EU sets new standard for VPN security, shifting industry from claims to compliance

The European Union has introduced formalised security requirements for VPN products, requiring manufacturers to demonstrate compliance through rigorous standards, marking a significant shift towards regulated cybersecurity in the digital market.

The European Union has begun formalising security requirements for virtual private networks, with the European Telecommunications Standards Institute publishing EN 304 620 under the Cyber Resilience Act. The standard sets an auditable baseline for VPN products sold in Europe, covering encryption, authentication, vulnerability handling and related controls. According to ETSI, it applies to VPN servers, gateways, clients and management tools used for secure remote access and for linking networks across untrusted domains.

The move is significant because it shifts VPN security from marketing claims and voluntary audits towards a common regulatory yardstick. Under the new framework, manufacturers will need to show that their products meet defined cybersecurity requirements rather than simply asserting that they are safe. The European Commission has said the CRA introduces conformity assessment procedures for digital products, including VPNs, with compliance expected either through harmonised standards or, in some cases, assessment by a notified body.

Industry participation has been central to the drafting process. TechRadar reported that companies including NordVPN and Surfshark worked alongside technology groups such as Palo Alto Networks, Cisco, Airbus and Google to shape the requirements. Miguel Fornes of Surfshark compared the change to the introduction of crash testing and seat belt rules in the car industry, arguing that formal standards force products to prove they are safe rather than merely claim it.

For users, the practical effect is a higher security floor across the European VPN market. Providers will have to demonstrate deterministic and testable controls, including how traffic is encapsulated and encrypted, and how keys are managed. The standard also reinforces accountability around vulnerability disclosure, with rapid reporting required for actively exploited flaws. ETSI has separately begun approval work on a wider set of CRA-related standards, covering categories such as password managers, antivirus software, smart home assistants, connected toys and wearables, suggesting the regulation will extend well beyond VPNs.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.