The EU Is Writing Security Rules for VPNs: What EN 304 620 Changes

24.08.2026 5 min 4

For the first time, the European Union is writing a dedicated VPN security standard. It is called ETSI EN 304 620, and it sets baseline cybersecurity requirements that a VPN product must meet to be considered secure in the EU. The draft grew out of the Cyber Resilience Act (CRA), the bloc's new law for software and connected devices, and it targets a simple gap: until now anyone could ship a basic proxy app, print "military-grade encryption" on the store page, and never prove any of it. The standard is still a draft, with publication expected in the second half of 2026.

What EN 304 620 actually is

The standard is being written by ETSI, the European Telecommunications Standards Institute, under a formal standardisation request from the European Commission (C(2025) 618 final) that supports Regulation (EU) 2024/2847, the Cyber Resilience Act. Meeting it will be voluntary, but once the standard is cited in the EU Official Journal, compliance will give a VPN a "presumption of conformity" with the CRA. In plain terms: follow the standard and you are treated as legally compliant. Companies from across the industry have taken part in drafting it, including Cisco, Google and Palo Alto Networks, alongside consumer VPN providers such as NordVPN and Surfshark.

What it requires of a VPN

The draft covers VPN client apps on phones and computers, VPN software on home routers, and business VPN management tools. It turns familiar privacy promises into checkable requirements:

  • Real encryption. Traffic must be protected against machine-in-the-middle attacks with sound cryptography, not just a label on the listing.
  • Proper authentication. Endpoints must verify who they are talking to, with progressively stronger controls for higher-risk uses.
  • Leak protection. The app must stop DNS and IPv6 leaks that would expose which sites you visit even while the tunnel is up.
  • No traffic outside the tunnel. Routing and traffic-filtering defaults must keep data from escaping the encrypted connection.
  • Data minimisation and protected logs. Collection is limited to what the service actually needs, and logs must be tamper-resistant.
  • Secure updates and no known holes. Updates must be delivered securely, the product must ship with no known exploitable vulnerabilities, and flaws must be handled through a formal disclosure process.
  • Safe key storage and deletion. Cryptographic keys and sensitive data must be stored securely and wiped when a device is retired.

Stricter profiles for high-risk users

One detail stands out for privacy. The standard does not treat every user the same: it defines security profiles, and the strictest ones are aimed at people like journalists and activists, where a DNS leak or a weak default is not an inconvenience but a real danger. For those profiles, leak protection, isolation and protected logging are tightened rather than optional. That is a rare case of a security standard naming at-risk users directly.

What changes for everyday users

The practical effect is a push from marketing slogans toward verifiable controls. A provider that wants the CRA safe harbour will have to back its "military-grade" claims with real cryptography, ship working leak protection, and run a proper vulnerability process instead of quietly patching problems. Apps that fail these baselines and are sold in the EU risk removal from major stores over time.

Important: this is still a draft. It becomes a real shortcut to CRA compliance only after it is published and cited in the EU Official Journal, and the CRA's main obligations apply from December 2027. It also does not cover everything: routers where the VPN is a minor feature, and free non-commercial open-source software, fall outside the presumption of conformity.

Why it matters

A security standard is only as good as its independent verification, and a voluntary route always leaves room for providers to skip it. But turning vague privacy marketing into a concrete, auditable checklist is a real gain for users, because it gives a shared yardstick to compare VPNs by instead of ad copy. The direction is clear: in the EU, calling an app a secure VPN is starting to mean something specific.

Does this ban free VPNs?
No. It does not ban anything by itself. Free non-commercial open-source apps are even excluded from the presumption of conformity. But commercial VPN software sold in the EU that ignores basic security can face pressure and store removal under the wider Cyber Resilience Act.
Is EN 304 620 law yet?
Not yet. It is a draft standard expected to be published in the second half of 2026. The law behind it, the Cyber Resilience Act, is already in force, with its main obligations applying from December 2027.
Does it mean my VPN is now independently audited?
Not automatically. The standard sets requirements and a conformity route, but following it is voluntary and a provider still has to demonstrate compliance. It is a baseline to check a VPN against, not a guarantee that every app has been audited.
Does it apply outside the EU?
It targets products sold in the EU market. In practice, providers often apply one security baseline everywhere, so users elsewhere may benefit indirectly, but the legal requirement is tied to the EU.

VPNCyber Resilience ActCRAEN 304 620ETSINordVPNSurfsharkprivacyEU

Read also