The European Telecommunications Standards Institute has introduced the EN 304 620 standard, establishing mandatory cybersecurity requirements for VPN providers operating within the European Union under the Cyber Resilience Act.
Key Points
- The new EN 304 620 standard mandates auditable security controls for VPN clients, servers, and gateways regarding encryption, authentication, and vulnerability management.
- Major industry participants, including NordVPN, Surfshark, Cisco, Google, and Palo Alto Networks, collaborated to help shape these technical security baselines.
- Providers must implement deterministic security measures and adhere to strict incident reporting protocols for any actively exploited vulnerabilities.
- The regulation is a core component of the broader Cyber Resilience Act, which requires digital product manufacturers to meet essential security standards by late 2027.
- These guidelines extend to other digital products, including password managers, antivirus software, and smart home devices, to improve overall European digital safety.