For years, VPN providers could label their services as “secure” without proving it. There was no universal definition of what a safe VPN actually looked like. That’s about to change.
Surfshark, alongside other companies, such as ZTE Corporation, BSI, Palo Alto Networks, Google, and Nord Security, has helped develop the world’s first official VPN security standard. The standard supports the EU Cyber Resilience Act, a law setting mandatory security requirements for digital products sold across Europe.
What is the new VPN standard?
The standard is called EN 304 620 — Cybersecurity requirements for VPNs. Miguel Fornés, Surfshark’s Information Security Manager, led the development as an official delegate at ETSI (European Telecommunications Standards Institute). ETSI is the organization that creates technical standards for the EU.
“Until now, there were no official rules for how safe a VPN had to be. Any provider could call its app ‘secure’ without having to prove it. That is now changing,” says Fornés. “The shift is comparable to the arrival of safety rules for cars. Before crash tests and seatbelt laws, drivers simply had to hope their car was safe. Once official safety standards existed, every car had to meet them. Surfshark is helping do the same thing for VPNs.”
The EU took a different approach with the Cyber Resilience Act. Rather than drafting regulations in dense legal language, they partnered with leading industry experts to develop standards companies can actually implement. The standard was approved and goes public in August 2026, with the Cyber Resilience Act taking effect on December 11, 2027.
What the standard requires
The new rules make VPNs safer and more private by default. Among the requirements Surfshark contributed to, the standard now expects VPN providers to:
Run a strict no-logs policy on RAM-only servers
Personal data stays on the user’s device, usage tracking (telemetry) must be opt-in rather than automatic, and servers can’t permanently store user data.
Remove passwords from system logs
VPNs must warn users before someone exports settings that include login details or other sensitive information. This prevents the risk of accidental data leaks.
Enforce safe memory handling and secure encryption
VPN apps must be built to block common hacking techniques. They must also encrypt any settings or data stored on your device, so no one can access it without your permission.
Test updates for known vulnerabilities
VPN providers must complete both automated and manual security testing before updates reach users.
Automatically install security patches on first launch
Security fixes install automatically when you first open the VPN, closing any known gaps before you even connect.
Clearly label security and privacy levels
VPNs must indicate the level of protection they offer for different use cases, from journalists requiring anonymity to households seeking privacy.
Future-proof the security requirements
The standard works for both traditional VPN servers and newer infrastructure. This ensures you stay protected as VPN technology advances.
Why this matters
With the new standard, VPN providers can no longer rely on vague marketing claims. They must demonstrate compliance with measurable security and privacy requirements.
”The new standard recognizes that protecting your privacy online is a basic right,” says Surfshark’s Information Security Manager Miguel Fornés. “We’re making sure strong protection isn’t just a promise from one company. Every VPN sold in Europe will eventually have to meet it. That gives consumers across Europe grounds to trust that their VPN is genuinely built to protect them.”
What this means to you
For users, the new standard means greater transparency and accountability. The days of simply trusting a VPN provider’s assurances are over. The standard ensures that every VPN on the European market is held to the same baseline of protection — and Surfshark was at the table helping shape it.