HomeIntelligenceBrief
BREACH BRIEF🟡 Medium Advisory

AWS Retires Shield Advanced L7 Automatic Mitigation – Migration to Anti‑DDoS Managed Rule Group Required by Jan 2027

AWS will discontinue Shield Advanced's automatic L7 DDoS mitigation on Jan 1 2027, forcing customers to adopt the new Anti‑DDoS managed rule group. The shift impacts any organization relying on AWS WAF for SOC 2‑aligned DDoS controls and requires updated evidence of control implementation.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 helpnetsecurity.com
🟡
Severity
Medium
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
2 recommended
📰
Source
helpnetsecurity.com

AWS Retires Shield Advanced L7 Automatic Mitigation – Customers Must Migrate to Anti‑DDoS Managed Rule Group by Jan 1 2027

What Happened — AWS announced that, effective January 1 2027, the automatic Layer 7 (L7) DDoS mitigation feature of Shield Advanced will be retired. Customers must transition to the new Anti‑DDoS managed rule group (added in Count mode during July – August 2026) or lose built‑in application‑layer DDoS protection.

Why It Matters for Compliance & Audit Readiness

  • The change creates a control‑gap risk: any web ACL that does not adopt the rule group will no longer have documented L7 DDoS controls, potentially violating SOC 2 CC6 (System and Communications Protection) and CC7 (Risk Management).
  • Continuous‑compliance programs must capture the migration as evidence of control remediation and update the control matrix to reflect the new rule‑group configuration.
  • Verisq’s Control Mapping capability can automatically map the new rule‑group settings to SOC 2 controls and generate audit‑ready evidence for the migration timeline.

Who Is Affected — All AWS customers that rely on Shield Advanced for application‑layer DDoS protection, spanning cloud‑infra, SaaS, fintech, e‑commerce, and any regulated industry using AWS WAF.

Recommended Actions

  • Review the Anti‑DDoS dashboard and compare DDoSDetected vs. DDoSAttackRequests metrics.
  • Update your SOC 2 control inventory to replace “Shield Advanced L7 automatic mitigation” with the “Anti‑DDoS managed rule group” control.
  • Amend IaC (Terraform, CloudFormation, etc.) to include the rule group, set appropriate sensitivity, and document the change as audit evidence.
  • Conduct a post‑migration validation test and capture logs/labels as continuous‑compliance artifacts.

Source: Help Net Security

Technical Notes

  • The new rule group runs in Count mode initially, then can be switched to Block or Challenge actions.
  • Capacity requirement drops from 150 WCUs to 50 WCUs, reducing cost and simplifying rule‑set management.
  • All inspected requests receive an AMR label, enabling custom WAF rules and richer logging.
📰 Original Source
https://www.helpnetsecurity.com/2026/07/28/aws-waf-anti-ddos-rule-group/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →