AWS Retires Shield Advanced L7 Automatic Mitigation – Customers Must Migrate to Anti‑DDoS Managed Rule Group by Jan 1 2027
What Happened — AWS announced that, effective January 1 2027, the automatic Layer 7 (L7) DDoS mitigation feature of Shield Advanced will be retired. Customers must transition to the new Anti‑DDoS managed rule group (added in Count mode during July – August 2026) or lose built‑in application‑layer DDoS protection.
Why It Matters for Compliance & Audit Readiness
- The change creates a control‑gap risk: any web ACL that does not adopt the rule group will no longer have documented L7 DDoS controls, potentially violating SOC 2 CC6 (System and Communications Protection) and CC7 (Risk Management).
- Continuous‑compliance programs must capture the migration as evidence of control remediation and update the control matrix to reflect the new rule‑group configuration.
- Verisq’s Control Mapping capability can automatically map the new rule‑group settings to SOC 2 controls and generate audit‑ready evidence for the migration timeline.
Who Is Affected — All AWS customers that rely on Shield Advanced for application‑layer DDoS protection, spanning cloud‑infra, SaaS, fintech, e‑commerce, and any regulated industry using AWS WAF.
Recommended Actions
- Review the Anti‑DDoS dashboard and compare
DDoSDetectedvs.DDoSAttackRequestsmetrics. - Update your SOC 2 control inventory to replace “Shield Advanced L7 automatic mitigation” with the “Anti‑DDoS managed rule group” control.
- Amend IaC (Terraform, CloudFormation, etc.) to include the rule group, set appropriate sensitivity, and document the change as audit evidence.
- Conduct a post‑migration validation test and capture logs/labels as continuous‑compliance artifacts.
Source: Help Net Security
Technical Notes
- The new rule group runs in Count mode initially, then can be switched to Block or Challenge actions.
- Capacity requirement drops from 150 WCUs to 50 WCUs, reducing cost and simplifying rule‑set management.
- All inspected requests receive an AMR label, enabling custom WAF rules and richer logging.