Skip to content

Regulation

Regulation and regional duties

No regulator names a DDoS product. What the instruments in this section do is impose duties — keep a service available, notify within a clock, assess your suppliers, keep the data where the law says — and those duties translate into properties a defence either has or does not. That translation is the whole subject here.

Two things recur across every jurisdiction covered. The first is that the obligation sits on the entity and cannot be contracted away, so a supplier assurance is not evidence. The second is that reporting duties are data duties: a notification clock is only survivable if the telemetry it needs was captured while the attack was happening and is still in your hands afterwards.

Every page cites the instrument itself rather than a summary of it, and says plainly where the binding text is a national transposition rather than the directive we link. This is technical implementation guidance, not legal advice — verify current obligations with the competent regulator and counsel.

Start here

Go deeper