
European standards body ETSI has begun the approval process for a new cybersecurity standard for VPN products, part of a wider package of 17 standards designed to support the EU Cyber Resilience Act (CRA).
The VPN standard, EN 304 620, introduces defined technical and privacy requirements that could eventually give VPN vendors a recognized way to demonstrate compliance with EU cybersecurity rules.
ETSI announced that the 17 final draft standards in its EN 304 xxx series had entered Public Inquiry, the first phase of the formal approval process. The drafts have been submitted to 41 member organizations across Europe, including national standardization bodies, which can provide comments before the standards progress further.
The VPN-specific standard was developed with input from multiple industry participants, including Surfshark, ZTE Corporation, BSI, Palo Alto Networks, Google, and Nord Security. The new VPN standard is intended to provide a technical baseline for what a secure VPN product should look like, replacing the largely self-defined security claims that providers have traditionally used.
According to details published by Surfshark, the draft includes requirements around data logging, telemetry, server architecture, credential handling, encryption, software updates, and vulnerability testing.
Among the proposed measures are strict no-logs practices, RAM-only server infrastructure, and requirements for telemetry to be opt-in rather than enabled by default. VPN applications should also avoid storing passwords in system logs and warn users before exporting configurations that contain credentials or other sensitive information.
The standard additionally addresses secure memory handling and encryption of data stored locally on users' devices. VPN providers are expected to perform automated and manual security testing before releasing updates and to install available security patches automatically when applications are launched.
Another requirement focuses on clearer communication of privacy and security capabilities, allowing users to better understand whether a VPN is appropriate for different threat models, ranging from everyday privacy needs to higher-risk use cases where anonymity is particularly important.
EN 304 620 forms part of ETSI's wider effort to translate the Cyber Resilience Act into practical technical requirements. The CRA applies broadly to commercial products with digital elements, including software, connected hardware, password managers, antivirus tools, smart home systems, wearables, and connected toys.
The 17 drafts are intended to become Harmonized Standards. If formally adopted and referenced for the CRA, manufacturers that comply with the relevant standards could receive a “presumption of conformity,” giving them an established path for demonstrating that their products meet the legislation's requirements.
ETSI says the approval procedures will run from mid-September through mid-November 2026, depending on the individual standard. Companies covered by the Cyber Resilience Act will be required to comply with its applicable cybersecurity obligations by the end of 2027.
For VPN users, EN 304 620 could make security claims easier to evaluate by establishing a common technical baseline across products sold in Europe. The draft remains under review, however, and its requirements may still change during the consultation and approval process.







Leave a Reply