Dataset
Regulatory instruments with a DDoS dimension
Instruments bearing on availability, incident reporting or data location in a way that changes DDoS architecture. Rows exist only where the instrument could be reached and read.
- Rows
- 6
- Last updated
- 2026-08-15
- Schema version
- 1.0
This is technical implementation reference, not legal advice, and it is deliberately incomplete. Several jurisdictions this site covers editorially — Qatar, the UAE, Kazakhstan, and the Turkish instruments above — have no verified link here because their official portals could not be reached from the environment this dataset was built in. An unverified citation would be worse than the gap.
Regulatory instruments with a DDoS dimension
| Jurisdiction | Instrument | Regulator | Sector | DDoS relevance | Incident reporting | Binding text | Official source |
|---|---|---|---|---|---|---|---|
| European Union | Directive (EU) 2022/2555 (NIS2) | National competent authorities per member state | Essential and important entities across listed sectors | Availability risk on an all-hazards basis; supply-chain security applied to the mitigation supplier. | Staged: early warning, fuller notification, final report | Your member state’s transposing act, not the directive itself | eur-lex.europa.eu/eli/dir/2022/2555/oj |
| European Union | Regulation (EU) 2022/2554 (DORA) | European Supervisory Authorities and national financial regulators | Financial entities and their ICT third-party providers | ICT risk management, resilience testing including an advanced regime, and third-party concentration. | Major ICT-related incident reporting under the regulation | The regulation applies directly; technical standards carry the detail | eur-lex.europa.eu/eli/reg/2022/2554/oj |
| Saudi Arabia | Personal Data Protection Law | SDAIA | Any controller processing personal data | Where mitigation processes personal data — source addresses, headers, session data — cross-border processing becomes a compliance question rather than an implementation detail. | not verified from a primary source for this dataset | The Arabic text; the linked English version is published for reference | sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf |
| Saudi Arabia | Telecommunications and IT licensing framework | Communications, Space & Technology Commission (CST) | Licensed operators | Licence conditions bearing on service continuity and network security for licensed operators. | not verified from a primary source for this dataset | The licence instrument issued by the Commission | cst.gov.sa/en |
| Türkiye | Personal Data Protection Law No. 6698 (KVKK) | Kişisel Verileri Koruma Kurumu | Any data controller | Cross-border transfer rules bear on where mitigation may terminate sessions and hold telemetry. | not verified from a primary source for this dataset | The published Turkish text | not linked — the official portal could not be verified from this repository |
| Türkiye | Law No. 5651 on internet publications | BTK | Hosting and access providers | Log retention duties interact with what DDoS telemetry must be kept and for how long. | not verified from a primary source for this dataset | The published Turkish text | not linked — the official portal could not be verified from this repository |
Sources
- Directive (EU) 2022/2555 (NIS2)
EUR-Lex · 2022-12-14 · accessed 2026-08-15
- Regulation (EU) 2022/2554 (DORA)
EUR-Lex · 2022-12-14 · accessed 2026-08-15
- Personal Data Protection Law (English translation)
SDAIA · accessed 2026-08-15
- Communications, Space & Technology Commission
CST · accessed 2026-08-15
What changed
- 2026-08-15Initial release: six instruments, four with verified primary links and two recorded without one.
Reuse: Free to reuse with attribution to ddosmitigationguide.com; source citations must be preserved.