← Back to Blog

WAF and DDoS SLAs: What AWS, Azure and Google Pay When the Shield Fails

September 24, 2026

Security services feel like insurance, and their SLAs are priced like uptime. Both intuitions are wrong in useful ways. The security edge is where the definitions of downtime get most inventive: AWS WAF counts requests it failed to inspect, Google Cloud Armor counts an error rate above a hundredth of a percent, and Azure DDoS Protection counts only the attacks it failed to mitigate that then broke something else. Read the definitions before the ladders, because here the definition decides whether the outage was yours or the provider's.

A cracked glass shield hovering in front of glowing servers, a thin amber streak leaking through the crack while the rest of the shield holds

The promises, side by side

ServiceCommitmentDowntime is defined as
AWS WAF99.95% per regionrequests that fail to be inspected, averaged over 5-minute intervals
AWS Shield Advancedno fixed uptime; it removes DDoS from the exclusion lists of the services it protectsavailability interruptions of designated resources caused by covered attacks
Azure DDoS Protection99.99%minutes where an attack was not mitigated and protected resources then failed their own SLA
Azure Application Gateway (where WAF runs)99.95%minutes where every connection attempt to the gateway fails
Google Cloud Armor99.99% for globally-scoped policies; 99.9% for regional (99.5% in Mexico and Stockholm)more than a 0.01% error rate on request or packet evaluation

The same zone-aware logic shows up next door in Azure Firewall: 99.95% when deployed inside a single availability zone and 99.99% across two or more, both on 10 and 25% ladders.

Where the definitions do the work

Each of these services measures failure differently, and the differences are not cosmetic.

AWS WAF scores availability per 5-minute interval as the share of inspected requests that do not fail, and an interval with no requests counts as 100% available. Quiet windows cannot hurt you, busy ones are averaged, and the SLA carries an unusual discretion clause: if availability is impacted by factors outside the metric, AWS may issue a credit considering those factors at its discretion.

Google Cloud Armor starts the clock at a 0.01% error rate, not at full unavailability. Intermittent failures lasting under 60 seconds do not count towards a downtime period, but a sustained failure to evaluate even a fraction of requests does. It is the most sensitive trigger on the edge, which is presumably why the payout is capped at 50%.

Azure DDoS Protection has the most conditional definition of all: a minute is unavailable "when DDoS Protection did not mitigate an attack which directly resulted in underlying Azure resources not meeting respective SLA". You are not paid because you were attacked. You are paid when the shield failed and the resource behind it failed as well, a two-condition test that most incident timelines will not satisfy.

AWS Shield Advanced is the structural odd one out. DDoS attacks are normally force majeure, excluded from the underlying service's SLA. Shield Advanced's commitment is that a covered attack "will not constitute an SLA exclusion with respect to a failure to meet any service commitments specified in the relevant SLA" for protected resources. It is the one clause in this set that converts an attack from an excuse into a payable event.

The credit shapes

ServiceLadder
AWS WAF10% / 25% / 100% (below 99.95%, 99.0% and 95.0%)
Azure DDoS Protection10% / 25% (below 99.99% and 99.95%); no 100% tier
Azure Application Gateway10% / 25% (below 99.95% and 99%); no 100% tier
Google Cloud Armor10% / 25% / 50% cap (below 99.99%, 99.0% and 95.0%)
AWS Shield Advancedno ladder: a day's average charge per affected 24-hour interval; 100% of the month at five or more

Two shapes deserve a second look. Shield Advanced is the only interval-based credit in this set: every 24-hour interval that sees an availability interruption pays the average daily subscription charge, and five separate bad intervals inside one month return the entire monthly fee. Meanwhile the Azure security services carry no full-refund rung at all; the highest any of them pays is 25%, while AWS WAF is the rare security service with a 100% tier.

The money, briefly

On $1,500 a month of security service, a month at 98.5% pays $375 on the WAF ladder, $375 on Cloud Armor's, and the same on Azure DDoS Protection. Push the month below 95% and AWS WAF pays the full $1,500, Cloud Armor stops at $750 because of its cap, and Azure DDoS still stops at $375. Shield Advanced behaves differently again: on a $3,000 a month subscription it pays roughly $100 for each affected day, and the full $3,000 once five separate days see interruptions.

The definitions decide everything on the security edge: WAF credits count uninspected requests, Armor counts error rates above a hundredth of a percent, Azure counts unmitigated attacks that broke the resource behind them, and Shield Advanced counts days on which a covered attack slipped through. The finer the definition, the harder the claim to prove, and the log files are always yours to produce.

Filing the security-edge claim

AWS wants the case by the end of the second billing cycle after the incident, with "SLA Credit Request" in the subject line, the dates, times and per-interval availabilities, and request logs; Shield Advanced claims follow the same flow with logs corroborating each interruption. Google asks for notification within 30 days with log files showing the downtime and when it occurred. Azure takes a portal request within two months. The evidence bar is the highest in the portfolio because these metrics are request-level, and a WAF claim is fundamentally a data exercise.

Three practical readings close the loop. If your architecture depends on surviving a DDoS attack, Shield Advanced is the one clause here that stops the attack from voiding your other SLAs; elsewhere on the edge, an attack is treated as your problem unless the provider's own mitigation broke. The Azure security stack tops out at 25%, so treat those credits as weak claims and the controls themselves as the value. And export the interval data when an incident happens, not when you file, because the windows are short and the evidence is granular. UptimeAudit tracks the big four's health feeds and drafts the credits these documents actually pay.