Compliance Evidence

Auditor-ready DDoS
resilience evidence

DORA, NIS2, PCI DSS, ISO 27001, SOC 2, and Bank of Israel Directive 361 all require testing that your DDoS protection actually works. DDactic generates OPI scores and hardening reports that satisfy each framework's specific evidence requirements.

The Compliance Gap

Your DDoS protection budget is approved. Has it ever been tested?

Most security audits accept the existence of a CDN or WAF contract as evidence of DDoS protection. They do not check whether that protection actually holds under real attack conditions. Origin IPs exposed behind Cloudflare, WAF rate limits set too high to matter, scrubbing services that fail under L7 load - none of these gaps appear in a vendor invoice review. They appear when an attacker finds them first.

Every major compliance framework now includes language requiring organizations to test their controls, not just document that controls exist. DDactic closes the gap between "we have a CDN" and "we know our CDN holds under attack."

Supported Compliance Frameworks

EU Financial Sector

DORA

Digital Operational Resilience Act (2022/2554) - in force Jan 2025
Art. 25 + Art. 26 (TLPT)

Requires financial entities to conduct penetration testing, scenario-based tests, and threat-led penetration testing. DDoS simulation is an explicit TLPT scenario.

See DORA mapping →
EU Critical Infrastructure

NIS2

Network and Information Security Directive 2 (2022/2555) - Oct 2024
Art. 21(1) + Art. 21(2)(e)

Requires essential and important entities to test business continuity and availability under adversarial conditions. Applies to energy, banking, health, transport, and digital infrastructure sectors.

See NIS2 mapping →
Payment Card Industry

PCI DSS 4.0

Payment Card Industry Data Security Standard v4.0 - effective Mar 2024
Req. 11.3.1 + Req. 11.4.1

Mandates annual external penetration testing of the cardholder data environment perimeter and requires a documented penetration testing methodology covering network-layer tests.

See PCI DSS mapping →
ISMS Standard

ISO 27001:2022

Information Security Management Systems - third edition 2022
Control 5.30 + Control 8.8

Requires ICT readiness testing based on business continuity objectives (Control 5.30) and technical vulnerability management (Control 8.8). DDoS attack surface exposure is a documented vulnerability class.

See ISO 27001 mapping →
Availability Trust Criteria

SOC 2 Type II

AICPA Trust Services Criteria - Availability category
A1.2 + A1.3 + CC9.2

Requires testing of recovery procedures supporting system availability (A1.3). Auditors expect evidence that availability controls were tested against realistic threat scenarios, not just documented.

See SOC 2 mapping →
Israeli Financial Sector

Bank of Israel Directive 361

Proper Conduct of Banking Business - Cyber Defense Management
Penetration Testing + DDoS Controls

Requires periodic penetration testing by qualified external parties covering DDoS threat scenarios. Updated after 2022-2023 Killnet and Anonymous Sudan campaigns targeting Israeli financial infrastructure.

See Directive 361 mapping →

What DDactic Produces as Evidence

Every DDactic assessment generates a package of artifacts suited for compliance audit submissions.

📊
OPI Validated Score

0-100 score across 6 components using the open OPI methodology (Apache 2.0, independently verifiable)

📄
PDF Test Report

Documented methodology, test scope, attack vectors, results per component. Formatted for auditor review.

🔎
Attack Surface Inventory

Full enumeration of exposed domains, origin IPs, and CDN bypass paths. Maps to vulnerability assessment requirements.

⚙
Hardening Steps

Vendor-specific CLI commands for Cloudflare, Akamai, Imperva, AWS Shield, F5. Documents corrective action.

🕑
12-Month Retention

All artifacts retained for 12 months. Supports SOC 2 Type II audit periods and year-over-year comparison.

🔗
Open Methodology

OPI standard is public at github.com/DDactic/opi-standard. Auditors can verify scoring methodology independently.

Start with a free scan

The passive OPI scan runs in minutes and reveals your DDoS attack surface at no cost. Upgrade to OPI Validated for auditor-ready evidence.

Run Free Scan

Questions? See the FAQ or contact us