AUTO-UPDATED

EU introduces strict new security rules for VPNs with the help of industry giants

The European Telecommunications Standards Institute has introduced the EN 304 620 standard, establishing mandatory cybersecurity requirements for VPN providers operating within the European Union under the Cyber Resilience Act.

Key Points

  • The new EN 304 620 standard mandates auditable security controls for VPN clients, servers, and gateways regarding encryption, authentication, and vulnerability management.
  • Major industry participants, including NordVPN, Surfshark, Cisco, Google, and Palo Alto Networks, collaborated to help shape these technical security baselines.
  • Providers must implement deterministic security measures and adhere to strict incident reporting protocols for any actively exploited vulnerabilities.
  • The regulation is a core component of the broader Cyber Resilience Act, which requires digital product manufacturers to meet essential security standards by late 2027.
  • These guidelines extend to other digital products, including password managers, antivirus software, and smart home devices, to improve overall European digital safety.

Why it Matters

This legislation shifts the burden of proof from consumer trust to mandatory regulatory compliance, effectively eliminating the market for insecure or opaque VPN services. By standardizing security benchmarks, the European Union is creating a more resilient digital ecosystem that protects user data through enforced, testable engineering requirements.
TechRadar Published by Rene Millman
Read original