sa/en
TürkiyePersonal Data Protection Law No. 6698 (KVKK)Kişisel Verileri Koruma KurumuAny data controllerCross-border transfer rules bear on where mitigation may terminate sessions and hold telemetry.not verified from a primary source for this datasetThe published Turkish textnot linked — the official portal could not be verified from this repository
TürkiyeLaw No. 5651 on internet publicationsBTKHosting and access providersLog retention duties interact with what DDoS telemetry must be kept and for how long.not verified from a primary source for this datasetThe published Turkish textnot linked — the official portal could not be verified from this repository

Sources

  1. Directive (EU) 2022/2555 (NIS2)

    EUR-Lex · 2022-12-14 · accessed 2026-08-15

  2. Regulation (EU) 2022/2554 (DORA)

    EUR-Lex · 2022-12-14 · accessed 2026-08-15

  3. Personal Data Protection Law (English translation)

    SDAIA · accessed 2026-08-15

  4. Communications, Space & Technology Commission

    CST · accessed 2026-08-15

What changed

  • 2026-08-15Initial release: six instruments, four with verified primary links and two recorded without one.

Reuse: Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.