The EU Is Writing Security Rules for VPNs: What EN 304 620 Changes
For the first time, the European Union is writing a dedicated VPN security standard. It is called ETSI EN 304 620, and it sets baseline cybersecurity requirements that a VPN product must meet to be considered secure in the EU. The draft grew out of the Cyber Resilience Act (CRA), the bloc's new law for software and connected devices, and it targets a simple gap: until now anyone could ship a basic proxy app, print "military-grade encryption" on the store page, and never prove any of it. The standard is still a draft, with publication expected in the second half of 2026.
What EN 304 620 actually is
The standard is being written by ETSI, the European Telecommunications Standards Institute, under a formal standardisation request from the European Commission (C(2025) 618 final) that supports Regulation (EU) 2024/2847, the Cyber Resilience Act. Meeting it will be voluntary, but once the standard is cited in the EU Official Journal, compliance will give a VPN a "presumption of conformity" with the CRA. In plain terms: follow the standard and you are treated as legally compliant. Companies from across the industry have taken part in drafting it, including Cisco, Google and Palo Alto Networks, alongside consumer VPN providers such as NordVPN and Surfshark.
What it requires of a VPN
The draft covers VPN client apps on phones and computers, VPN software on home routers, and business VPN management tools. It turns familiar privacy promises into checkable requirements:
- Real encryption. Traffic must be protected against machine-in-the-middle attacks with sound cryptography, not just a label on the listing.
- Proper authentication. Endpoints must verify who they are talking to, with progressively stronger controls for higher-risk uses.
- Leak protection. The app must stop DNS and IPv6 leaks that would expose which sites you visit even while the tunnel is up.
- No traffic outside the tunnel. Routing and traffic-filtering defaults must keep data from escaping the encrypted connection.
- Data minimisation and protected logs. Collection is limited to what the service actually needs, and logs must be tamper-resistant.
- Secure updates and no known holes. Updates must be delivered securely, the product must ship with no known exploitable vulnerabilities, and flaws must be handled through a formal disclosure process.
- Safe key storage and deletion. Cryptographic keys and sensitive data must be stored securely and wiped when a device is retired.
Stricter profiles for high-risk users
One detail stands out for privacy. The standard does not treat every user the same: it defines security profiles, and the strictest ones are aimed at people like journalists and activists, where a DNS leak or a weak default is not an inconvenience but a real danger. For those profiles, leak protection, isolation and protected logging are tightened rather than optional. That is a rare case of a security standard naming at-risk users directly.
What changes for everyday users
The practical effect is a push from marketing slogans toward verifiable controls. A provider that wants the CRA safe harbour will have to back its "military-grade" claims with real cryptography, ship working leak protection, and run a proper vulnerability process instead of quietly patching problems. Apps that fail these baselines and are sold in the EU risk removal from major stores over time.
Why it matters
A security standard is only as good as its independent verification, and a voluntary route always leaves room for providers to skip it. But turning vague privacy marketing into a concrete, auditable checklist is a real gain for users, because it gives a shared yardstick to compare VPNs by instead of ad copy. The direction is clear: in the EU, calling an app a secure VPN is starting to mean something specific.