Regulation
Regulation and regional duties
No regulator names a DDoS product. What the instruments in this section do is impose duties — keep a service available, notify within a clock, assess your suppliers, keep the data where the law says — and those duties translate into properties a defence either has or does not. That translation is the whole subject here.
Two things recur across every jurisdiction covered. The first is that the obligation sits on the entity and cannot be contracted away, so a supplier assurance is not evidence. The second is that reporting duties are data duties: a notification clock is only survivable if the telemetry it needs was captured while the attack was happening and is still in your hands afterwards.
Every page cites the instrument itself rather than a summary of it, and says plainly where the binding text is a national transposition rather than the directive we link. This is technical implementation guidance, not legal advice — verify current obligations with the competent regulator and counsel.
Start here
NIS2 and DDoS: What Essential and Important Entities Must Implement
Directive duties turned into architecture
DORA and DDoS Resilience Testing for EU Financial Entities
Financial-sector resilience, tested and evidenced
Data Residency and DDoS Mitigation in the GCC: Why Attack Traffic Shouldn't Leave the Country
Residency, transfer and where inspection happens
Go deeper
Regulated operators · Last updated August 2026
DDoS as a Licence Obligation: What Changes When Your Subscribers Are the Ones Harmed
An enterprise buys DDoS mitigation to protect itself. A licensed operator, data centre or cloud provider in the Kingdom buys it to discharge a duty owed to subscribers and to a sector regulator — which changes the unit of harm, the accountability chain and the design.
Institutional readiness · Last updated August 2026
The Decision, the Evidence and the Answer: DDoS Readiness for a Knowledge Economy
A knowledge-based economy needs three things in country when a national-scale incident happens: the people who can make the call, the record that proves what occurred, and the organisation that answers for it afterwards. Architecture decides where all three sit.
Policy and capability · Last updated August 2026
Vision 2030 and the DDoS Layer: Why Traffic That Leaves Also Takes the Learning With It
A national digital-economy goal makes the availability of carrier-grade services a public asset. The architectural consequence is not only where data is processed — it is where the operational capability to defend it accumulates.
Compliance and architecture · Last updated August 2026
DDoS Protection and the NCA Essential Cybersecurity Controls: An Architecture and Evidence Guide
How the availability, network security, logging and continuity themes of Saudi Arabia's Essential Cybersecurity Controls translate into a DDoS architecture decision — plus the PDPL residency question that cloud scrubbing raises, and the evidence an assessor expects.
Compliance and architecture · Last updated August 2026
Kazakhstan's Data Localisation Requirements and On-Premise DDoS Mitigation
Kazakhstan requires personal data about its citizens to be held in country. A foreign scrubbing tier cannot filter traffic without processing source addresses, headers and session identifiers. This guide works through what that tension actually is, what an on-premise tier changes, and what to put in the contract.
Financial sector · Last updated August 2026
The SAMA Cyber Security Framework and DDoS Resilience: Architecture, Evidence and Testing
How the Saudi Central Bank's cyber security framework reshapes a DDoS decision for supervised financial institutions — the two-tier reference architecture, the latency budget on payment paths, outsourcing when scrubbing sits abroad, and an RFP that survives supervisory review.
Regional cooperation · Last updated August 2026
Cybersecurity Cooperation Across the Turkic States: The DDoS Layer
Regional cooperation on denial-of-service defence only becomes operational when a mitigation request has a format both sides implement. This guide sets out what that interface is — DOTS and BGP FlowSpec — what shared signalling and joint exercises would have to test, and how common procurement criteria reduce collective supplier concentration.