AWS Starts a Five-Phase Shift in L7 DDoS Protection
AWS began rolling out the AWS WAF Anti-DDoS managed rule group to eligible Shield Advanced web access control lists on July 27, 2026. The deployment runs in Count mode. It is expected to finish by August 7, 2026. It does not touch live traffic yet. Your existing automatic mitigation keeps running alongside it.
This is not an optional upgrade. As of January 1, 2027, Shield Advanced application-layer automatic mitigation will no longer be available. Resources that have not moved to the new rule group will lose automatic L7 DDoS protection on that date.
Cloud platform owners, security leaders, and application teams need to understand the timeline and act before October 1.
Why AWS Is Making the Change
HTTP request floods are now among the most common vectors targeting web applications, using valid-looking requests that blend with normal traffic. AWS launched the Anti-DDoS managed rule group in June 2025 to address that gap at the application layer.
The new rule group profiles traffic and establishes a baseline in minutes rather than hours. When an attack starts, it reacts within seconds with no health checks to configure. It also adds a Challenge action alongside Block and Count. The Challenge option includes a silent browser verification that runs in the background with no interstitial page. Real users see nothing while automated traffic is filtered.
Capacity consumption drops as well. The rule group requires 50 web ACL capacity units, down from the 150 the previous protection needed, freeing room for your other WAF rules. During active mitigation, blocked DDoS requests are excluded from your monthly request count, covering WAF fees, rule group fees, and Shield Advanced request charges.
The rule group also labels every inspected request with event-detected flags and graduated suspicion levels. You can match on those labels in your own WAF rules when you need logic the rule group does not cover.
The Five-Phase Timeline
Phase 1 (July 27 – August 7, 2026): AWS adds the rule group in Count mode to every Shield Advanced web ACL with at least one resource using automatic mitigation that is not already running it.
Phase 2 (July 27 – September 30, 2026): All Anti-DDoS managed rule group charges are waived during this evaluation period, including subscription, per-request, and WCU costs for eligible web ACLs. Use the DDoSAttackRequests metric, WAF labels, and the Anti-DDoS dashboard in the AWS Management Console to compare detection results against your existing mitigation.
Phase 3 (October 1, 2026): The auto-upgrade mirrors your existing automatic mitigation configuration. A Block setup comes up in Block mode; Count comes up in Count mode. The handoff is a single atomic operation with no protection gap. You can opt out by contacting AWS Support before October 1.
Phase 4 (July 27 – December 31, 2026): Guided migration is available for web ACLs not eligible for the auto-upgrade, including mixed-mode ACLs and those with resources that do not have automatic mitigation enabled. Work with your AWS account team or AWS Support to complete these.
Phase 5 (January 1, 2027): Automatic mitigation is retired. Any resource still relying on it loses application-layer DDoS protection.
What to Do Before October
The evaluation window through September 30 is your clearest signal. Pull the DDoSAttackRequests metric and review the Anti-DDoS dashboard. If the new rule group is catching what your current mitigation catches, let the October auto-upgrade proceed.
If you have mixed-mode web ACLs or resources without automatic mitigation enabled, those are not eligible for the auto-upgrade. Guided migration is the path for those ACLs, and the window closes December 31.
As a practical check: audit every Shield Advanced web ACL now. Identify which ones qualify for the October auto-upgrade and which need guided migration. Flag any application paths that cannot support the Challenge action, since those paths fall back to Block mitigations and you will want to configure that exclusion deliberately.
Sensitivity settings for Block and Challenge are configurable independently at Low, Medium, or High. Set them before October 1 rather than inheriting defaults under pressure during an active event.

