The EU just published the world's first official cybersecurity standard for VPNs, and we co-authored it
The European Telecommunications Standards Institute (ETSI) has just released EN 304 620, the world's first official cybersecurity standard for VPNs. It sits under the EU's Cyber Resilience Act, which will be enforced from December 11, 2027, and it defines the minimum security requirements every VPN sold in Europe will eventually have to meet.
"Until now, there were no official rules for how safe a VPN had to be. Any provider could call its app 'secure' without having to prove it. That is now changing. The shift is comparable to the arrival of safety rules for cars. Before crash tests and seatbelt laws, drivers simply had to hope their car was safe. Once official safety standards existed, every car had to meet them," says Miguel Fornés, Surfshark’s Information Security Manager.
Surfshark participated as an official ETSI Member Delegate alongside ZTE Corporation, BSI, Palo Alto Networks, Google, and Nord Security. Miguel authored and refined a lot of the rules that VPN products are now expected to follow.
A few examples of what we pushed into the standard:
- Strict no-logs deployments on RAM-only servers;
- Personal data stays on the device, telemetry is optional, and permanent storage of user data on servers is blocked;
- Passwords stripped from diagnostic logs, plus a warning before users export settings that contain credentials;
- Safe memory handling and strong encryption of stored data, protecting it even if a device is lost or stolen;
- Automated and manual testing for known exploits before updates reach users;
- Critical security patches installed the very first time the VPN is switched on;
- Clear labeling of the security and privacy level for different use cases (journalists vs. households, for example);
- Protection extended to modern, decentralized infrastructure like mesh networks.
TL;DR: for years, "secure VPN" was a marketing phrase anyone could use. Now it's a technical standard with defined requirements, and providers actually have to prove it. That's a much better world for users, whichever VPN they end up choosing.
Happy to answer questions in the comments.