**Title:** “AWS Retiring Shield Advanced L7 on January 1, 2027: Key Dates and Implications
AWS Shield Advanced, a service designed to safeguard applications against external threats, is integrating an Anti-DDoS managed rule group into eligible web access control lists (ACLs) operating in Count mode.
AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027
AWS Shield Advanced, a service designed to safeguard applications against external threats, is integrating an Anti-DDoS managed rule group into eligible web access control lists (ACLs) operating in Count mode. This addition aims to provide application-layer (L7) DDoS protection while maintaining uninterrupted traffic flow alongside existing L7 automatic mitigation and AWS WAF rules. The rule group is accessible to all AWS WAF customers and is included in AWS Shield Advanced subscriptions.
Migration timeline
From July 27 to August 7, 2026
AWS will deploy the Anti-DDoS managed rule group in Count mode to qualifying Shield Advanced web ACLs. Customers are encouraged to assess the rule group and initiate migration before the automated upgrade in October. AWS advises reviewing the new Anti-DDoS dashboard within the AWS WAF console, comparing DDoSDetected and DDoSAttackRequests metrics to verify detection accuracy, and utilizing AWS WAF labels to analyze suspicious traffic.
During the evaluation phase
Customers should begin with the Low sensitivity setting for Block actions, adjust configurations based on dashboard data and labels, review rule priorities, configure URI exemptions for unsupported paths, and update infrastructure-as-code (IaC) templates following automatic integration. The Shield Advanced L7 protection upgrade follows a phased rollout. Existing automatic mitigation remains active until the rule group assumes responsibility. As of January 1, 2027, AWS will discontinue Shield Advanced application-layer automatic mitigation. Resources that have not transitioned to the rule group will lose automatic L7 DDoS protection.
Anti-DDoS rule group capabilities
The managed rule group enhances Shield Advanced automatic mitigation by analyzing normal traffic patterns, responding to attacks, and functioning independently of health checks. It introduces a Challenge action alongside Block and Count. Challenge decisions rely on AMR labels and support silent browser verification. Block and Challenge sensitivity settings can be configured separately, with unsupported paths defaulting to Block. The update reduces web ACL capacity requirements from 150 to 50 WCUs, introduces a dashboard tracking DDoS Blocked requests, and excludes active mitigation traffic from AWS WAF and Shield Advanced request charges. AWS Shield Advanced is not required to utilize these features.
Shield Advanced Monitoring and visibility
The rule group adds new Amazon CloudWatch metrics and labels for attack monitoring. Existing DDoSDetected metrics continue to report Layer 3 and Layer 4 activity. During the transition, customers can use both metrics to validate detection before migrating alerts. Each inspected request receives labels indicating detected threats. Additional metrics track request handling, including Challenge, Block, or Count actions, aiding teams in evaluating mitigation effectiveness and adjusting rule sensitivity as needed.
Infrastructure updates
Organizations using AWS CloudFormation, AWS CDK, Terraform, or other IaC tools must update templates. AWS configures the rule group via AWS WAF, requiring replacement of existing Shield automatic mitigation settings with an AWS WAF managed rule group. Post-upgrade, teams should import the revised web ACL into IaC tooling. AWS Firewall Manager users must add the AWSManagedRulesAntiDDoSRuleSet to an AWS WAF Firewall Manager policy, as application-layer protection shifts from Shield Advanced policies to AWS WAF. Firewall Manager-managed web ACLs require updates through the policy, either via the console or infrastructure-as-code methods. Policies should be scoped to cover the same accounts and resources as existing Shield Advanced policies to prevent loss of application-layer protection during migration.
Pricing
AWS Shield Advanced includes the rule group for up to 50 billion monthly requests across an organization. During active mitigation in Block or Challenge mode, blocked DDoS traffic is excluded from AWS WAF, rule group, and Shield Advanced request charges. Eligible web ACLs updated through the automatic rollout between July 27 and September 30, 2026, incur no per-request fees or WCU consumption during evaluation, including Count mode operation. Manual rule group additions are billed under standard AWS WAF pricing.
