Auditor-ready DDoS
resilience evidence
DORA, NIS2, PCI DSS, ISO 27001, SOC 2, and Bank of Israel Directive 361 all require testing that your DDoS protection actually works. DDactic generates OPI scores and hardening reports that satisfy each framework's specific evidence requirements.
The Compliance Gap
Your DDoS protection budget is approved. Has it ever been tested?
Most security audits accept the existence of a CDN or WAF contract as evidence of DDoS protection. They do not check whether that protection actually holds under real attack conditions. Origin IPs exposed behind Cloudflare, WAF rate limits set too high to matter, scrubbing services that fail under L7 load - none of these gaps appear in a vendor invoice review. They appear when an attacker finds them first.
Every major compliance framework now includes language requiring organizations to test their controls, not just document that controls exist. DDactic closes the gap between "we have a CDN" and "we know our CDN holds under attack."
Supported Compliance Frameworks
DORA
Requires financial entities to conduct penetration testing, scenario-based tests, and threat-led penetration testing. DDoS simulation is an explicit TLPT scenario.
See DORA mapping → EU Critical InfrastructureNIS2
Requires essential and important entities to test business continuity and availability under adversarial conditions. Applies to energy, banking, health, transport, and digital infrastructure sectors.
See NIS2 mapping → Payment Card IndustryPCI DSS 4.0
Mandates annual external penetration testing of the cardholder data environment perimeter and requires a documented penetration testing methodology covering network-layer tests.
See PCI DSS mapping → ISMS StandardISO 27001:2022
Requires ICT readiness testing based on business continuity objectives (Control 5.30) and technical vulnerability management (Control 8.8). DDoS attack surface exposure is a documented vulnerability class.
See ISO 27001 mapping → Availability Trust CriteriaSOC 2 Type II
Requires testing of recovery procedures supporting system availability (A1.3). Auditors expect evidence that availability controls were tested against realistic threat scenarios, not just documented.
See SOC 2 mapping → Israeli Financial SectorBank of Israel Directive 361
Requires periodic penetration testing by qualified external parties covering DDoS threat scenarios. Updated after 2022-2023 Killnet and Anonymous Sudan campaigns targeting Israeli financial infrastructure.
See Directive 361 mapping →What DDactic Produces as Evidence
Every DDactic assessment generates a package of artifacts suited for compliance audit submissions.
0-100 score across 6 components using the open OPI methodology (Apache 2.0, independently verifiable)
Documented methodology, test scope, attack vectors, results per component. Formatted for auditor review.
Full enumeration of exposed domains, origin IPs, and CDN bypass paths. Maps to vulnerability assessment requirements.
Vendor-specific CLI commands for Cloudflare, Akamai, Imperva, AWS Shield, F5. Documents corrective action.
All artifacts retained for 12 months. Supports SOC 2 Type II audit periods and year-over-year comparison.
OPI standard is public at github.com/DDactic/opi-standard. Auditors can verify scoring methodology independently.
Questions? See the FAQ or contact us