Cybersecurity Requirements for VPN Services!

The purpose of ETSI EN 304 620 is to establish essential cybersecurity requirements for VPN services, in line with the EU’s upcoming Cyber Resilience Act (CRA).

The standard aims to improve the level of security for both consumers and businesses through clear requirements for, among other things, encryption, authentication, and vulnerability management by VPN providers. This work marks an important step towards a more secure digital infrastructure within the EU.

This is a new work item pending approval by WGSA via voting.

You are welcome to comment by the 23rd of July!

Published: 2025-07-08

Newsfeed from ETSI

Membership

Be part of shaping the communication of the future

Become a member of our network that brings together Swedish industry experts in IT and telecommunications to influence the development of standards.

Become a member