Brussels has drawn a firm line under years of patchy oversight for virtual private networks. The European Telecommunications Standards Institute released a new framework that demands every VPN sold across the bloc meet auditable tests for encryption strength, key handling and vulnerability response. Published just yesterday, the draft arrives at a moment when consumers and businesses alike question the real protection these tools deliver.
The standard carries the identifier EN 304 620. It forms one piece of the much larger Cyber Resilience Act that takes full effect at the close of 2027. Until now VPN providers could tout military-grade encryption or no-logs promises without independent verification that regulators could easily check. That changes. Manufacturers must prove their products satisfy concrete criteria on data confidentiality, authentication mechanisms and secure updates.
TechRadar first reported the development on 14 August 2026. The article highlighted how NordVPN and Surfshark joined forces with Palo Alto Networks, Cisco, Airbus and Google to help shape the parameters. Their involvement matters. Industry input reduces the risk that rules become impractical or overly burdensome for legitimate operators.
Miguel Fornes, speaking on behalf of Surfshark, offered a clear analogy. “Before crash tests and seatbelt laws, drivers simply had to hope their car was safe. Once official safety standards existed, every car had to meet them. Surfshark is helping do the same thing for VPNs.” The comparison lands. Safety features in automobiles moved from optional marketing claims to mandatory, testable requirements. VPNs now follow suit.
And the timing feels deliberate. Reporting obligations under the Cyber Resilience Act begin on 11 September 2026, according to the European Commission’s own guidance published 27 July. Providers will soon face deadlines to disclose actively exploited vulnerabilities within tight windows. The pressure is real. A single serious breach that goes unreported could trigger fines or market bans.
The ETSI document targets VPN clients, servers and gateways alike. It spells out how traffic must be encapsulated and encrypted when crossing untrusted networks. AES-256 remains a baseline. WireGuard implementations receive scrutiny. Even RAM-only server architectures, long praised by privacy advocates, must demonstrate deterministic controls that auditors can verify. Nothing is taken on faith.
Free VPN services that have long operated in legal gray zones could find themselves squeezed hardest. Many rely on advertising or data practices that would fail the new tests. The standard effectively raises the floor. Shoddy operators must either invest in proper engineering or exit the European market. Users gain from that shift. They no longer wonder whether the tool protecting their traffic also sells their data on the side.
Yet the move is not without trade-offs. Some privacy campaigners worry that formalized standards could make it easier for governments to demand backdoors or logging in the name of compliance. Recent debates around age-verification systems and data retention have already sparked rumors of VPN restrictions. Euronews ran a fact check in May that pushed back against claims the EU planned an outright crackdown. No such proposal exists. Still, the tension lingers.
The Cyber Resilience Act itself entered into force in December 2024. Its scope reaches far beyond VPNs. On 13 August 2026 ETSI launched the public enquiry process for 17 related standards covering password managers, antivirus tools, smart-home devices and connected wearables. Sandra Feliciano, chair of the relevant technical committee, explained the division of labor. “The Cyber Resilience Act lays down what manufacturers, and the market need to achieve, but it does not tell you how. The role of the Standards Developing Organisations is to detail the technical aspects of how to achieve compliance with the legislation through standards.”
Her words underscore a basic truth. Legislation sets the goals. Engineers write the specifications. The collaboration between regulators and companies like NordVPN and Surfshark aims to produce rules that actually work in production environments rather than gathering dust on a shelf.
Implementation will not happen overnight. Full obligations kick in at the end of 2027. That gives providers time to adapt architectures, update documentation and prepare for third-party assessments. It also gives market-surveillance authorities time to build capacity. Early movers who already publish detailed transparency reports may hold an advantage. Laggards could face costly retrofits.
Security researchers have long pointed out gaps in the VPN sector. Many apps fail basic leak tests. Certificate handling can be sloppy. Update mechanisms sometimes rely on unsecured channels. The new standard confronts those weaknesses head-on by demanding measurable controls. Auditors will check source code practices, cryptographic implementations and incident-response plans. The bar sits higher than most voluntary audits currently require.
But does it solve every problem? Hardly. Sophisticated adversaries can still target endpoint devices before traffic ever reaches the VPN tunnel. Nation-state actors may compromise certificate authorities or pressure providers directly. Standards address engineering quality. They do not eliminate every threat vector. Users must still choose reputable services and maintain good device hygiene.
The European approach contrasts with other regions. The United States continues to rely more heavily on voluntary certifications and sector-specific rules. Some countries in Asia impose outright restrictions on VPN usage. Brussels has chosen standardization and mandatory compliance. The bet is that clear, enforceable baselines will build consumer trust and reduce fragmentation across the single market.
Industry giants did not participate merely out of civic duty. They stand to benefit from rules that legitimize their products while raising costs for smaller or less scrupulous competitors. NordVPN topped TechRadar’s independent tests earlier this year for speed, streaming performance and overall security. Surfshark earned praise for aggressive pricing and feature set. Both now gain regulatory cover that smaller outfits may struggle to match.
Public comment on the draft runs for a set period. ETSI invites feedback using a specific template available in its documentation portal. Changes remain possible before the final version receives formal adoption. Observers expect the core requirements around encryption and vulnerability handling to survive largely intact.
So what should businesses and individual users do in the meantime? Review current providers against the emerging criteria. Ask for evidence of preparation for the new standard. Prioritize services that already publish independent audit reports and maintain transparent infrastructure. The transition period offers a window to switch before compliance becomes mandatory.
The arrival of EN 304 620 marks a quiet but significant milestone. VPNs move from marketing slogans to regulated products with defined safety specifications. Consumers gain reassurance that the tool they trust with their data meets a government-backed baseline. Providers face new accountability. And the broader digital-product market receives notice that the era of self-certification is drawing to a close.
Additional reporting from the European Commission on 27 July clarified several implementation questions for manufacturers of all sizes. The guidance document stresses that presumption of conformity flows from harmonized standards once they are cited in the Official Journal. Until then companies must perform their own risk assessments against the essential requirements listed in the Act itself.
That creates a two-track process for the next year. Forward-looking VPN companies are already mapping their systems to the draft standard while simultaneously preparing vulnerability-reporting procedures that activate next month. The dual pressure tests operational maturity.
Critics of heavy regulation argue that innovation could suffer. Yet the involvement of established players suggests the standard incorporates lessons from years of real-world deployment. The result may prove more practical than rules written in isolation. Time and audit results will tell.